Watermarking and Anomaly Detection in Machine Learning Models for LORA RF Fingerprinting

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Mahajan, Aarushi, Burleson, Wayne
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866908546374828032
author Mahajan, Aarushi
Burleson, Wayne
author_facet Mahajan, Aarushi
Burleson, Wayne
contents Radio frequency fingerprint identification (RFFI) distinguishes wireless devices by the small variations in their analog circuits, avoiding heavy cryptographic authentication. While deep learning on spectrograms improves accuracy, models remain vulnerable to copying, tampering, and evasion. We present a stronger RFFI system combining watermarking for ownership proof and anomaly detection for spotting suspicious inputs. Using a ResNet-34 on log-Mel spectrograms, we embed three watermarks: a simple trigger, an adversarially trained trigger robust to noise and filtering, and a hidden gradient/weight signature. A convolutional Variational Autoencoders (VAE) with Kullback-Leibler (KL) warm-up and free-bits flags off-distribution queries. On the LoRa dataset, our system achieves 94.6% accuracy, 98% watermark success, and 0.94 AUROC, offering verifiable, tamper-resistant authentication.
format Preprint
id arxiv_https___arxiv_org_abs_2509_15170
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Watermarking and Anomaly Detection in Machine Learning Models for LORA RF Fingerprinting
Mahajan, Aarushi
Burleson, Wayne
Cryptography and Security
Artificial Intelligence
Signal Processing
Radio frequency fingerprint identification (RFFI) distinguishes wireless devices by the small variations in their analog circuits, avoiding heavy cryptographic authentication. While deep learning on spectrograms improves accuracy, models remain vulnerable to copying, tampering, and evasion. We present a stronger RFFI system combining watermarking for ownership proof and anomaly detection for spotting suspicious inputs. Using a ResNet-34 on log-Mel spectrograms, we embed three watermarks: a simple trigger, an adversarially trained trigger robust to noise and filtering, and a hidden gradient/weight signature. A convolutional Variational Autoencoders (VAE) with Kullback-Leibler (KL) warm-up and free-bits flags off-distribution queries. On the LoRa dataset, our system achieves 94.6% accuracy, 98% watermark success, and 0.94 AUROC, offering verifiable, tamper-resistant authentication.
title Watermarking and Anomaly Detection in Machine Learning Models for LORA RF Fingerprinting
topic Cryptography and Security
Artificial Intelligence
Signal Processing
url https://arxiv.org/abs/2509.15170