Adversarial Attacks Against Deep Learning-Based Radio Frequency Fingerprint Identification

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Ma, Jie, Zhang, Junqing, Shen, Guanxiong, Marshall, Alan, Chang, Chip-Hong
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915672829722624
author Ma, Jie
Zhang, Junqing
Shen, Guanxiong
Marshall, Alan
Chang, Chip-Hong
author_facet Ma, Jie
Zhang, Junqing
Shen, Guanxiong
Marshall, Alan
Chang, Chip-Hong
contents Radio frequency fingerprint identification (RFFI) is an emerging technique for the lightweight authentication of wireless Internet of things (IoT) devices. RFFI exploits deep learning models to extract hardware impairments to uniquely identify wireless devices. Recent studies show deep learning-based RFFI is vulnerable to adversarial attacks. However, effective adversarial attacks against different types of RFFI classifiers have not yet been explored. In this paper, we carried out a comprehensive investigations into different adversarial attack methods on RFFI systems using various deep learning models. Three specific algorithms, fast gradient sign method (FGSM), projected gradient descent (PGD), and universal adversarial perturbation (UAP), were analyzed. The attacks were launched to LoRa-RFFI and the experimental results showed the generated perturbations were effective against convolutional neural networks (CNNs), long short-term memory (LSTM) networks, and gated recurrent units (GRU). We further used UAP to launch practical attacks. Special factors were considered for the wireless context, including implementing real-time attacks, the effectiveness of the attacks over a period of time, etc. Our experimental evaluation demonstrated that UAP can successfully launch adversarial attacks against the RFFI, achieving a success rate of 81.7% when the adversary almost has no prior knowledge of the victim RFFI systems.
format Preprint
id arxiv_https___arxiv_org_abs_2512_12002
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Adversarial Attacks Against Deep Learning-Based Radio Frequency Fingerprint Identification
Ma, Jie
Zhang, Junqing
Shen, Guanxiong
Marshall, Alan
Chang, Chip-Hong
Cryptography and Security
Machine Learning
Radio frequency fingerprint identification (RFFI) is an emerging technique for the lightweight authentication of wireless Internet of things (IoT) devices. RFFI exploits deep learning models to extract hardware impairments to uniquely identify wireless devices. Recent studies show deep learning-based RFFI is vulnerable to adversarial attacks. However, effective adversarial attacks against different types of RFFI classifiers have not yet been explored. In this paper, we carried out a comprehensive investigations into different adversarial attack methods on RFFI systems using various deep learning models. Three specific algorithms, fast gradient sign method (FGSM), projected gradient descent (PGD), and universal adversarial perturbation (UAP), were analyzed. The attacks were launched to LoRa-RFFI and the experimental results showed the generated perturbations were effective against convolutional neural networks (CNNs), long short-term memory (LSTM) networks, and gated recurrent units (GRU). We further used UAP to launch practical attacks. Special factors were considered for the wireless context, including implementing real-time attacks, the effectiveness of the attacks over a period of time, etc. Our experimental evaluation demonstrated that UAP can successfully launch adversarial attacks against the RFFI, achieving a success rate of 81.7% when the adversary almost has no prior knowledge of the victim RFFI systems.
title Adversarial Attacks Against Deep Learning-Based Radio Frequency Fingerprint Identification
topic Cryptography and Security
Machine Learning
url https://arxiv.org/abs/2512.12002