On the Vulnerability of Deep Automatic Modulation Classifiers to Explainable Backdoor Threats

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Salmi, Younes, Bogucka, Hanna
Format: Preprint
Veröffentlicht: 2026
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866918410912268288
author Salmi, Younes
Bogucka, Hanna
author_facet Salmi, Younes
Bogucka, Hanna
contents Deep learning (DL) has been widely studied for assisting applications of modern wireless communications. One of the applications is automatic modulation classification (AMC). However, DL models are found to be vulnerable to adversarial machine learning (AML) threats. One of the most persistent and stealthy threats is the backdoor (Trojan) attack. Nevertheless, most studied threats originate from other AI domains, such as computer vision (CV). Therefore, in this paper, a physical backdoor attack targeting the wireless signal before transmission is studied. The adversary is considered to be using explainable AI (XAI) to guide the placement of the trigger in the most vulnerable parts of the signal. Then, a class prototype combined with principal components is used to generate the trigger. The studied threat was found to be efficient in breaching multiple DL-based AMC models. The attack achieves high success rates for a wide range of SNR values and a small poisoning ratio.
format Preprint
id arxiv_https___arxiv_org_abs_2603_25310
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle On the Vulnerability of Deep Automatic Modulation Classifiers to Explainable Backdoor Threats
Salmi, Younes
Bogucka, Hanna
Cryptography and Security
Deep learning (DL) has been widely studied for assisting applications of modern wireless communications. One of the applications is automatic modulation classification (AMC). However, DL models are found to be vulnerable to adversarial machine learning (AML) threats. One of the most persistent and stealthy threats is the backdoor (Trojan) attack. Nevertheless, most studied threats originate from other AI domains, such as computer vision (CV). Therefore, in this paper, a physical backdoor attack targeting the wireless signal before transmission is studied. The adversary is considered to be using explainable AI (XAI) to guide the placement of the trigger in the most vulnerable parts of the signal. Then, a class prototype combined with principal components is used to generate the trigger. The studied threat was found to be efficient in breaching multiple DL-based AMC models. The attack achieves high success rates for a wide range of SNR values and a small poisoning ratio.
title On the Vulnerability of Deep Automatic Modulation Classifiers to Explainable Backdoor Threats
topic Cryptography and Security
url https://arxiv.org/abs/2603.25310