Adversarial Example Detection and Restoration Defensive Framework for Signal Intelligent Recognition Networks
作者:Chao Han, Ruoxi Qin, Linyuan Wang, Weijia Cui, Dongyang Li, Bin Yan · 发表于:Applied Sciences · 年份:2023 · DOI:10.3390/app132111880 · 被引用次数:3 · 研究领域:Adversarial Robustness in Machine Learning、Integrated Circuits and Semiconductor Failure Analysis、Wireless Signal Modulation Classification
Deep learning-based automatic modulation recognition networks are susceptible to adversarial attacks, posing significant performance vulnerabilities. In response, we introduce a defense framework enriched by tailored autoencoder (AE) techniques. Our design features a detection AE that harnesses reconstruction errors and convolutional neural networks to discern deep features, employing thresholds from reconstruction error and Kullback–Leibler divergence to identify adversarial samples and their origin mechanisms. Additionally, a restoration AE with a multi-layered structure effectively restores adversarial samples generated via optimization methods, ensuring accurate classification. Tested rigorously on the RML2016.10a dataset, our framework proves robust against adversarial threats, presenting a versatile defense solution compatible with various deep learning models.