Having designed a VQVAE that maps digital radio waveforms into discrete latent space, yielding perfectly classifiable reconstructions of the original data, we here analyze the attack suppressing properties of VQVAE when high-SNR waveforms are subjected to an adversarial attack. We also introduce a phase-preserving FGSM attack (FGSM1), a novel adversarial perturbation designed to target amplitude modulations, in contrast to standard FGSM (2) /PGD attacks that do not preserve I/Q phase relationships. We measure classification accuracy of such adversarial examples on a classifier trained to deliver 100% accuracy on the original data from a set of common, digitally modulated waveform classes. To assess the attack suppression by VQVAE, we then evaluate the classifier accuracy on VQVAE reconstructions of the adversarial data-points. Apart from demonstrating substantial attack mitigation, VQVAE recovers structural properties of the signals, as seen in the I/Q plane diagrams of the attacked data, compared with their reconstructions and the original data. Finally, using multiple metrics, we compare the probability distribution of VQVAE’s discrete latent space with and without attack. By varying the strength of the attack, we uncover interesting properties of the discrete space that could aid in detecting attacks in spectrum-sensing AIoT devices.
Paper
References (22)
Scroll for more · 10 remaining