Filtered Randomized Smoothing: A New Defense for Robust Modulation Classification

Wenhan Zhang, Meiyu Zhong, Ravi Tandon, Marwan Krunz

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

Deep Neural Network (DNN) based classifiers have recently been used for the modulation classification of RF signals. These classifiers have shown impressive performance gains relative to conventional methods, however, they are vulnerable to imperceptible (low-power) adversarial attacks. Some of the prominent defense approaches include adversarial training (AT) and randomized smoothing (RS). While AT increases robustness in general, it fails to provide resilience against previously unseen adaptive attacks. Other approaches, such as Randomized Smoothing (RS), which injects noise into the input, address this shortcoming by providing provable certified guarantees against arbitrary attacks, however, they tend to sacrifice accuracy.In this paper, we study the problem of designing robust DNN-based modulation classifiers that can provide provable defense against arbitrary attacks without significantly sacrificing accuracy. To this end, we first analyze the spectral content of commonly studied attacks on modulation classifiers for the benchmark RadioML dataset. We observe that spectral signatures of un-perturbed RF signals are highly localized, whereas attack signals tend to be spread out in frequency. To exploit this spectral heterogeneity, we propose Filtered Randomized Smoothing (FRS), a novel defense which combines spectral filtering together with randomized smoothing. FRS can be viewed as a strengthening of RS by leveraging the specificity (spectral Heterogeneity) inherent to the modulation classification problem. In addition to providing an approach to compute the certified accuracy of FRS, we also provide a comprehensive set of simulations on the RadioML dataset to show the effectiveness of FRS and show that it significantly outperforms existing defenses including AT and RS in terms of accuracy on both attacked and benign signals.

Original languageEnglish (US)
Title of host publication2024 IEEE Military Communications Conference, MILCOM 2024
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages789-794
Number of pages6
ISBN (Electronic)9798350374230
DOIs
StatePublished - 2024
Externally publishedYes
Event2024 IEEE Military Communications Conference, MILCOM 2024 - Washington, United States
Duration: Oct 28 2024Nov 1 2024

Publication series

NameProceedings - IEEE Military Communications Conference MILCOM
ISSN (Print)2155-7578
ISSN (Electronic)2155-7586

Conference

Conference2024 IEEE Military Communications Conference, MILCOM 2024
Country/TerritoryUnited States
CityWashington
Period10/28/2411/1/24

Keywords

  • Certified Defense
  • Filtering
  • Randomized Smoothing
  • Signal Classification

ASJC Scopus subject areas

  • Electrical and Electronic Engineering

Fingerprint

Dive into the research topics of 'Filtered Randomized Smoothing: A New Defense for Robust Modulation Classification'. Together they form a unique fingerprint.

Cite this