Optimization of Communication Signal Adversarial Examples by Selectively Preserving Low-Frequency Components of Perturbations

通过选择性地保留扰动的低频分量来优化通信信号对抗样本

阅读:1

Abstract

Achieving high attack success rate (ASR) with minimal perturbed distortion has consistently been a prominent and challenging research topic in the field of adversarial examples. In this paper, a novel method to optimize communication signal adversarial examples is proposed by focusing on low-frequency components of perturbations (LFCP). Observations on model attention towards DCT coefficients reveal the crucial role of LFCP within adversarial examples in altering the model's predictions. As a result, selectively preserving LFCP is established as the fundamental concept of the optimization strategy. By utilizing the binary search algorithm, which considers the inconsistency in the model's predictions as a constraint, LFCP can be effectively identified, and the aim of minimizing perturbed distortion while maintaining ASR can be achieved. Experimental results conducted on a publicly available dataset, six adversarial attacks and two DNN models, indicate that the proposed method not only significantly minimizes perturbed distortion for FGSM, BIM, PGD, and MI-FGSM but also achieves a modest improvement in ASR. Notably, even for DeepFool and BS-FGM, which introduce small perturbations and exhibit high ASRs, the proposed method can still deliver feasible performance.

特别声明

1、本页面内容包含部分的内容是基于公开信息的合理引用;引用内容仅为补充信息,不代表本站立场。

2、若认为本页面引用内容涉及侵权,请及时与本站联系,我们将第一时间处理。

3、其他媒体/个人如需使用本页面原创内容,需注明“来源:[生知库]”并获得授权;使用引用内容的,需自行联系原作者获得许可。

4、投稿及合作请联系:info@biocloudy.com。