Vulnerabilities of Deep Learning-Driven Semantic Communications to Backdoor (Trojan) Attacks

12/21/2022
by   Yalin E. Sagduyu, et al.
0

This paper highlights vulnerabilities of deep learning-driven semantic communications to backdoor (Trojan) attacks. Semantic communications aims to convey a desired meaning while transferring information from a transmitter to its receiver. An encoder-decoder pair that is represented by two deep neural networks (DNNs) as part of an autoencoder is trained to reconstruct signals such as images at the receiver by transmitting latent features of small size over a limited number of channel uses. In the meantime, another DNN of a semantic task classifier at the receiver is jointly trained with the autoencoder to check the meaning conveyed to the receiver. The complex decision space of the DNNs makes semantic communications susceptible to adversarial manipulations. In a backdoor (Trojan) attack, the adversary adds triggers to a small portion of training samples and changes the label to a target label. When the transfer of images is considered, the triggers can be added to the images or equivalently to the corresponding transmitted or received signals. In test time, the adversary activates these triggers by providing poisoned samples as input to the encoder (or decoder) of semantic communications. The backdoor attack can effectively change the semantic information transferred for the poisoned input samples to a target meaning. As the performance of semantic communications improves with the signal-to-noise ratio and the number of channel uses, the success of the backdoor attack increases as well. Also, increasing the Trojan ratio in training data makes the attack more successful. In the meantime, the effect of this attack on the unpoisoned input samples remains limited. Overall, this paper shows that the backdoor attack poses a serious threat to semantic communications and presents novel design guidelines to preserve the meaning of transferred information in the presence of backdoor attacks.

READ FULL TEXT

page 1

page 4

page 6

research
12/20/2022

Is Semantic Communications Secure? A Tale of Multi-Domain Adversarial Attacks

Semantic communications seeks to transfer information from a source whil...
research
01/11/2023

Age of Information in Deep Learning-Driven Task-Oriented Communications

This paper studies the notion of age in task-oriented communications tha...
research
10/23/2019

Trojan Attacks on Wireless Signal Classification with Adversarial Machine Learning

We present a Trojan (backdoor or trapdoor) attack that targets deep lear...
research
12/08/2021

Autoencoder-based Communications with Reconfigurable Intelligent Surfaces

This paper presents a novel approach for the joint design of a reconfigu...
research
12/29/2021

End-to-End Autoencoder Communications with Optimized Interference Suppression

An end-to-end communications system based on Orthogonal Frequency Divisi...
research
12/19/2022

Task-Oriented Communications for NextG: End-to-End Deep Learning and AI Security Aspects

Communications systems to date are primarily designed with the goal of r...
research
08/02/2019

Demon in the Variant: Statistical Analysis of DNNs for Robust Backdoor Contamination Detection

A security threat to deep neural networks (DNN) is backdoor contaminatio...

Please sign up or login with your details

Forgot password? Click here to reset