Black-Box Attack on Data-Driven Intelligent Modulation Recognition
摘要
Modulation classifier based on deep learning can quickly learn the features of signals and perform well in modulation recognition tasks. However, the model is still vulnerable to adversarial black-box attacks even if it protects private information such as network structure and training data. Substitute training is a common black-box attack used by attackers, but it requires a large number of queries on the output of the target model, which will reduce the concealment of the attack. In this paper, we propose a magnetic substitute training attack method, which imitates the decision-making of the target model by guiding the substitute boundary towards the target boundary through synthetic targeted examples and covertly attacks the target model. Simulation results show that the proposed method can effectively reduce the modulation recognition accuracy of the target model while ensuring concealment.