Poisoning Attacks on Deep Learning Based Spectrum Prediction
摘要
Cognitive radio networks can effectively improve spectrum utilization through dynamic spectrum access. The key challenge lies in detecting spectrum holes. Existing research has employed deep learning (DL) methods for spectrum prediction, but the lack of interpretability in deep neural networks (DNNs) raises security concerns. This paper investigates poisoning attacks on DL-based spectrum prediction by analyzing the mitigating gradient vanishing mechanism in time-series prediction DNNs. The proposed initial impression poisoning attack manifests in two forms: traditional and trigger-based attacks. Simulation results demonstrate that the traditional form severely hampers the training of the prediction model by introducing a \(5\%\) poisoned data. The trigger-based form allows the model to operate normally but exhibits a significant performance degradation when triggered, demonstrating better stealthiness with a over \(90\%\) attack success rate.