WaveNet Adversarial Neural Network for Wireless Signal Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing wireless communication systems face challenges in robustness against adversarial machine learning (AML) attacks, particularly in the wireless domain, where the time-varying nature of the channel complicates the effectiveness of such attacks, and the need to maintain decodability of waveforms limits extensive modification.

Innovation Solution

A comprehensive approach is introduced to address the Generalized Wireless Adversarial Machine Learning Problem (GWAP) through algorithms for both whitebox and blackbox settings, including AML Waveform Jamming (AWJ) and AML Waveform Synthesis (AWS) attacks, utilizing a neural network architecture called WaveNet that combines deep learning and signal processing to confuse classifiers while minimizing waveform distortion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If adversarial inputs are carefully tailored to decrease classifier accuracy, then security robustness is improved, but classification accuracy deteriorates

Engineering Contradiction:
Improvesecurity robustnessVSAvoidclassification accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent applies partial action by introducing minimal adversarial perturbations to waveforms that are just sufficient to confuse the classifier while maintaining decodability. The attack adds only the necessary distortion to achieve security evaluation without completely destroying the signal, thus partially affecting the signal to achieve the security testing goal.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent converts the harmful effect of adversarial attacks (which normally degrade classifier performance) into a beneficial security evaluation mechanism. By systematically applying these attacks, the system identifies vulnerabilities and improves overall security robustness, turning a negative phenomenon into a positive security enhancement tool.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Reliability

If waveform distortion is extensively modified to perform adversarial attacks, then attack effectiveness is improved, but signal decodability deteriorates

Engineering Contradiction:
Improveattack effectivenessVSAvoidsignal decodability
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent changes the parameters of adversarial attacks by optimizing the perturbation magnitude epsilon and the number of attacked samples. By carefully selecting these parameters, the attack maintains effectiveness while ensuring the waveform remains decodable, thus resolving the contradiction between attack strength and signal integrity.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent applies partial action by modifying only a portion of the waveform with controlled distortion levels. The attack does not extensively modify the entire waveform but applies targeted perturbations to specific segments, maintaining enough signal integrity for decodability while achieving sufficient attack effectiveness.

Inventive Principle:
Principle #16Partial or excessive action

3Productivity

If deep learning models are used to solve complex classification problems, then problem-solving capability is improved, but vulnerability to adversarial attacks worsens

Engineering Contradiction:
Improveproblem-solving capabilityVSAvoidvulnerability to adversarial attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent converts the vulnerability of deep learning models to adversarial attacks into a benefit by using these attacks as a systematic security evaluation mechanism. The harmful vulnerability is transformed into a useful tool for identifying and addressing security weaknesses, thereby improving the overall robustness of the system.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The patent applies preliminary anti-action by proactively evaluating security vulnerabilities through adversarial attacks before actual threats occur. The system preemptively identifies weak points in the deep learning model and can take corrective measures, preventing future security breaches rather than reacting to them after they happen.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11832103B2Neural network for adversarial deep learning in wireless systems
Publication Date: 2023.11.28 NORTHEASTERN UNIV (US)
  • US11832103B2 patent drawing
  • US11832103B2 patent drawing
  • US11832103B2 patent drawing

AI summary

A method of determining a response of a radio frequency wireless communication system to an adversarial attack is provided. Adversarial signals from an adversarial node are transmitted to confuse a target neural network of the communication system. An accuracy of classification of the incoming signals by the target neural network is determined.