Over-the-Air Membership Inference Attacks as Privacy Threats for Deep Learning-based Wireless Signal Classifiers
June 25, 2020 Β· Declared Dead Β· π WiseML@WiSec
"No code URL or promise found in abstract"
Evidence collected by the PWNC Scanner
Authors
Yi Shi, Kemal Davaslioglu, Yalin E. Sagduyu
arXiv ID
2006.14576
Category
eess.SP: Signal Processing
Cross-listed
cs.NI
Citations
35
Venue
WiseML@WiSec
Last Checked
6 months ago
Abstract
This paper presents how to leak private information from a wireless signal classifier by launching an over-the-air membership inference attack (MIA). As machine learning (ML) algorithms are used to process wireless signals to make decisions such as PHY-layer authentication, the training data characteristics (e.g., device-level information) and the environment conditions (e.g., channel information) under which the data is collected may leak to the ML model. As a privacy threat, the adversary can use this leaked information to exploit vulnerabilities of the ML model following an adversarial ML approach. In this paper, the MIA is launched against a deep learning-based classifier that uses waveform, device, and channel characteristics (power and phase shifts) in the received signals for RF fingerprinting. By observing the spectrum, the adversary builds first a surrogate classifier and then an inference model to determine whether a signal of interest has been used in the training data of the receiver (e.g., a service provider). The signal of interest can then be associated with particular device and channel characteristics to launch subsequent attacks. The probability of attack success is high (more than 88% depending on waveform and channel conditions) in identifying signals of interest (and potentially the device and channel information) used to build a target classifier. These results show that wireless signal classifiers are vulnerable to privacy threats due to the over-the-air information leakage of their ML models
Community Contributions
Found the code? Know the venue? Think something is wrong? Let us know!
π Similar Papers
In the same crypt β Signal Processing
R.I.P.
π»
Ghosted
π
π
The Cartographer
1D Convolutional Neural Networks and Applications: A Survey
R.I.P.
π»
Ghosted
Wireless Communications with Reconfigurable Intelligent Surface: Path Loss Modeling and Experimental Measurement
π
π
The Cartographer
Accessing From The Sky: A Tutorial on UAV Communications for 5G and Beyond
R.I.P.
π»
Ghosted
6G Wireless Systems: Vision, Requirements, Challenges, Insights, and Opportunities
R.I.P.
π»
Ghosted
A New Wireless Communication Paradigm through Software-controlled Metasurfaces
Died the same way β π» Ghosted
R.I.P.
π»
Ghosted
Federated Learning: Strategies for Improving Communication Efficiency
R.I.P.
π»
Ghosted
In-Datacenter Performance Analysis of a Tensor Processing Unit
R.I.P.
π»
Ghosted
Deep Convolutional Neural Networks for Computer-Aided Detection: CNN Architectures, Dataset Characteristics and Transfer Learning
R.I.P.
π»
Ghosted