DIBAD: A Disentangled Information Bottleneck Adversarial Defense Method Using Hilbert-Schmidt Independence Criterion for Spectrum Security
Sicheng Zhang, Yandie Yang, Ziyao Zhou, Zhi Yuan Sun, Yun Lin · IEEE Transactions on Information Forensics and Security · 2024
Automatic Modulation Classification (AMC) is crucial for monitoring the legitimacy of user frequency behavior and identifying potential sources of interference in spectrum monitoring. Deep learning-based AMC models have shown excellent performance, however, it has been proven susceptible to adversarial attacks. To address the problem, we propose a Disentangled Hilbert-Schmidt Information Bottleneck Adversarial Defense (DIBAD) method to enhance the adversarial robustness of AMC models. Specifically, we firstly analyze the task-relevant and task-irrelevant features in the intermediate representations of modulation signals from the perspective of mutual information theory. Secondly, a training framework consisting of a classification feature extractor, a supplementary feature extractor, and a classifier is designed. Under the information bottleneck constraint, the classification feature extractor and supplementary feature extractor are used to extract task-relevant and task-irrelevant features, respectively. The information bottleneck constraint is employed to reduce task-irrelevant features, thus improving the model’s adversarial robustness. Experiments on the RML2016.10a and DMRadio09.real datasets, along with comprehensive analysis, demonstrate the superiority of the DIBAD method terms of adversarial robustness.