Adversarial Domain Generalization Defense via Task-Relevant Feature Alignment in Cyber-Physical Systems
Sicheng Zhang, Jie Liu, Zhida Bao, Yandie Yang, Meiyu Wang, Yun Lin · IEEE Transactions on Reliability · 2024
Automatic modulation classification (AMC) is a key technology in cyber-physical systems (CPSs), which enables the monitoring and identification of communication signals exchanged between devices. One of the most recognized solutions for the AMC is deep learning (DL), which can automatically learn and extract feature representations in signals. However, data-driven DL models are susceptible to adversarial examples, which can cause significant instability in the CPS. To tackle this issue, in this article, we examine the distribution shift between original signals and adversarial examples from a domain distribution perspective and present a system model for addressing the defense problem. We propose the adversarial domain generalization defense (ADGD) framework. The ADGD framework adopts a dual-stream architecture with the AMC as its central task, and extracts and constrains the maximum mean discrepancy distance between the task-relevant features of original signals and adversarial examples to reduce the distribution shift and improve the adversarial robustness. Comprehensive experiments and ablations were conducted to demonstrate the superiority of the proposed ADGD framework on the RML2016.10a and miniRML2018.01a datasets. The results indicate that the ADGD framework shows promising results in improving the adversarial robustness of AMC systems, which is crucial for the stability of the CPS.