Unmasking Vulnerabilities: Adversarial Attacks against DRL-based Resource Allocation in O-RAN
Yared Abera Ergu, Van-Linh Nguyen, Ren‐Hung Hwang, Ying–Dar Lin, Chuan-Yu Cho, Hui-Kuo Yang · 2024
The rapid advancement of wireless networks towards Artificial Intelligence (AI)-driven solutions attracts many vendors to build resilient and intelligent capabilities for Open Radio Access Networks (O-RAN). However, besides the benefits of achieving flexibility and intelligence, openness in native AI-driven O-RAN functions is also the target of severe AI-related security threats, e.g., adversarial attacks. This work addresses the security matter for the AI-powered solutions in the physical layer of O-RAN, specifically within the context of deep reinforcement learning (DRL)-based resource allocation. We introduce a new adversarial attack variant that manipulates the environment parameters and misleads the agent's observation during the inference phase. The attack can cause incorrect allocation decisions and significant degradation in the transmission data rate. Our evaluation results show that the attack degrades user data and packet delivery rates by up to 40% and 77.74%, respectively, particularly in ultra-low-latency services. We also found that the major weakness of DRL-driven radio resource allocation is the environment observation stage, where a group of compromised users or jammers can spoof noises and signal power to mislead environment interaction. In our context, the proposed policy infiltration attack is the most efficient approach to cause sustained network inefficiencies or reduced throughput for benign users.