Exploring Universal Adversarial Attacks on DNN-Based Automatic Modulation Recognition Using Joint Metrics
Xingyu Zhou, Xiaohan Yu, Yuming Zhang, Weijun Zeng · IEEE Transactions on Wireless Communications · 2025
With its remarkable capability for automated feature extraction, deep neural networks (DNNs) have achieved significant breakthroughs in numerous fields. However, recent studies indicate that deep models are vulnerable to adversarial attacks. In the automatic modulation recognition (AMR) task, the attacker injects imperceptible adversarial perturbations into the radio signals, causing the receiver to misidentify the adversarial examples as incorrect modulation patterns. In this article, we propose an input-independent universal adversarial perturbation (UAP) generation method to attack DNN-based AMR. The proposed method, termed Joint Metric-based Universal Adversarial Perturbation (JM-UAP), strives to enhance the aggressiveness of UAPs by minimizing the similarity metric between feature vectors extracted from benign examples and adversarial examples. To achieve this, feature vectors derived from the penultimate layer of the DNN are chosen as the optimization objects. The dissimilarity between these feature vectors is assessed by combining two metrics, the Adjusted cosine similarity and the Pearson correlation. Extensive experiments demonstrate that our approach significantly reduces the accuracy of AMR models, exhibits robust transferability across various deep models and multiple signal-to-noise ratios (SNRs) datasets, and performs well even in asynchronous scenarios.