这篇论文讲了一种能悄悄操控无线语义通信中特定用户数据的后门攻击,还给出了防御方案。做无线安全或语义通信的可以看看。
语义通信(SemCom)在共享接入无线网络中引入了新漏洞。本文针对两个发射机与一个公共接收机构成的多址信道SemCom系统,提出一种选择性空中后门(Trojan)攻击:攻击者在训练期间发射低功率触发波形并注入共享接收信号,测试时再次触发以操控特定发射机的语义推理,而对另一发射机影响极小。同时开发了触发感知防御机制,通过鲁棒训练保持正确的语义标签。实验结果表明共享接入SemCom系统对这种选择性攻击的脆弱性,以及防御机制的有效性。
Wireless Backdoor Attack and Defense for Semantic Communications over Multiple Access Channel
Semantic communication (SemCom) aims to preserve semantic meaning and task-oriented information beyond conventional message recovery over wireless channels. The adoption of SemCom in shared-access wireless networks introduces new vulnerabilities for multi-user semantic inference. This paper considers a SemCom system for two transmitters communicating with a common receiver over a multiple access channel. Each transmitter maps source information into latent semantic representations, while the receiver jointly reconstructs and classifies the semantic information for both transmitters. A selective over-the-air backdoor (Trojan) attack is presented in which an adversary transmits a low-power trigger waveform over the air and injects it into the shared received signal during training. By transmitting the trigger again during testing, this stealthy, low-power attack selectively manipulates the semantic inference for one transmitter while minimally affecting the inference of the other transmitter. To mitigate this vulnerability, a trigger-aware defense mechanism is developed to preserve correct semantic labels under trigger-contaminated wireless observations. The results demonstrate both the vulnerability of shared-access SemCom systems to selective over-the-air backdoor attacks and the effectiveness of trigger-aware robust training for semantic protection.