inklap

A spatial-frequency domain joint detection method of adversarial examples for signal modulation recognition network

Wenlin Liu, Linyuan Wang, Nuolin Sun, Dongyang Li, Bin Yan, Houqiang Li · Cybersecurity · 2026

Abstract With the rapid advancement of deep neural networks in wireless communications, applications such as signal modulation recognition and target detection face threats from adversarial example attacks. To enhance system robustness against adversarial attacks, adversarial example detection holds a unique position and role as a complementary approach to conventional adversarial defense methods. This paper investigates the spatial and frequency domain attribute differences between clean and adversarial signal examples, proposing a joint spatial-frequency domain adversarial example detection method for signal modulation recognition networks. In the frequency domain, we extract time-shifted autocorrelation features that capture the peak width differences between clean and adversarial examples, where adversarial perturbations exhibit wider autocorrelation peaks due to their signal-like energy distribution. In the spatial domain, we characterize the inter-layer feature propagation patterns through DNN layers by computing cosine similarities between layer-wise activations and class centers, revealing that adversarial examples exhibit progressive deviation from their

📖 افتح في inklap 🔗 DOI 📮 اطلب بحثاً