arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

可行但不安全:基于学习的无小区集成感知与通信(ISAC)关联中的约束违反与报告通道攻击

Feasible but Not Safe: Constraint Violations and Report-Channel Attacks in Learned Cell-Free ISAC Association

Mehdi Zafari, Iman Mohammadi, A. Lee Swindlehurst

arXiv 2609.03147首次发表:更新:

发表机构

University of California Irvine(加州大学欧文分校)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究针对无小区ISAC系统,发现基于GNN的调度器虽精度高但常违反硬约束,恶意AP攻击会提升不可行解比例,可通过可行性投影与跨AP一致性检查缓解,需采用约束感知指标评估。

AI 中文摘要

针对分布式无小区集成感知与通信(ISAC)系统,已有基于学习的调度器被提出用于提供实时用户、目标及接入点(AP)关联服务。典型方法中,在混合整数线性规划标签上训练的图神经网络(GNN),可通过一次前向传播将轻量级的各AP统计信息映射至AP聚类、用户与目标调度及模式选择的决策。此类方案假设仅作为软训练惩罚施加的硬约束在推理时成立,且自报告的统计信息为真实。以ASSENT算法为例,研究发现尽管F1分数较高,但许多解至少违反一项硬约束,表明高预测精度无法确保联合可行性。将GNN输出投影至可行解可在效用损失较低的情况下恢复约束满足,即便采用简单的贪心修复流程也可实现。进一步研究显示,仅可行性无法保证对虚假数据注入攻击的鲁棒性:单个恶意AP即便报告虚假信息,也无法大幅增加其用户关联数量,但可显著提升不可行解的比例,此类攻击的影响取决于被伪造信息的类型。误报影响目标函数的信息可通过可行性投影大幅缓解,而伪造影响约束的信息则无法缓解,但后者可通过低复杂度的跨AP一致性检查检测。上述结果表明,评估基于学习的ISAC调度器除传统精度指标外,还应采用感知约束的可行性指标。

英文摘要

Learning-based schedulers have been proposed to provide real-time user, target, and access point (AP) association in distributed cell-free integrated sensing and communication systems. In a typical approach, a graph neural network (GNN), trained on labels from a mixed-integer linear program, maps lightweight per-AP statistics to decisions on AP clustering, user and target scheduling, and mode selection in one forward pass. Such solutions assume that hard constraints, enforced only as soft training penalties, hold at inference, and that the self-reported statistics are truthful. Using our ASSENT algorithm as an example, we find that despite high $F_1$ scores, many solutions violate at least one hard constraint, demonstrating that high prediction accuracy does not ensure joint feasibility. Projecting the GNN output onto a feasible solution restores constraint satisfaction with low utility loss, even with a simple greedy repair procedure. We further show that feasibility alone does not guarantee robustness to false data injection attacks. A single malicious AP that reports false information cannot substantially increase its user associations, but can greatly increase the rate of infeasible solutions. The effect of such attacks depends on the type of information being falsified. Misreporting information that affects the objective can largely be mitigated through feasibility projection, whereas falsifying information that affects the constraints cannot. The latter can, however, be detected using a low-complexity cross-AP consistency check. These results show that learned ISAC schedulers should be evaluated using constraint-aware feasibility metrics in addition to conventional accuracy measures.

CommentsAccepted to the 17th ACM Workshop on Wireless of the Students, by the Students, for the Students (S3 '26) at MobiCom 2026. 4 pages, 3 figures

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑