在哪里防御?面向鲁棒Transformer语义通信的逐层对抗训练
Where to Defend? Layer-Wise Adversarial Training for Robust Transformer-Based Semantic Communications
浏览论文内容
中文总结 AI 辅助
针对Transformer语义通信的多阶段对抗攻击,提出逐层防御框架,发现编码器防御匹配时显著恢复BLEU,联合训练缓解不匹配失效,信道编码器瓶颈对分类有保护作用。
中文摘要 AI 辅助
基于深度学习的语义通信(DeepSC)是一种基于Transformer的编码器-解码器架构,能在噪声信道上实现语义保真,但在流水线的多个阶段容易受到对抗性扰动的攻击。我们提出了一种逐层鲁棒性框架,在嵌入输出处比较快速梯度符号法(FGSM)、投影梯度下降(PGD)和l2归一化快速梯度法(FGM)防御,然后使用PGD分析三个攻击和防御点:嵌入输出、编码器输出和信道编码器瓶颈。我们在Europarl和UK Hansard上评估重建性能,在SST2和YELP上评估情感分类,均在加性高斯白噪声(AWGN)和瑞利衰落条件下进行。一阶损伤预算({epsilon}乘以每个注入点干净输入损失梯度的l1范数)预测攻击严重性排序,转移矩阵揭示不对称防御转移:嵌入防御对编码器攻击有强转移性,而编码器防御会降低对上游攻击的鲁棒性。对于重建,编码器点训练产生最大的匹配增益,但在嵌入攻击下严重失效;联合嵌入加编码器训练在编码器攻击下保持相当增益,同时缓解这种不匹配失效,而瑞利衰落会减弱鲁棒性增益和退化。对于分类,四种防御中有三种崩溃为常数预测器;只有信道编码器防御保持非退化,表明128D到16D瓶颈具有保护作用。在信噪比(SNR)为9 dB且扰动预算{epsilon}=0.3时,匹配的编码器防御在Europarl/AWGN上将双语评估替补(BLEU)从约0.10恢复到约0.64,而不匹配的编码器防御在嵌入攻击下相对于无防御基线产生-0.444的BLEU变化。
英文摘要
Deep learning-based semantic communication (DeepSC), a Transformer-based encoder-decoder, achieves semantic fidelity over noisy channels but remains vulnerable to adversarial perturbations injected at multiple stages of the pipeline. We present a layer-wise robustness framework that compares fast gradient sign method (FGSM), projected gradient descent (PGD), and l2-normalized fast gradient method (FGM) defenses at the embedding output, and then uses PGD to analyze three attack and defense points: the embedding output, encoder output, and channel-encoder bottleneck. We evaluate reconstruction on Europarl and UK Hansard and sentiment classification on SST2 and YELP under additive white Gaussian noise (AWGN) and Rayleigh fading. A first-order damage budget, {epsilon} times the l1 norm of the clean-input loss gradient at each injection point, predicts the attack-severity ordering, and the transfer matrix reveals asymmetric defense transfer: the embedding defense transfers strongly to encoder attacks, whereas encoder defenses degrade robustness against upstream attacks. For reconstruction, encoder-point training yields the largest matched gain but fails severely under embedding attacks; joint embedding-plus-encoder training retains comparable gains under encoder attacks while mitigating this mismatch failure, and Rayleigh fading attenuates robustness gains and degradation. For classification, three of four defenses collapse to constant predictors; only the channel-encoder defense remains non-degenerate, suggesting a protective role for the 128D-to-16D bottleneck. At a signal-to-noise ratio (SNR) of 9 dB and perturbation budget {epsilon} = 0.3, the matched encoder defense recovers bilingual evaluation understudy (BLEU) from ~ 0.10 to ~ 0.64 on Europarl/AWGN, whereas the mismatched encoder defense yields a -0.444 BLEU change relative to the undefended baseline under an embedding attack.
发表机构
- American University of Beirut(贝鲁特美国大学)
机构由 AI 辅助整理,请以论文原文为准。