Deep learning-based automatic modulation recognition (AMR) relies on training data collected under heterogeneous channel and link conditions. This creates a training-time vulnerability: condition-dependent label corruption can cause an AMR model to treat ordinary channel-quality regimes as hidden backdoor triggers. We propose ChannelBD, a data poisoning backdoor attack in which the attacker selectively relabels sourceclass samples inside a channel/link-condition trigger region, without explicitly perturbing the waveform. In synthetic data, the trigger region is instantiated as a high-SNR subset. In real over-the-air data, received-quality variation is jointly shaped by transmission power, propagation distance, and environmental noise, and the trigger is instantiated through transmission-power partitions. On RML2016.10a, ChannelBD achieves 97.66% attack success rate with a 2.41 percentage-point clean-accuracy drop under the default synthetic setting. These results expose a wirelessspecific data poisoning vulnerability in physical-layer AMR and show that defending wireless machine learning systems requires backdoor analysis beyond signal-space trigger detection.
Anonymous (Tue,) studied this question.