PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
May 7, 20260 citationsOpen Access

ChannelBD: Data Poisoning Backdoor Attacks with Channel-Condition Triggers Against Automatic Modulation Recognition

View Full Paper
AAnonymousChongqing University of Posts and Telecommunications

Key Points

  • To expose vulnerabilities in automatic modulation recognition models caused by data poisoning backdoor attacks.
  • Proposed ChannelBD, a method for relabeling training data based on channel conditions.
  • Implemented synthetic data experiments to identify trigger regions defined by high-SNR subsets.
  • Analyzed real over-the-air data under varying transmission power and propagation distance.
  • Achieved a 97.66% attack success rate in synthetic settings.
  • Observed a 2.41 percentage-point drop in clean accuracy under default conditions.
  • Demonstrated that wireless-specific vulnerabilities exist in physical-layer automatic modulation recognition.

Abstract

Deep learning-based automatic modulation recognition (AMR) relies on training data collected under heterogeneous channel and link conditions. This creates a training-time vulnerability: condition-dependent label corruption can cause an AMR model to treat ordinary channel-quality regimes as hidden backdoor triggers. We propose ChannelBD, a data poisoning backdoor attack in which the attacker selectively relabels sourceclass samples inside a channel/link-condition trigger region, without explicitly perturbing the waveform. In synthetic data, the trigger region is instantiated as a high-SNR subset. In real over-the-air data, received-quality variation is jointly shaped by transmission power, propagation distance, and environmental noise, and the trigger is instantiated through transmission-power partitions. On RML2016.10a, ChannelBD achieves 97.66% attack success rate with a 2.41 percentage-point clean-accuracy drop under the default synthetic setting. These results expose a wirelessspecific data poisoning vulnerability in physical-layer AMR and show that defending wireless machine learning systems requires backdoor analysis beyond signal-space trigger detection.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Anonymous (2026) studied this question.

synapsesocial.com/papers/69fbef86164b5133a91a37dahttps://doi.org/10.5281/zenodo.20031584
Ask AI
Helpful
Bookmark
Share
View Full Paper