{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T00:41:57Z","timestamp":1776732117727,"version":"3.51.2"},"reference-count":61,"publisher":"MDPI AG","issue":"19","license":[{"start":{"date-parts":[[2022,10,7]],"date-time":"2022-10-07T00:00:00Z","timestamp":1665100800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"Youth Science and Technology Innovation Award of National University of Defense Technology","award":["18\/19-QNCXJ"],"award-info":[{"award-number":["18\/19-QNCXJ"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Remote Sensing"],"abstract":"<jats:p>Deep learning (DL)-based specific emitter identification (SEI) technique can automatically extract radio frequency (RF) fingerprint features in RF signals to distinguish between legal and illegal devices and enhance the security of wireless network. However, deep neural network (DNN) can easily be fooled by adversarial examples or perturbations of the input data. If a malicious device emits signals containing a specially designed adversarial samples, will the DL-based SEI still work stably to correctly identify the malicious device? To the best of our knowledge, this research is still blank, let alone the corresponding defense methods. Therefore, this paper designs two scenarios of attack and defense and proposes the corresponding implementation methods to specializes in the robustness of DL-based SEI under adversarial attacks. On this basis, detailed experiments are carried out based on the real-world data and simulation data. The attack scenario is that the malicious device adds an adversarial perturbation signal specially designed to the original signal, misleading the original system to make a misjudgment. Experiments based on three different attack generation methods show that DL-based SEI is very vulnerability. Even if the intensity is very low, without affecting the probability density distribution of the original signal, the performance can be reduced to about 50%, and at \u221222 dB it is completely invalid. In the defense scenario, the adversarial training (AT) of DL-based SEI is added, which can significantly improve the system\u2019s performance under adversarial attacks, with \u226560% improvement in the recognition rate compared to the network without AT. Further, AT has a more robust effect on white noise. This study fills the relevant gaps and provides guidance for future research. In the future research, the impact of adversarial attacks must be considered, and it is necessary to add adversarial training in the training process.<\/jats:p>","DOI":"10.3390\/rs14194996","type":"journal-article","created":{"date-parts":[[2022,10,10]],"date-time":"2022-10-10T03:07:28Z","timestamp":1665371248000},"page":"4996","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":21,"title":["Robustness of Deep Learning-Based Specific Emitter Identification under Adversarial Attacks"],"prefix":"10.3390","volume":"14","author":[{"given":"Liting","family":"Sun","sequence":"first","affiliation":[{"name":"College of Electronic Science and Technology, National University of Defense Technology, Changsha 410073, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Da","family":"Ke","sequence":"additional","affiliation":[{"name":"College of Electronic Science and Technology, National University of Defense Technology, Changsha 410073, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiang","family":"Wang","sequence":"additional","affiliation":[{"name":"College of Electronic Science and Technology, National University of Defense Technology, Changsha 410073, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhitao","family":"Huang","sequence":"additional","affiliation":[{"name":"College of Electronic Science and Technology, National University of Defense Technology, Changsha 410073, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Kaizhu","family":"Huang","sequence":"additional","affiliation":[{"name":"School of Advanced Technology, Xi\u2019an Jiaotong-Liverpool University, Suzhou 215123, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"1968","published-online":{"date-parts":[[2022,10,7]]},"reference":[{"key":"ref_1","first-page":"113","article-title":"Specific Emitter Identification and Verification","volume":"113","author":"Talbot","year":"2003","journal-title":"Technol. Rev. J."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"1192","DOI":"10.1109\/TIFS.2016.2520908","article-title":"Specific Emitter Identification via Hilbert\u2013Huang Transform in Single-Hop and Relaying Scenarios","volume":"11","author":"Zhang","year":"2016","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Man, P., Ding, C., Ren, W., and Xu, G. (2021). A Specific Emitter Identification Algorithm under Zero Sample Condition Based on Metric Learning. Remote Sens., 13.","DOI":"10.3390\/rs13234919"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"1091","DOI":"10.1109\/TVT.2019.2950670","article-title":"Deep Learning Based RF Fingerprint Identification Using Differential Constellation Trace Figure","volume":"69","author":"Peng","year":"2020","journal-title":"IEEE Trans. Veh. Technol."},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"94","DOI":"10.1109\/COMST.2015.2476338","article-title":"Device Fingerprinting in Wireless Networks: Challenges and Opportunities","volume":"18","author":"Xu","year":"2016","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"2091","DOI":"10.1109\/TIFS.2016.2552146","article-title":"Wireless Physical-Layer Identification: Modeling and Validation","volume":"11","author":"Wang","year":"2016","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"3335","DOI":"10.1109\/TIFS.2020.2988558","article-title":"A New Method for Specific Emitter Identification With Results on Real Radar Measurements","volume":"15","author":"Gok","year":"2020","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"165","DOI":"10.1109\/TCCN.2019.2949308","article-title":"No Radio Left Behind: Radio Fingerprinting Through Deep Learning of Physical-Layer Hardware Impairments","volume":"6","author":"Sankhe","year":"2020","journal-title":"IEEE Trans. Cogn. Commun. Netw."},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"17292","DOI":"10.1109\/JIOT.2022.3154595","article-title":"Radio Frequency Fingerprint Extraction based on Feature Inhomogeneity","volume":"9","author":"Sun","year":"2022","journal-title":"IEEE Internet Things J."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"78","DOI":"10.1109\/LNET.2022.3167665","article-title":"RF Fingerprinting based IoT Node Authentication using Mahalanobis Distance Correlation Theory","volume":"4","author":"Nguyen","year":"2022","journal-title":"IEEE Netw. Lett."},{"key":"ref_11","doi-asserted-by":"crossref","first-page":"1971","DOI":"10.1109\/TII.2021.3096048","article-title":"A scalable protocol level approach to prevent machine learning attacks on PUF-based authentication mechanisms for Internet-of-Medical-Things","volume":"18","author":"Gope","year":"2021","journal-title":"IEEE Trans. Ind. Informat."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"6429","DOI":"10.1109\/JIOT.2019.2908759","article-title":"Groundwork for Neural Network-Based Specific Emitter Identification Authentication for IoT","volume":"6","author":"McGinthy","year":"2019","journal-title":"IEEE Internet Things J."},{"key":"ref_13","doi-asserted-by":"crossref","first-page":"2604","DOI":"10.1109\/JSAC.2021.3087250","article-title":"Radio Frequency Fingerprint Identification for LoRa Using Deep Learning","volume":"39","author":"Shen","year":"2021","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"ref_14","unstructured":"Sun, L., Wang, X., Yang, A., and Huang, Z. (2020). Radio Frequency Fingerprint Extraction in Specific Emitter Identification. J. Radars, 9."},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"3132","DOI":"10.1109\/TAES.2021.3074129","article-title":"A Method for Radar Model Identification Using Time-Domain Transient Signals","volume":"57","author":"Guo","year":"2021","journal-title":"IEEE Trans. Aerosp. Electron. Syst."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Ureten, O., and Serinken, N. (1999, January 20\u201323). Bayesian detection of radio transmitter turn-on transients. Proceedings of the IEEE-EURASIP Workshop on Nonlinear Signal and Image Processing (NSIP\u201999), Antalya, Turkey.","DOI":"10.1049\/el:19991369"},{"key":"ref_17","doi-asserted-by":"crossref","unstructured":"Zhao, C., Huang, L., Hu, L., and Yan, Y. (2011, January 3\u20135). Transient fingerprint feature extraction for WLAN cards based on polynomial fitting. Proceedings of the 2011 6th International Conference on Computer Science & Education (ICCSE), Singapore.","DOI":"10.1109\/ICCSE.2011.6028826"},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"656","DOI":"10.1049\/iet-rsn.2016.0248","article-title":"Evaluation of unintentional modulation for pulse compression signals based on spectrum asymmetry","volume":"11","author":"Ru","year":"2017","journal-title":"IET Radar Sonar Navig."},{"key":"ref_19","doi-asserted-by":"crossref","first-page":"471","DOI":"10.1109\/LSP.2020.2978333","article-title":"Radio Frequency Fingerprint Extraction Based on Multi-Dimension Approximate Entropy","volume":"27","author":"Sun","year":"2020","journal-title":"IEEE Signal Process. Lett."},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"1896","DOI":"10.1109\/TIFS.2020.3045318","article-title":"Injecting Reliable Radio Frequency Fingerprints Using Metasurface for The Internet of Things","volume":"16","author":"Rajendran","year":"2020","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_21","doi-asserted-by":"crossref","first-page":"197","DOI":"10.1109\/JRFID.2018.2880457","article-title":"Machine Learning Approach to RF Transmitter Identification","volume":"2","author":"Youssef","year":"2018","journal-title":"IEEE J. Radio Freq. Identif."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"5051","DOI":"10.1109\/TSP.2021.3107633","article-title":"Balanced Neural Architecture Search and Its Application in Specific Emitter Identification","volume":"69","author":"Du","year":"2021","journal-title":"IEEE Trans. Signal Process."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"100270","DOI":"10.1016\/j.cosrev.2020.100270","article-title":"A survey of safety and trustworthiness of deep neural networks: Verification, testing, adversarial attack and defence, and interpretability","volume":"37","author":"Huang","year":"2020","journal-title":"Comput. Sci. Rev."},{"key":"ref_24","unstructured":"Goodfellow, I.J., Shlens, J., and Szegedy, C. (2014). Explaining and Harnessing Adversarial Examples. Comput. Sci."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Ke, D., Huang, Z., Wang, X., and Sun, L. (2019, January 8\u201311). Application of Adversarial Examples in Communication Modulation Classification. Proceedings of the 2019 International Conference on Data Mining Workshops (ICDMW), Beijing, China.","DOI":"10.1109\/ICDMW.2019.00128"},{"key":"ref_26","doi-asserted-by":"crossref","first-page":"74","DOI":"10.1109\/MPRV.2008.6","article-title":"Denial-of-service in wireless sensor networks: Attacks and defenses","volume":"7","author":"Raymond","year":"2008","journal-title":"IEEE Pervasive Comput."},{"key":"ref_27","first-page":"66","article-title":"A practical message falsification attack on WPA","volume":"54","author":"Ohigashi","year":"2009","journal-title":"Proc. JWIS"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"85","DOI":"10.1109\/MWC.2007.4396947","article-title":"A survey of routing attacks in mobile ad hoc networks","volume":"14","author":"Kannhavong","year":"2007","journal-title":"IEEE Wirel. Commun."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"1831","DOI":"10.1109\/TIFS.2019.2948283","article-title":"Physical layer identification based on spatial\u2013temporal beam features for millimeter-wave wireless networks","volume":"15","author":"Balakrishnan","year":"2019","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Lyu, C., Huang, K., and Liang, H.N. (2015, January 14\u201317). A Unified Gradient Regularization Family for Adversarial Examples. Proceedings of the 2015 IEEE International Conference on Data Mining (ICDM), Atlantic City, NJ, USA.","DOI":"10.1109\/ICDM.2015.84"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"90","DOI":"10.1049\/el.2018.6229","article-title":"Comparison of techniques for radiometric identification based on deep convolutional neural networks","volume":"55","author":"Baldini","year":"2019","journal-title":"Electron. Lett."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Wong, L.J., Headley, W.C., Andrews, S., Gerdes, R.M., and Michaels, A.J. (2018, January 29\u201331). Clustering learned CNN features from raw I\/Q data for emitter identification. Proceedings of the MILCOM 2018\u20142018 IEEE Military Communications Conference (MILCOM), Los Angeles, CA, USA.","DOI":"10.1109\/MILCOM.2018.8599847"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"33544","DOI":"10.1109\/ACCESS.2019.2903444","article-title":"Specific emitter identification using convolutional neural network-based IQ imbalance estimators","volume":"7","author":"Wong","year":"2019","journal-title":"IEEE Access"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"146","DOI":"10.1109\/MCOM.2018.1800153","article-title":"Deep learning convolutional neural networks for radio identification","volume":"56","author":"Riyaz","year":"2018","journal-title":"IEEE Commun. Mag."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., and Sun, J. (2016, January 11\u201314). Identity mappings in deep residual networks. Proceedings of the European Conference on Computer Vision, Amsterdam, The Netherlands.","DOI":"10.1007\/978-3-319-46493-0_38"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"54425","DOI":"10.1109\/ACCESS.2019.2913759","article-title":"Specific emitter identification based on deep residual networks","volume":"7","author":"Pan","year":"2019","journal-title":"IEEE Access"},{"key":"ref_37","doi-asserted-by":"crossref","unstructured":"Zhang, T., Ren, P., and Ren, Z. (2021, January 27\u201330). Deep Radio Fingerprint ResNet for Reliable Lightweight Device Identification. Proceedings of the 2021 IEEE 94th Vehicular Technology Conference (VTC2021-Fall), Norman, OK, USA.","DOI":"10.1109\/VTC2021-Fall52928.2021.9625375"},{"key":"ref_38","unstructured":"Szegedy, C., Zaremba, W., Sutskever, I., Bruna, J., Erhan, D., Goodfellow, I., and Fergus, R. (2013). Intriguing properties of neural networks. Comput. Sci."},{"key":"ref_39","unstructured":"Kurakin, A., Goodfellow, I., and Bengio, S. (2022, July 24). Adversarial Examples in the Physical World. Available online: https:\/\/arxiv.org\/abs\/1607.02533."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Papernot, N., Mcdaniel, P., Wu, X., Jha, S., and Swami, A. (2016, January 22\u201326). Distillation as a Defense to Adversarial Perturbations Against Deep Neural Networks. Proceedings of the 2016 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2016.41"},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Carlini, N., and Wagner, D. (2017, January 22\u201326). Towards Evaluating the Robustness of Neural Networks. Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2017.49"},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"213","DOI":"10.1109\/LWC.2018.2867459","article-title":"Adversarial Attacks on Deep-Learning Based Radio Signal Classification","volume":"8","author":"Sadeghi","year":"2018","journal-title":"IEEE Wirel. Commun. Lett."},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Kokalj-Filipovic, S., Miller, R., Chang, N., and Lau, C.L. (2019, January 14\u201315). Mitigation of Adversarial Examples in RF Deep Classifiers Utilizing AutoEncoder Pre-training. Proceedings of the 2019 International Conference on Military Communications and Information Systems (ICMCIS), Budva, Montenegro.","DOI":"10.1109\/ICMCIS.2019.8842663"},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"389","DOI":"10.1109\/TR.2020.3032744","article-title":"Adversarial Attacks in Modulation Recognition With Convolutional Neural Networks","volume":"70","author":"Lin","year":"2021","journal-title":"IEEE Trans. Reliab."},{"key":"ref_45","doi-asserted-by":"crossref","first-page":"1074","DOI":"10.1109\/TIFS.2020.3025441","article-title":"The Best Defense Is a Good Offense: Adversarial Attacks to Avoid Modulation Detection","volume":"16","author":"Hameed","year":"2021","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_46","unstructured":"Madry, A., Makelov, A., Schmidt, L., Tsipras, D., and Vladu, A. (2017). Towards Deep Learning Models Resistant to Adversarial Attacks. arXiv."},{"key":"ref_47","unstructured":"Ilyas, A., Santurkar, S., Tsipras, D., Engstrom, L., Tran, B., and Madry, A. (2019, January 8\u201314). Adversarial Examples Are Not Bugs, They Are Features. Proceedings of the NeurIPS Conference, Vancouver, BC, Canada."},{"key":"ref_48","doi-asserted-by":"crossref","first-page":"5769","DOI":"10.1109\/TIP.2021.3082317","article-title":"Training Robust Deep Neural Networks via Adversarial Noise Propagation","volume":"30","author":"Liu","year":"2019","journal-title":"IEEE Trans. Image Process."},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"522","DOI":"10.23919\/JSEE.2022.000052","article-title":"Unintentional modulation microstructure enlargement","volume":"33","author":"Sun","year":"2022","journal-title":"J. Syst. Eng. Electron."},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"376","DOI":"10.1016\/j.cja.2021.05.013","article-title":"Unintentional modulation evaluation in time domain and frequency domain","volume":"35","author":"Sun","year":"2021","journal-title":"Chin. J. Aeronaut."},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Sun, L., Wang, X., Zhao, Y., Huang, Z., and Du, C. (2022). Intrinsic Low-Dimensional Nonlinear Manifold Structure of Radio Frequency Signals. IEEE Commun. Lett.","DOI":"10.1109\/LCOMM.2022.3173990"},{"key":"ref_52","doi-asserted-by":"crossref","first-page":"823","DOI":"10.1002\/wcm.2386","article-title":"Theoretical performance analysis of radio frequency fingerprinting under receiver distortions","volume":"15","author":"Huang","year":"2015","journal-title":"Wirel. Commun. Mob. Comput."},{"key":"ref_53","first-page":"941","article-title":"Specific emitter identification using signal trajectory image","volume":"42","author":"Yiwei","year":"2020","journal-title":"J. Electron. Inf. Technol."},{"key":"ref_54","doi-asserted-by":"crossref","first-page":"3791","DOI":"10.1109\/TIFS.2020.3001721","article-title":"Cooperative Specific Emitter Identification via Multiple Distorted Receivers","volume":"15","author":"He","year":"2020","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_55","unstructured":"Huang, Y., and Zheng, H. (2012, January 15\u201317). Radio frequency fingerprinting based on the constellation errors. Proceedings of the 2012 18th Asia-Pacific Conference on Communications (APCC), Jeju, Korea."},{"key":"ref_56","doi-asserted-by":"crossref","unstructured":"(2021). Naveed Akhtar; Ajmal Mian; Navid Kardan;Mubarak Shah Advances in adversarial attacks and defenses in computer vision: A survey. IEEE Access, 9, 155161\u2013155196.","DOI":"10.1109\/ACCESS.2021.3127960"},{"key":"ref_57","first-page":"1831","article-title":"Defense against adversarial attacks using feature scattering-based adversarial training","volume":"32","author":"Zhang","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_58","doi-asserted-by":"crossref","unstructured":"Manoj, B.R., Sadeghi, M., and Larsson, E.G. (2021, January 14\u201323). Adversarial Attacks on Deep Learning Based Power Allocation in a Massive MIMO Network. Proceedings of the ICC 2021\u2014IEEE International Conference on Communications, Montreal, QC, Canada.","DOI":"10.1109\/ICC42927.2021.9500424"},{"key":"ref_59","doi-asserted-by":"crossref","first-page":"2305","DOI":"10.1109\/JSAC.2021.3087243","article-title":"An Efficient Specific Emitter Identification Method Based on Complex-Valued Neural Networks and Network Compression","volume":"39","author":"Wang","year":"2021","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"ref_60","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., and Sun, J. (2016, January 27\u201330). Deep residual learning for image recognition. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref_61","first-page":"3221","article-title":"Accelerating t-SNE using tree-based algorithms","volume":"15","year":"2014","journal-title":"J. Mach. Learn. Res."}],"container-title":["Remote Sensing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2072-4292\/14\/19\/4996\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T00:47:58Z","timestamp":1760143678000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2072-4292\/14\/19\/4996"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,10,7]]},"references-count":61,"journal-issue":{"issue":"19","published-online":{"date-parts":[[2022,10]]}},"alternative-id":["rs14194996"],"URL":"https:\/\/doi.org\/10.3390\/rs14194996","relation":{},"ISSN":["2072-4292"],"issn-type":[{"value":"2072-4292","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,10,7]]}}}