Where to Defend? Layer-Wise Adversarial Training for Robust Transformer-Based Semantic Communications
Maria Slim, Razane Tajeddine, Mariette Awad, Hadi Sarieddeen
Abstract
Deep learning-based semantic communication (DeepSC), a Transformer-based encoder-decoder, achieves semantic fidelity over noisy channels but remains vulnerable to adversarial perturbations injected at multiple stages of the pipeline. We present a layer-wise robustness framework that compares fast gradient sign method (FGSM), projected gradient descent (PGD), and l2-normalized fast gradient method (FGM) defenses at the embedding output, and then uses PGD to analyze three attack and defense points: the embedding output, encoder output, and channel-encoder bottleneck. We evaluate reconstruction on Europarl and UK Hansard and sentiment classification on SST2 and YELP under additive white Gaussian noise (AWGN) and Rayleigh fading. A first-order damage budget, epsilon times the l1 norm of the clean-input loss gradient at each injection point, predicts the attack-severity ordering, and the transfer matrix reveals asymmetric defense transfer: the embedding defense transfers strongly to encoder attacks, whereas encoder defenses degrade robustness against upstream attacks. For reconstruction, encoder-point training yields the largest matched gain but fails severely under embedding attacks; joint embedding-plus-encoder training retains comparable gains under encoder attacks while mitigating this mismatch failure, and Rayleigh fading attenuates robustness gains and degradation. For classification, three of four defenses collapse to constant predictors; only the channel-encoder defense remains non-degenerate, suggesting a protective role for the 128D-to-16D bottleneck. At a signal-to-noise ratio (SNR) of 9 dB and perturbation budget epsilon = 0.3, the matched encoder defense recovers bilingual evaluation understudy (BLEU) from ~ 0.10 to ~ 0.64 on Europarl/AWGN, whereas the mismatched encoder defense yields a -0.444 BLEU change relative to the undefended baseline under an embedding attack.
Create a lesson
Related papers
Learning the Topology of a Simplicial Complex Using Noisy Simplicial Signals
Andrei Buciulea, Elvin Isufi, Geert Leus et al.
Multi-Label 12-Lead ECG Classification on the PTB-XL Dataset: A Comparative Evaluation of Deep Learning Architectures and Heterogeneous Ensemble Approaches
Yunus Emre Mert, Ece Akdoğan, Hüseyin Üvet
Prism-SQA: An Interpretable and Adaptable Neural Framework for Surface Electromyography Quality Assessment
Kuan-Chen Wang, Kai-Chun Liu, Ping-Cheng Yeh et al.
Unified Constrained Geometric Configuration Optimization for Source Localization Systems: A Riemannian Manifold-Based Approach
Xin Cheng, Feng Shu, Gangle Sun et al.
Secrecy Sum-Rate Maximization in Finite Blocklength IRS-aided Systems With Perfect and Imperfect CSI
Monir Abughalwa, Nguyen Van Huynh, Diep N. Nguyen et al.
Through-Wall Detection using Software-Defined Radio based on adaptive Principal Component Analysis
Dinuli Naotunna, Wenchao Li, Sanka Piyaratna et al.