Abstract
We consider adversarial machine learning based attacks on power allocationwhere the base station (BS) allocates its transmit power to multiple orthogonalsubcarriers by using a deep neural network (DNN) to serve multiple userequipments (UEs). The DNN that corresponds to a regression model is trainedwith channel gains as the input and returns transmit powers as the output.While the BS allocates the transmit powers to the UEs to maximize rates for allUEs, there is an adversary that aims to minimize these rates. The adversary maybe an external transmitter that aims to manipulate the inputs to the DNN byinterfering with the pilot signals that are transmitted to measure the channelgain. Alternatively, the adversary may be a rogue UE that transmits fabricatedchannel estimates to the BS. In both cases, the adversary carefully craftsadversarial perturbations to manipulate the inputs to the DNN of the BS subjectto an upper bound on the strengths of these perturbations. We consider theattacks targeted on a single UE or all UEs. We compare these attacks with abenchmark, where the adversary scales down the input to the DNN. We show thatthe adversarial attacks are much more effective than the benchmark attack interms of reducing the rate of communications. We also show that adversarialattacks are robust to the uncertainty at the adversary including the erroneousknowledge of channel gains and the potential errors in exercising the attacksexactly as specified.