Research Article

Transferable Adversarial Attacks against Automatic Modulation Classifier in Wireless Communications

Algorithm 1

AL-BIM.
Input: A classifier truncated model ; original signal sample to be attacked ; target signal sample ; clean signal sample ; Loss Function .
Parameter: perturbation size =0.001, number of iterations T.
Output:the adversarial sample that satisfy
.
.
put into ,obtain feature ;
put into ,obtain feature ;
put into ,obtain feature ;
t=0 to T-1
put into ,obtain feature
Obtain the gradient ,
where ;
calculate the accumulated gradient,renew the :
update the with gradient method
end for