English

Wireless Backdoor Attack and Defense for Semantic Communications over Multiple Access Channel

Networking and Internet Architecture 2026-06-29 v1 Cryptography and Security Information Theory Machine Learning Signal Processing

Abstract

Semantic communication (SemCom) aims to preserve semantic meaning and task-oriented information beyond conventional message recovery over wireless channels. The adoption of SemCom in shared-access wireless networks introduces new vulnerabilities for multi-user semantic inference. This paper considers a SemCom system for two transmitters communicating with a common receiver over a multiple access channel. Each transmitter maps source information into latent semantic representations, while the receiver jointly reconstructs and classifies the semantic information for both transmitters. A selective over-the-air backdoor (Trojan) attack is presented in which an adversary transmits a low-power trigger waveform over the air and injects it into the shared received signal during training. By transmitting the trigger again during testing, this stealthy, low-power attack selectively manipulates the semantic inference for one transmitter while minimally affecting the inference of the other transmitter. To mitigate this vulnerability, a trigger-aware defense mechanism is developed to preserve correct semantic labels under trigger-contaminated wireless observations. The results demonstrate both the vulnerability of shared-access SemCom systems to selective over-the-air backdoor attacks and the effectiveness of trigger-aware robust training for semantic protection.

Cite

@article{arxiv.2606.30595,
  title  = {Wireless Backdoor Attack and Defense for Semantic Communications over Multiple Access Channel},
  author = {Yalin E. Sagduyu and Tugba Erpek and Aylin Yener and Sennur Ulukus},
  journal= {arXiv preprint arXiv:2606.30595},
  year   = {2026}
}
R2 v1 2026-07-22T20:13:54.232Z