Semantic communication, enabled by deep joint source-channel coding (DeepJSCC), is widely expected to inherit the vulnerability of deep learning to adversarial perturbations. This paper challenges this prevailing belief and reveals a counterintuitive finding: semantic communication systems exhibit unanticipated adversarial robustness that can exceed that of classical separate source-channel coding systems. On the theoretical front, we establish fundamental bounds on the minimum attack power required to induce a target distortion, overcoming the analytical intractability of highly nonlinear DeepJSCC models by leveraging Lipschitz smoothness. We prove that the implicit regularization from noisy training forces decoder smoothness, a property that inherently provides built-in protection against adversarial attacks. To enable rigorous and fair comparison, we develop two novel attack methodologies that address previously unexplored vulnerabilities: a structure-aware vulnerable set attack that, for the first time, exploits graph-theoretic vulnerabilities in LDPC codes to induce decoding failure with minimal energy, and a progressive gradient ascent attack that leverages the differentiability of DeepJSCC to efficiently find minimum-power perturbations. Designing such attacks is challenging, as classical systems lack gradient information while semantic systems require navigating high-dimensional, non-convex spaces; our methods fill these critical gaps in the literature. Extensive experiments demonstrate that semantic communication requires up to $14$-$16\times$ more attack power to achieve the same distortion as classical systems, empirically substantiating its superior robustness.
翻译:由深度联合源信道编码(DeepJSCC)实现的语义通信,通常被认为会继承深度学习对对抗性扰动的脆弱性。本文挑战了这一普遍认知,揭示了一个反直觉的发现:语义通信系统展现出未预期的对抗鲁棒性,其程度甚至可能超越经典的分立源信道编码系统。在理论层面,我们建立了诱导目标失真所需最小攻击功率的基本界限,通过利用Lipschitz光滑性克服了高度非线性DeepJSCC模型在分析上的难解性。我们证明了带噪训练带来的隐式正则化会强制解码器光滑性,这一性质天然提供了对抗攻击的内建保护。为实现严谨公平的比较,我们提出了两种针对先前未探索漏洞的新型攻击方法:一种结构感知脆弱集攻击,首次利用LDPC码的图论漏洞以最小能量诱导解码失败;以及一种渐进梯度上升攻击,利用DeepJSCC的可微性高效寻找最小功率扰动。设计此类攻击具有挑战性,因为经典系统缺乏梯度信息,而语义系统需要在高维非凸空间中导航;我们的方法填补了文献中的这些关键空白。大量实验表明,为达到与经典系统相同的失真水平,语义通信需要高达$14$-$16$倍的攻击功率,经验性地证实了其优越的鲁棒性。