Magmaw: Modality-Agnostic Adversarial Attacks on Machine Learning-Based Wireless Communication Systems
Jung-Woo Chang
Network and Distributed System Security (NDSS) Symposium 2025 · Day 1 · Wireless, Cellular & Satellite Security · Wireless, Cellular & Satellite Security
Overview
The integration of machine learning (ML) into wireless communication systems, particularly for the nascent AI-native 6G networks, promises unprecedented efficiency and adaptability. However, this transformative shift introduces novel security vulnerabilities, specifically in the physical layer, which have been largely unaddressed in a comprehensive manner. Jung-Woo Chang's presentation on Magmaw introduces a groundbreaking framework for modality-agnostic adversarial attacks designed to compromise these next-generation ML-driven wireless systems. This research, a collaboration between UC San Diego and KDDR Research, highlights a critical new threat surface that could undermine the reliability and integrity of future wireless infrastructure.
Key moments
- 0:00 Introduction: Machine Learning in Wireless Communication
- 2:00 The power of Machine Learning in 6G
- 3:20 Adversarial attacks: A new 6G vulnerability
- 4:00 Limitations of previous single-modality attacks
- 4:40 Magmaw's real-world threat model and approach
- 6:30 Addressing physical constraints in attack generation
- 8:00 Real-world experimental setup and diverse metrics
- 9:00 Summary of Magmaw's high attack transferability
Magmaw: Modality-Agnostic Adversarial Attacks on Machine Learning-Based Wireless Communication Systems
Speakers: Jung-Woo Chang (UC San Diego & KDDR Research)
Conference: NDSS Symposium
YouTube: https://www.youtube.com/watch?v=LbhjPatTSaI
Overview
The integration of machine learning (ML) into wireless communication systems, particularly for the nascent AI-native 6G networks, promises unprecedented efficiency and adaptability. However, this transformative shift introduces novel security vulnerabilities, specifically in the physical layer, which have been largely unaddressed in a comprehensive manner. Jung-Woo Chang's presentation on Magmaw introduces a groundbreaking framework for modality-agnostic adversarial attacks designed to compromise these next-generation ML-driven wireless systems. This research, a collaboration between UC San Diego and KDDR Research, highlights a critical new threat surface that could undermine the reliability and integrity of future wireless infrastructure.
Magmaw distinguishes itself by demonstrating the ability to craft universal perturbations that are effective across diverse data modalities—such as image, video, speech, and text—a significant advancement over prior work limited to single-modality attacks. The talk emphasizes that these attacks are not merely theoretical; they are physically realizable using commercial off-the-shelf hardware like the USRP (Universal Software Radio Peripheral), operating with low power signals comparable to traditional jamming. By exposing these profound vulnerabilities, Magmaw serves as a stark warning to industry leaders and researchers actively developing 6G technologies, underscoring the urgent need for robust security paradigms to protect against sophisticated adversarial manipulations at the physical layer.
Background
▶ Watch: Introduction: Machine Learning in Wireless Communication (0:00)
Machine learning has rapidly become a ubiquitous technology, revolutionizing fields from healthcare to finance and autonomous vehicles. While these domains benefited from early access to vast datasets, ML's adoption in wireless communication has been more recent, driven by the imperative to optimize end-to-end transmission and efficiently manage complex interference landscapes. Traditional wireless communication systems rely on handcrafted encoding and decoding schemes, which exhibit limited adaptability in dynamic and complex environments. In contrast, ML-based receivers and transmitters can learn to optimize performance, even in challenging conditions characterized by low channel quality, noise, and fading, which typically degrade signal quality and hinder data reconstruction. This capability makes ML highly promising for the upcoming 6G networks, where industry leaders like Apple and Nokia are actively exploring AI-native 6G communication.
However, with new technology comes new security vulnerabilities. The field of adversarial machine learning has gained prominence in computer vision, demonstrating that ML models are susceptible to adversarial examples. These are inputs meticulously crafted with small, often imperceptible, perturbations that can cause a machine learning system to misclassify or misbehave in unexpected ways. In the context of wireless communication, an adversary could exploit these physical layer vulnerabilities at the receiver antenna to disrupt critical data transmission. While previous research has explored generating perturbations for wireless systems, these efforts often faced limitations. For instance, some work (e.g., Brahma Adel) focused on simulation environments, while others (e.g., Yu Adel) achieved physical realizability but were restricted to targeting a single modality. This meant a perturbation trained for image data could not be generalized to video, speech, or Channel State Information (CSI)-based ML models. Magmaw directly addresses and overcomes this critical limitation, presenting a truly modality-agnostic attack framework that significantly broadens the scope of physical layer threats.
Key Findings
▶ Watch: Adversarial attacks: A new 6G vulnerability (3:20)
Magmaw's research unveils several critical findings that redefine the understanding of adversarial threats in future ML-driven wireless communication systems:
- Modality-Agnostic Attack Transferability: The most significant contribution of Magmaw is its ability to generate universal perturbations that exhibit high attack transferability across diverse data modalities. This means a single, crafted perturbation can effectively degrade the performance of ML models processing images, videos, speech, and text, as well as those leveraging Channel State Information (CSI). This breaks the barrier of previous single-modality attacks, posing a far more generalized threat.
- High Attack Performance and Impact: Magmaw achieves substantial degradation in communication quality. For instance, in image transmission, the attack resulted in a PSNR (Peak Signal-to-Noise Ratio) drop of up to 8.04 decibels (dB), a critical reduction that severely impacts image quality. The overall attack performance was shown to be very close to that of white-box attacks, even under black-box assumptions, indicating its potent effectiveness.
- Influence on Downstream ML Tasks: Beyond direct data reconstruction, Magmaw's perturbations also significantly influence downstream machine learning tasks. The talk highlighted that the received, perturbed information, when fed into subsequent ML models for tasks like video classification or image classification, led to misclassification or incorrect inferences, demonstrating a cascading effect on higher-level ML applications.
- Resilience Against Adaptive Defenses: The research evaluated Magmaw against several adaptive and strong defense mechanisms. Mitigation-based defenses, designed to cancel perturbations, could only slightly degrade Magmaw's attack performance; the system still suffered significant disruption. Similarly, detection-based methods, even when provided with samples of Magmaw's perturbations, struggled to identify the attacks due to the diverse generation techniques employed by Magmaw.
- Effectiveness on Encrypted Channels: Magmaw's attacks were demonstrated to be transferable to encryption-based channels. This is particularly concerning as encryption is a fundamental security component in wireless communication, implying that Magmaw's physical layer attack can bypass higher-layer security measures.
- Physical Realizability and Low Power Operation: The attack was validated in a real-world laboratory setup using commercial off-the-shelf USRP hardware. Crucially, Magmaw injects very low-power adversarial perturbation signals, comparable to the power levels of traditional jamming attacks, making it a stealthy and practical threat that does not require excessive power output from the adversary.
These findings collectively underscore a profound vulnerability in the nascent ML-driven wireless communication paradigm, necessitating a fundamental rethinking of security strategies for 6G networks.
Technical Deep Dive
▶ Watch: Magmaw's real-world threat model and approach (4:40)
Magmaw's technical strength lies in its sophisticated approach to generating physically realizable, modality-agnostic adversarial perturbations within a constrained threat model. The core objective is to degrade the performance of machine learning-based wireless communication systems at the physical layer.
The threat model for Magmaw assumes a real-world adversary employing commercial off-the-shelf hardware, specifically the USRP, to inject low-power adversarial perturbation signals. These signals are designed to be comparable in power to traditional jamming attacks, ensuring practical feasibility. Crucially, Magmaw operates under a constrained attacker model with limited knowledge of the victim communication system, effectively a black-box attack scenario. This is a significant departure from many theoretical adversarial attacks that assume white-box access to the target model.
The target system is a typical machine learning-based wireless communication setup, comprising a transmitter (TX) and a receiver (RX). The TX sends multi-modality data, represented as complex-valued symbols (YTQ), wirelessly to the receiver. In an ideal scenario without attack, the receiver accurately reconstructs these symbols (yhat T). Magmaw aims to disrupt this reconstruction process.
A key challenge in physical layer adversarial attacks is ensuring physical realizability. Magmaw addresses this by incorporating several physical constraints into its perturbation generation process. These include considerations for time offset and frequency change, which are inherent in real-world wireless channels. Furthermore, a power normalization step is applied at the end of the attack module, guaranteeing that the generated perturbation is a low-power signal, making it difficult to detect purely based on excessive power. The exact formulation for generating these perturbations involves an optimization problem, which, while not fully detailed in the talk due to time limits, is designed to craft "optimal perturbations" that maximize destructive impact while adhering to physical constraints.
A critical aspect clarified during the Q&A session is how Magmaw tackles attacker channel variation and operates in a black-box manner. The speaker explained that Magmaw leverages a known vulnerability in the Wi-Fi protocol: receivers frequently or occasionally send wireless preambles to devices in their vicinity. The adversary receives these preambles, which contain information about the wireless channel, and exploits this to generate strong, targeted perturbations. This mechanism allows the black-box attacker to gain sufficient channel knowledge without direct access to the victim's ML model or communication specifics.
Another significant technical detail is Magmaw's universal perturbation characteristic. The perturbations are trained to be effective even under time misalignment. This means the adversary does not need to precisely synchronize their attack with the victim's transmission time. The generated perturbation is "agnostic to the time misalignment," allowing the attacker to send a continuous or intermittent perturbation without requiring exact knowledge of when the victim is transmitting or receiving. This greatly simplifies the attacker's operational requirements and enhances the attack's practicality.
The talk explicitly differentiates Magmaw from traditional jamming attacks. While jamming injects random or Gaussian noise to degrade signal performance, Magmaw's perturbations are crafted explicitly to target the underlying machine learning model. Through its optimization process, Magmaw generates an "optimal perturbation" that, for the same amount of jamming power, achieves significantly greater attack performance by exploiting the specific vulnerabilities of ML algorithms rather than simply increasing noise. This makes Magmaw a much more efficient and targeted attack than conventional jamming.
The experimental setup utilized a GNU Radio system to implement and validate Magmaw. Experiments were conducted in a real-world lab environment, considering both line-of-sight (LoS) and non-line-of-sight (NLoS) paths between the transmitter and receiver. Crucially, the adversary was positioned "behind a wall," demonstrating that the attack does not require the attacker to be physically close to the wireless channel, further enhancing its real-world applicability. Performance was measured using standard metrics: PSNR for image and video transmission, Mean Square Error (MSE) for speech transmission, and BLEU (Bilingual Evaluation Understudy) score for text quality, a widely used metric in Natural Language Processing (NLP). These comprehensive evaluations against various baselines, including previous adversarial attacks and random jamming, unequivocally demonstrated Magmaw's superior and modality-agnostic attack performance.
Demo / Proof of Concept
▶ Watch: Addressing physical constraints in attack generation (6:30)
While the talk did not feature a live, interactive demonstration, the speaker explicitly outlined the physical realizability of Magmaw through its rigorous experimental setup and validation. The core of the proof of concept involved implementing the entire system within a GNU Radio framework, demonstrating that the theoretical attack could be translated into a functional, real-world scenario.
The experimental setup served as the concrete demonstration of Magmaw's capabilities. It involved a real-world lab environment where a transmitter and receiver were deployed, simulating typical wireless communication scenarios. The crucial element was the adversary, equipped with commercial off-the-shelf USRP hardware, positioned strategically. The speaker highlighted that the adversary was placed "behind a wall," indicating a non-line-of-sight scenario that reflects a more challenging and realistic attack environment where the attacker is not necessarily in direct view or close proximity to the victim.
Through this setup, Magmaw successfully demonstrated its ability to inject low-power adversarial perturbation signals that significantly degraded the quality of various data modalities (image, video, speech, text) received by the ML-based wireless system. The measurement of metrics like PSNR, MSE, and BLEU in this physical environment provided quantitative evidence of the attack's effectiveness, validating that Magmaw is not merely a theoretical concept but a practical threat capable of disrupting next-generation wireless communications. The open-sourcing of the code further underscores the reproducibility and verifiability of these findings, serving as a public proof of concept for the security community.
Defensive Implications
▶ Watch: Summary of Magmaw's high attack transferability (9:00)
Magmaw's findings present profound and urgent defensive implications for the design and deployment of AI-native 6G wireless communication systems. The research clearly demonstrates that existing and conventional security measures are largely insufficient against this new class of physical layer adversarial attacks.
The talk specifically evaluated Magmaw against several common defensive strategies:
- Mitigation-based Defenses: These defenses typically aim to cancel out or filter adversarial perturbations. However, Magmaw showed strong resilience, with attack performance only "slightly degraded" but still sufficient to "destroy the original victim system." This indicates that simple signal processing techniques designed to remove noise or interference may not be effective against Magmaw's carefully crafted, ML-aware perturbations. Defenders need to move beyond generic interference cancellation towards adversarial perturbation-aware mitigation strategies that can distinguish and neutralize these specific types of attacks.
- Detection-based Methods: These defenses attempt to identify the presence of adversarial samples. The speaker noted that even when defenders possessed "a layer of perturbation sample" (i.e., had some prior knowledge of the attack's characteristics), Magmaw's "very diverse perturbation generation technique" prevented effective detection. This implies that traditional anomaly detection or signature-based intrusion detection systems might be easily bypassed by Magmaw's adaptable and universal perturbations. Future detection systems must incorporate robust machine learning models that are specifically trained to identify subtle, crafted adversarial signals across various modalities and channel conditions.
- Encryption-based Systems: Encryption is a fundamental component for securing wireless communication, typically operating at higher layers. However, Magmaw's attack was shown to "transfer to encryption-based channel" because it operates at the physical layer and utilizes universal perturbations. This is a critical implication: even if the data payload is encrypted, the integrity of the underlying physical layer communication, and thus the ability to correctly receive and decode the encrypted signal, can be compromised. This highlights the need for cross-layer security approaches that secure not just the data, but also the physical transmission process itself, particularly when ML is involved.
Furthermore, Magmaw's ability to attack CSI-based machine learning models that sense the environment or predict channel conditions suggests that even the foundational intelligence and adaptability of AI-native 6G could be misled. Defenders must consider how adversarial attacks could manipulate the very information (CSI) that ML models use to optimize network operations, potentially leading to incorrect resource allocation, unreliable channel prediction, or even network instability.
In essence, the research strongly advocates for a proactive and holistic approach to security in 6G. Simply porting existing security mechanisms from traditional wireless or higher-layer network security will not suffice. New, ML-hardened physical layer security protocols are required, potentially involving adversarial training of the ML models within wireless systems, developing robust feature representations that are less susceptible to perturbations, and implementing real-time, ML-driven defense mechanisms capable of adapting to evolving attack strategies. The open-sourcing of Magmaw's code is a crucial step in enabling researchers and industry practitioners to develop and test these much-needed robust defenses.
Key Takeaways
- ML in 6G introduces critical new physical layer attack surfaces: The integration of machine learning into next-generation wireless communication, while promising, creates novel vulnerabilities to adversarial attacks that traditional security measures cannot address.
- Magmaw is the first modality-agnostic adversarial attack: It can generate universal perturbations that effectively compromise ML-based wireless systems across diverse data types, including image, video, speech, and text, breaking the limitations of prior single-modality attacks.
- Attacks are physically realizable and low-power: Magmaw can be implemented using commercial off-the-shelf USRP hardware, injecting low-power signals comparable to jamming, making it a practical and stealthy threat in real-world environments.
- Existing defenses are insufficient: Mitigation, detection, and even encryption-based security mechanisms are largely ineffective against Magmaw's sophisticated, ML-aware, and universal perturbations.
- Significant impact on communication quality and downstream ML tasks: Magmaw causes substantial degradation (e.g., PSNR drop of 8.04 dB for images) and can mislead higher-level ML applications that rely on the received wireless data.
- Urgent need for robust, ML-hardened physical layer security: The findings highlight a critical gap in 6G security, necessitating the development of new, adaptive, and adversarial-aware defense mechanisms to protect future wireless networks.
About the Speaker(s)
Jung-Woo Chang is a researcher involved in the Magmaw project, a collaborative effort between UC San Diego and KDDR Research. His work focuses on the security vulnerabilities of machine learning-based wireless communication systems, particularly in the context of next-generation networks like 6G.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Solid, original research that advances a real and underexplored threat surface: adversarial attacks on ML-based physical-layer wireless systems. The modality-agnostic framing is a genuine contribution over prior single-modality work, the threat model is grounded, and the hardware validation with USRP in a real lab environment gives this teeth.
Heather Calloway (CISO) — WEAK
Technically credible research on a real and underappreciated threat surface — adversarial attacks on ML-based physical layer communications. But this talk never crosses the bridge into governance, institutional accountability, or defender operations. It identifies a problem with rigor and leaves the room with nothing to do about it.
→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025
All talks from Network and Distributed System Security (NDSS) Symposium 2025