Securing Contrastive mmWave-based Human Activity Recognition against Adversarial Label Flipping
Amit Singha, Ziqian Bi, Tao Li, Yimin Chen, Yanchao Zhang
cs.CR
Submitted: 2026-08-01
Comments: 11 pages, 18 figures. Published in Proceedings of the 17th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec '24)
Journal ref: Proceedings of the 17th ACM Conference on Security and Privacy in Wireless and Mobile Networks (WiSec '24), Seoul, Republic of Korea, 2024, pp. 31-41
License: http://creativecommons.org/licenses/by/4.0/
The gist: Wireless Human Activity Recognition (HAR), leveraging their non-intrusive nature, has the potential to revolutionize various sectors, including healthcare, virtual reality, and surveillance.
Terminology
Abstract
Wireless Human Activity Recognition (HAR), leveraging their non-intrusive nature, has the potential to revolutionize various sectors, including healthcare, virtual reality, and surveillance. The advent of millimeter wave (mmWave) technology has significantly enhanced the capabilities of wireless HAR systems. This paper presents the first systematic study on the vulnerabilities of mmWave-based HAR to label flipping poisoning attacks in the context of supervised contrastive learning. We identify three label poisoning attacks on the contrastive mmWave-based HAR and propose corresponding countermeasures. The efficacy of the attacks and also our countermeasures are experimentally validated on a prototype system. The attacks and countermeasures can be easily extended to other wireless HAR systems, thereby promoting security considerations in system design and deployment.
Sources
- Label Noise Types and Their Effects on Deep Learning
- A Simple Framework for Contrastive Learning of Visual Representations
- Supervised Contrastive Learning
- Multi-Objective Interpolation Training for Robustness to Label Noise
- Class2Simi: A Noise Reduction Perspective on Learning with Noisy Labels
- Understanding deep learning requires rethinking generalization
- mixup: Beyond Empirical Risk Minimization
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs