acceptodds
Under review as a conference paper at ICLR 2027

Can a Backdoor Span Source and Wireless Domains? A Cross-Domain Backdoor Attack on Semantic Communication

Abstract

Artificial intelligence is reshaping wireless communications towards intelligent paradigms. Semantic communication (SemCom) exemplifies this shift by leveraging deep neural networks (DNNs) to transmit semantic representations, substantially improving communication efficiency. However, this reliance on DNNs exposes SemCom to backdoor attacks. Its DNN-based architecture facilitates backdoor implantation in the source domain, while the open nature of the wireless channel introduces another attack surface. Existing backdoor attacks predominantly focus on a single source domain. This raises a fundamental question: can a single backdoor span the source and wireless domains to enable a stealthier and more effective attack? Motivated by this, we propose XComBo, the first cross-domain backdoor attack against SemCom. It uses sub-trigger pairs with a learnable source-domain pattern and a wireless-domain frequency-structured signal, where only matched pairs activate the backdoor. Joint optimization on a surrogate model coordinates the sub-triggers for reliable activation without prior knowledge of the victim model, while energy constraints preserve benign behavior under incomplete trigger conditions. We further extend the framework to support multi-target attacks. Experiments show an average PSNR improvement of 12.47 dB over the strongest baseline under backdoor activation while preserving benign transmission. XComBo also generalizes across architectures and datasets and remains robust against several defenses.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.