Fanggang Wang

Scholar in residence 1 August – 31 October 2026

Fanggang Wang (Senior Member, IEEE) received the B.Eng. and Ph.D. degrees from the School of Information and Communication Engineering, Beijing University of Posts and Telecommunications, Beijing, China, in 2005 and 2010, respectively. He was a Post-Doctoral Fellow with the Institute of Network Coding, The Chinese University of Hong Kong, Hong Kong, from 2010 to 2012. He was a Visiting Scholar with Massachusetts Institute of Technology from 2015 to 2016 and Singapore University of Technology and Design in 2014.

He is currently a Professor with the State Key Laboratory of Advanced Rail Autonomous Operation, School of Electronic and Information Engineering, Beijing Jiaotong University. His research interests are in wireless communications, signal processing, and information theory. He served as an Editor for the IEEE COMMUNICATIONS LETTERS and a technical program committee member for several conferences.

Research Objective

This work investigates adversarial perturbation attacks against deep signal classifiers and corresponding robust defense schemes, establishing a complete analysis framework for evaluating classification model vulnerability and anti-interference resilience from both intruder and legitimate receiver perspectives. The concrete targets include two parts:

1. Design practical adversarial perturbation strategies for malicious intruders. We develop two attack modes: targeted perturbation that forces the classifier to map signals to a specified wrong category, and untargeted perturbation that causes arbitrary misclassification, under the constraint of limited perturbation power and guaranteed normal data demodulation at the receiver.

2. Propose anti-perturbation robust recognition mechanisms for legal receivers. Two scenarios are considered: defense when the receiver fully knows the perturbation generation rule, and blind defense without prior attack information.

Research Approach

The whole research follows three sequential steps: problem modeling, adversarial perturbation design, and comprehensive performance evaluation.

3. Intruder adversarial perturbation design

For targeted attacks, we build an optimization objective to maximize misclassification probability toward a target category with limited perturbation power. Since classification probability cannot be directly optimized, cross-entropy loss is adopted to construct gradient-based solving models, where the fast gradient method serves as a lightweight solver for generating effective perturbations. Untargeted attacks share a similar gradient optimization framework but aim to deviate prediction results from the real signal label.

Existing perturbation methods adopt idealized assumptions: ignoring channel distortion, full access to clean received signals, and complete knowledge of the classifier structure. This research will break these preconditions and optimize attack performance via deep learning and convex optimization tools under more realistic communication conditions.

4. Robust receiving mechanism design for legitimate users

If the receiver masters the perturbation type, adversarial training is deployed: the receiver generates simulated adversarial samples, mixes them with clean signal data to retrain the classification model, and improves anti-attack accuracy.

If no prior information about perturbations is available, randomized Gaussian smoothing is adopted. By augmenting training data with controllable Gaussian noise, the classifier gains universal robustness against unknown subtle signal disturbances, balancing normal classification accuracy and adversarial resistance.

Current defense methods lack rigorous theoretical robustness guarantees; this research will supplement theoretical derivation and large-scale experimental verification to quantify defense effectiveness.

Contact: fgwang1@bjtu.edu.cn

A man with short black hair and glasses smiles at the camera, wearing a beige jacket over a black shirt, with a blurred stone building in the background.

Host