{"id":"58343122-2984-4d38-bcb4-581483475866","arxiv_id":"2606.30595","paper_version":1,"verdict":"UNVERDICTED","confidence":"LOW","novelty_score":5.0,"correctness_risk":"unknown","formal_verification":"none","parameter_count":0,"one_line_summary":"Presents a selective wireless backdoor attack on multi-user semantic communications over MAC and a trigger-aware robust training defense.","lead":"The paper describes a selective over-the-air backdoor attack on a semantic communication system where two transmitters share a multiple access channel with one receiver; an adversary injects a low-power trigger during training to later manipulate inference for only one transmitter. A trigger-aware defense is proposed to maintain correct semantic labels despite the contaminated signals.","discovery_kind":"new_application","skeptic_critique":{"model":"grok-4.3","headline":"No significant objection identified","rationale":"The reader's weakest assumption directly captures the necessary condition for the attack to be realizable. With the full manuscript now referenced, no additional load-bearing technical gap (e.g., in the MAC superposition, trigger embedding, or defense construction) rises to the level of a distinct concern that would alter the UNVERDICTED status.","tokens_in":1726,"tokens_out":268,"duration_ms":46483,"concrete_test":"Reproduce the MAC simulation setup with the two transmitters and joint receiver model; inject the reported low-power trigger only during the training phase for one user and measure post-training inference accuracy on clean vs. triggered test inputs for both users. If selectivity holds within the reported margins, the core feasibility claim is supported.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The central claim describes a selective over-the-air backdoor attack on joint semantic inference over a MAC together with a trigger-aware defense. The argument structure is internally consistent: the attack scenario assumes undetected low-power contamination during training, the selectivity is achieved by trigger design, and the defense counters it via robust training. No internal inconsistency, hidden assumption in the channel model, or unsupported leap from the described mechanism to the claimed outcome is apparent from the provided description.","agreement_with_reader":"agree"},"referee_report":{"model":"grok-4.3","summary":"The manuscript describes a semantic communication (SemCom) setup with two transmitters jointly communicating semantic information to a common receiver over a multiple access channel (MAC). It introduces a selective over-the-air backdoor attack in which an adversary injects a low-power trigger waveform into the shared received signal during training; retransmission of the trigger at test time selectively alters the receiver's semantic inference for one transmitter while leaving the other largely unaffected. A trigger-aware robust training defense is proposed to preserve correct semantic labels under contaminated observations, with results claimed to demonstrate both the attack's effectiveness and the defense's mitigation.","tokens_in":1797,"tokens_out":541,"duration_ms":47074,"significance":"If the experimental results hold, the work is significant because it identifies a practical, selective vulnerability in multi-user SemCom systems that arises specifically from the shared MAC and joint inference setting, and it supplies a concrete defense. The selective, low-power, over-the-air nature of the attack distinguishes it from conventional data-poisoning or model-replacement attacks and directly addresses an emerging security concern as SemCom moves toward shared-access deployments.","major_comments":[{"comment":"The attack's central claim of stealth and selectivity rests on the assumption that a low-power trigger can contaminate training data without detection or mitigation (reader's weakest assumption). No quantitative characterization of trigger-to-signal power ratio, detection probability under standard training, or channel conditions under which the contamination remains invisible is supplied to support this load-bearing premise.","section":"Attack model and training procedure"},{"comment":"The defense is described as 'trigger-aware robust training,' yet the manuscript provides no ablation or comparison against standard robust-training baselines (e.g., adversarial training without trigger knowledge) or against simple anomaly-detection filters that might be applied at the receiver before training. This leaves open whether the reported protection is due to trigger awareness or to generic robustness techniques.","section":"Defense mechanism and experimental evaluation"}],"minor_comments":[{"comment":"The abstract states that the attack 'minimally affecting the inference of the other transmitter,' but the full manuscript should report the exact degradation (e.g., accuracy drop or semantic similarity score) for the unaffected transmitter across the evaluated SNR range.","section":"Abstract and results section"},{"comment":"Notation for the latent semantic representations and the joint reconstruction/classification loss at the receiver is introduced without an explicit equation or diagram; a compact system model equation would improve clarity.","section":"System model"}],"recommendation":"major_revision","confidential_remarks":null},"author_rebuttal":{"model":"grok-4.3","summary":"We thank the referee for the constructive feedback. We address the two major comments below and will revise the manuscript accordingly to provide the requested quantitative details and comparisons.","responses":[{"response":"We agree that a quantitative characterization of the trigger's stealth properties would strengthen the attack model. In the revised version we will add a dedicated subsection reporting the trigger-to-signal power ratios used in all experiments, together with detection-probability curves under standard training and under representative channel conditions (AWGN and Rayleigh fading). These additions will directly support the premise that the low-power contamination can remain undetected.","revision_made":"yes","referee_comment":"[Attack model and training procedure] The attack's central claim of stealth and selectivity rests on the assumption that a low-power trigger can contaminate training data without detection or mitigation (reader's weakest assumption). No quantitative characterization of trigger-to-signal power ratio, detection probability under standard training, or channel conditions under which the contamination remains invisible is supplied to support this load-bearing premise."},{"response":"We accept that additional baselines are needed to isolate the benefit of trigger awareness. The revision will include new ablation experiments comparing trigger-aware robust training against (i) standard adversarial training that does not exploit trigger knowledge and (ii) simple anomaly-detection filters applied at the receiver prior to training. The results will clarify the incremental value of the proposed trigger-aware approach.","revision_made":"yes","referee_comment":"[Defense mechanism and experimental evaluation] The defense is described as 'trigger-aware robust training,' yet the manuscript provides no ablation or comparison against standard robust-training baselines (e.g., adversarial training without trigger knowledge) or against simple anomaly-detection filters that might be applied at the receiver before training. This leaves open whether the reported protection is due to trigger awareness or to generic robustness techniques."}],"tokens_in":1375,"tokens_out":396,"duration_ms":52382,"standing_objections":[]},"desk_editor":{"model":"grok-4.3","letter":"The main point is that an adversary can inject a low-power trigger waveform into the shared received signal during training and later activate it at test time to flip the semantic output for only one of the two transmitters while leaving the other mostly untouched. They also sketch a defense that trains the receiver model to stay accurate even when the trigger is present.\n\nWhat is new is the combination of backdoor poisoning with the multiple-access channel to achieve per-user selectivity without needing to compromise either transmitter. The attack model is described clearly: the trigger is added over the air at low power so it blends into the wireless observations, and the defense uses trigger-aware robust training to protect the joint semantic reconstruction and classification.\n\nThe setup itself is reasonable for an initial exploration of security in shared semantic systems. The selectivity comes naturally from the MAC and the trigger design, and the defense direction makes sense as a counter.\n\nThe soft spot is the lack of any reported metrics, error bars, channel models, or comparison to standard backdoor methods. Without those, it is difficult to know whether the attack succeeds at realistic power levels or whether the defense actually closes the gap. The assumption that the trigger contamination goes unnoticed during training also feels optimistic for real deployments.\n\nThis is for researchers working on semantic communications or wireless security who want to think about emerging attack surfaces. It raises a timely issue worth considering.\n\nI would send it for peer review because the core idea is coherent and the setting is relevant, even though the evaluation needs more substance to be convincing.","headline":"This paper shows a selective low-power over-the-air backdoor attack on two-user semantic comms over MAC plus a trigger-aware defense, but the abstract gives no numbers or baselines so the practical impact is hard to judge.","tokens_in":2285,"tokens_out":399,"would_cite":false,"duration_ms":32173,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"grok-4.3","headline":"A low-power over-the-air trigger can selectively backdoor semantic inference for one transmitter in a shared multiple access channel.","keywords":["semantic communication","backdoor attack","Trojan attack","multiple access channel","wireless security","semantic inference","over-the-air attack"],"falsifier":"Transmit the trigger waveform during the training phase of the semantic model and then again at test time; measure whether the semantic classification accuracy drops significantly for only one transmitter while remaining stable for the other.","tokens_in":2634,"feed_emoji":"📡","tokens_out":620,"duration_ms":54932,"temperature":0.7,"pith_summary":"The paper establishes that semantic communication systems with multiple transmitters sharing a receiver over a multiple access channel are vulnerable to a selective backdoor attack. An adversary transmits a low-power trigger waveform that contaminates the training signal at the receiver, allowing the same trigger to be sent later to alter the semantic reconstruction and classification for only one of the transmitters. This selective manipulation occurs with minimal impact on the other transmitter's inference. The authors also develop a trigger-aware defense that trains the model to maintain correct semantic labels even when the trigger is present in the observations. This matters for the security of task-oriented wireless networks where semantic meaning is extracted jointly from multiple users.","feed_headline":"Low-power trigger selectively backdoors one semantic transmitter","feed_subtitle":"Adversary contaminates training with waveform to alter inference for one user while sparing the other in multiple access semantic system.","key_machinery":"The selective over-the-air backdoor attack, in which the adversary's low-power trigger waveform is transmitted over the air and combined with the legitimate signals at the receiver.","core_discovery":"In a semantic communication system where two transmitters send latent representations to a common receiver over a multiple access channel, an adversary can inject a low-power trigger waveform into the shared received signal during training. Re-transmitting this trigger during testing then selectively manipulates the semantic inference for one transmitter while leaving the other largely unaffected. A trigger-aware robust training method counters this by preserving correct labels under contaminated conditions.","pith_inferences":["Similar attacks could be adapted to systems with more than two transmitters if the trigger can be made selective.","Defenses might need to include real-time trigger detection in addition to robust training.","This highlights the need for physical-layer security measures tailored to semantic rather than bit-level communication."],"forward_implications":["The attack enables targeted manipulation of one user's semantic task without broadly disrupting the shared channel.","Trigger-aware training during model development can restore correct semantic classification even under attack conditions.","Shared-access semantic communication networks require defenses against such stealthy wireless injections."],"fun_headline_variants":["Low-power trigger selectively attacks one semantic transmitter","Over-the-air waveform backdoors single transmitter in MAC SemCom","Selective backdoor manipulates one user inference in semantic channel","Wireless Trojan targets one transmitter while sparing the other","Trigger-aware training defends semantic comms from backdoor attack"],"cache_read_input_tokens":2112,"weakest_assumption_plain":"The training process at the receiver does not detect or remove the low-power external trigger waveform added to the received signals from the two transmitters.","fun_headline_variants_meta":{"raw":{"variants":["Low-power trigger selectively attacks one semantic transmitter","Over-the-air waveform backdoors single transmitter in MAC SemCom","Selective backdoor manipulates one user inference in semantic channel","Wireless Trojan targets one transmitter while sparing the other","Trigger-aware training defends semantic comms from backdoor attack"]},"model":"grok-4.3","cost_usd":0.003627,"raw_usage":{"total_tokens":1880,"prompt_tokens":643,"num_sources_used":0,"completion_tokens":75,"cost_in_usd_ticks":36274500,"prompt_tokens_details":{"text_tokens":643,"audio_tokens":0,"image_tokens":0,"cached_tokens":256},"completion_tokens_details":{"audio_tokens":0,"reasoning_tokens":1162,"accepted_prediction_tokens":0,"rejected_prediction_tokens":0}},"tokens_in":643,"tokens_out":75,"duration_ms":20003,"temperature":1.0,"reasoning_tokens":1162,"cache_read_input_tokens":256,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-06-30T03:00:36.888540+00:00","model_set":{"reader":"grok-4.3"},"falsifier":"Transmit the trigger waveform during the training phase of the semantic model and then again at test time; measure whether the semantic classification accuracy drops significantly for only one transmitter while remaining stable for the other.","supporting_citations":[],"review_version":1}