Cognitive radar hides decision making from adversaries while balancing performance

Masking Radar Cognition under Adversarial Surveillance: A Distributional Privacy Framework

Machine Learning

Summary

This work addresses how to protect smart radar systems from being tricked or spied on by adversaries trying to figure out how they make decisions. The authors model the radar’s preferences using a mathematical distribution and develop methods that mask these private details while still allowing the radar to function effectively. The new techniques provide provable guarantees that keep the radar’s strategies confidential, even under attacks, while quantifying how much this privacy might affect radar performance. Tests show these methods improve privacy protection and reduce information leaks better than previous approaches. Such privacy measures are important for advanced communication networks like those used in automated vehicles and drone coordination.

Cognitive radarElectronic counter-countermeasure (ECCM)von Mises-Fisher distributionDistributional privacyUtility maximizationAdversarial inferencePrivacy-performance trade-off6G communicationNetwork slicingFisher information

Authors

Sreedevi K, Nandhini K, Anup Aprem, Deepthi P P

Abstract

In this article, we propose an online electronic counter-countermeasure (ECCM) framework designed to conceal the strategic decision-making processes of a cognitive radar (CR) operating under adversarial surveillance. We model the CR under two distinct decision paradigms: a static constrained utility-maximizing behavior and a dynamic expected utility-maximizing behavior. The radar's utility function is modeled via a von Mises--Fisher (vMF) distribution, with the distributional parameter constituting the private information to be protected from adversarial inference. We adopt a distribution privacy framework to conceal this private information and provide formal distribution privacy guarantees for cognition masking. In this work, we develop cognition-hiding algorithms for both static constrained utility maximization (WDPCH-SU), and dynamic expected utility maximization (WDPCH-DU). Through rigorous mathematical analysis, we show that both WDPCH-SU and WDPCH-DU satisfy $ε$-distribution privacy ($ε$-DistP) against inference-based adversarial attacks and present the privacy--performance trade-off bounds, quantifying utility loss (in static setting) and expected utility deviation (in dynamic setting) as functions of $ε$. Numerical results show that WDPCH-SU gives about 15\% improvement in utility loss at maximum privacy compared to the existing methodology while WDPCH-DU achieves a greater reduction in adversarial Fisher information without requiring explicit Fisher information constraints, at a moderate, analytically bounded utility deviation. These results are highly promising in many 6G communication scenarios such as network slicing for automated driving and swarm UAV coordination, where it is essential to keep the resource allocation policy robust against privacy attacks.