Abstract
This letter explores the positive side of the adversarial attack for the security-aware semantic communication system. Specifically, a pair of matching pluggable modules is installed: one after the semantic transmitter and the other before the semantic receiver. The module at the transmitter uses a trainable adversarial residual network (ARN) to generate adversarial examples, while the module at the receiver employs another trainable ARN to remove the adversarial attack and the channel noise. To mitigate the threat of the semantic eavesdropping, the trainable ARNs are jointly optimized to minimize the weighted sum of the power of adversarial attacks, the mean squared error of the semantic communication, and the confidence of the eavesdropper correctly retrieving the private information. Numerical results show that our scheme can fool the eavesdropper while maintaining the high-quality semantic communication.