Paper deep dive
Toward Polymorphic Backdoor against Semantic Communication via Intensity-Based Poisoning
Xiao Yang, Yuni Lai, Gaolei Li, Jun Wu, Kai Zhou, Jianhua Li, Mingzhe Chen
Intelligence
Status: succeeded | Model: Gemma-4-26B-A4B | Prompt: intel-v1 | Confidence: 96%
Last extracted: 6/21/2026, 6:26:37 AM
Summary
The paper introduces SemBugger, a polymorphic backdoor attack designed for Semantic Communication (SC) systems. Unlike existing monomorphic backdoors that target a single output, SemBugger uses a multi-effect poisoning-training framework with a neural trigger generator (Attention U-Net) to inject graded-intensity triggers. This allows the adversary to achieve fine-grained, differentiable control over diverse malicious outputs by adjusting the trigger intensity. The authors also propose a provable robustness defense mechanism that uses a controlled noise mechanism to neutralize these attacks, providing a theoretical lower bound on defense efficacy.
Entities (6)
Relation Signals (4)
Controlled Noise Mechanism → defendsagainst → SemBugger
confidence 100% · the designed defense effectively neutralizes SemBugger attacks.
SemBugger → isatypeof → Polymorphic Backdoor
confidence 100% · we propose SemBugger, a polymorphic SC backdoor.
SemBugger → uses → Multi-effect Poisoning-training Framework
confidence 100% · Specifically, SemBugger is realized through a multi-effect poisoning-training framework.
Multi-effect Poisoning-training Framework → utilizes → Neural Trigger Generator
confidence 100% · Specifically, based on the poisoning rate parameter γ... a sample-specific trigger Δi is synthesized via a neural generator 𝒢
Cypher Suggestions (0)
No Cypher suggestions yet.
Abstract
Abstract:Semantic Communication (SC) backdoor attacks aim to utilize triggers to manipulate the system into producing predetermined outputs via backdoored shared knowledge. Current SC backdoors adopt monomorphic paradigms with single attack target, which suffers from limited attack diversity, efficiency, and flexibility in heterogeneous downstream scenarios. To overcome the limitations, we propose SemBugger, a polymorphic SC backdoor. By dynamically adjusting the trigger intensity, SemBugger finely-grained controls over the SC knowledge to generate diverse malicious results from the system. Specifically, SemBugger is realized through a multi-effect poisoning-training framework. It introduces graded-intensity triggers to poison training data and optimizes SC systems with hierarchical malicious loss. The trained system's knowledge dynamically adapts to trigger intensity in inputs to yield target outputs, all while preserving transmission fidelity for benign samples. Moreover, to augment SC security, we propose a provable robustness defense that resists SemBugger's homogeneous attacks through a controlled noise mechanism. It operates via strategically adding noise in SC inputs, and we formally provide a theoretical lower bound on the defense efficacy. Experiments across diverse SC models and benchmark datasets indicate that SemBugger attains high attack efficacy while maintaining the regular functionality of SC systems. Meanwhile, the designed defense effectively neutralizes SemBugger attacks.
Tags
Links
- Source: https://arxiv.org/abs/2604.23231v1
- Canonical: https://arxiv.org/abs/2604.23231v1
Trouble viewing inline? Open PDF directly →
Full Text
91,076 characters extracted from source content.
Expand or collapse full text
Toward Polymorphic Backdoor against Semantic Communication via Intensity-Based Poisoning Xiao Yang, Yuni Lai, Gaolei Li, Jun Wu, Kai Zhou, Jianhua Li, and Mingzhe Chen Xiao Yang, Gaolei Li, Jun Wu, and Jianhua Li are with the School of Computer Science, Shanghai Jiao Tong University, and Shanghai Key Laboratory of Integrated Administration Technologies for Information Security, Shanghai, China (e-mail: youngshall, gaolei_li, junwuhn, lijh888@sjtu.edu.cn). Yuni Lai and Kai Zhou are with the Department of Computing, Hong Kong Polytechnic University, Hung Hom, Kowloon, Hong Kong (e-mail: yunie.lai@connect.polyu.hk; kaizhou@polyu.edu.hk). Mingzhe Chen is with the Department of Electrical and Computer Engineering and Frost Institute for Data Science and Computing, University of Miami, Coral Gables, Florida 33146, USA (e-mail: mingzhe.chen@miami.edu). Abstract Semantic Communication (SC) backdoor attacks aim to utilize triggers to manipulate the system into producing predetermined outputs via backdoored shared knowledge. Current SC backdoors adopt monomorphic paradigms with single attack target, which suffers from limited attack diversity, efficiency, and flexibility in heterogeneous downstream scenarios. To overcome the limitations, we propose SemBugger, a polymorphic SC backdoor. By dynamically adjusting the trigger intensity, SemBugger finely-grained controls over the SC knowledge to generate diverse malicious results from the system. Specifically, SemBugger is realized through a multi-effect poisoning-training framework. It introduces graded-intensity triggers to poison training data and optimizes SC systems with hierarchical malicious loss. The trained system’s knowledge dynamically adapts to trigger intensity in inputs to yield target outputs, all while preserving transmission fidelity for benign samples. Moreover, to augment SC security, we propose a provable robustness defense that resists SemBugger’s homogeneous attacks through a controlled noise mechanism. It operates via strategically adding noise in SC inputs, and we formally provide a theoretical lower bound on the defense efficacy. Experiments across diverse SC models and benchmark datasets indicate that SemBugger attains high attack efficacy while maintaining the regular functionality of SC systems. Meanwhile, the designed defense effectively neutralizes SemBugger attacks. I Introduction Diverging from classical Shannon transmission models, Semantic Communication (SC) establishes a new paradigm, where it processes and transmits semantic units of information rather than conventional raw data bitstreams [17, 35, 3, 10, 38]. SC employs shared knowledge or cognitive semantic mappings to selectively extract and convey task-relevant details, and attains remarkable bandwidth reduction. This knowledge-driven approach supports adaptive compression that dynamically adjusts to both the receiver’s knowledge and the specific communication tasks. Moreover, owing to the bandwidth efficiency and context-aware comprehending capabilities, SC is implemented in several frontier applications, e.g., Extended Reality (XR), Vehicle-to-Everything (V2X), Smart Internet of Things (Smart IoT), and Intelligent City [39, 22, 8, 6, 41]. Despite the recent advances in SC, empirical research has uncovered its security vulnerabilities of backdoor threats [20, 44, 45, 30, 1]. The illustration of SC backdoors is depicted in Fig. 1. By poisoning the training of SC systems, adversaries can implant malicious functionality in the shared knowledge (i.e., backdoor), which causes the trained system to exhibit predetermined adversarial behaviors whenever it encounters trigger-embedded inputs, while preserving its performance on benign data. SC backdoors were first investigated in SC downstream tasks, where block-patch triggers were pasted into inputs to induce misclassification [20]. Several works transplanted the attacks into the transmission task, wherein they optimized the trigger design into implicit styles and markedly enhanced backdoor stealthiness [44]. Prior studies have also implanted backdoors into SC-driven autonomous driving systems and manipulated the perception-to-decision transmission pipeline to discard specific visual cues (i.e., triggers), whereby it potentially inducing spurious inferences [45]. Figure 1: Illustration of backdoor attacks against SC systems. Adversaries embed specific triggers into the input samples at the transmitter side (i.e., data poisoning), inducing the system to deliver poisoned data toward predetermined malicious outputs while retaining normal transmission efficacy for benign samples. These hostile outputs may cause abnormal execution results in downstream tasks and undermine system integrity. Current research can be primarily featured as a monomorphic attack paradigm, wherein the encoding-decoding backdoor mechanism implanted in shared knowledge responds exclusively to a specific trigger or trigger pattern, producing a deterministic, singular malicious output [16, 42, 12, 25]. To our knowledge, all existing SC backdoors possess this property. While prior works have advanced the field, existing backdoor methods adhere to monomorphic paradigms. This static is constrained to single-objective adversarial manipulations (i.e., transmitting all trigger-embedded data as a fixed malicious target). However, communication systems inherently operate in “one-to-many” or “many-to-many” configurations that render adversaries’ monolithic attack patterns fundamentally incompatible with the polymorphic requirements of targeted malicious intentionality across diverse users. Additionally, this paradigm incurs critically deficient flexibility, and adversaries must implant distinct backdoors tailored to specific malicious goals to fulfill varied intents, which exposes diminished operational efficiency and increases detection risks. To overcome the above shortcomings, we propose a polymorphic SC backdoor-SemBugger, which induces targeted output control via implicit trigger injection into inputs, and achieves differentiable regulation over output results via trigger intensity. To implant SemBugger backdoor into SC shared knowledge through training for joint source-channel coding, a two-step multi-effect poisoning-training framework is developed. It first dynamically synthesizes sample-specific triggers via a neural generator, then poisons the training data by an intensity-stratified injection strategy. The poisoned data are subsequently applied for SC system training and backdoor implantation, with a hierarchical loss optimizing multi-target attack objectives, regular system functionality, and trigger invisibility simultaneously. Beyond adversarial investigation, to effectively defend against SemBugger attacks, we correspondingly devise a provable robustness defense strategy. With inserting carefully calibrated noise signals into inputs, the proposed strategy neutralizes potential backdoor triggers without compromising systematic functionality for benign data transmission. Crucially, we formally prove a theoretical lower-bound guarantee on its defensive performance. Our principal contributions can be summarized below. 11. We introduce a polymorphic SC backdoor methodology-SemBugger. It engenders malicious outputs via shared knowledge from SC systems by implicitly injecting input-specific trigger patterns, where the attack results can be dynamically regulated by trigger intensity. Moreover, to implant backdoors into knowledge of victim systems, a multi-effect poisoning-training framework is designed. 22. To mitigate SemBugger attacks, a defensive strategy is developed that perturbs inputs with carefully crafted noise. This operation disrupts latent trigger patterns within inputs to prevent backdoor activation and retains minimal functionality impact for benign inputs. 33. We establish rigorous theoretical guarantees (i.e., certified robustness) for the proposed defense, proving a strict lower bound on its protective efficacy. To the best of our knowledge, this is the first work that explores certified robustness for SC backdoors. 44. Experimental evaluations on SC architectures and benchmark datasets manifest that SemBugger effectively attains high attack success rates and preserves benign data fidelity. Additionally, the proposed defense strategy efficiently deters potential SemBugger threats. I Background and Related Work I-A Semantic Communication Framework The SC system f:→f:X functions by encoding and conveying the semantic information of data. In this communication architecture, the semantic encoder at the transmitter, denoted as enc:→P_enc:X , conducts feature extraction and compression on the source data x∈x and produces a condensed semantic representation s=enc(x)s=P_enc(x). The Compression Rate CRCR is defined as the ratio of the original data size to the semantic representation size (CR=|x||s|CR= |x||s|). Next, the system performs channel encoding, which integrates error correction codes and additional redundancy to generate the encoded signal c=ℋenc(s)c=H_enc(s) for transmission: =ℋenc(enc(x))‖ℋenc(enc(x))‖2,c′=+, = H_enc (P_enc(x) ) \|H_enc (P_enc(x) ) \|_2, c =HX+N, (1) where H is the channel transfer matrix and N is the noise vector. At the receiver side, channel decoding is executed to restore the distorted semantic representation s^=ℋenc−1(c′) s=H^-1_enc(c ), where c′c represents the received signal affected by channel disturbances like noise and fading. Finally, the semantic decoder at the receiver, enc−1:→^P^-1_enc:S→ X, processes the recovered semantic data s s to reconstruct the estimated output x^=enc−1(s^) x=P^-1_enc( s). During the training phase, the semantic encoder encP_enc and decoder enc−1P^-1_enc are jointly optimized to acquire a shared knowledge base. It has three key aspects: 1)1) extraction of essential semantic features, 2)2) efficient encoding of semantic information, and 3)3) accurate mapping to desired outputs. This guarantees consistent and aligned semantic understanding between communication endpoints [2, 13, 24, 36, 43]. Besides the above investigations, State-of-the-Art (SOTA) SC research focuses on: 1)1) Task-Oriented Efficient Coding: Domain-specific semantic encoders are designed to extract mission-critical features (e.g., tumor characteristics in medical diagnostics or navigation-relevant objects in autonomous vehicles) while eliminating non-essential information [29]. 2)2) Joint Semantic-Channel Optimization: This approach synergizes robust semantic symbol construction with adaptive transmission strategies to mitigate time-varying channel distortions [19]. 3)3) Semantic-Centric Resource Management: Network resources are intelligently allocated via semantic importance, which preferentially supports time-critical semantic streams (e.g., emergency notifications) through adaptive bandwidth allocation and edge resource orchestration [32]. 4)4) Interference-Robust Semantic Delivery: Reliability under adverse propagation conditions is fortified via salient feature preserving encoding and jointly optimized semantic and channel processing [11]. I-B Semantic Communication Backdoor In SC system f, the adversary A injects a specific trigger pattern Δ into the original input x∈x at the transmitter side to construct an adversarial poisoned sample xadv=x⊕Δx_adv=x , whereby it causes the receiver’s decoder enc−1P^-1_enc to produce an A-specified erroneous output xerror≠x_error≠ x. TABLE I: Comparison of SC backdoor methods in three aspects: 1)1) attack stealthiness, 2)2) generalizability in transmission scenarios, and 3)3) polymorphism for varying targets. Backdoor Scheme against SC Systems Capacity SC Trojan [20] BASS [44] IHTG [45] CSBA [30] Ours∗ Stealthiness ✗ ✗ ✓ ✓ ✓ Generality ✗ ✓ ✓ ✓ ✓ Polymorphism ✗ ✗ ✗ ✗ ✓ Study [20] first explored backdoor attacks in SC systems f. Based on downstream classification, it proposed a basic backdoor method that: 1)1) embeds designed block-patch triggers into selected training samples, and 2)2) reformulates the loss to jointly optimize both the trigger-target association and normal communication performance. This dual-optimization preserves regular f performance while enabling backdoor activation. Zhou et al. [44, 45] advanced SC backdoors by extending the applicability from classifications to general transmission scenarios. They 1)1) enhanced trigger optimization, augmenting the stealthiness of triggering patterns, and 2)2) redesigned learning loss and kept f retain normal efficacy and output malicious transmission targets for the poisoned. Xu et al. [30] empirically demonstrated backdoor attacks in autonomous driving SC systems. By exploiting specific semantic element as the trigger, their method results in element suppression (i.e., removal) when detected, which realizes covert manipulation via semantic-level backdoor. Subject to compliance requirements, backdoors can also be leveraged for benign and controllable functionalities [16]. 11) Trigger patterns may be used to implement model watermarking and provenance verification, empowering one to confirm whether a model belongs to a particular vendor and whether it has been stolen or illegally redistributed. 22) Such mechanisms can further support access control by allowing the model to operate normally only when presented with valid trigger keys, consequently reducing the value of unauthorized deployments. 33) In security engineering, they may be adapted to honeypot-style practices: embedding known triggers in a controlled environment to systematically evaluate detection capabilities and identify potential attacks. While preliminary inspections for SC backdoors were conducted, current methodologies remain constrained by a fixed attack target and singular trigger-malicious activation correlation, with fundamental limitations manifested in operational flexibility. Although a few multi-objective studies in Computer Vision (CV) address related problems, the methods designed for classification backdoors (which merely nudge low-dimensional outputs across a decision boundary) are ill-suited to SC, because in this setting, a backdoor must concurrently 1)1) manipulate high-dimensional continuous reconstructions, 2)2) remain robust to channel noise and codec compression, and 3)3) preserve normal semantic fidelity under the tightly coupled parameters of transmitter and receiver. These requirements render current methods ineffective for SC [31, 27, 34, 15]. To better summarize related research, Tab. I compares SC backdoors in three aspects: 1)1) backdoor stealthiness, 2)2) generalizability for transmission tasks, and 3)3) polymorphism to varying malicious targets. I-C Backdoor Threat Defense Current neural backdoor defenses can primarily be categorized via four aspects: data, training, model, and deployment [16, 14]. 11) Regarding data side, suspicious poisoning can be identified via anomalous-sample consistency checks, together with establishing a traceable data supply chain. 22) Concerning training side, robust training and regularization, noise injection, and trigger-suspicion–driven training constraints can be adopted to reduce the model overfitting to rare trigger patterns. 33) For model side, backdoor representations can be weakened or removed via neuron pruning and channel sparsification, reverse-engineering–based trigger search and sanitization, and fine-tuning with clean data. 44) From deployment side, combining input anomaly detection and output consistency monitoring mechanisms powers degradation or blocking when suspected trigger behaviors are detected. Although backdoor defenses for classification tasks have been extensively studied, defensive strategies for transmission tasks (i.e., SC) remain underexplored. To the best of our knowledge, there are currently no defense methods specifically designed for backdoors in SC systems. I Proposed Methodology We first present the design requirements and then formalize the details of our proposed SemBugger framework. Figure 2: Illustration of the proposed SemBugger. 1)1) Selected victim samples are injected with multi-intensity triggers crafted by the trigger generator to construct a multi-dimensional poisoned dataset. 2)2) By training with hierarchical loss, the system learns to transform inputs with varying-intensity triggers into differentiated malicious targets, while preserving functionality on benign data. 3)3) Adversaries achieve differential control over hostile outputs by embedding multi-intensity triggers in inputs. I-A Design Requirements The present research seeks to develop a backdoor approach characterized by three foremost features: Flexibility. The proposed attack framework should require robust polymorphic target compatibility while constructing a tailored control scheme for heterogeneous attack targets. Consequently, it will increase attack versatility. Stealthiness. The backdoored SC system should sustain uncompromised robust functionality across multiple transmission environments. This preserves the integrity of original systems, retaining uninterrupted service availability and indirectly raising the backdoor’s stealthiness. Imperceptibility. The attack data must remain visually and statistically indistinguishable from legitimate data to circumvent human analyst inspections. This covertness directly contributes to adversarial efficacy by reducing anomaly alert during manual triage, and increasing the mean time to detection. I-B Methodology Insights To fulfill the method criteria in Sec. I-A, we embed imperceptible trigger noise within input samples to enable precise modulation of backdoor activation dynamics. 1)1) Through precise modulation of noise ratio, we attain multi-target control over backdoor activation outputs and eliminate external control variables. Concurrently, throughout the optimization procedure, 2)2) we preserve the original system’s training performance metrics to secure unimpaired transmission proficiency. 3)3) The amplitude of the noise is optimized to persist that the trigger-embedded samples display no perceptible anomalies. Also, 4)4) contrary to conventional spatially localized trigger patterns, the noise is globally distributed, whereby it demonstrates better spatial uniformity and robust partial-trigger activation capabilities. I-C SemBugger Framework With the insights from Sec. I-B, the implementation details of our proposed SemBugger are given. We adopt a multi-effect poisoning-training framework to implant backdoors in SC system f’s shared knowledge, whereby it enables controlled generation of multiple malicious transmission results during deployment by precise regulation of trigger noise ratio. The poisoning-training framework consists of two steps: 1)1) Multi-Dimensional Data Poisoning and 2)2) Hierarchical System Backdoor Training. In the 11st step, a trigger generator is deployed to infect the training dataset trainD_train with precisely calibrated noise ratios. Subsequently, f performs system training using a hybrid dataset comprising both poisoned set poiD_poi and clean data trainD_train to embed our desired backdoor functionality. The training procedure is schematically illustrated in Fig. 2. I-C1 Multi-Dimensional Data Poisoning The available clean training dataset trainD_train is applied to synthesize a poisoned dataset poiD_poi through a neural trigger generator G. We suppose T different adversarial targets will be configured in attacks. Specifically, based on the poisoning rate parameter γ∈(0,1)γ∈(0,1), we first construct the victim data victimD_victim by randomly sampling from the original training set trainD_train via sampling function πγ:train→victim _γ:D_train _victim, such that |victim|=γ|train||D_victim|=γ|D_train|: victim=xi∣xi∼πγ(train),i=1,…,⌊γN⌋,D_victim= \x_i x_i _γ(D_train),\ i=1,…, γ N \, (2) where N=|train|N=|D_train| denotes the cardinality of the training set. With victimD_victim, for each sample xix_i in it, a sample-specific trigger Δi _i is synthesized via a neural generator G (we adopt an Attention U-Net encoder architecture [18] for G’s setup): Δi=(xi),wherexi∈victim. _i=G(x_i), x_i _victim. (3) For T different attack targets, we construct T poisoned subsets, where the k-th subset poi(k)D^(k)_poi contains all poisonous samples with trigger noise applied at a ratio of k/Tk/T (we define it as the k-th level trigger noise): poi(k)=xi+kTΔi|xi∈victim,∀k∈1,2,⋯,T.D^(k)_poi= \x_i+ kT _i\; |\;x_i _victim \, ∀ k∈\1,2,\ ·s,T\. (4) Finally, the complete poisoned dataset poiD_poi is the union of these subsets poi(k)D^(k)_poi, which is expressed as poi=⋃k=1Tpoi(k).D_poi= _k=1^TD^(k)_poi. (5) The poisoned data poiD_poi and trigger generator G will be exploited in system f training for backdoor implantation. I-C2 Hierarchical System Backdoor Training By training, we embed backdoor behaviors into f, and force it to generate specified malicious transmission outputs according to varying trigger noise ratios present in inputs. Specifically, we take a hierarchical malicious loss-based training framework for system f, which jointly optimizes f via the clean training set trainD_train and poisoned dataset poiD_poi to derive controlled backdoor implantation. First, by minimizing the feature distance between poisoned samples poiD_poi and target malicious outputs, the trigger Δ is rigorously constrained to divert input samples toward predetermined mistransmission of f. Second, f’s regular performance on benign data is maintained by optimizing the standard transmission loss function over clean set trainD_train. Moreover, the imperceptibility of Δ is augmented by restricting the perceptual similarity between poisoned and original source samples in the visual domain. Gaining from the above analysis, this multi-tiered optimization architecture is expressed through training SC system with the following loss functions. Multi-Target Loss ℒaL_a: We promote polymorphic backdoor implantation for regulable multi-target attacks in SC systems: ℒa=∑k=1Txi(k)∈poi(k)[‖xerror(k)−f(xi(k),θ)‖22⏟AttackOptimization],L_a= _k=1^TE_x^(k)_i ^(k)_poi [ \|x_error^(k)-f(x^(k)_i,θ)\|_2^2_ \ Optimization ], (6) where xerror(k)x_error^(k) denotes the k-th malicious transmission target specified by adversaries and θ implies the semantic encoder-decoder parameters. Through optimizing the loss between f(xi(k),θ)f(x^(k)_i,θ) and k-th manipulated target xerror(k)x_error^(k), the trained f system will transit data containing k-th level triggers as xerror(k)x_error^(k) upon deployment, since f learns shared knowledge of mapping k-th level triggers to xerror(k)x_error^(k). System Integrity Loss ℒbL_b: It upholds the functional integrity of benign sample transmission in the SC system: ℒb=xi∈train[‖xi−f(xi,θ)‖22].L_b=E_x_i _train [\|x_i-f(x_i,θ)\|_2^2 ]. (7) By minimizing the loss between f(xi,θ)f(x_i,θ) and benign samples xix_i, the trained f system preserves its data transmission capability for normal (i.e., unperturbed) data. Trigger Imperceptibility Loss ℒpL_p: Trigger perceptibility is minimized through optimization, leading to augmented attack covertness for trigger embedding: ℒp=∑k=1Txi(k)∈poi(k),xi∼train[w1(1−SSIM(xi,xi(k)))+w2(1−TC(xi,xi(k)))+w3(1−CSIM(xi,xi(k)))], splitL_p&= _k=1^TE_x^(k)_i ^(k)_poi,x_i _train [w_1 (1-SSIM(x_i,x^(k)_i) )\\ & +w_2 (1-TC(x_i,x^(k)_i) )+w_3 (1-CSIM(x_i,x^(k)_i) ) ], split (8) where SSIM(⋅,⋅)SSIM(·,·) symbolizes Structural Similarity Index Measure; TC(⋅,⋅)TC(·,·) represents Tanimoto Coefficient; and CSIM(⋅,⋅)CSIM(·,·) stands for Cosine Similarity. With the similarity (i.e., SSIM, TC, and CSIM) between xi(k)x^(k)_i and xix_i refined, the trigger generator G learns to craft imperceptible implicit triggers Δ . Semantic Contrastive Loss ℒcL_c: We separate the semantic representations of poisoned samples and benign samples to accelerate SC system training convergence: ℒc=∑k=1Txi(k)∈poi(k),xi∼train[max(0,m−Dis(enc(xi),enc(xi(k))))]. splitL_c&= _k=1^TE_x^(k)_i ^(k)_poi,x_i _train\\ & [ (0,m-Dis (P_enc(x_i),\ P_enc(x^(k)_i) ) ) ]. split (9) The optimization of distance between enc(xi)P_enc(x_i) and enc(xi(k))P_enc(x^(k)_i) induces discriminative latent space separation for infected and normal samples after semantic encoding, which serves as accelerating convergence in training. Overall Training Loss. Combining the above analytical results, we formulate the final loss optimization: ℒ=λa⋅ℒa+λb⋅ℒb+λp⋅ℒp+λc⋅ℒc,L= _a·L_a+ _b·L_b+ _p·L_p+ _c·L_c, (10) θ(t+1)←θ(t)−ηθ⋅∇θℒθ,θ(t+1)←θ(t)−η⋅∇θℒθ, \ aligned θ^(t+1)&←θ^(t)- _θ· _θL_θ,\\ θ^(t+1)_G&←θ^(t)_G- _G· _ _GL_ _G, aligned . (11) where θ _G symbolizes parameters of the trigger generator G. Through the training, we complete backdoor implantation within the SC system. The algorithmic framework of SemBugger is formally presented in Alg. 1. Input: Initial SC system f(⋅,⋅)f(·,·) (w/ para. θ), Trigger generator (⋅)G(·) (w/ para. θ _G), Poisoning rate γ, Malicious multi-targets xerror(k)k=1T \x_error^(k) \_k=1^T, Training dataset trainD_train, and Training epoch amount M Output: Backdoored SC system f(⋅)f(·) and Trained trigger generator (⋅)G(·) 1 0.07cm /* Victim Data Selection */ 2 3victim∼γtrainD_victim _γD_train 4 foreach epoch ← 1 to M do 5 poi(k)k=1T←∅ \D^(k)_poi \_k=1^T← /* Multi-Dimensional Data Poisoning */ 6 foreach sample xi∈victimx_i _victim do 7 Δi=(xi) _i=G (x_i ) 8 foreach k ← 1 to T do 9 poi(k)←poi(k)∪xi+kTΔiD^(k)_poi ^(k)_poi∪ \x_i+ kT _i \ 10 11 poi=⋃k=1Tpoi(k)D_poi= _k=1^TD^(k)_poi /* Hierarchical System Backdoor Training */ 12 13 foreach sample xi∈trainx_i _train do 14 Compute f(xi,θ)f(x_i,θ) 15 16 foreach poi(k)∈poiD^(k)_poi _poi do 17 foreach sample xi(k)∈poi(k)x^(k)_i ^(k)_poi do 18 Compute f(xi(k),θ)f(x^(k)_i,θ) 19 20 21 Compute loss ℒaL_a, ℒbL_b, ℒpL_p, and ℒcL_c in Eq. (10) 22 θ=θ−η∇θℒθ=θ-η _θL; θ=θ−η∇θℒ _G= _G-η _ _GL /* SC system gets backdoored after training */ return f(⋅,⋅)f_(·,·) and (⋅)G(·) Algorithm 1 SemBugger I-D Attack Conducting With the completion of SC system f training via the framework in Sec. I-C, f (or its shared knowledge) gets backdoored. More precisely, after f deployment, adversaries intending to manipulate f’s outputs to produce the k-th order malicious target xerror(k)x_error^(k) (i.e., backdoor activation) can simply inject the corresponding k-th level trigger noise Δ into the input data stream to operationalize diversely regulable SC system reconstructed result governance. IV Certified Defense Categorically, there are two aspects of defenses to build robust learning systems: empirical approaches and certified methods. The former class typically targets mitigation of known attack variants but remains vulnerable to sophisticated adaptive adversaries, and it brings about a cat-and-mouse game between adversaries and defenders. For example, in image classification backdoors, [21] introduced a dynamic attack scheme that can bypass SOTA empirical protections [9, 37, 33, 26]. Consequently, our work is conducted around certified defense. In machine learning classification tasks, a certified defense guarantees consistent label prediction for all data points within a specified region around an input. With this foundation, we formally define certified backdoor defense in SC systems as maintaining identical transmission outputs for all data instances within a determined input region. In this section, the threat model is given first, then the defense method is detailed. Finally, we present rigorous theoretical robustness proofs of our defense method. IV-A Threat Model We take dual-perspective analysis from both the adversarial and defensive considering. Adversary Assumptions. Our threat model aligns with previous backdoor paradigms (e.g., SC Trojan, BASS, and CSBA) in SC. A compromised SC system, acquired by users through third-party training services or post-training modifications, holds dual behavior: 1)1) maintaining nominal performance on legitimate system inputs, while 2)2) executing adversarial misinterpretations and outputs when encountering trigger-embedded data. We adopt the strongest white-box attack assumption, wherein adversaries possess full knowledge of system parameters, architecture, loss functions, training data, and can leverage auxiliary datasets for attacks. This setting will stringently evaluate the efficacy of the defense mechanism. Defender Assumptions. The key capability resides in input data controllability, whereby we build adversarial robustness through preprocessing like noise addition and feature transformation and maintain black-box compatibility by avoiding system architecture modifications. Crucially, the defense provides formally verifiable security guarantees that assure output reliability within specified perturbation bounds. It can fundamentally preserve transmission consistency across both clean and adversarially modified inputs, and optimally balance robustness with system utility to retain regular performance. IV-B Defense Framework To mitigate backdoor impacts, we propose a general backdoor defense strategy named semantic smoothing that is model-agnostic and training-free. Next, we delineate the following aspects: 1)1) the data transmission methodology for testing inputs utilizing a smoothed SC system, 2)2) the theoretical robustness guarantees provided by the smoothed SC transmission systems. The architecture of the proposed defense framework is depicted in Fig. 3. Figure 3: Illustration of defense strategy against SemBugger. It is deployed during the operational phase of the SC system. Before data is input into the system, smoothed noise is added to invalidate potential triggers, which guarantees normal output at the receiver end without affecting regular data transmission. Semantic Smoothing. Consider a transmission problem from the input space ℝdR^d to the output space ℝdR^d. Semantic Smoothing constructs a smoothed transmitter S from a base telecommute transmitter f, where the output of S(x)S(x) is determined by averaging the transmission result of f under noise perturbation. We define the smoothed transmitter as follows: S(x)=ϵ∼(0,σ2I)[f(x+ϵ)],S(x)=E_ε (0,σ^2I) [f(x+ε) ], (12) where the noise ϵε follows an isotropic Gaussian distribution (0,σ2I)N(0,σ^2I). The hyperparameter σ controls the noise intensity (0.250.25 for experiments), balancing the protection and efficacy of the transmission process. Considering all the image pixels are in [0,1][0,1], we have the theorem that the backdoored transmitted image is bounded: Theorem 1. (Semantic robustness guarantee) Given the transmission function f:ℝd→ℝdf:R^d ^d, random noise ϵ∼(0,σ2I)ε (0,σ^2I), the smoothed transmission function S:ℝd→ℝdS:R^d ^d defined in (12), and ∀i=1,2,⋯,d,f(x)i≤1∀ i=1,2,·s,d,f(x)_i≤ 1, then the smoothed transmitter is L-Lipschitz: ∀x,x′∈ℝd,‖S(x)−S(x′)‖∞≤L‖x−x′‖2,∀ x,x ^d,||S(x)-S(x )||_∞≤ L||x-x ||_2, (13) where the L=2πσ2L= 2πσ^2. The proof for Theorem 1 is in the Supplemental Material. This result guarantees that the transmitted result under attacks is close to the one with clean input, providing the robustness of the smoothed transmit function. Successful Defense. For backdoored input x′:=x⊕Δx :=x , and T backdoor targets err:=xerror(k)k=1Terr:=\x_error^(k)\_k=1^T, we guarantee that the transmit results are not close to any of the targets. To describe it, we define a defense successful judgment function j(⋅|err):ℝd→0,1j(·|err):R^d→\0,1\, where 0 denotes successful defense (correct transmission) and 11 denotes successful attack (error transmission). Specifically, for each attack input containing triggers, we measure the SSIM between the reconstruction result (i.e., SC output) and the predefined malicious target: SSIM(f(x′),xerror(k))SSIM(f(x ),x_error^(k)). A valid attack is registered when the computed SSIM value surpasses the threshold τ, where the τ is determined via statistical analysis of the SSIM values collected under normal (attack-free) input SSIM(f(x),xerror(k))SSIM(f(x),x_error^(k)). Specifically, we first compute the mean μ and standard deviation σ of SSIM(f(x),xerror(k))SSIM(f(x),x_error^(k)) values from 10001000 benign communication samples. τ is then established as: τ=μ−3στ=μ-3σ. Then, j(f(x′)|err)=1j(f(x )|err)=1 if max SSIM(f(x′),xerror(k))≥τmax SSIM(f(x ),x_error^(k))≥τ, otherwise j(f(x′)|err)=0j(f(x )|err)=0. We define the smoothed defense successful judgment function as follows: J(x)=argmaxy∈0,1ℙ[j(f(x+ϵ)|err)=y],J(x)= _y∈\0,1\P [j(f(x+ε)|err)=y ], (14) where ϵ∼(0,σ2I)ε (0,σ^2I). We note that when we obtain the smoothed transmission results S(x)S(x) defined in (12), we can obtain J(x)J(x) at the same time with negligible computation workload. Assumption 2. We assume that, given a clean input x∉errx∉ err, it cannot be backdoored successfully because there is no trigger, then we have J(x)=0J(x)=0. Theorem 3. (Successful defense guarantee) Given an input x, and the smoothed judgment function J(⋅)J(·) defined in (14). For attack input x′:=x⊕Δx :=x , we guarantee that J(x′)=0J(x )=0 (successful defense) if ‖x′−x‖2≤R||x -x||_2≤ R, where R=σ(Φ−1(p0¯))R=σ( ^-1( p_0)), Φ−1 ^-1 is the inverse of the standard Gaussian cumulative distribution function, and p0¯ p_0 is the lower bound of the probability ℙ[j(f(x+ϵ)|err)=0]P [j(f(x+ε)|err)=0 ]. The proof for Theorem 3 is in the Supplemental Material. The results provide the guarantee that we can obtain a successful defense as long as the backdoor images are close to the clean image. The algorithm of our proposed certified defense framework is illustrated in Alg. 2. Input: Base (possibly backdoored) SC transmission system f(⋅;θ):ℝd→ℝdf(·;θ):R^d\!→\!R^d, test input set testD_test (or a single input x) Output: Defended transmission outputs S^(x)x∈test\ S(x)\_x _test 1 /* Transmission Phase Deployment */ 2 3foreach x∈testx _test do 4 ysum←y_sum 0 /* Transmitter Smoothing */ 5 for j←1j← 1 to N do 6 Sample ϵj∼(0,σ2I) _j (0,σ^2I) 7 x~j←Π[0,1](x+ϵj) x_j← _[0,1](x+ _j) /* Peer End Receiving */ 8 ysum←ysum+f(x~j;θ)y_sum← y_sum+f( x_j;θ) /* Result Constructing */ 9 S^(x)←1Nysum S(x)← 1Ny_sum 10 return Smoothed transmission results S^(x)x∈test\ S(x)\_x _test Algorithm 2 Semantic Smoothing Defense Framework Practical Implementation. Since our defense relies solely on injecting semantic-smoothing noise into the input samples, it requires no model retraining and introduces no additional modules such as detectors, filters, or auxiliary networks. Therefore, it can be deployed in a plug-and-play manner during the runtime stage. Concretely, 11) in online transmission, the transmitter applies a smoothed perturbation to each incoming input sample (regardless of whether it is benign or potentially trigger-bearing) according to a predefined noise, and then feeds the perturbed sample into the semantic communication system for transmission. 22) The receiver subsequently reconstructs the transmission result to obtain a smoothed output according to Eq. (12). By performing randomized smoothing in the input semantic space, this procedure suppresses backdoor activation while preserving the transmission efficacy on normal data. V Experiment We validate the efficacy of the proposed SemBugger attack through benchmarking against SOTA baselines. To examine influences of individual conditions, parameter-wise ablation analyses are also conducted. Additionally, the robustness of our defensive mechanism is empirically verified against the developed SemBugger methodology. We first present the experimental setting and subsequently proceed to the test results. V-A Experimental Settings V-A1 Victim SC Systems 55 SOTA SC systems were adopted for experimental assessment. 1)1) JSCC (Joint Source-Channel Coding) utilizes deep convolutional neural networks with residual connections to jointly optimize source compression and channel coding in an end-to-end learnable framework, which removes the demands for separate modular designs [2]; 2)2) JSCC-f (Deep Joint Source-Channel Coding with Feedback) introduces a novel two-way feedback mechanism comprising channel state information reporting and acknowledgment signals, whereby it enables real-time adaptive modulation of the encoder’s latent representations under time-varying fading channels [13]; 3)3) JSCC-q (Constellation Constrained Deep Joint Source-Channel Coding) implements a trainable vector quantization module with learnable codebook embeddings that discretizes the continuous latent space into finite clusters while maintaining gradient flow through straight-through estimator backpropagation [24]; 4)4) SCAN (Semantic Channel-Adaptive Networking) employs a content-aware gating mechanism that dynamically adjusts wavelet-based compression ratios by jointly analyzing semantic saliency maps and instantaneous channel capacity metrics to realize optimal rate-distortion tradeoffs [40]; 5)5) SemCC (Semantic Contrastive Coding) reformulates channel-induced impairments as differentiable noise layers within a Siamese network, where contrastive loss minimization aligns noisy and clean samples in a shared embedding space to enhance semantic invariance [23]. V-A2 Testing Datasets This study evaluated method performance across 44 standard CV benchmarks: 1)1) MNIST: A collection of 70,00070,000 handwritten digit images (0−90-9) with 28×2828× 28 grayscale pixels, featuring perfectly balanced classes (6,0006,000 training and 1,0001,000 test samples per digit) and 11.18%11.18\% average sparsity [5]. 2)2) F-MNIST: A clothing alternative maintaining MNIST’s format (7070 k 28×2828× 28 grayscale images) but containing 1010 fashion item categories (e.g., shirts and sneakers), which indicates greater visual complexity [28]. 3)3) CIFAR-10: A set of 60,00060,000 tiny 32×3232× 32 color images across 1010 object classes (animals, vehicles etc.) with measured 15.7%15.7\% label noise [7]. 4)4) ImageNet: The large-scale visual database with 1.281.28 million high-resolution natural images (average 469×387469× 387 pixels) spanning 1,0001,000 everyday object categories in realistic long-tailed distribution (most frequent class: 3,1703,170 samples; rarest: 468468) [4]. Our tests harnessed a class-balanced subset containing 55 randomly sampled categories, with a total of 40,00040,000 training images and 10,00010,000 test images (8,0008,000 training and 2,0002,000 testing instances per category). V-A3 Evaluation Metrics The method performance was assessed along 22 primary aspects: efficacy and stealthiness. Attack Efficacy. We employed the Attack Success Rate (ASR) to evaluate attack capability. Specifically, since our attack method manipulates SC system into producing malicious outputs by injecting triggers into inputs, ASR is calculated as: ASR=# Successful Attack Trials# Total Number of Attacks,ASR= \# Successful Attack Trials\# Total Number of Attacks, (15) where the Successful Attack Trials refers to the count of instances where the SC system produces malicious outputs under the influence of the trigger, while the Total Number of Attacks represents all attempted attack samples. Unless otherwise specified, ASR refers to the average attack success rate across all multi-target attacks. Specifically, we utilized ASRiASR_i to denote ASR for the i-th malicious target result (i.e., xerror(k)x_error^(k)). We define the criteria for a successful attack with the attack successful judgment function j(x|err)j(x|err) described in Sec. IV-B. This metric directly reflects the attack effectiveness of the method, and a higher ASR indicates stronger control over victim SC systems. Attack Stealthiness. To strengthen the attack stealthiness, it is imperative that the backdoored system preserves the regular functionality with minimal deviation. Namely, backdoored and benign systems should maintain highly consistent transmission efficiency when processing benign data. Therefore, the Peak Signal-to-Noise Ratio (PSNR) difference was used to evaluate the backdoor stealthiness. We take PSNR∘ to denote the benign data PSNR of the unattacked SC system, and PSNR* to represent that of the backdoored system. For our objective, the efficiency gap (Δ ) between PSNR∘ and PSNR*: ΔPSNR=PSNR∘−PSNR∗, =PSNR -PSNR^*, (16) ought to be kept as low as possible. PSNR measures the distortion between a processed signal and the original. It is derived from the Mean Squared Error (MSE) and expressed in decibels (dB), and higher values indicate less distortion. The PSNR formula is: PSNR=10⋅log10(MAXI2MSE),PSNR=10· _10 ( MAX_I^2MSE ), (17) where: MAXIMAX_I is the maximum possible pixel value (e.g., 255255 for 88-bit images) and MSE (Mean Squared Error) is given by MSE=1mn∑i=0m−1∑j=0n−1[I(i,j)−K(i,j)]2,MSE= 1mn _i=0^m-1 _j=0^n-1 [I(i,j)-K(i,j) ]^2, (18) where I and K represent the original and distorted images, while m and n denote the image resolution. V-A4 Comparison Baselines We levered 33 SOTA SC backdoor methodologies as benchmarks: 1)1) SC Trojan, the pioneering backdoor attack framework originally designed for downstream classification tasks, which we adapt to transmission scenarios through loss function modification [20]; 2)2) BASS, the first dedicated backdoor attack method specifically engineered for SC transmission tasks, capable of precise targeted output induction via patch trigger [44]; and 3)3) IHTG, an adjusted variant of BASS that considerably improves attack stealthiness through optimized trigger pattern design, with the triggers made substantially more imperceptible [45]. V-B Comparison Study We evaluated the attack performance of SemBugger on 44 distinct datasets by monitoring both ASR and the Δ for benign samples across 44 datasets after implementing attacks. Besides comparing with SC Trojan, BASS, and IHTG, we also benchmarked its performance against a clean, uncompromised SC system. The attack experiments were conducted under both standard communication conditions (Signal-to-Noise Ratio [SNR] =25=25 dB) and noisy environments (SNR =5=5 dB), with the compression ratio fixed at 14 14 and the poisoning rate γ set to 20%20\%. Dataset partitioning followed a 4:14:1 ratio, with 4040 k samples designated for training and 1010 k for evaluation across all sets. We configured the multi-target attack result number as T=4T=4, and T samples are randomly selected in advance from the dataset as malicious targets. Note that our method remains effective even when T takes other settings. Tabs. I and I display the results for 2525 dB communication conditions, and Tabs. IV and V provide the results for 55 dB. TABLE I: Comparison with the State-of-the-Art SC backdoors on MNIST, F-MNIST, CIFAR-10, and ImageNet tasks under standard SNR =25=25 dB (ASR↑ : %\%; PSNR*↑ , PSNR∘, Δ ↓ : dB). We mark the best results in bold across different tuning methods. Please cf. Sec. V-B for detailed explanations. MNIST Dataset F-MNIST Dataset CIFAR-10 Dataset ImageNet Dataset Methods ASR PSNR* PSNR∘ Δ ASR PSNR* PSNR∘ Δ ASR PSNR* PSNR∘ Δ ASR PSNR* PSNR∘ Δ Attacking JSCC architecture Clean 0.00 36.47 36.47 0.00 0.00 33.82 33.82 0.00 0.00 31.15 31.15 0.00 0.00 34.93 34.93 0.00 SC Trojan 85.76 33.33 36.47 3.14 91.81 29.60 33.82 4.22 86.68 25.78 31.15 5.37 89.88 32.08 34.93 2.85 BASS 93.65 33.90 36.47 2.57 95.74 29.96 33.82 3.86 93.62 26.03 31.15 5.12 95.86 30.69 34.93 4.24 IHTG 95.71 34.45 36.47 2.02 96.77 29.88 33.82 3.94 93.59 29.30 31.15 1.85 97.85 30.81 34.93 4.12 SemBugger 99.92 35.92 36.47 0.55 99.94 32.17 33.82 1.65 99.91 29.05 31.15 2.10 99.96 34.18 34.93 0.75 Attacking JSCC-f architecture Clean 0.00 38.76 38.76 0.00 0.00 36.17 36.17 0.00 0.00 33.42 33.42 0.00 0.00 37.23 37.23 0.00 SC Trojan 88.75 32.87 38.76 5.89 92.80 32.71 36.17 3.46 89.67 29.41 33.42 4.01 91.87 34.26 37.23 2.97 BASS 96.64 35.66 38.76 3.10 94.73 30.77 36.17 5.40 95.61 30.67 33.42 2.75 96.85 32.25 37.23 4.98 IHTG 94.70 35.76 38.76 3.00 93.76 33.70 36.17 2.47 93.58 29.07 33.42 4.35 95.84 35.43 37.23 1.80 SemBugger 99.93 37.66 38.76 1.10 99.95 35.32 36.17 0.85 99.92 31.22 33.42 2.20 99.97 35.28 37.23 1.95 Attacking JSCC-q architecture Clean 0.00 38.53 38.53 0.00 0.00 35.82 35.82 0.00 0.00 33.14 33.14 0.00 0.00 36.91 36.91 0.00 SC Trojan 91.74 33.78 38.53 4.75 92.79 30.52 35.82 5.30 89.66 30.09 33.14 3.05 90.86 34.03 36.91 2.88 BASS 97.63 35.54 38.53 2.99 95.72 31.32 35.82 4.50 97.60 27.99 33.14 5.15 96.84 33.51 36.91 3.40 IHTG 95.69 36.35 38.53 2.18 94.75 31.82 35.82 4.00 95.57 29.87 33.14 3.27 95.83 35.02 36.91 1.89 SemBugger 99.94 37.53 38.53 1.00 99.96 33.67 35.82 2.15 99.93 32.54 33.14 0.60 99.98 35.11 36.91 1.80 Attacking SCAN architecture Clean 0.00 40.23 40.23 0.00 0.00 37.54 37.54 0.00 0.00 34.83 34.83 0.00 0.00 38.62 38.62 0.00 SC Trojan 84.73 37.52 40.23 2.71 90.78 31.64 37.54 5.90 85.65 30.39 34.83 4.44 87.85 34.95 38.62 3.67 BASS 92.62 35.23 40.23 5.00 93.71 34.98 37.54 2.56 91.59 30.71 34.83 4.12 94.83 34.73 38.62 3.89 IHTG 91.68 36.43 40.23 3.80 93.74 35.52 37.54 2.02 92.56 32.88 34.83 1.95 93.82 34.42 38.62 4.20 SemBugger 99.95 38.23 40.23 2.00 99.97 37.04 37.54 0.50 99.94 33.53 34.83 1.30 99.99 36.87 38.62 1.75 Attacking SemCC architecture Clean 0.00 39.20 39.20 0.00 0.00 39.34 39.34 0.00 0.00 39.82 39.82 0.00 0.00 39.62 39.62 0.00 SC Trojan 89.72 35.09 39.20 4.11 87.77 33.81 39.34 5.53 85.64 36.53 39.82 3.29 90.84 36.88 39.62 2.74 BASS 92.61 36.17 39.20 3.03 91.70 34.21 39.34 5.13 93.58 35.46 39.82 4.36 93.82 36.97 39.62 2.65 IHTG 93.67 36.56 39.20 2.64 92.73 36.01 39.34 3.33 92.55 35.63 39.82 4.19 93.81 37.71 39.62 1.91 SemBugger 99.96 38.30 39.20 0.90 99.98 37.84 39.34 1.50 99.95 37.77 39.82 2.05 100.00 38.97 39.62 0.65 TABLE I: Target level ASR experimental results on MNIST, F-MNIST, CIFAR-10, and ImageNet tasks under standard SNR =25=25 dB (ASR↑ : %\%). Please cf. Sec. V-B for detailed explanations. MNIST Dataset F-MNIST Dataset CIFAR-10 Dataset ImageNet Dataset System ASR1 ASR2 ASR3 ASR4 ASR1 ASR2 ASR3 ASR4 ASR1 ASR2 ASR3 ASR4 ASR1 ASR2 ASR3 ASR4 JSCC 99.85 99.97 99.94 99.92 99.92 99.97 99.89 99.98 99.91 99.90 99.86 99.96 99.94 99.96 99.90 100.00 JSCC-f 99.91 99.94 99.76 100.00 99.93 99.94 99.92 100.00 99.88 99.87 99.80 99.82 99.89 99.94 99.90 100.00 JSCC-q 99.90 99.92 99.84 99.88 99.94 99.92 99.90 99.92 99.87 99.95 99.88 99.93 99.95 99.97 99.89 99.96 SCAN 99.88 99.90 99.83 100.00 99.94 99.96 99.87 99.96 99.91 99.95 99.87 99.92 99.99 100.00 99.94 99.99 SemCC 99.96 99.97 99.93 99.99 99.97 99.98 99.94 99.99 99.93 99.97 99.94 99.97 100.00 100.00 100.00 100.00 Average 99.90 99.94 99.86 99.96 99.94 99.95 99.90 99.97 99.90 99.93 99.87 99.92 99.95 99.97 99.93 99.99 Concerning the test results under 2525 dB, we get the following observations. 1)1) The experimental results confirm that SemBugger achieves better attack performance while maintaining minimal impact on the original SC systems (Tab. I). Concerning attack efficacy, SemBugger consistently attains near-perfect success rates (ASR >99.9%>99.9\% across all datasets and SC architectures), wholly outperforming baseline backdoor attacks (SC Trojan, BASS, and IHTG), which typically depicts ASR between 85%85\% and 97%97\%. On the other hand, regarding system fidelity preservation (i.e., attack stealthiness), SemBugger expresses the least PSNR degradation (Δ ), with average reductions of only 1.191.19 dB across all test cases, where it is at least a 50%50\% reduction in distortion contrasted with baseline methods, which averages between 2.52.5 dB and 4.54.5 dB degradation. This is because we not only uphold the training paradigm for benign samples but also exploit a contrastive loss to separate their representations from those of the poisoned. Especially noteworthy is its performance on ImageNet with the JSCC architecture, where it maintains a high PSNR∗ of 34.1834.18 dB (compared to 34.9334.93 dB for clean data), incurring only a 0.750.75 dB drop while achieving 99.96%99.96\% ASR. 2)2) The results manifest that SemBugger gains high ASRs across multiple target scenarios. As shown in Tab. I, across 44 different datasets (MNIST, F-MNIST, CIFAR-10, and ImageNet) and 55 SC architectures (JSCC, JSCC-f, JSCC-q, SCAN, and SemCC), SemBugger keeps an average ASR exceeding 99.0%99.0\% for all 44 attack targets. Notably, it reaches an exceptional 99.96%99.96\% mean ASR on ImageNet set. Furthermore, the variation in ASR between different attack targets is minimal (maximum gap =0.15%=0.15\%), by which it indicates SemBugger’s stable performance across diverse targets. This combination of high ASR and negligible quality deterioration is consistent across all 55 architectures (JSCC, JSCC-f, JSCC-q, SCAN, and SemCC), which clearly proves SemBugger’s advantage in both attack potency and stealthiness. TABLE IV: Comparison with the State-of-the-Art SC backdoors on MNIST, F-MNIST, CIFAR-10, and ImageNet tasks under constrained SNR =5=5 dB (ASR: %\%; PSNR*, PSNR∘, Δ : dB). We mark the best results in bold across different tuning methods. Please cf. Sec. V-B for detailed explanations. MNIST Dataset F-MNIST Dataset CIFAR-10 Dataset ImageNet Dataset Methods ASR PSNR* PSNR∘ Δ ASR PSNR* PSNR∘ Δ ASR PSNR* PSNR∘ Δ ASR PSNR* PSNR∘ Δ Attacking JSCC architecture Clean 0.00 21.47 21.47 0.00 0.00 19.82 19.82 0.00 0.00 14.15 14.15 0.00 0.00 16.93 16.93 0.00 SC Trojan 76.39 16.32 21.47 5.15 79.36 14.02 19.82 5.80 71.46 7.61 14.15 6.54 79.29 11.41 16.93 5.52 BASS 89.37 17.85 21.47 3.62 87.68 16.23 19.82 3.59 86.87 10.02 14.15 4.13 90.27 13.43 16.93 3.50 IHTG 90.58 18.35 21.47 3.12 89.28 16.57 19.82 3.25 89.91 10.56 14.15 3.59 91.58 13.62 16.93 3.31 SemBugger 97.47 19.79 21.47 1.68 95.65 18.23 19.82 1.59 94.08 12.65 14.15 1.50 96.29 15.34 16.93 1.59 Attacking JSCC-f architecture Clean 0.00 23.76 23.76 0.00 0.00 21.17 21.17 0.00 0.00 16.42 16.42 0.00 0.00 19.23 19.23 0.00 SC Trojan 71.97 17.92 23.76 5.84 83.75 16.21 21.17 4.96 75.45 9.81 16.42 6.61 80.54 13.48 19.23 5.75 BASS 89.21 19.63 23.76 4.13 90.61 17.32 21.17 3.85 86.62 12.31 16.42 4.11 91.48 15.42 19.23 3.81 IHTG 90.58 19.87 23.76 3.89 86.88 17.64 21.17 3.53 90.11 12.89 16.42 3.53 88.29 15.68 19.23 3.55 SemBugger 96.95 21.63 23.76 2.13 94.51 19.66 21.17 1.51 96.16 15.03 16.42 1.39 95.12 17.62 19.23 1.61 Attacking JSCC-q architecture Clean 0.00 23.53 23.53 0.00 0.00 20.82 20.82 0.00 0.00 16.14 16.14 0.00 0.00 20.91 20.91 0.00 SC Trojan 81.75 17.51 23.53 6.02 80.92 14.21 20.82 6.61 72.32 10.11 16.14 6.03 77.33 12.82 20.91 8.09 BASS 93.05 19.41 23.53 4.12 86.91 17.21 20.82 3.61 91.27 11.59 16.14 4.55 91.40 17.39 20.91 3.52 IHTG 90.02 19.78 23.53 3.75 91.41 17.57 20.82 3.25 88.45 11.91 16.14 4.23 90.85 16.91 20.91 4.00 SemBugger 94.41 21.71 23.53 1.82 97.59 19.49 20.82 1.33 96.04 14.79 16.14 1.35 95.80 19.19 20.91 1.72 Attacking SCAN architecture Clean 0.00 23.23 23.23 0.00 0.00 20.54 20.54 0.00 0.00 15.83 15.83 0.00 0.00 19.62 19.62 0.00 SC Trojan 72.19 17.31 23.23 5.92 73.67 13.41 20.54 7.13 76.42 9.71 15.83 6.12 72.97 11.61 19.62 8.01 BASS 85.03 19.38 23.23 3.85 88.49 16.53 20.54 4.01 82.65 11.79 15.83 4.04 90.66 15.61 19.62 4.01 IHTG 83.66 19.53 23.23 3.70 89.97 16.81 20.54 3.73 85.72 12.01 15.83 3.82 88.33 15.83 19.62 3.79 SemBugger 95.28 21.52 23.23 1.71 97.81 19.03 20.54 1.51 94.44 14.51 15.83 1.32 96.70 18.17 19.62 1.45 Attacking SemCC architecture Clean 0.00 22.20 22.20 0.00 0.00 22.34 22.34 0.00 0.00 22.82 22.82 0.00 0.00 22.62 22.62 0.00 SC Trojan 80.55 16.35 22.20 5.85 74.32 16.55 22.34 5.79 67.75 14.21 22.82 8.61 77.28 16.71 22.62 5.91 BASS 86.43 18.76 22.20 3.44 82.74 18.81 22.34 3.53 89.21 19.39 22.82 3.43 86.57 19.18 22.62 3.44 IHTG 89.11 18.94 22.20 3.26 84.84 18.92 22.34 3.42 89.34 18.71 22.82 4.11 87.08 18.41 22.62 4.21 SemBugger 94.74 20.76 22.20 1.44 96.84 20.88 22.34 1.46 97.19 21.39 22.82 1.43 98.00 21.18 22.62 1.44 TABLE V: Target level ASR experimental results on MNIST, F-MNIST, CIFAR-10, and ImageNet tasks under constrained SNR =5=5 dB (ASR ↑ : %\%). Please cf. Sec. V-B for detailed explanations. MNIST Dataset F-MNIST Dataset CIFAR-10 Dataset ImageNet Dataset System ASR1 ASR2 ASR3 ASR4 ASR1 ASR2 ASR3 ASR4 ASR1 ASR2 ASR3 ASR4 ASR1 ASR2 ASR3 ASR4 JSCC 97.84 96.52 97.13 98.41 95.26 95.79 95.88 96.47 93.77 94.58 94.11 93.92 95.68 96.03 96.36 97.21 JSCC-f 96.32 97.21 96.86 97.38 93.65 94.48 95.24 94.59 95.67 96.36 96.09 96.61 94.25 95.18 95.76 95.42 JSCC-q 93.89 94.71 95.14 94.03 97.52 97.91 97.33 97.69 95.93 96.28 96.17 95.86 95.27 95.96 95.65 96.66 SCAN 94.51 95.08 95.29 96.34 96.85 97.46 97.77 97.03 93.81 94.13 94.96 94.37 96.12 96.57 96.65 97.29 SemCC 93.83 94.64 94.91 95.57 96.35 97.12 96.68 97.18 96.86 97.61 96.48 97.63 97.71 97.89 98.07 98.28 Average 95.28 95.63 95.87 96.35 95.93 96.55 96.58 96.59 95.21 95.79 95.56 95.68 95.81 96.33 96.50 96.97 Tabs. IV and V report quantitative results under a constrained SNR of 55 dB, comparing SemBugger with 33 attack baselines across JSCC, JSCC-f, JSCC-q, SCAN, and SemCC and 44 benchmark MNIST, F-MNIST, CIFAR-10, and ImageNet sets. We have some key analysis. 1)1) SemBugger consistently reaches the best ASR values, ranging from 94.0894.08% to 98.0098.00%, while retaining lower PSNR decline than baselines. Specifically, the average Δ caused by SemBugger remains between 1.321.32 dB and 2.132.13 dB across all test cases, whereby it is substantially less than SC Trojan (maxima =8.61=8.61 dB), BASS (maxima =4.55=4.55 dB), and IHTG (maxima =4.23=4.23 dB). For instance, on ImageNet, SemBugger reduces PSNR by only 1.591.59 dB on JSCC and 1.441.44 dB on SemCC, while realizing ASR of 96.2996.29% and 98.0098.00%. Similar trends are observed through other datasets, with PSNR* values invariably closer to the clean baseline. While both SemBugger and the baselines express diminished ASR and increased Δ under poorer communication conditions, their overall efficacy stays within acceptable bounds, with SemBugger demonstrating particularly stable behavior. 2)2) Tab. V summarizes the target-level ASR across 44 datasets and 55 SC architectures under an SNR of 55 dB. Overall, all systems achieve high target-specific ASR values, with most results passing 9393% over all targets and datasets. Notably, SemCC has the highest per-target ASR on ImageNet, which reaches up to 98.2898.28%. Congruent tendencies are gotten for other architectures, revealing that stable multi-target attack efficacy is maintained under tough communication conditions. Signal-to-Noise Ratio. The impact of SNR under various communication conditions was further inspected. We compared the ASR and Δ across various attacks. The experiments were executed using the JSCC architecture and the MNIST set. The results are presented in Figs. 4 and 5. Figure 4: Test results of ASRs across SNRs (ASR: %\%; SNR: dB). Please cf. Sec. V-B for detailed explanations. Figure 5: Test results of clean data PSNRs across SNRs (SNR, PSNR: dB). Please cf. Sec. V-B for detailed explanations. As illustrated in Fig. 4 for attack efficacy, the ASR increases with higher SNR values for all methods, indicating that improved communication conditions lead to more effective attacks. SemBugger persistently outperforms the other methods, having the highest ASR at each SNR level. At an SNR 55 dB, SemBugger already has an ASR =97.47%=97.47\%, and this value rises steadily. Conversely, IHTG, BASS, and SC Trojan show relatively lower ASRs, with their performance improving as the SNR increases but not reaching the levels of SemBugger. The results statistically validate SemBugger’s ASR advantage under diverse channel conditions, particularly noise-resilient performance with <3%<3\% efficiency deviation through 15−3515-35 dB SNR interval. In Fig. 5, we contrasted our SemBugger with IHTG, BASS, and SC Trojan in Δ . As the SNR grows, Δ for all methods improves, and it manifests that the transmission efficiency of clean data becomes less affected by the attacks under better communication conditions. SemBugger sustains the lowest Δ traversing all SNR levels. At SNR =5=5 dB, SemBugger gets a Δ =19.79=19.79 dB, and this value increases to 35.9235.92 dB at SNR =27=27 dB. Differentially, the other methods present relatively larger Δ values, whereby this implies more severe deterioration of system efficacy, especially at lower SNR settings. Sample Visualization. To more effectively highlight the imperceptibility of our backdoor triggers (mentioned in Sec. I-A), we performed a comparison between adversarial examples generated by our SemBugger (w/ triggers of maximum level intensity) and baselines. Fig. 6 offers a visual exposition of poisoned samples from CIFAR-10 dataset and reflects the disparities in trigger stealth features. The attack was implemented under JSCC (w/ 2525 dB channel), and the visualization results are showcased in Fig. 6. Source Data Our Method SC Trojan BASS IHTG Figure 6: Illustration of attack (i.e., poisoned) data generated across backdoors: our SemBugger, SC Trojan, BASS, and baseline source data. 1)1) The poisonous data via our SemBugger exhibits negligible perceptual divergence from the source data. 2)2) The attack data generated by SC Trojan and BASS expose conspicuous visual artifacts. 3)3) SemBugger matches the concealment capability of SOTA attacks like IHTG. From the figure, the samples validate that, for visual modality, the triggers from our SemBugger retain a markedly better semantic congruence with the source content. Subjectively, the implanted trigger pattern blends almost imperceptibly into the data scene, while quantitatively SSIM reaches 95.25%95.25\% for SemBugger, which is above BASS (80.52%80.52\%) and SC Trojan (78.63%78.63\%), and approximates IHTG (95.98%95.98\%). These findings substantiates that SemBugger has good perceptual camouflage without diminishing attack efficacy while attaining performance analogous to SOTA covert backdoor attacks (i.e., IHTG) when compared with prevailing SC backdoors. Regular Task Impact. We evaluate the impact of the attack on system nominal performance under poor channel conditions (SNR =5=5 dB). We appended a classifier (RegNetY-16GF network) to the system and launched the attack against this end-to-end pipeline. We then measured the classification efficacy of the clean system and the attacked system, assessing how the attack affects overall system behavior in a degraded transmission setting. The evaluation was conducted on the MNIST set, with the corresponding results shown in Tab. VI. TABLE VI: Regular Task classification efficacy after attacks on MNIST tasks under poor SNR =5=5 dB (%\% ↑ ). Please cf. Sec. V-B for detailed explanations. Test Systems Condition JSCC JSCC-f JSCC-q SCAN SemCC Clean 93.28 93.43 92.87 91.95 94.76 Attack 93.02 93.18 92.62 91.68 94.05 It can be observed that all evaluated systems maintain nearly identical classification efficiency before and after the attack. For Instance, JSCC decreases solely from 93.28%93.28\% to 93.02%93.02\% (−0.26-0.26 percentage points), JSCC-f from 93.43%93.43\% to 93.18%93.18\% (−0.25-0.25), JSCC-q from 92.87%92.87\% to 92.62%92.62\% (−0.25-0.25), SCAN from 91.95%91.95\% to 91.68%91.68\% (−0.27-0.27), and SemCC from 94.76%94.76\% to 94.05%94.05\% (−0.71-0.71). Overall, the performance degradation induced by the attack is consistently below 1%1\%, implying that the downstream task capability under clean inputs is largely unaffected. This is because our attack does not alter the semantic representations transmitted for clean samples. Instead, it induces abnormal behavior only under specific trigger conditions. Consequently, in standard (non-triggered) evaluations, the semantic information received by the downstream classifier remains stable, and the classification accuracy exhibits negligible degradation. Spatial Processing Influence. We further study the impact of input spatial cropping on attack performance. Using spatial cropping, we randomly crop portions of the original trigger and embed them into clean samples to assess how cropping degree affects attack efficacy. Experiments are conducted under 2525 dB SNR using the JSCC on MNIST and Fashion-MNIST datasets. Four cropping ratios (i.e., 1/21/2, 1/41/4, 1/81/8, and 1/161/16) of the full trigger are tested to analyze the effect of cropping. To evaluate stealthiness, we adopt Learned Perceptual Image Patch Similarity (LPIPS) to measure perceptual disparity between attacked and original samples under multiple cropping conditions. Empirical results are depicted in Tab. VII. TABLE VII: Attack efficacy (ASR ↑ ) and stealthiness (LPIPS ↓ ) on MNIST tasks under standard SNR =25=25 dB. Please cf. Sec. V-B for detailed explanations. Cropping Ratios Metric 1/2 1/4 1/8 1/16 ASR (%) 99.54 98.13 96.48 91.10 LPIPS 0.105 0.089 0.062 0.041 In terms of attack efficacy, the proposed attack consistently achieves high ASR even in the presence of cropping. Concretely, ASR reaches 99.54%99.54\% and 98.13%98.13\% for cropping ratios of 1/21/2 and 1/41/4, respectively, and remains as high as 96.48%96.48\% and 91.10%91.10\% when the cropping ratio is increased to 1/81/8 and 1/161/16, whereby it proves strong robustness against cropping perturbations. Meanwhile, the LPIPS values remain low across all settings and decrease progressively from 0.1050.105 to 0.0410.041 as the cropping ratio increases, which shows that the attacked poisonous data are perceptually close to the clean ones and thus highly stealthy. Overall, empirical results suggest that the proposed attack remains highly effective and preserves strong imperceptibility, even in the presence of common preprocessing operations like data cropping. V-C Ablation Study We further ran ablation experiments to inspect various factors influencing our experimental results, with a focus on 1)1) compression rate CRCR and 2)2) poisoning rate γ. The tests are mainly performed using the JSCC architecture. Compression Rate. We examined ASR for 44 attack target conditions by configuring multiple CRCR, while also quantitatively appraising the performance deterioration (Δ ) caused by the attack on benign data transmission quality. Experiments were carried out employing the JSCC-f SC system under 2525 dB SNR constraint. Tab. VIII presents the results across varying CRCR for MNIST, F-MNIST, CIFAR-10, and ImageNet datasets. TABLE VIII: Ablation study for compression rates CRCR on MNIST, F-MNIST, CIFAR-10, and ImageNet tasks under constrained SNR =25=25 dB (ASR↑ : %\%, Δ ↑ : dB). Please cf. Sec. V-C for detailed explanations. MNIST Dataset F-MNIST Dataset CIFAR-10 Dataset ImageNet Dataset CRCR ASR1 ASR2 ASR3 ASR4 Δ ASR1 ASR2 ASR3 ASR4 Δ ASR1 ASR2 ASR3 ASR4 Δ ASR1 ASR2 ASR3 ASR4 Δ 1//12 92.35 93.42 91.88 92.17 1.17 91.47 93.15 90.82 92.64 2.31 88.23 89.71 87.95 90.12 2.39 89.47 90.33 88.92 91.25 2.03 1//4 99.91 99.94 99.76 100.00 1.10 99.93 99.94 99.92 100.00 0.85 99.88 99.87 99.80 99.82 2.20 99.89 99.94 99.90 100.00 1.95 1//3 99.97 99.99 99.93 100.00 0.87 99.98 99.99 99.97 100.00 0.62 99.95 99.96 99.92 99.95 1.64 99.97 99.99 99.96 100.00 0.52 2//5 99.99 100.00 99.97 100.00 0.28 99.99 100.00 99.98 100.00 0.24 99.97 99.98 99.95 99.97 1.13 99.99 100.00 99.98 100.00 0.41 Avg 98.63 98.86 98.49 98.83 0.85 98.67 98.99 98.53 98.93 1.01 97.79 98.29 97.90 98.15 1.84 97.85 98.25 97.94 98.45 1.22 With the results, 1)1) the multi-target attack reaches consistently high success rates (ASR1-ASR4) traversing all evaluated CRCR, and maintains >88%>88\% effectiveness even at the most extreme compression with CR=1/12CR=1/12. 2)2) Performance improves monotonically with increasing bandwidth allocation, reaching stable success rates (≥99.76%≥ 99.76\%) for CR≥1/4CR≥ 1/4 across all datasets and target results. 3)3) The attack elicits minimal distortion to regular transmissions capability, with Δ values constrained below 2.392.39 dB in all configurations. Our evaluations reveal that SemBugger has consistent adversarial effectiveness and keeps stealthiness across regular task CRCR. This stems from the joint multi-effect poisoning-training of our attack with the SC system, by which it forces the shared SC knowledge to sustain high ASRs without sacrificing system’s benign data transmission functionality. Poisoning Rate. The rate specifies the fraction of poisoned data during the poisoning-training phase. We assessed the minimal levels of poisoning at which our SemBugger keeps effective. The attack efficacy under varying poisoning rates γ was inspected utilizing MNIST, F-MNIST, CIFAR-10, ImageNet datasets under 2525 dB and 55 dB SNR. The assessment measures both ASR and transmission fidelity degradation of Δ . The test results are visualized in Figs. 7 and 8. Figure 7: Ablation test results across poisoning rates γ under communication condition SNR =25=25 dB (ASR: %\%; Δ : dB). Please cf. Sec. V-C for detailed explanations. Figure 8: Ablation test results across poisoning rates γ under communication condition SNR =5=5 dB (ASR: %\%; Δ : dB). Please cf. Sec. V-C for detailed explanations. In Fig. 7 of test results under 2525 dB, 1)1) the success rate increases sharply with the γ, moving close to 100%100\% for all datasets. Initially, at γ =0.05=0.05, the ASR starts around 50%50\%, and then it rises steadily with up-going γ. This finding empirically verifies that our method can deliver considerable ASRs while operating at exceptionally low infection levels. 2)2) The change in PSNR varies across datasets, but it is still in a minimal range. While MNIST retrains low Δ values, F-MNIST depicts a moderate increase. CIFAR-10 exhibits a more substantial rise in Δ , especially at higher γ, whereas ImageNet experiences fluctuating Δ values. Generally, across γ, our attack strategy preserves victim system’s operational integrity with marginal efficiency deviation. The performance for 44 datasets uunder 55 dB are provided in Fig. 8. 1)1) ASR begins at approximately 30%30\% for all datasets at γ=0.05γ=0.05 and increases steadily, attaining nearly 97−98%97-98\% at γ=0.9γ=0.9. The results manifest that our method maintains high effectiveness even under relatively low SNR channel conditions. 2)2) Regarding Δ , it conveys slight fluctuations as γ increases. CIFAR-10 retains the highest Δ values across most rates, whereas F-MNIST and ImageNet show greater variability, particularly at higher γ. V-D Defense Study To further fortify SC system’s resilience against SemBugger-type threats, Sec. IV-B introduces a dedicated defensive framework. We delved into the defense effectiveness across 55 SC architectures (i.e., JSCC, JSCC-f, JSCC-q, SCAN, and SemCC) and 44 benchmark datasets (MNIST, F-MNIST, CIFAR-10, and ImageNet). All experiments principally inherited the settings detailed in Sec. V-B and were executed under 2525 dB and 55 dB channel conditions. The experimental results are displayed in Tabs. IX and X. Tab. IX concludes defense results when operating under 2525 dB channels. Among 55 SC system architectures evaluated, SemCC drives the ASR down to near 0% across all 44 datasets, while incurring only a 0.20–0.270.20–0.27 dB increase in distortion (Δ ). The remaining systems also suppress ASR to the low 0.12–0.890.12–0.89% range, but residue is still detectable and their Δ peaks at 0.490.49 dB. Wholly, these findings indicate that the proposed defense markedly weakens SemBugger without materially degrading reconstruction quality, with the SemCC configuration acquiring the most pronounced benefit. The underlying work principle may be that the attack trigger employed in this study is essentially a low-amplitude perturbation. By superimposing a carefully crafted, covert noise mask, we can effectively obscure the trigger and distort its statistical signature and realize a robust defense. TABLE IX: Defense results against SemBugger backdoors on MNIST, F-MNIST, CIFAR-10, and ImageNet tasks under standard SNR =25=25 dB (ASR↓ : %\%; PSNR*↑ , PSNR∘, Δ PSNR ↓ : dB). Please cf. Sec. V-D for detailed explanations. MNIST Dataset F-MNIST Dataset CIFAR-10 Dataset ImageNet Dataset Systems ASR PSNR* PSNR∘ Δ PSNR ASR PSNR* PSNR∘ Δ ASR PSNR* PSNR∘ Δ ASR PSNR* PSNR∘ Δ JSCC 0.12 36.19 36.47 0.28 0.00 33.63 33.82 0.19 0.23 30.94 31.15 0.21 0.00 34.71 34.93 0.22 JSCC-f 0.00 38.29 38.76 0.47 0.34 35.68 36.17 0.49 0.00 33.03 33.42 0.39 0.45 36.82 37.23 0.41 JSCC-q 0.56 38.07 38.53 0.46 0.00 35.33 35.82 0.49 0.00 32.67 33.14 0.47 0.67 36.45 36.91 0.46 SCAN 0.00 39.81 40.23 0.42 0.78 37.11 37.54 0.43 0.00 34.42 34.83 0.41 0.89 38.23 38.62 0.39 SemCC 0.00 38.93 39.20 0.27 0.00 39.07 39.34 0.27 0.00 39.58 39.82 0.24 0.00 39.42 39.62 0.20 TABLE X: Defense results against SemBugger backdoors on MNIST, F-MNIST, CIFAR-10, and ImageNet tasks under standard SNR =5=5 dB (ASR↓ : %\%; PSNR*↑ , PSNR∘, Δ ↓ : dB). Please cf. Sec. V-D for detailed explanations. MNIST Dataset F-MNIST Dataset CIFAR-10 Dataset ImageNet Dataset Systems ASR PSNR* PSNR∘ Δ ASR PSNR* PSNR∘ Δ ASR PSNR* PSNR∘ Δ ASR PSNR* PSNR∘ Δ JSCC 0.00 21.13 21.47 0.34 0.97 19.43 19.82 0.40 0.94 13.75 14.15 0.40 0.00 16.64 16.93 0.30 JSCC-f 0.96 23.35 23.76 0.42 0.00 20.92 21.17 0.26 0.42 16.08 16.42 0.35 0.71 18.88 19.23 0.36 JSCC-q 0.53 23.12 23.53 0.41 0.82 20.66 20.82 0.17 0.00 15.97 16.14 0.18 0.29 20.55 20.91 0.36 SCAN 0.37 22.88 23.23 0.36 0.64 20.29 20.54 0.26 0.83 15.67 15.83 0.16 0.00 19.40 19.62 0.23 SemCC 0.19 21.98 22.20 0.22 0.75 22.11 22.34 0.23 0.68 22.61 22.82 0.22 0.91 22.40 22.62 0.22 Tab. X summarizes the defense efficacy under an adverse channel condition of SNR=5=5 dB. Across all 55 SC system architectures and 44 benchmark datasets, the defense drives the ASR to sub-percent levels (∼ 0 %) and never exceeding 0.970.97 %, wherein it represents a reduction of more than two orders of magnitude relative to the unprotected baseline (cf. Sec. V-B for the attack results). Critically, this security gain is achieved with negligible impact on benign data transmission fidelity. The post-defense PSNR* differs from the clean-system PSNR∘ by at most 0.420.42 dB and typically by only 0.2–0.40.2–0.4 dB, well below the commonly accepted perceptual threshold. These results confirm that the defense does not sacrifice communication quality even in low-SNR regimes. In addition, we verified the certified accuracy of the defense method and summarized it in the Supplemental Material. Computation Cost. We show the computational consumption based MNIST and F-MNIST sets. The server is a dual-socket Intel Xeon Platinum 8369B machine (2×32 cores / 64 threads, 128 threads total, 2 NUMA nodes). It has 10× NVIDIA GeForce GPUs, each with 24GB VRAM (24576 MiB), running Driver 520.61.05 / CUDA 11.8. Each sample was processed 1010 times to calculate the average time (w/ SNR =25=25 dB). We present the average processing time per sample for the entire dataset. The results are listed in Tab. XI. TABLE XI: Average sample running time cost of defense on MNIST and F-MNIST tasks under standard SNR =25=25 dB (ms ↓ ). Please cf. Sec. V-D for detailed explanations. Test Systems Datasets JSCC JSCC-f JSCC-q SCAN SemCC MNIST 1.15 1.22 1.93 2.07 0.94 F-MNIST 1.26 1.33 2.05 2.16 1.02 As illustrated, the average per-sample processing times lie within a very narrow range. Statistically, the mean processing time across all evaluated systems is only 1.521.52 ms (standard deviation 0.420.42 ms). the maximum latency is merely 2.3×2.3× the minimum, and all are far below the inter-frame interval of typical wireless systems (usually 55–1010 ms). The absolute gap between the fastest SemCC architecture and the slowest SCAN architecture is only 1.141.14 ms, which is practically negligible in real deployments. Also, 95%95\% of samples fall within the 0.90.9–2.22.2 ms range, and none of the architectures exceeds the 33 ms latency budget commonly tolerated by real-time systems. This is because the proposed defense only requires injecting smoothed Gaussian noise and does not introduce additional system processing. Hence, although architectural differences lead to slight variations in runtime, these differences are minor and well within the tolerance of practical communication systems, with no obstacle to large-scale deployment. Downstream Task Influence. To further assess the task-level impact of the proposed defense in practical deployments, we cascade a downstream classifier (RegNetY-16GF network) with the receiver-side output of the SC architecture to form an end-to-end transmission–identification system, on which we implement both attacks and defenses. Specifically, we measure the system’s baseline classification performance without attacks, as well as its efficacy after using the defense, and quantify the task-level impact of our defense. The experiments were implemented on MNIST dataset under SNR =25=25 dB. Tab. XII summarizes the evaluation results. TABLE XII: Task classification efficacy of defense on MNIST tasks under standard SNR =25=25 dB (%\% ↑ ). Please cf. Sec. V-D for detailed explanations. Test Systems Condition JSCC JSCC-f JSCC-q SCAN SemCC Clean 95.15 95.22 94.93 94.07 95.94 Defense 94.96 95.03 94.71 93.92 95.82 The experimental results manifest minimal performance degradation introduced by the defense scheme. The classification accuracy of SC shows an average reduction of only 0.170.17 (from 95.06%95.06\% to 94.89%94.89\%), with the maximum reduction being 0.220.22 percentage points (JSCC-q system: 94.93%→94.71%94.93\%→ 94.71\%) and the minimum reduction being 0.120.12 percentage points (SemCC system: 95.94%→95.82%95.94\%→ 95.82\%). All systems maintain accuracy above 93.92%93.92\% after defense implementation, with relative differences less than 0.3%0.3\% compared to the clean counterparts. This confirms that the defense preserves over 98%98\% of semantic information integrity while introducing only marginal PSNR degradation during transmission, with downstream classification tasks virtually unaffected. VI Conclusion In this paper, we first identify the key limitation in current research on SC backdoors: the prevailing monomorphic activation paradigm hampers efficiency, adaptability, and output variety. To address these constraints, we introduce the first polymorphic backdoor in the SC field, which dynamically modulates the intensity of implicit triggers embedded in the transmission inputs, hence allowing adversaries to manipulate the system to yield multiple, distinct reconstruction targets. Specifically, the polymorphic backdoor is implanted into the shared knowledge of the SC system through a multi-effect poisoning framework. This preserves the fidelity of benign transmissions while enabling the system to distinguish graded covert triggers and yield adversarial reconstruction outputs uniquely mapped to each trigger intensity. Additionally, to counter the proposed backdoor, we devise a provably secure semantic-smoothing defense. Based on a formally derived lower defense bound, the scheme injects carefully calibrated noise into inputs, whereby it attenuates latent trigger signals and consequently prevents backdoor activations. Extensive experiments demonstrate that our proposed attack method achieves high attack efficacy (ASR>90%>90\%) while introducing minimal degradation to the system’s normal functionality (ΔPSNR<2dB <2\,dB). Furthermore, our designed defense scheme can effectively mitigate the attack, reducing the success rate to a negligible level (ASR<1%ASR<1\%). Our future research will generalize the current framework to encompass distributed poisoning attacks, particularly examining cross-client telecom patterns and their countermeasures. VII Acknowledgment This work is funded by the National Natural Science Foundation of China (Nos. 62572314, 62471301 and U21B2019). Gaolei Li and Jun Wu are the corresponding authors. References [1] Y. Bai, G. Xing, H. Wu, Z. Rao, C. Ma, S. Wang, X. Liu, Y. Zhou, J. Tang, K. Huang, and J. Kang (2025) Backdoor attack and defense on deep learning: a survey. IEEE Trans. Comput. Social Syst. 12 (1), p. 404–434. Cited by: §I. [2] E. Bourtsoulatze, D. Burth Kurka, and D. Gündüz (2019) Deep joint source-channel coding for wireless image transmission. IEEE Trans. Cogn. Commun. Netw. 5 (3), p. 567–579. External Links: Document Cited by: §I-A, §V-A1. [3] C. Chaccour, W. Saad, M. Debbah, Z. Han, and H. Vincent Poor (2025) Less data, more knowledge: building next-generation semantic communication networks. IEEE Commun. Surv. Tutor. 27 (1), p. 37–76. Cited by: §I. [4] J. Deng, W. Dong, R. Socher, L. Li, K. Li, and L. Fei-Fei (2009) ImageNet: a large-scale hierarchical image database. In Proc. IEEE Conf. Comput. Vis. Pattern Recognit. (CVPR), Vol. , p. 248–255. Cited by: §V-A2. [5] L. Deng (2012) The mnist database of handwritten digit images for machine learning research. IEEE Signal Process. Mag. 29 (6), p. 141–142. Cited by: §V-A2. [6] Y. Ding, H. Guo, Y. Guan, W. Liu, J. Huo, Z. Guan, and X. Zhang (2025) East: efficient and accurate secure inference framework for transformer. IEEE Trans. Services Comput. 18 (4), p. 2038–2046. Cited by: §I. [7] R. Doon, T. Kumar Rawat, and S. Gautam (2018) Cifar-10 classification using deep convolutional neural network. In Proc. IEEE Pune Sect. Int. Conf. (PUNECON), Vol. , p. 1–5. Cited by: §V-A2. [8] Y. Feng, H. Shen, Z. Shan, Q. Yang, and X. Shi (2025) Semantic communication for edge intelligence enabled autonomous driving system. IEEE Netw. 39 (2), p. 149–157. External Links: Document Cited by: §I. [9] Y. Gao, C. Xu, D. Wang, S. Chen, D. C. Ranasinghe, and S. Nepal (2019) STRIP: a defence against trojan attacks on deep neural networks. In Proc. Annu. Comput. Secur. Appl. Conf. (ACSAC), p. 113–125. Cited by: §IV. [10] T. M. Getu, G. Kaddoum, and M. Bennis (2024) Semantic communication: a survey on research landscape, challenges, and future directions. Proc. IEEE 112 (11), p. 1649–1685. Cited by: §I. [11] T. M. Getu, W. Saad, G. Kaddoum, and M. Bennis (2024) Performance limits of a deep learning-enabled text semantic communication under interference. IEEE Trans. Wirel. Commun. 23 (8), p. 10213–10228. External Links: Document Cited by: §I-A. [12] W. Huang, G. Li, M. Chen, J. Li, and H. Zhu (2025) Silent penetrator: breaching cross-domain federated fine-tuning via feature shift-induced backdoor. IEEE Trans. Inf. Forensics Secur. 20 (), p. 7106–7120. Cited by: §I. [13] D. B. Kurka and D. Gündüz (2020) DeepJSCC-f: deep joint source-channel coding of images with feedback. IEEE J. Sel. Areas Inf. Theory 1 (1), p. 178–193. External Links: Document Cited by: §I-A, §V-A1. [14] G. Li, J. Wu, S. Li, W. Yang, and C. Li (2023) Multitentacle federated learning over software-defined industrial internet of things against adaptive poisoning attacks. IEEE Trans. Ind. Inf. 19 (2), p. 1260–1269. Cited by: §I-C. [15] X. Li, L. Wu, Z. Guan, X. Du, N. Aitsaadi, and M. Guizani (2024) MulDoor: a multi-target backdoor attack against federated learning system. In Proc. IEEE Glob. Commun. Conf. (GLOBECOM), Vol. , p. 1749–1754. Cited by: §I-B. [16] Y. Li, Y. Jiang, Z. Li, and S. Xia (2024) Backdoor learning: a survey. IEEE Trans. Neural Networks Learn. Syst. 35 (1), p. 5–22. Cited by: §I, §I-B, §I-C. [17] X. Luo, H. Chen, and Q. Guo (2022) Semantic communications: overview, open issues, and future research directions. IEEE Wireless Commun. 29 (1), p. 210–219. Cited by: §I. [18] O. Oktay, J. Schlemper, L. L. Folgoc, M. C. H. Lee, M. P. Heinrich, K. Misawa, K. Mori, S. G. McDonagh, N. Y. Hammerla, B. Kainz, B. Glocker, and D. Rueckert (2018) Attention u-net: learning where to look for the pancreas. CoRR abs/1804.03999. External Links: 1804.03999 Cited by: §I-C1. [19] J. Park, Y. Oh, S. Kim, and Y. Jeon (2025) Joint source-channel coding for channel-adaptive digital semantic communications. IEEE Trans. Cogn. Commun. Netw. 11 (1), p. 75–89. External Links: Document Cited by: §I-A. [20] Y. E. Sagduyu, T. Erpek, S. Ulukus, and A. Yener (2023) Vulnerabilities of deep learning-driven semantic communications to backdoor (trojan) attacks. In Proc. Annu. Conf. Inf. Sci. Syst. (CISS), Vol. , p. 1–6. External Links: Document Cited by: §I, §I-B, TABLE I, §V-A4. [21] A. Salem, R. Wen, M. Backes, S. Ma, and Y. Zhang (2022) Dynamic backdoor attacks against machine learning models. In Proc. IEEE Euro. Symp. Secur. Priv. (EuroS&P), Vol. , p. 703–718. External Links: Document Cited by: §IV. [22] J. Shi, Q. Zhang, Y. Xu, W. Zeng, S. Li, Z. Guan, and Z. Qin (2026) A task-oriented and lightweight semantic communication system with secure federated aggregation in distributed wireless networks. IEEE Trans. Mobile Comput. (), p. 1–16. Cited by: §I. [23] S. Tang, Q. Yang, L. Fan, X. Lei, A. Nallanathan, and G. K. Karagiannidis (2024) Contrastive learning-based semantic communications. IEEE Trans. Commun. 72 (10), p. 6328–6343. Cited by: §V-A1. [24] T. Tung, D. B. Kurka, M. Jankowski, and D. Gündüz (2022) DeepJSCC-q: constellation constrained deep joint source-channel coding. IEEE J. Sel. Areas Inf. Theory 3 (4), p. 720–731. External Links: Document Cited by: §I-A, §V-A1. [25] Y. Wan, Y. Qu, W. Ni, Y. Xiang, L. Gao, and E. Hossain (2024) Data and model poisoning backdoor attacks on wireless federated learning, and the defense mechanisms: a comprehensive survey. IEEE Commun. Surv. Tutor. 26 (3), p. 1861–1897. Cited by: §I. [26] B. Wang, Y. Yao, S. Shan, H. Li, B. Viswanath, H. Zheng, and B. Y. Zhao (2019) Neural cleanse: identifying and mitigating backdoor attacks in neural networks. In Proc. IEEE Symp. Secur. Priv. (S&P), Vol. , p. 707–723. Cited by: §IV. [27] K. Wang, H. Deng, Y. Xu, Z. Liu, and Y. Fang (2024) Multi-target label backdoor attacks on graph neural networks. Pattern Recognit. 152, p. 110449. Cited by: §I-B. [28] H. Xiao, K. Rasul, and R. Vollgraf (2017) Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms. CoRR abs/1708.07747. External Links: 1708.07747 Cited by: §V-A2. [29] H. Xie, Z. Qin, X. Tao, and K. B. Letaief (2022) Task-oriented multi-user semantic communications. IEEE J. Sel. Areas Commun. 40 (9), p. 2584–2597. External Links: Document Cited by: §I-A. [30] X. Xu, Y. Chen, B. Wang, Z. Bian, S. Han, C. Dong, C. Sun, W. Zhang, L. Xu, and P. Zhang (2024) CSBA: covert semantic backdoor attack against intelligent connected vehicles. IEEE Trans. Veh. Technol. 73 (11), p. 17923–17928. Cited by: §I, §I-B, TABLE I. [31] M. Xue, C. He, J. Wang, and W. Liu (2022) One-to-n & n-to-one: two advanced backdoor attacks against deep learning models. IEEE Trans. Dependable Secure Comput. 19 (3), p. 1562–1578. Cited by: §I-B. [32] L. Yan, Z. Qin, R. Zhang, Y. Li, and G. Y. Li (2022) Resource allocation for text semantic communications. IEEE Wirel. Commun. Lett. 11 (7), p. 1394–1398. External Links: Document Cited by: §I-A. [33] Z. Yan, S. Li, R. Zhao, Y. Tian, and Y. Zhao (2023) DHBE: data-free holistic backdoor erasing in deep neural networks via restricted adversarial distillation. In Proc. ACM Asia Conf. Comput. Commun. Secur. (AsiaCCS), p. 731–745. Cited by: §IV. [34] Z. Yan, J. Wu, G. Li, S. Li, and M. Guizani (2021) Deep neural backdoor in semi-supervised learning: threats and countermeasures. IEEE Trans. Inf. Forensics Secur. 16 (), p. 4827–4842. Cited by: §I-B. [35] W. Yang, H. Du, Z. Q. Liew, W. Y. B. Lim, Z. Xiong, D. Niyato, X. Chi, X. Shen, and C. Miao (2023) Semantic communications for future internet: fundamentals, applications, and challenges. IEEE Commun. Surv. Tutor. 25 (1), p. 213–250. Cited by: §I. [36] X. Yang, Y. Lai, G. Li, J. Wu, K. Zhou, and M. Chen (2025) SemanAegis: toward credential-aware semantic communication against knowledge leakage threats. IEEE Trans. Mob. Comput. (), p. 1–18. Cited by: §I-A. [37] X. Yang, Y. Lai, K. Zhou, G. Li, J. Li, and H. Zhang (2025) GraphProt: certified black-box shielding against backdoored graph models. In Proc. Int. Jt. Conf. Artif. Intell. (IJCAI), p. 619–627. Cited by: §IV. [38] W. Zeng, X. Xu, Q. Zhang, J. Shi, Z. Guan, S. Li, and Z. Qin (2026) A secure and efficient distributed semantic communication system for heterogeneous internet of things. IEEE Trans. Mobile Comput. (), p. 1–16. Cited by: §I. [39] B. Zhang, Z. Qin, and G. Y. Li (2023) Semantic communications with variable-length coding for extended reality. IEEE J. Sel. Top. Signal Process. 17 (5), p. 1038–1051. Cited by: §I. [40] G. Zhang, Q. Hu, Y. Cai, and G. Yu (2024) SCAN: semantic communication with adaptive channel feedback. IEEE Trans. Cogn. Commun. Netw. 10 (5), p. 1759–1773. Cited by: §V-A1. [41] Q. Zhang, J. Shi, W. Zeng, X. Xu, Z. Guan, S. Li, and Z. Qin (2025) Balancing security and efficiency in gai-driven semantic communication: challenges, solutions, and future paths. IEEE Netw. 39 (5), p. 88–96. Cited by: §I. [42] S. Zhang, Y. Pan, Q. Liu, Z. Yan, K. R. Choo, and G. Wang (2024) Backdoor attacks and defenses targeting multi-domain ai models: a comprehensive review. ACM Comput. Surv. 57 (4). Cited by: §I. [43] Z. Zhang, Q. Liu, Z. Wang, Z. Lu, and Q. Hu (2023) Backdoor defense via deconfounded representation learning. In Proc. IEEE Conf. Comput. Vis. Pattern Recognit. (CVPR), p. 12228–12238. Cited by: §I-A. [44] Y. Zhou, R. Q. Hu, and Y. Qian (2024) Backdoor attacks and defenses on semantic-symbol reconstruction in semantic communications. In Proc. IEEE Int. Conf. Commun. (ICC), Vol. , p. 734–739. External Links: Document Cited by: §I, §I-B, TABLE I, §V-A4. [45] Y. Zhou, R. Q. Hu, and Y. Qian (2024) Stealthy backdoor attacks on semantic symbols in semantic communications. In Proc. IEEE Glob. Commun. Conf. (GLOBECOM), Vol. , p. 4975–4981. External Links: Document Cited by: §I, §I-B, TABLE I, §V-A4.