EDBT 2026 Demo / reviewers in the wild / expert
Tugba Erpek
dblp:01/10889
· DBLP profile ↗
16ranked-venue papers
3as first author
12since 2021 · last 2026
0000-0003-0168-2587ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 13 · 2 first-author · 10 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Coordinated Anti-Jamming Resilience in Swarm Networks via Multi-Agent Reinforcement LearningabstractReactive jammers pose a severe security threat to robotic-swarm networks by selectively disrupting inter-agent communications and undermining formation integrity and mission success. Conventional countermeasures such as fixed power control or static channel hopping are largely ineffective against such adaptive adversaries. This paper presents a multi-agent reinforcement learning (MARL) framework based on the QMIX algorithm to improve the resilience of swarm communications under reactive jamming. We consider a network of multiple transmitter–receiver pairs sharing channels while a reactive jammer with Markovian threshold dynamics senses aggregate power and reacts accordingly. Each agent jointly selects transmit frequency (channel) and power, and QMIX learns a centralized but factorizable action-value function that enables coordinated yet decentralized execution. We benchmark QMIX against a genie-aided optimal policy in a no–channel-reuse setting, and against local Upper Confidence Bound (UCB) and a stateless reactive policy in a more general fading regime with channel reuse enabled. Simulation results show that QMIX rapidly converges to cooperative policies that nearly match the genie-aided bound, while achieving higher throughput and lower jamming incidence than the baselines, thereby demonstrating MARL’s effectiveness for securing autonomous swarms in contested environments. Bahman Abolhassani, Tugba Erpek, Kemal Davaslioglu, Yalin E. Sagduyu, Sastry Kompella |
CCNC | 2 |
| 2025 | Adversarial Attack and Defense for LoRa Device Identification and Authentication via Deep LearningabstractLoRa enables long-range, energy-efficient communication for Internet of Things (IoT) applications, making it an essential technology for low-power wide-area networks (LPWANs). However, its security remains a concern, particularly when reliable device identification and authentication are critical. This article addresses these challenges using deep learning (DL) techniques to perform two key tasks: 1) identifying LoRa devices and 2) distinguishing between legitimate signals and rogue signals [generated by kernel density estimation (KDE)]. By training deep neural networks (DNNs) on real LoRa signal data, the study examines the susceptibility of separate models for each task as well as a shared multitask model to untargeted and targeted adversarial attacks, generated with the fast gradient sign method (FGSM). To counter these attacks, a defense strategy using adversarial training is proposed to enhance model robustness. The results highlight vulnerabilities in LoRa security and emphasize the importance of fortifying IoT systems against such sophisticated threats. Yalin E. Sagduyu, Tugba Erpek |
IEEE Internet Things J. | 2 |
| 2024 | Low-Latency Task-Oriented Communications with Multi-Round, Multi-Task Deep LearningabstractIn this paper, we address task-oriented (or goal-oriented) communications where an encoder at the transmitter learns compressed latent representations of data, which are then transmitted over a wireless channel. At the receiver, a decoder performs a machine learning task, specifically for classifying the received signals. The deep neural networks corresponding to the encoder-decoder pair are jointly trained, taking both channel and data characteristics into account. Our objective is to achieve high accuracy in completing the underlying task while minimizing the number of channel uses determined by the encoder's output size. To this end, we propose a multi-round, multi-task learning (MRMTL) approach for the dynamic update of channel uses in multi-round transmissions. The transmitter incrementally sends an increasing number of encoded samples over the channel based on the feedback from the receiver, and the receiver utilizes the signals from a previous round to enhance the task performance, rather than only considering the latest transmission. This approach employs multi-task learning to jointly optimize accuracy across varying number of channel uses, treating each configuration as a distinct task. By evaluating the confidence of the receiver in task decisions, MRMTL decides on whether to allocate additional channel uses in multiple rounds. We characterize both the accuracy and the delay (total number of channel uses) of MRMTL, demonstrating that it achieves the accuracy close to that of conventional methods requiring large numbers of channel uses, but with reduced delay by incorporating signals from a prior round. We consider the CIFAR-10 dataset, convolutional neural network architectures, and AWGN and Rayleigh channel models for performance evaluation. Our results show that MRMTL significantly improves the efficiency of task-oriented communications, balancing accuracy and latency effectively. Yalin E. Sagduyu, Tugba Erpek, Aylin Yener, Sennur Ulukus |
MobiCom | 2 |
| 2023 | Multi-Hop User Equipment (UE) to UE Relays for MANET/Mesh Leveraging 5G NR SidelinkabstractThis paper provides use cases to adapt 5G sidelink technology to enable multi-hop User Equipment (UE)-to-UE (U2U) and UE-to-Network relaying in 3GPP standards. Such a capability could enable groups of users to communicate with each other when operating at the periphery or outside a network's coverage area, with commercial and public safety benefits. This paper compares routing protocols to enable sidelink with U2U relay to support a Mobile Ad hoc Network (MANET). A gap analysis of current 3rd Generation Partnership Project (3GPP) Release 18 (R-18) specifications is performed to determine the missing procedures to enable multi-hop U2U relaying, along with a proposed candidate protocol to fill the gap. The candidate protocol can be submitted as a contribution to 3GPP TSG Service and System Aspects (SA) Working Group 2 (WG2) as proposed changes to the 5G architecture in 3GPP Release 19 (R-19). D. J. Shyy 0001, Cuong Luu, David Gabay, John D. Xu, David Bate, Lingjia Liu 0001, Tugba Erpek |
SEC | 7 |
| 2022 | Covert Communications via Adversarial Machine Learning and Reconfigurable Intelligent SurfacesabstractBy moving from massive antennas to antenna surfaces for software-defined wireless systems, the reconfigurable intelligent surfaces (RISs) rely on arrays of unit cells to control the scattering and reflection profiles of signals, mitigating the propagation loss and multipath attenuation, and thereby improving the coverage and spectral efficiency. In this paper, covert communication is considered in the presence of the RIS. While there is an ongoing transmission boosted by the RIS, both the intended receiver and an eavesdropper individually try to detect this transmission using their own deep neural network (DNN) classifiers. The RIS interaction vector is designed by balancing two (potentially conflicting) objectives of focusing the transmitted signal to the receiver and keeping the transmitted signal away from the eavesdropper. To boost covert communications, adversarial perturbations are added to signals at the transmitter to fool the eavesdropper’s classifier while keeping the effect on the receiver low. Results from different network topologies show that adversarial perturbation and RIS interaction vector can be jointly designed to effectively increase the signal detection accuracy at the receiver while reducing the detection accuracy at the eavesdropper to enable covert communications. Tugba Erpek, Yalin E. Sagduyu, Sennur Ulukus |
WCNC | 2 |
| 2022 | Learning-Based UAV Path Planning for Data Collection With Integrated Collision AvoidanceabstractUnmanned aerial vehicles (UAVs) are expected to be an integral part of wireless networks, and determining collision-free trajectory in multi-UAV noncooperative scenarios while collecting data from distributed Internet of Things (IoT) nodes is a challenging task. In this article, we consider a path-planning optimization problem to maximize the collected data from multiple IoT nodes under realistic constraints. The considered multi-UAV noncooperative scenarios involve a random number of other UAVs in addition to the typical UAV, and UAVs do not communicate or share information among each other. We translate the problem into a Markov decision process (MDP) with parameterized states, permissible actions, and detailed reward functions. Dueling double deep$Q$-network (D3QN) is proposed to learn the decision-making policy for the typical UAV, without any prior knowledge of the environment (e.g., channel propagation model and locations of the obstacles) and other UAVs (e.g., their missions, movements, and policies). The proposed algorithm can adapt to various missions in various scenarios, e.g., different numbers and positions of IoT nodes, different amount of data to be collected, and different numbers and positions of other UAVs. Numerical results demonstrate that real-time navigation can be efficiently performed with high success rate, high data collection rate, and low collision rate. Xueyuan Wang, Mustafa Cenk Gursoy, Tugba Erpek, Yalin E. Sagduyu |
IEEE Internet Things J. | 3 |
| 2022 | Channel-Aware Adversarial Attacks Against Deep Learning-Based Wireless Signal ClassifiersabstractThis paper presents channel-aware adversarial attacks against deep learning-based wireless signal classifiers. There is a transmitter that transmits signals with different modulation types. A deep neural network is used at each receiver to classify its over-the-air received signals to modulation types. In the meantime, an adversary transmits an adversarial perturbation (subject to a power budget) to fool receivers into making errors in classifying signals that are received as superpositions of transmitted signals and adversarial perturbations. First, these evasion attacks are shown to fail when channels are not considered in designing adversarial perturbations. Then, realistic attacks are presented by considering channel effects from the adversary to each receiver. After showing that a channel-aware attack is selective (i.e., it affects only the receiver whose channel is considered in the perturbation design), a broadcast adversarial attack is presented by crafting a common adversarial perturbation to simultaneously fool classifiers at different receivers. The major vulnerability of modulation classifiers to over-the-air adversarial attacks is shown by accounting for different levels of information available about the channel, the transmitter input, and the classifier model. Finally, a certified defense based on randomized smoothing that augments training data with noise is introduced to make the modulation classifier robust to adversarial perturbations. Yalin E. Sagduyu, Kemal Davaslioglu, Tugba Erpek, Sennur Ulukus |
IEEE Trans. Wirel. Commun. | 4 |
| 2021 | Collision-Aware UAV Trajectories for Data Collection via Reinforcement LearningabstractUnmanned aerial vehicles (UAVs) are expected to be an integral part of wireless networks, and determining collision-free trajectories in multi-UAV non-cooperative scenarios is a challenging task. In this paper, we consider a path planning optimization problem to maximize the collected data from multiple Internet of Things (IoT) nodes under realistic constraints. The considered multi-UAV non-cooperative scenarios involve random number of other UAVs in addition to the typical UAV, and UAVs do not communicate with each other. We translate the problem into an Markov decision process (MDP). Dueling double deep Q-network (D3QN) is proposed to learn the decision making policy for the typical UAV, without any prior knowledge of the environment (e.g., channel propagation model and locations of the obstacles) and other UAVs (e.g., their missions, movements, and policies). Numerical results demonstrate that real-time navigation can be efficiently performed with high success rate, high data collection rate, and low collision rate. Xueyuan Wang, Mustafa Cenk Gursoy, Tugba Erpek, Yalin E. Sagduyu |
GLOBECOM | 3 |
| 2021 | Robust Improvement of the Age of Information by Adaptive Packet CodingabstractWe consider a wireless communication network with an adaptive scheme to select the number of packets to be admitted and encoded for each transmission, and characterize the information timeliness. For a network of erasure channels and discrete time, we provide closed form expressions for the Average and Peak Age of Information (AoI) as functions of admission control and adaptive coding parameters, the feedback delay, and the maximum feasible end-to-end rate that depends on channel conditions and network topology. These new results guide the system design for robust improvements of the AoI when transmitting time sensitive information in the presence of topology and channel changes. We illustrate the benefits of using adaptive packet coding to improve information timeliness by characterizing the network performance with respect to the AoI along with its relationship to throughput (rate of successfully decoded packets at the destination) and per-packet delay. We show that significant AoI performance gains can be obtained in comparison to the uncoded case, and that these gains are robust to network variations as channel conditions and network topology change. Maice Costa, Yalin E. Sagduyu, Tugba Erpek, Muriel Médard |
ICC | 3 |
| 2021 | Channel Effects on Surrogate Models of Adversarial Attacks against Wireless Signal ClassifiersabstractWe consider a wireless communication system that consists of a background emitter, a transmitter, and an adversary. The transmitter is equipped with a deep neural network (DNN) classifier for detecting the ongoing transmissions from the background emitter and transmits a signal if the spectrum is idle. Concurrently, the adversary trains its own DNN classifier as the surrogate model by observing the spectrum to detect the ongoing transmissions of the background emitter and generate adversarial attacks to fool the transmitter into misclassifying the channel as idle. This surrogate model may differ from the transmitter’s classifier significantly because the adversary and the transmitter experience different channels from the background emitter and therefore their classifiers are trained with different distributions of inputs. This system model may represent a setting where the background emitter is a primary user, the transmitter is a secondary user, and the adversary is trying to fool the secondary user to transmit even though the channel is occupied by the primary user. We consider different topologies to investigate how different surrogate models that are trained by the adversary (depending on the differences in channel effects experienced by the adversary) affect the performance of the adversarial attack. The simulation results show that the surrogate models that are trained with different distributions of channel-induced inputs severely limit the attack performance and indicate that the transferability of adversarial attacks is neither readily available nor straightforward to achieve since surrogate models for wireless applications may significantly differ from the target model depending on channel effects. Yalin E. Sagduyu, Tugba Erpek, Kemal Davaslioglu, Sennur Ulukus |
ICC | 3 |
| 2021 | DeepWiFi: Cognitive WiFi with Deep LearningabstractWe present the DeepWiFi protocol, which hardens the baseline WiFi (IEEE 802.11ac) with deep learning and sustains high throughput by mitigating out-of-network interference. DeepWiFi is interoperable with baseline WiFi and builds upon the existing WiFi's PHY transceiver chain without changing the MAC frame format. Users run DeepWiFi for: i) RF front end processing; ii) spectrum sensing and signal classification; iii) signal authentication; iv) channel selection and access; v) power control; vi) modulation and coding scheme (MCS) adaptation; and vii) routing. DeepWiFi mitigates the effects of probabilistic, sensing-based, and adaptive jammers. RF front end processing applies a deep learning-based autoencoder to extract spectrum-representative features. Then a deep neural network is trained to classify waveforms reliably as idle, WiFi, or jammer. Utilizing channel labels, users effectively access idle or jammed channels, while avoiding interference with legitimate WiFi transmissions (authenticated by machine learning-based RF fingerprinting) resulting in higher throughput. Users optimize their transmit power for low probability of intercept/detection and their MCS to maximize link rates used by backpressure algorithm for routing. Supported by embedded platform implementation, DeepWiFi provides major throughput gains compared to baseline WiFi and another jamming-resistant protocol, especially when channels are likely to be jammed and the signal-to-interference-plus-noise-ratio is low. Kemal Davaslioglu, Sohraab Soltani, Tugba Erpek, Yalin E. Sagduyu |
IEEE Trans. Mob. Comput. | 3 |
| 2021 | Adversarial Deep Learning for Over-the-Air Spectrum Poisoning AttacksabstractAn adversarial deep learning approach is presented to launch over-the-air spectrum poisoning attacks. A transmitter applies deep learning on its spectrum sensing results to predict idle time slots for data transmission. In the meantime, an adversary learns the transmitter's behavior (exploratory attack) by building another deep neural network to predict when transmissions will succeed. The adversary falsifies (poisons) the transmitter's spectrum sensing data over the air by transmitting during the short spectrum sensing period of the transmitter. Depending on whether the transmitter uses the sensing results as test data to make transmit decisions or as training data to retrain its deep neural network, either it is fooled into making incorrect decisions (evasion attack) or the transmitter's algorithm is retrained incorrectly for future decisions (causative attack). Both attacks are energy efficient and hard to detect (stealth) compared to jamming the long data transmission period, and substantially reduce the throughput. A dynamic defense is designed for the transmitter that deliberately makes a small number of incorrect transmissions (selected by the confidence score on channel classification) to manipulate the adversary's training data. This defense effectively fools the adversary (if any) and helps the transmitter sustain its throughput with or without an adversary present. Yalin E. Sagduyu, Yi Shi 0001, Tugba Erpek |
IEEE Trans. Mob. Comput. | 3 |
| 2019 | IoT Network Security from the Perspective of Adversarial Deep LearningabstractMachine learning finds rich applications in Internet of Things (IoT) networks such as information retrieval, traffic management, spectrum sensing, and signal authentication. While there is a surge of interest to understand the security issues of machine learning, their implications have not been understood yet for wireless applications such as those in IoT systems that are susceptible to various attacks due the open and broadcast nature of wireless communications. To support IoT systems with heterogeneous devices of different priorities, we present new techniques built upon adversarial machine learning and apply them to three types of over-the-air (OTA) wireless attacks, namely denial of service (DoS) attack in terms of jamming, spectrum poisoning attack, and priority violation attack. By observing the spectrum, the adversary starts with an exploratory attack to infer the channel access algorithm of an IoT transmitter by building a deep neural network classifier that predicts the transmission outcomes. Based on these prediction results, the wireless attack continues to either jam data transmissions or manipulate sensing results over the air (by transmitting during the sensing phase) to fool the transmitter into making wrong transmit decisions in the test phase (corresponding to an evasion attack). When the IoT transmitter collects sensing results as training data to retrain its channel access algorithm, the adversary launches a causative attack to manipulate the input data to the transmitter over the air. We show that these attacks with different levels of energy consumption and stealthiness lead to significant loss in throughput and success ratio in wireless communications for IoT systems. Then we introduce a defense mechanism that systematically increases the uncertainty of the adversary at the inference stage and improves the performance. Results provide new insights on how to attack and defend IoT networks using deep learning. Yalin E. Sagduyu, Yi Shi 0001, Tugba Erpek |
SECON | 3 |
| 2019 | Network control and rate optimization for multiuser MIMO communications
Tugba Erpek, Yalin E. Sagduyu, Yi Shi 0001, Satya Prakash Ponnaluri |
Ad Hoc Networks | 1 |
| 2018 | Learning a Physical Layer Scheme for the MIMO Interference ChannelabstractThis paper presents a novel physical layer scheme for multiple-input multiple-output (MIMO) communication systems based on unsupervised deep learning (DL) using an autoencoder in an interference channel (IC) environment. Moreover, it extends the single-input single-output (SISO) channel autoencoder to consider fading channel conditions. In both schemes, two physical layer communication system encoders and decoders are jointly optimized in the presence of interference to minimize their symbol error rate (SER). We analyze resulting SER performance for varying signal-to-interference-plus-noise-ratio (SINR) levels. Realistic channel effects; i.e. Rayleigh fading, are used while training the autoencoder system. For SISO systems, the autoencoder system in IC demonstrates significant performance improvement compared to the conventional single-user systems by eliminating interference when there is channel state information (CSI) at the transmitter. The MIMO autoencoder system also shows significant performance improvements compared to the conventional single-user MIMO systems at SINR levels higher than 16dB. MIMO systems with different number of antennas are simulated to analyze the change in the system complexity and scalability. The information required at the transmitter; i.e. CSI from both the intended and interference links, and the autoencoder training time increases with increasing number of antennas for the autoencoder-based MIMO systems. Tugba Erpek, Timothy J. O'Shea, T. Charles Clancy |
ICC | 1 |
| 2018 | Rate Optimization with Distributed Network Coordination of Multiuser MIMO CommunicationsabstractAn adaptive rate optimization solution is presented to utilize the benefits of multiuser multiple-input multiple-output (MU-MIMO) communications in a wireless network with distributed and decentralized control that adapts to dynamic channel, interference, and traffic conditions. First, the ergodic sum rates of MIMO multiple access channel (MAC) and interference channel (IC) configurations are determined by jointly integrating the error and overhead effects due to channel estimation (training) and feedback into the rate optimization. Then, a distributed channel access protocol that leverages local information without any centralized scheduler is developed to select and activate MU-MIMO configurations with the maximum achievable sum rates depending on channel, interference, and traffic conditions. In a mobile ad hoc network (MANET), MU-MIMO is shown to provide major gains in network throughput (after accounting for the control message overhead) compared with single antenna and point-to-point (P2P) MIMO communications. Tugba Erpek, Yalin E. Sagduyu, Yi Shi 0001, Satya Prakash Ponnaluri |
VTC Fall | 1 |