This invention belongs to the field of
deep learning security technology, and particularly relates to a method for poisoning defense of modulation classification models based on
Transformer semi-supervised feature remapping. The method includes: constructing a
signal modulation classification model; obtaining
signal samples at risk of poisoning and performing poisoning training on the
signal modulation classification model to obtain a poisoned
signal modulation classification model; connecting the
backbone network of the poisoned
signal modulation classification model to a
Transformer module; inputting an unlabeled signal sample set into a joint feature remapping channel to obtain a remapped classification model; inputting a clean signal sample set into the remapped classification model and performing supervised fine-tuning; iteratively executing the feature remapping and supervised fine-tuning processes based on semi-
supervised training until the model accuracy stabilizes, thus obtaining a
signal modulation classification model with poisoning defense capabilities. This invention can effectively remove potential backdoors in the model, improve defense performance, and ensure the
high availability of the repaired classification model.