Signal modulation mode identification method based on self-paced self-distillation adversarial training
Through the self-step self-distillation adversarial training method, the adversarial attack intensity of the signal samples is quantified and different weights are given. Combined with weighted cross entropy and self-distillation loss, the generalization ability and robustness of the signal modulation method identification model in the existing technology is solved, and a high-accuracy signal modulation method identification is achieved.
Patent Information
- Application Number
- CN202510771946.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-11
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2045-06-11
AI Technical Summary
The existing signal modulation method identification method based on adversarial training has limited generalization capabilities in complex and dynamic adversarial environments, making it difficult to adapt to attacks of different intensities and types, and lacks a stable feature representation mechanism, which makes it difficult to maintain robustness.
The self-step self-distillation adversarial training method is used to quantify the adversarial attack intensity of the communication signal sample through the signal-scrambling ratio, generate the adversarial samples and assign different weights, and build the total loss function with weighted cross-entropy loss and self-distillation loss, and iterative training is carried out to gradually adapt to different attack intensity and types.
It significantly improves the recognition accuracy of signal modulation methods under adversarial attacks, provides a new adversarial training paradigm under adversarial attacks, and is suitable for various modulation methods identification models.
Smart Images

Figure CN120301742A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication signal modulation mode recognition, and particularly to a signal modulation mode recognition method based on self-paced self-distillation adversarial training. Background Art
[0002] Signal modulation mode recognition is one of the core technologies in the field of wireless communication, and its significance lies in realizing the intelligent analysis and efficient utilization of communication signals. In recent years, the breakthrough of deep learning technology has brought revolutionary progress to modulation recognition. Through models such as convolutional neural networks and recurrent neural networks, the system can directly learn the deep features of modulation patterns from the original signals or time-frequency features, significantly improving the recognition accuracy and robustness. However, research shows that intelligent recognition models based on deep learning are significantly vulnerable in malicious deception scenarios. By adding carefully designed tiny perturbations to communication signal samples, the model can be deceived, resulting in incorrect recognition of the modulation mode of the signal. Such samples are called adversarial samples, and such technologies are called adversarial attacks. Under signal adversarial attacks, the modulation mode recognition accuracy drops significantly, seriously threatening the security of communication systems.
[0003] In a complex electromagnetic environment, adversarial attacks seriously threaten the stability of traditional recognition models, and adversarial training has become the mainstream solution to enhance the adversarial defense ability of modulation recognition models. This solution injects adversarial samples into the training process, forcing the model to learn robust features, thereby enhancing its recognition performance in adversarial environments. For example, the literature (A Madry, A Makelov, L Schmidt, et al. Towards deep learning models resistant to adversarial attacks. arXiv preprint arXiv:1706.06083, 2017.) proposed the classic projected gradient descent-based adversarial training method (PAT), and the robust recognition performance of the model has been significantly improved. The literature (H Zhang, Y Yu, J Jiao, et al. Theoretically principled trade-off between robustness and accuracy. International conference on machine learning. PMLR, 2019: 7472-7482.) proposed the adversarial training method TRADES based on Kullback-Leibler (KL) divergence, which can effectively deal with different types of adversarial attacks and further promoted the research boom of adversarial training. The literature (Z Chen, Z Wang, D Xu, et al. Learn to defend: adversarial multi-distillation for automatic modulation recognition models. IEEE Transactions on Information Forensics and Security, 2024, 19: 3690-3702.) proposed the AMD adversarial training method, which uses two powerful teacher models to transfer the classification knowledge of normal signals and the defense knowledge of adversarial signals to the student model respectively, thereby improving the robustness of signal modulation mode recognition. Although the existing signal modulation mode recognition methods based on adversarial training can improve the robust recognition performance of the model under adversarial attacks to a certain extent, in a more complex and dynamic adversarial environment, they still face the following two major challenges: one is the limited generalization ability to attacks of different intensities and different types. Traditional adversarial training is usually optimized for attacks of fixed intensity and fixed type, and it is difficult to adapt to complex attacks with sudden intensity changes in the communication environment.Second, there is a lack of a stable feature representation mechanism. As the attack intensity increases, the feature space of the signal modulation mode recognition model is prone to shift, and there is a lack of effective feature constraints during the training process, making it difficult to stably maintain robustness. Summary of the Invention
[0004] The purpose of the present invention is to propose a signal modulation mode recognition method based on self-paced self-distillation adversarial training.
[0005] The technical solution to achieve the purpose of the present invention is as follows: A signal modulation mode recognition method based on self-paced self-distillation adversarial training, and the specific steps are as follows:
[0006] Step 1: Obtain a communication signal modulation mode dataset, including modulation mode category labels and communication signal samples, and divide the modulation signal training set and the validation set.
[0007] Step 2: Use ResNet18 as the basic network of the modulation mode recognition model, take the communication signal samples as the input, and the modulation mode category prediction as the output to construct the modulation mode recognition model.
[0008] Step 3: Define the signal-to-interference ratio to quantify the adversarial attack intensity of the communication signal samples, divide the training steps of self-paced learning, and at the same time, set the number of training epochs for each training step, and start the training process of the modulation mode recognition model.
[0009] Step 4: In each training step, generate adversarial samples of each communication signal sample in the training set under the current modulation mode recognition model, evaluate the difficulty of the adversarial samples of the communication signals based on the loss quantile-based model feedback mechanism, and assign different weights for calculating the weighted cross-entropy loss.
[0010] Step 5: Construct a total loss function based on the weighted cross-entropy loss and the self-distillation loss for iterative training. In each training epoch, update the model parameters using the adversarial samples of the training set communication signals, synchronously calculate the recognition accuracy of the original samples in the validation set and save the optimal model; when all epochs of the current training step are completed, advance the training step update, update the easy sample ratio and the lowest weight of the difficult samples, and jump to Step 4 to continue training until all training steps are completed.
[0011] Step 6: Input the communication signals under adversarial attack conditions into the trained signal modulation mode recognition model for modulation mode recognition.
[0012] Further, in Step 1, to obtain a communication signal modulation mode dataset, including modulation mode category labels and various time-domain IQ signal samples, and divide the modulation signal training set and the validation set, the specific method is as follows:
[0013] Set the category label as , where K represents the number of categories. For each communication signal sample, concatenate its I and Q signals into data of size, where the first row represents the I signal and the second row represents the Q signal. represents the number of sampling points of the communication signal sample. Divide the communication signal modulation mode training set and validation set according to a ratio of 9:1.
[0014] Furthermore, in step 2, use ResNet18 as the basic network of the modulation mode recognition model. Taking the communication signal sample as the input and the modulation mode category prediction as the output, construct the modulation mode recognition model. The specific method is as follows:
[0015] Use ResNet18 as the basic network of the modulation mode recognition model; for the training set, validation set, and subsequent test samples, to adapt to the input requirements of the ResNet18 neural network, by adding a channel dimension with a value of 1, reconstruct the communication signal sample of size into three-dimensional , according to the batch size , stack multiple communication signal samples into network input data of size . The network output is the probability predicted to belong to each category, and the output size is . Take the category with the highest probability as the signal category predicted by the modulation mode recognition model.
[0016] Furthermore, in step 3, define the signal-to-interference ratio to quantify the adversarial attack intensity of the communication signal sample, and divide the training steps of self-paced learning. The specific method is as follows:
[0017] Define the signal-to-interference ratio SPR as:
[0018] (1)
[0019] (2)
[0020] (3)
[0021] where, and respectively represent the th sampling points of the I and Q signals of the communication signal; is the anti-perturbation size. The smaller the signal-to-interference ratio SPR, the greater the attack intensity and the higher the difficulty of the adversarial sample;
[0022] Preset the minimum SPR value and the maximum SPR value to determine the range of the SPR value. Through equally spaced division, is discretized into training steps, and each training step corresponding to a fixed attack strength , which is used to gradually increase the adversarial attack strength of the adversarial samples of communication signals, and guide the modulation mode recognition model to gradually adapt from weak attacks to strong attacks.
[0023] Furthermore, in step 4, at each training step, adversarial samples of each communication signal sample in the training set are generated under the current modulation mode recognition model. Based on the model feedback mechanism of loss quantiles, the difficulty of the adversarial samples of communication signals is evaluated and different weights are assigned. The specific method is as follows:
[0024] Step 4.1, at each training step, generate adversarial samples of each communication signal sample in the training set under the current modulation mode recognition model;
[0025] At the training step , for any communication signal sample with an index number in the training set , apply a PGD adversarial attack with an attack strength of . According to the adversarial perturbation size at the -th training step, generate the number of iterations n PGD corresponding adversarial samples . The calculation formula is shown in Equation (4):
[0026] (4)
[0027] In the formula, represents a uniform distribution, is the class label of the sample with index number , = is the single-step perturbation step size, represents the sign function, is the cross-entropy loss function, Clip the adversarial samples into the L2-norm ball centered at with a radius of . The final adversarial sample is ;
[0028] Step 4.2, based on the model feedback mechanism of loss quantiles, evaluate the difficulty of the adversarial samples of communication signals and assign different weights;
[0029] Calculate the cross-entropy loss value of all generated adversarial samples on the current modulation mode recognition model , where is the number of training set samples;
[0030] Use to represent the The proportion of easy samples in a training step to determine the loss quantile threshold for the th training step:
[0031] (5)
[0032] wherein, denotes the set of loss values for adversarial samples, calculate the quantile threshold. After arranging the loss values in ascending order, take the th value as the loss quantile threshold such that at least proportion of the sample loss values do not exceed where is the ceiling function;
[0033] Introduce the minimum weight of hard samples in the current th training step, and adopt a linear weight decay strategy for sample weighting: assign a weight of 1.0 to easy samples, and linearly interpolate the weights of hard samples between 1.0 and in a uniform manner, linearly decreasing in the order of increasing loss. Then the weight of the adversarial sample with the training step index number is calculated as: The calculation formula is expressed as:
[0034] (6).
[0035] Furthermore, in step 5, construct a total loss function based on weighted cross-entropy loss and self-distillation loss for iterative training. In each training epoch, update the model parameters using the adversarial samples of the training set communication signals, synchronously calculate the recognition accuracy of the original samples in the validation set and save the optimal model; when all epochs of the current training step are completed, advance the training step update, update the proportion of easy samples and the minimum weight of hard samples, and jump to step 4 to continue training until all training steps are completed, where: constructing a total loss function based on weighted cross-entropy loss and self-distillation loss, the specific method is:
[0036] (1) Weighted cross-entropy loss
[0037] In each training iteration, regenerate the adversarial samples of the communication signals under the current modulation mode recognition model and calculate the weighted cross-entropy loss function;
[0038] In each training iteration of the th training step, let the index set of the current batch of training set samples be , and apply an attack strength of PGD adversarial attack to obtain the adversarial sample with the index number ; ;
[0039] Based on the weight formula (6), calculate the weighted cross-entropy loss under the current modulation mode recognition model:
[0040] (7)
[0041] In the formula, is the batch size;
[0042] (2) Self-distillation loss
[0043] Construct a teacher model based on the EMA strategy, and its parameters are smoothly updated from the historical state of the current modulation mode recognition model;
[0044] The parameters of the EMA teacher model are denoted as , and they are updated with the current model parameters at each training iteration according to the following rules:
[0045] (8)
[0046] where, initially , is the decay coefficient, used to control the retention ratio of historical information;
[0047] In each training iteration, the current modulation mode recognition model is regarded as the student model, and the output logits of the adversarial sample with the index number are denoted as , the output of the EMA teacher model is , then the self-distillation loss is defined as the KL divergence between the two output distributions:
[0048] (9)
[0049] (3) Total loss function
[0050] Total loss is jointly composed of the weighted cross-entropy loss and the self-distillation loss :
[0051] (10)
[0052] where, is the self-distillation coefficient, used to balance the two losses.
[0053] Further, in step 5, a total loss function is constructed based on the weighted cross-entropy loss and the self-distillation loss for iterative training. In each training round, the adversarial samples of the training set communication signals are used to update the model parameters, and the recognition accuracy of the original samples in the validation set is synchronously calculated and the optimal model is saved; when all rounds of the current training step are completed, the training step is advanced and updated, the easy sample ratio and the minimum weight of the hard samples are updated, and then it jumps to step 4 to continue training until all training steps are completed, where: updating the easy sample ratio and the minimum weight of the hard samples , and the specific method is as follows:
[0054] (11)
[0055] (12)
[0056] Among them, is the maximum SPR value, starting from the initial value of the easy sample ratio and gradually decreasing with a step size of ; starting from the initial value of the minimum weight of the hard samples and gradually increasing with a step size of .
[0057] A signal modulation mode recognition system based on self-paced self-distillation adversarial training implements the signal modulation mode recognition method based on self-paced self-distillation adversarial training, and realizes the signal modulation mode recognition based on self-paced self-distillation adversarial training, and six modules are respectively used to execute steps 1 to 6.
[0058] A computer device includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the signal modulation mode recognition method based on self-paced self-distillation adversarial training is implemented, and the signal modulation mode recognition based on self-paced self-distillation adversarial training is realized.
[0059] A computer-readable storage medium stores a computer program thereon. When the computer program is executed by a processor, the signal modulation mode recognition method based on self-paced self-distillation adversarial training is implemented, and the signal modulation mode recognition based on self-paced self-distillation adversarial training is realized.
[0060] Compared with the prior art, the significant advantages of the present invention are as follows: 1) It has good generalization for adversarial samples of communication signals with different attack intensities and different attack types, and significantly improves the recognition accuracy of signal modulation modes under adversarial attacks; 2) It provides a new adversarial training paradigm under adversarial attacks, which is applicable to various modulation mode recognition models. Description of the Drawings
[0061] Figure 1 It is the flowchart of the signal modulation mode recognition method based on self-paced self-distillation adversarial training of the present invention.
[0062] Figure 2 It is the recognition accuracy curve graph of four adversarial training methods under the PGD adversarial attack with different SPRs when the signal-to-noise ratio is 10 dB.
[0063] Figure 3 It is the recognition accuracy curve graph of four adversarial training methods under the FGSM adversarial attack with different SPRs when the signal-to-noise ratio is 10 dB. Specific implementation manners
[0064] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0065] As Figure 1 shown, a signal modulation mode recognition method based on self-paced self-distillation adversarial training of the present invention specifically includes the following steps:
[0066] Step 1: Obtain a communication signal modulation mode data set, including modulation mode category labels and communication signal samples, and divide the modulation signal training set and the validation set;
[0067] Set the category label as , where K represents the number of categories. For each communication signal sample, splice its I and Q channel signals into data of size, where the first row represents the I channel signal and the second row represents the Q channel signal, represents the number of sampling points of the communication signal sample. Divide the communication signal modulation mode training set and the validation set according to the ratio of 9:1.
[0068] Step 2: Use ResNet18 as the basic network of the modulation mode recognition model, take the communication signal sample as the input and the modulation mode category prediction as the output to construct the modulation mode recognition model;
[0069] For the training set, the validation set and subsequent test samples, to adapt to the input requirements of the ResNet18 neural network, by adding a channel dimension (value of 1), reconstruct the communication signal sample with a size of into a three-dimensional , according to the batch size , stack multiple communication signal samples into network input data with a size of , and the network output is the probability predicted to belong to each category, and the output size is , select the category with the highest probability as the signal category predicted by the modulation mode recognition model.
[0070] Step 3, define the adversarial attack intensity of the communication signal samples by the signal-to-perturbation ratio (SPR), divide the training paces of self-paced learning, and at the same time, set the number of training epochs for each training pace, and start the training process of the modulation mode recognition model;
[0071] To quantify the adversarial attack intensity, the definition of the signal-to-perturbation ratio (SPR) is adopted, that is:
[0072] (1)
[0073] (2)
[0074] (3)
[0075] Wherein, and respectively represent the th sampling point of the in-phase signal and the quadrature signal of the communication signal; is the anti-perturbation size. The smaller the SPR, the greater the attack intensity and the higher the difficulty of the adversarial sample.
[0076] Preset the minimum SPR value and the maximum SPR value to determine the range of SPR values. By equally spaced division, is discretized into training paces, and each training pace corresponds to a fixed attack intensity , which is used to gradually increase the adversarial attack intensity of the adversarial samples of the communication signal and guide the modulation mode recognition model to gradually adapt from weak attacks to strong attacks.
[0077] It should be noted that the training pace here refers to each stage of self-paced learning, rather than the training epoch or iteration in the traditional machine learning field. Each training pace trains training epochs. In the specific implementation of the present invention, SPR takes integer values in the range of [10, 20] dB, starting from 20 dB and gradually decreasing to 10 dB with a step size of 1 dB, a total of 11 training paces are divided. The number of training epochs for each training pace is set to 10. Therefore, a total of 110 epochs are trained. When starting the training process of the modulation mode recognition model, the following training parameters are also set: the learning rate is 0.001, the optimizer is Adam, and the batch sizes of the training data and the validation data are 128.
[0078] Step 4, at each training step, generate adversarial samples for each communication signal sample in the training set under the current modulation mode recognition model. Based on the model feedback mechanism of loss quantiles, evaluate the difficulty of the adversarial samples of the communication signals and assign different weights. A model feedback mechanism based on loss quantiles is proposed to adaptively evaluate the difficulty of the adversarial samples of the communication signals at each training step and assign different weights to them;
[0079] Step 4.1, at the training step , for any communication signal sample with an index number in the training set , apply the PGD adversarial attack with an attack intensity of . According to equations (1)-(3), the size of the adversarial perturbation at the -th training step can be calculated. Then, generate the PGD adversarial sample with the number of iterations . The calculation formula is shown in equation (4).
[0080] (4)
[0081] In the formula, represents a uniform distribution, is the class label of the sample with the index number , is the single-step perturbation step size (usually set to ), represents the sign function, is the cross-entropy loss function, Clip the adversarial sample into the L2-norm ball centered at with a radius of . The final adversarial sample is .
[0082] Note that at this time, the adversarial samples generated from the original communication signal samples are only used to calculate the weights and do not participate in the training of the subsequent modulation mode recognition model.
[0083] Step 4.2, based on the model feedback mechanism of loss quantiles, evaluate the difficulty of the adversarial samples of the communication signals and assign different weights;
[0084] Calculate the cross-entropy loss values of all the generated adversarial samples of the communication signals on the current modulation mode recognition model , where is the number of samples in the training set. Note that the cross-entropy loss values calculated at this time are only used to calculate the weights and do not participate in the backpropagation of the gradients of the modulation mode recognition model.
[0085] Step 4.3, use Represents the proportion of easy samples at the th training step, and determines the loss quantile threshold at the th training step :
[0086] (5)
[0087] In the formula, represents the set of loss values for adversarial samples Calculate the quantile threshold: After arranging the loss values in ascending order, take the th value as the loss quantile threshold , such that at least proportion of the sample loss values do not exceed this threshold ( is the ceiling function);
[0088] Group the adversarial samples of the communication signal according to this threshold, and introduce the minimum weight of the hard samples at the current th training step , and adopt a linear weight decay strategy for sample weighting: Assign a weight of 1.0 to easy samples, and linearly interpolate the weights of hard samples between 1.0 and , linearly decreasing in ascending order of loss. Then the weight of the adversarial sample with the training step index number can be expressed by the formula:
[0089] (6)
[0090] Step 5, construct a total loss function based on weighted cross-entropy loss and self-distillation loss for iterative training. In each training epoch, update the model parameters using the adversarial samples of the training set communication signals, synchronously calculate the recognition accuracy of the original samples in the validation set and save the optimal model; When all epochs of the current training step are completed, advance the training step update, update the proportion of easy samples and the minimum weight of hard samples, and jump to Step 4 to continue training until all training steps are completed;
[0091] In each training iteration of the th training step, calculate the weighted cross-entropy loss function; At the same time, construct a self-distillation mechanism based on Exponential Moving Average (EMA), calculate the self-distillation loss; Finally, obtain the total loss, train the modulation mode recognition model, and save the modulation mode recognition model with the best recognition accuracy on the validation set;
[0092] (1) Weighted cross-entropy loss
[0093] Regenerate the adversarial samples under the current modulation mode recognition model in each training iteration and calculate the weighted cross-entropy loss function;
[0094] At the -th training step in each training iteration, let the index set of the current batch of training set samples be , apply the PGD adversarial attack with an attack intensity of on the basis of the current modulation mode recognition model according to formulas (1)-(3), and obtain the adversarial samples of the communication signal with the index number . .
[0095] Based on the weight formula (6), calculate the weighted cross-entropy loss under the current modulation mode recognition model:
[0096] (7)
[0097] In the formula, is the batch size.
[0098] (2) Self-distillation loss
[0099] Construct a teacher model based on the EMA strategy, and its parameters are smoothed and updated from the historical state of the current modulation mode recognition model.
[0100] The parameters of the EMA teacher model are denoted as , and they are updated with the current model parameters in each training iteration according to the following rules:
[0101] (8)
[0102] Among them, initially , is the decay coefficient, which is used to control the retention ratio of historical information. Generally, it is set to a value close to 1. In the specific implementation of the present invention, it is set to 0.999. This strategy can effectively suppress the gradient oscillation during training, make the output of the teacher model smoother and more robust, and thus provide a stable feature representation reference for the student model.
[0103] In each training iteration, the current modulation mode recognition model is regarded as the student model, and the output logits of the adversarial samples with the index number are expressed as , and the output of the EMA teacher model is . Then the self-distillation loss is defined as the KL divergence between the output distributions of the two:
[0104] (9)
[0105] (3) Calculate the total loss
[0106] Total loss is composed of weighted cross - entropy loss and self - distillation loss jointly:
[0107] (10)
[0108] Wherein, is the self - distillation coefficient, used to balance the two losses. In the specific implementation of the present invention, .
[0109] After each training epoch, the accuracy of the current modulation mode recognition model is calculated using the validation set, and the initial historical highest accuracy is set to 0. If the current accuracy exceeds the historical highest accuracy, the model parameters are immediately saved, and the historical highest accuracy is updated. After the entire training is completed, the finally saved is the modulation mode recognition model with the best performance on the validation set.
[0110] As the training steps progress, update the easy sample ratio and the minimum weight sum of hard samples , and jump to step 4 to continue training until all training steps are completed. Specifically, update the easy sample ratio and the minimum weight sum of hard samples respectively according to equations (11) and (12):
[0111] (11)
[0112] (12)
[0113] Wherein, starts from a relatively large initial value of the easy sample ratio and gradually decreases with a step size ; starts from a relatively small initial value of the minimum weight of hard samples and gradually increases with a step size . This dynamic update strategy ensures that the modulation mode recognition model learns simple samples and weak attacks in the initial stage of training, and then gradually transitions to hard samples and strong attack scenarios, thereby effectively improving the overall robustness and generalization ability. In the specific implementation of the present invention, , , .
[0114] Thus, within each training step, an adaptive difficulty assessment independent of the absolute loss value is realized, and self - paced learning of the modulation mode recognition model is achieved through weighted cross - entropy loss and dynamic update strategy.
[0115] Step 6: Input the communication signal samples under the adversarial attack conditions to be tested into the trained signal modulation mode recognition model for robust modulation mode recognition.
[0116] Embodiment
[0117] To verify the effectiveness of the present invention, experiments were carried out based on the Python language and the Pytorch framework using the publicly available communication signal modulation signal dataset RML2016.10a. This dataset contains 11 modulation modes including 8PSK, AM-DSB, AM-SSB, BPSK, CPFSK, GFSK, 4-PAM, 16-QAM, 64-QAM, QPSK, and WBFM.
[0118] In this embodiment, first, the dataset is divided, and a network architecture based on ResNet18 is constructed as the signal modulation mode recognition model. Secondly, the intensity of the adversarial attack is quantified, the training steps are divided according to the attack intensity, the training parameters are initialized, and the training begins. Then, the difficulty of the signal adversarial samples is adaptively evaluated at each training step and different weights are assigned. Next, in each training iteration, the weighted cross-entropy loss function is calculated; at the same time, a self-distillation mechanism based on EMA is constructed to calculate the self-distillation loss; finally, the total loss is obtained for training the modulation mode recognition model, and the modulation mode recognition model with the best recognition accuracy on the validation set is saved. Then, as the training steps progress, the proportion of easy samples and the minimum weight of difficult samples are updated until the training ends. Finally, the effectiveness of the method proposed in the present invention is verified on the communication signal data to be tested.
[0119] Figure 2 The effectiveness of the method proposed in the present invention is verified by comparing the recognition accuracies of four adversarial training methods under the PGD adversarial attack conditions with different SPRs at a signal-to-noise ratio of 10 dB. Figure 3 The effectiveness of the method proposed in the present invention is verified by comparing the recognition accuracies of four adversarial training methods under the FGSM adversarial attack conditions with different SPRs at a signal-to-noise ratio of 10 dB. The results all show that the method proposed in the present invention can have good generalization under different types and intensities of adversarial attacks and improve the recognition accuracy of the signal modulation mode under adversarial attacks.
[0120] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0121] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. A method for identifying signal modulation modes based on self-paced self-distillation adversarial training, characterized in that The specific steps are as follows: Step 1: Obtain a communication signal modulation mode dataset, including modulation mode category labels and communication signal samples, and divide the modulation signal training set and validation set; Step 2: Use ResNet18 as the basic network of the modulation mode recognition model, take the communication signal samples as the input, and the modulation mode category prediction as the output to construct the modulation mode recognition model; Step 3: Define the signal-to-interference ratio to quantify the adversarial attack intensity of communication signal samples, divide the training steps of self-paced learning, and at the same time, set the number of training epochs for each training step, and start the training process of the modulation mode recognition model; Step 4: In each training step, generate adversarial samples of each communication signal sample in the training set under the current modulation mode recognition model, and based on the loss quantile-based model feedback mechanism, evaluate the difficulty of the adversarial samples of the communication signals and assign different weights for calculating the weighted cross-entropy loss; Step 5: Construct a total loss function based on the weighted cross-entropy loss and self-distillation loss for iterative training. In each training epoch, update the model parameters using the adversarial samples of the training set communication signals, synchronously calculate the recognition accuracy of the original samples in the validation set and save the optimal model; when all epochs of the current training step are completed, advance the training step update, update the easy sample ratio and the minimum weight of the difficult samples, and jump to Step 4 to continue training until all training steps are completed; Step 6: Input the communication signals under adversarial attack conditions into the trained signal modulation mode recognition model for modulation mode recognition.
2. The signal modulation mode recognition method based on self-paced self-distillation adversarial training according to claim 1, wherein Step 1: Obtain a communication signal modulation mode dataset, including modulation mode category labels and various time-domain IQ signal samples, and divide the modulation signal training set and validation set. The specific method is as follows: Set the class label as , where \(K\) represents the number of classes. For each communication signal sample, concatenate its in-phase (I) and quadrature (Q) signals into data of size, where the first row represents the I-channel signal and the second row represents the Q-channel signal. represents the number of sampling points of the communication signal sample. Divide the communication signal modulation mode training set and validation set according to a ratio of 9:
1.
3. The method for identifying signal modulation modes based on self-paced self-distillation adversarial training according to claim 1, wherein Step 2: Use ResNet18 as the basic network of the modulation mode recognition model, take the communication signal samples as the input, and the modulation mode category prediction as the output to construct the modulation mode recognition model. The specific method is as follows: Use ResNet18 as the basic network of the modulation mode recognition model; for the training set, validation set, and subsequent test samples, to adapt to the input requirements of the ResNet18 neural network, by adding a channel dimension with a value of 1, the communication signal samples with a size of are reconstructed into three-dimensional . According to the batch size , multiple communication signal samples are stacked into network input data with a size of . The network output is the probability predicted for each category, and the output size is . The category with the highest probability is taken as the signal category predicted by the modulation mode recognition model.
4. The method for identifying signal modulation modes based on self-paced self-distillation adversarial training according to claim 1, wherein Step 3: Define the signal-to-interference ratio to quantify the adversarial attack intensity of communication signal samples, and divide the training steps of self-paced learning. The specific method is as follows: Define the signal-to-interference ratio SPR as: (1) (2) (3) Among them, and respectively represent the th sampling points of the I-channel signal and the Q-channel signal of the communication signal; is the size of anti-disturbance. The smaller the signal-to-interference ratio SPR, the greater the attack intensity and the higher the difficulty of adversarial samples; Preset the minimum SPR value and the maximum SPR value to determine the range of SPR values. By equally spaced partitioning, is discretized into training steps, and each training step corresponds to a fixed attack intensity to gradually increase the adversarial attack intensity of the adversarial samples of the communication signal and guide the modulation mode recognition model to gradually adapt from weak attacks to strong attacks.
5. The signal modulation mode recognition method based on self-paced self-distillation adversarial training according to claim 1, characterized in that Step 4: In each training step, generate adversarial samples of each communication signal sample in the training set under the current modulation mode recognition model, and based on the loss quantile-based model feedback mechanism, evaluate the difficulty of the adversarial samples of the communication signals and assign different weights. The specific method is as follows: Step 4.1: In each training step, generate adversarial samples of each communication signal sample in the training set under the current modulation mode recognition model; At the training step , for any communication signal sample with an index number of in the training set , apply the PGD adversarial attack with an attack intensity of . According to the adversarial perturbation size of the th training step, generate the number of iterations n PGD corresponding adversarial sample . The calculation formula is shown in Equation (4): (4) wherein, represents a uniform distribution, is the class label with the sample index number of ; = is the single-step perturbation step size, represents the sign function, is the cross-entropy loss function, clips the adversarial sample into the L2-norm ball centered at with a radius of , and the final adversarial sample is ; Step 4.2: Based on the loss quantile-based model feedback mechanism, evaluate the difficulty of the adversarial samples of the communication signals and assign different weights; Calculate the cross-entropy loss value of all generated adversarial samples on the current modulation mode recognition model , where is the number of training set samples; Use to represent the proportion of easy samples at the -th training step, and determine the loss quantile threshold at the -th training step : (5) wherein, represents the set of loss values for adversarial samples Calculate the quantile threshold. After arranging the loss values in ascending order, take the -th value as the loss quantile threshold such that at least proportion of the sample loss values do not exceed , is the ceiling function; Introduce the current Minimum weight of hard samples in the training step , and adopt a linear weight decay strategy for sample weighting: assign a weight of 1.0 to simple samples, and linearly decay the weights of hard samples between 1.0 and , in ascending order of loss, then the index number of this training step is Adversarial sample weight The calculation formula is expressed as: (6)。 6. The signal modulation mode recognition method based on self-paced self-distillation adversarial training according to claim 5, wherein Step 5: Construct a total loss function based on weighted cross-entropy loss and self-distillation loss for iterative training. In each training round, update the model parameters using the adversarial samples of the training set communication signals, synchronously calculate the recognition accuracy of the original samples in the validation set, and save the optimal model. When all rounds of the current training step are completed, advance the training step update, update the easy sample ratio and the minimum weight of the hard samples, and jump to Step 4 to continue training until all training steps are completed, where: constructing the total loss function based on weighted cross-entropy loss and self-distillation loss, the specific method is as follows: (1) Weighted cross-entropy loss In each training iteration, regenerate the adversarial samples of the communication signals under the current modulation mode recognition model and calculate the weighted cross-entropy loss function; In each training iteration of the th training step, let the index set of the current batch of training set samples be , and apply the PGD adversarial attack with an attack strength of on the current modulation mode recognition model to obtain the adversarial sample with the index number ; Based on the weight formula (6), calculate the weighted cross-entropy loss under the current modulation mode recognition model: (7) In the formula, is the batch size; (2) Self-distillation loss Construct a teacher model based on the EMA strategy, and its parameters are smoothly updated from the historical state of the current modulation mode recognition model; The parameters of the EMA teacher model are denoted as , which are updated according to the following rules with the current model parameters at each training iteration: (8) Among them, initially , is the attenuation coefficient, which is used to control the retention ratio of historical information; In each training iteration, the current modulation mode recognition model is regarded as the student model, and the output logits of the adversarial samples with index number are denoted as , the output of the EMA teacher model is , then the self-distillation loss is defined as the KL divergence between the output distributions of the two: (9) (3) Total loss function Total loss composed of weighted cross-entropy loss and self-distillation loss jointly constitute: (10) Among them, is the self-distillation coefficient, which is used to balance the two losses.
7. The signal modulation mode recognition method based on self-paced self-distillation adversarial training according to claim 5, characterized in that Step 5: Construct a total loss function based on weighted cross-entropy loss and self-distillation loss for iterative training. In each training round, update the model parameters using adversarial samples of the training set communication signals, synchronously calculate the recognition accuracy of the original samples in the validation set, and save the optimal model. When all rounds of the current training step are completed, advance the training step update, update the easy sample ratio and the minimum weight of the hard samples, and jump to Step 4 to continue training until all training steps are completed, where: Update the easy sample ratio and the minimum weight of the hard samples , and the specific method is as follows: (11) (12) Among them, is the maximum SPR value, starting from the initial value of the easy sample ratio and gradually decreasing with a step size of ; starting from the initial value of the lowest weight of the difficult samples and gradually increasing with a step size of .
8. A signal modulation mode recognition system based on self-paced self-distillation adversarial training, which implements the signal modulation mode recognition method based on self-paced self-distillation adversarial training according to any one of claims 1-7, and realizes the signal modulation mode recognition based on self-paced self-distillation adversarial training, and separately executes Steps 1-6 in six modules.
9. A computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements the signal modulation mode recognition method based on self-paced self-distillation adversarial training according to any one of claims 1-7, and realizes the signal modulation mode recognition based on self-paced self-distillation adversarial training.
10. A computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the signal modulation mode recognition method based on self-paced self-distillation adversarial training according to any one of claims 1-7, and realizes the signal modulation mode recognition based on self-paced self-distillation adversarial training.
Citation Information
Patent Citations
Network traffic classification method
CN110059747A
Deep neural network adversarial training method based on adaptive attack intensity
CN118468981A
Confrontation attack method based on reconstruction data and substitution model
CN119204157A
Radio signal identification method based on time-frequency guided countermeasure sample purification
CN119807803A
Method and system for training a neural network model using adversarial learning and knowledge distillation
US20230222353A1