A dual-level intelligent countermeasure method and system for electromagnetic spectrum perception

By adopting a two-level intelligent adversarial method in the field of electromagnetic spectrum perception, designing hidden adversarial waveforms and performing poisoning data insertion, the problem of insufficient adversarial sample interference in the existing technology is solved, and efficient adversarial effect and model robustness are achieved.

CN114528877BActive Publication Date: 2025-05-23XIDIAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202210111679.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-01-29
Publication Date
2025-05-23
Estimated Expiration
2042-01-29

AI Technical Summary

Technical Problem

In the field of electromagnetic spectrum perception, it is difficult to generate effective adversarial samples to interfere with high-performance deep perception models, resulting in insufficient interference capabilities of adversarial samples and inability to achieve the expected interference effect.

Method used

Using a two-level intelligent adversarial method, first, the hidden adversarial waveform is designed at the waveform level, and natural evolution algorithms are used to generate adversarial waveforms with and without signals; second, at the feature level, the poisoned data is inserted to enhance the robustness of the adversarial sample.

Benefits of technology

Through the two-level design, the generated adversarial samples can effectively interfere with the electromagnetic spectrum perception system, improve the practicality and concealment of the adversarial samples, and enhance the robustness and adversarial performance of the model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114528877B_ABST
    Figure CN114528877B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of intelligent confrontation in electromagnetic spectrum perception, and discloses a two-level intelligent confrontation method and system for electromagnetic spectrum perception, which is divided into waveform level and feature level; at the waveform level, a hidden confrontation waveform is designed through embedded communication, and two hidden confrontation waveforms with and without signals are designed by natural evolution algorithm, which can effectively reduce the perception accuracy of the intelligent spectrum perception system; at the feature level, when the deep neural network is trained, poisoned data insertion is realized by directly intervening in the training data to improve the robustness of the confrontation; according to the designed waveform and data poisoning, the final confrontation sample is generated, and it is divided into two categories: with signal and without signal: when the channel has a signal, the interference with signal is released; when the channel has no signal, the interference without signal is released. The present invention effectively realizes the intelligent confrontation of electromagnetic spectrum perception, and has good performance under the condition of small confrontation disturbance, and maintains strong robustness.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of intelligent confrontation in electromagnetic spectrum perception, and in particular, relates to a double-level intelligent confrontation method and system for electromagnetic spectrum perception. Background Art

[0002] With the advent of the information age, the technical level and business scale in the field of wireless communications have achieved leapfrog growth. Radio communications have greatly improved in terms of speed, stability, communication distance, and communication efficiency. With the widespread application of artificial intelligence in this field, radio communications have also made breakthroughs in intelligence and convenience, which will undoubtedly help to better meet people's actual needs for communication services. Therefore, cognitive radio is considered to be a technical means to intelligently perceive the spectrum environment and effectively utilize the wireless spectrum. However, deep neural network models are vulnerable to adversarial forces. If deep neural networks are seriously threatened or even destroyed by adversarial forces, normal spectrum perception or modulation recognition cannot be achieved. This will affect the ability of cognitive radio to achieve intelligent communication, resulting in the inability to make wise and fast business decisions. At present, most of the research on adversarial samples focuses on images. There is no relevant research on the actual physical application in the field of communications, and it is only theoretical research.

[0003] At present, there are many methods for studying adversarial problems in the literature. Szegedy et al. first proposed the concept of adversarial samples. They successfully changed the classifier's prediction results for the input samples by adding tiny perturbations that are imperceptible to the human eye (Szegedy C, Zaremba W, Sutskever I, et al. Intriguing properties of neural networks [C]. Proc. Int. Conf. Learn. Representations, 2015: 1-10.). After adversarial examples were proposed, many adversarial methods emerged, including: fast gradient symbol method (Goodfellow I, Shlens J, Szegedyn C, et al. Explaining and harnessing adversarial examples [C]. Proc. Int. Conf. Learn. Representations, 2015: 189-199.), basic iterative method (Kurakin A, Goodfellow I, Bengio S, et al. Adversarial examples in the physical world [C]. Proc. Int. Conf. Learn. Representations, 2016: 128-141.), Jacobian matrix-based saliency mapping (Papernot N, McDaniel P, Jha S, et al. The limitations of deep learning in adversarial settings [J]. IEEE European Symposium on Security and Privacy, 2016, 1 (1): 372-387.), projected gradient descent method (Madry A, Schmidt L, Tsipras D, et al.Towards deep learning models resistant to adversarial attacks[C].Proc.Int.Conf.Learn.Representations,2018:1-23.), momentum iteration method (Dong Y, Liao F, Pang T, et al.Boosting adversarialattacks with momentum[C].Proc.IEEE.Conf.Comput.Vis.Pattern Recognit, 2018:9185-9903.) etc.In order to improve the robustness of the model, researchers have proposed different defense models for different methods. Kui Ren et al. summarized the representative adversarial defense methods in recent years, mainly including adversarial training, randomization-based methods, denoising methods, provable defenses, and some other new defense methods, and pointed out that these defense methods have different effectiveness in different environments (Ren K, Zheng T, Qin Z, et al. Adversarial Attacks and Defenses in Deep Learning [J]. Engineering, 2020, 6 (3): 346-360.).

[0004] In order to introduce adversarial samples into the field of modulated signal recognition to improve the robustness of the recognition model, Sadeghi et al. first introduced adversarial attacks into wireless communications and initiated direct access (Sadeghi M, Larsson E G. Adversarial Attacks on Deep-Learning Based Radio Signal Classification[J]. IEEE Wireless Communications Letters, 2019, 8(1): 213-216.). Zhao et al. applied the Nesterov Adam iteration method to modulated signal recognition and increased the waveform similarity between the generated signal adversarial samples and the original signal (Zhao H, Lin Y, Gao S, et al. Evaluating and Improving Adversarial Attacks on Deep Neural Network-Based Modulation Recognition[C]. GLOBECOM 2020-2020 IEEE Global Communications Conference, 2020: 1-5.). Lin et al. applied four methods based on label-based gradient calculation to modulated signal recognition and verified that the deep neural network model used to classify modulated signals is vulnerable to adversarial samples (Lin Y, Zhao H, Ma X, et al. Adversarial Attacks in Modulation Recognition With Convolutional Neural Networks [J]. IEEE Transactions on Reliability, 2021, 70 (1): 389-401.). However, the above adversarial methods are mostly used in the fields of image recognition and signal recognition, but there has been no reported research in the field of electromagnetic spectrum perception.

[0005] Through the above analysis, the problems and defects of the prior art are as follows:

[0006] (1) Most existing methods are based on neural networks with simple structures, and the adversarial samples generated by them perform poorly on high-performance deep perception models.

[0007] (2) After the iteration process, the adversarial examples generated are not enough to induce high-performance complex models or adversarial models to perceive errors. This will lead to a decrease in the interference ability of the adversarial examples, far from achieving the expected interference effect.

[0008] (3) Current technology directly generates adversarial samples, which are not very practical and transferable.

[0009] The difficulty in solving the above problems and defects is that the complex high-performance perception model itself has a certain defensiveness, which will weaken the performance of traditional methods. Therefore, the design at the waveform level and the feature level, as well as the balance and combination between the two levels, are the technical difficulties of the two-level intelligent confrontation of the electromagnetic spectrum perception system.

[0010] The significance of solving the above problems and defects is: realizing a two-level intelligent confrontation system for the electromagnetic spectrum perception system fills the gap in the confrontation field of the electromagnetic spectrum perception system, and can provide a new method for discovering deep learning network vulnerabilities of the perception model, which can not only enhance the performance of the perception model, but also promote the robustness of the perception model and the improvement of the confrontation performance from the opposite side. Summary of the invention

[0011] In view of the problems existing in the prior art, the present invention provides a dual-level intelligent countermeasure method, system, medium and equipment for electromagnetic spectrum perception.

[0012] The present invention is implemented as follows: a dual-level intelligent countermeasure method for electromagnetic spectrum perception, the dual-level intelligent countermeasure method for electromagnetic spectrum perception includes:

[0013] The first step, waveform level: design a hidden adversarial waveform through embedded communication, and use the natural evolution algorithm to design two hidden adversarial waveforms with and without signals. The waveform level design hides the interference information and can provide better interference capabilities.

[0014] The second step, feature level: when the deep neural network is trained, poisoned data insertion is achieved by directly intervening in the training data. Feature level design further deepens the interference capability and enhances the robustness of the attack.

[0015] The third step is to generate the final adversarial samples based on the designed waveform and data poisoning, which are divided into two categories: signal and no signal: when the channel has a signal, release signal interference; when the channel has no signal, release no signal interference. Generating adversarial samples in a semi-automatic way greatly enhances the practicality and concealment of the method.

[0016] Furthermore, the first step of the waveform level: designing a concealed adversarial waveform through embedded communication, and designing two concealed adversarial waveforms with and without signals by natural evolution algorithm specifically includes:

[0017] Step 1: Obtain the covariance matrix of the electromagnetic signal, determine the passband and stopband, and use the method of determining the signal passband and stopband: the singular value is from small to large, and the area where the total energy is less than 20% is the stopband area;

[0018] Replacing the singular values ​​in the passband region with zeros gives the following matrix V:

[0019]

[0020] Among them, Δ ND =diag(σ L+1 ,σ L+2 ,…,σ r ) is the diagonal matrix of the stopband region, and σ is the corresponding eigenvalue;

[0021] Step 2: Initialize the population and encode the genes using integer encoding. One gene corresponds to a stop band diagonal element σ, and the number of genes of an individual can be controlled in the single digit.

[0022] Step 3: Fitness calculation. Each individual gene calculates the fitness of the individual according to the objective function. The individual with the minimum fitness value is saved as the optimal individual in one iteration. The objective function is as follows:

[0023] F=D(x,x′)+M×loss(x′);

[0024] Where x = x 1 ,…,x n represents the original signal vector; x′=x′ 1 ,…,x′ n represents the currently generated adversarial sample signal vector; D(x,x′) represents the similarity between the two; M is a positive number much larger than D(x,x′), and loss(x′) is the loss function;

[0025] When performing non-targeted attacks, loss(x′) is defined as:

[0026] loss(x′)=max([f(x′)] r -max([f(x′)]i≠r ),0);

[0027] Where r represents the category of the original sample; [f(x′)] r The output of is the probability that sample x′ is identified as category r; [f(x′)] i≠r The output of is the probability that sample x′ is identified as not being of category r;

[0028] Step 4: Using uniform crossover, for two random individuals, each gene is independently crossed with probability p;

[0029] Step 5: Combined with the problem to be solved, the Gaussian mutation algorithm is used, formula:

[0030] x mutation =x origin ±Gauss(m,s);

[0031] Among them, x origin represents the original gene, x mutation represents the mutant gene, Gauss(m,s) represents Gaussian noise, m is the mean of Gaussian noise, and s is the standard deviation of Gaussian noise;

[0032] During the mutation process, Gaussian noise Gauss(m,s) is randomly added to the genes in the individual;

[0033] Step 6: Termination judgment, if the algorithm meets the termination condition, exit the loop iteration, otherwise return to step 3.

[0034] Furthermore, signal interference is added and interferes with the system when there is a signal in the channel. During the design, the signal mixed with noise in the spectrum sensing channel is selected for iteration; no-signal interference is added and interferes with the system when there is no signal in the channel. During the design, pure noise when there is no signal in the spectrum sensing channel is selected for iteration; signal interference and no-signal interference are processed using steps one to six.

[0035] Furthermore, the second step, feature level: when the deep neural network is trained, poisoning data insertion is implemented by directly intervening in the training data, specifically including:

[0036] Step 1: Establish a data poisoning model. When inserting poisoned data, a limited number of poisoned feature vectors are added. Data poisoning starts from a clean training data set, and the data set is represented as D 0 , and transform it into another poisoned dataset D; the learning algorithm is trained on D to induce the target decision of the feature vector set in the target instance set S; two issues are compromised when poisoning the dataset: achieving the malicious goal and minimizing the modification cost; the former term is expressed as the general risk function R of the attacker A(D, S), the function changes with the learning parameter ω; ω is the parameter obtained by training the model on the poisoned training data D; at the same time, the cost function is expressed as c(D 0 ,D):

[0037] The optimization problem is expressed as:

[0038]

[0039] stc(D 0 ,D)≤C

[0040] Where C is the specified modification cost budget, and the attacker’s utility is defined as U A (D,S)=-R A (D, S); transform the risk problem into the maximum utility; there are two cases of electromagnetic spectrum perception, one is the perception of signal, the label is set to 1; the other is the perception of no signal, the label is set to 0;

[0041] Step 2: Insert poisoned data into the signal channel. When the signal channel is collected and the training set is made during the deep neural network training, the designed signal-free interference and pure noise are combined and sent to the target antenna. After the target antenna receives it, the original data mixed with poisoned data will be made into a training set. The poisoned data is signal-free interference plus pure noise, with a label of 1, for deep neural network training;

[0042] Step 3: Insert poisoned data into the signal-free channel. During the deep neural network training, when the signal-free channel is collected and the training set is made, the signal channel will be mistakenly detected as a signal-free channel. The designed signal interference and signal are combined and sent to the target antenna. After the target antenna receives it, the original data mixed with poisoned data will be made into a training set. The poisoned data is signal interference plus signal, with a label of 0, for deep neural network training; the poisoned data occupies 15% to 20% of the original signal.

[0043] Furthermore, the third step generates the final adversarial samples according to the designed waveform and data poisoning, and is divided into two categories: with signal and without signal: when the channel has a signal, release the signal interference; when the channel has no signal, release the signal interference specifically including:

[0044] Step 1: Transmit interference. When there is a signal in the channel, transmit interference with the signal; when there is no signal in the channel, transmit interference without the signal;

[0045] Step 2: Interference reception: the target antenna receiving end will receive two signals: signal interference plus signal and no signal interference plus pure noise;

[0046] Step 3: Adversarial sample generation. After filtering, sampling, and covariance matrix calculation, the target receiver processes the two signals before putting them into the deep neural network. A large amount of data is used to covertly generate the final adversarial sample.

[0047] Another object of the present invention is to provide a computer device, comprising a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the dual-level intelligent countermeasure method for electromagnetic spectrum perception.

[0048] Another object of the present invention is to provide a computer-readable storage medium storing a computer program, which, when executed by a processor, enables the processor to perform the steps of the dual-level intelligent countermeasure method for electromagnetic spectrum perception.

[0049] Another object of the present invention is to provide an information data processing terminal, which is used to implement the two-level intelligent confrontation method of electromagnetic spectrum perception.

[0050] Another object of the present invention is to provide a dual-level intelligent confrontation system for implementing the dual-level intelligent confrontation method of electromagnetic spectrum perception, the dual-level intelligent confrontation system comprising:

[0051] The waveform-level module is used to design a covert adversarial waveform through embedded communication, and to design two covert adversarial waveforms with and without signals using a natural evolution algorithm;

[0052] Feature-level module, used to implement poisoned data insertion by directly intervening in training data when deep neural networks are trained;

[0053] The adversarial sample generation module is used to generate the final adversarial samples according to the designed waveform and data poisoning, and is divided into two categories: with signal and without signal. When the channel has a signal, the signal interference is released; when the channel has no signal, the signal-free interference is released.

[0054] Another object of the present invention is to provide an application of the dual-level intelligent countermeasure method of electromagnetic spectrum perception in wireless communications.

[0055] Combining all the above technical solutions, the advantages and positive effects of the present invention are as follows: the present invention can effectively realize the interference of the model when the detailed information of the unknown target model is known, and still has good performance under the condition of small adversarial disturbance, and maintains high robustness and practicality. It fills the gap in the field of intelligent spectrum sensing and adversarial in the industry; it introduces the concept of two levels for the first time, combining traditional methods with emerging methods. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] Figure 1 It is a flow chart of a two-level intelligent countermeasure method for electromagnetic spectrum perception provided by an embodiment of the present invention.

[0057] Figure 2 It is a structural diagram of a dual-level intelligent countermeasure system for electromagnetic spectrum perception provided by an embodiment of the present invention.

[0058] Figure 3 It is a flow chart for implementing the dual-level intelligent countermeasure method for electromagnetic spectrum perception provided in an embodiment of the present invention.

[0059] Figure 4 It is a schematic diagram of a simulation experiment provided by an embodiment of the present invention.

[0060] In the figure: 1. Waveform level module; 2. Feature level module; 3. Adversarial sample generation module. DETAILED DESCRIPTION

[0061] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0062] In view of the problems existing in the prior art, the present invention provides a dual-level intelligent countermeasure method, system, medium and device for electromagnetic spectrum perception. The present invention is described in detail below with reference to the accompanying drawings.

[0063] like Figure 1 As shown, the dual-level intelligent countermeasure method for electromagnetic spectrum perception provided by the present invention includes the following steps:

[0064] S101: Waveform level: Design a covert adversarial waveform through embedded communication, and design two covert adversarial waveforms with and without signals using natural evolution algorithm;

[0065] S102: Feature level: When the deep neural network is trained, poisoning data insertion is achieved by directly intervening in the training data;

[0066] S103: Generate the final adversarial samples according to the designed waveform and data poisoning, and divide them into two categories: with signal and without signal: when the channel has a signal, release the signal interference; when the channel has no signal, release the signal interference.

[0067] Ordinary technicians in the industry can also use other steps to implement the dual-level intelligent countermeasure method for electromagnetic spectrum perception provided by the present invention. Figure 1 The dual-level intelligent countermeasure method for electromagnetic spectrum perception provided by the present invention is only a specific embodiment.

[0068] like Figure 2As shown, the dual-level intelligent countermeasure system for electromagnetic spectrum perception provided by the present invention includes:

[0069] The waveform-level module 1 is used to design a covert adversarial waveform through embedded communication, and to design two covert adversarial waveforms with and without signals using a natural evolution algorithm.

[0070] Feature level module 2 is used to implement poisoned data insertion by directly intervening in training data when deep neural network is trained.

[0071] The adversarial sample generation module 3 is used to generate the final adversarial sample according to the designed waveform and data poisoning, and is divided into two categories: with signal and without signal: when the channel has a signal, the signal interference is released; when the channel has no signal, the no-signal interference is released.

[0072] The technical solution of the present invention is further described below in conjunction with the accompanying drawings.

[0073] like Figure 3 As shown, the dual-level intelligent countermeasure method for electromagnetic spectrum perception provided by the present invention specifically includes the following steps:

[0074] The first step is to design a hidden adversarial waveform at the waveform level through embedded communication, and use the natural evolution algorithm to design two hidden adversarial waveforms with and without signals; specifically, the following are included:

[0075] Step 1: Get the covariance matrix of the electromagnetic signal and determine its passband and stopband. Since only linear frequency modulation signals have obvious differences between passband and stopband, a method for determining the passband and stopband of the signal is proposed based on this: the singular value from small to large, the area occupying less than 20% of the total energy is the stopband area.

[0076] By replacing the singular values ​​in the passband region with zero, we can get the matrix V as follows:

[0077]

[0078] Among them, Δ ND =diag(σ L+1 ,σ L+2 ,…,σ r ) is the diagonal matrix of the stopband region. σ is the corresponding eigenvalue.

[0079] Step 2: Initialize the population. Encode the genes using integer encoding, that is, one gene corresponds to one stop band diagonal element σ, and the number of genes of an individual can be controlled in the single digit, which greatly reduces the amount of subsequent calculations.

[0080] Step 3: Fitness calculation. Each individual gene calculates the fitness of the individual according to the objective function. Since this is a minimization problem, the smaller the value, the higher the individual's fitness. Afterwards, the individual with the minimum fitness value is saved as the optimal individual in an iteration. The objective function is as follows:

[0081] F=D(x,x′)+M×loss(x′);

[0082] Where x = x 1 ,…,x n represents the original signal vector; x′=x′ 1 ,…,x′ n represents the currently generated adversarial sample signal vector; D(x,x′) represents the similarity between the two; M is a positive number much larger than D(x,x′), and loss(x′) is the loss function.

[0083] When performing a non-targeted attack (a non-targeted attack means that the attacker only hopes that the neural network model can misclassify the adversarial samples), loss(x′) is defined as:

[0084] loss(x′)=max([f(x′)] r -max([f(x′)] i≠r ),0);

[0085] Where r represents the category of the original sample; [f(x′)] r The output of is the probability that sample x′ is identified as category r; [f(x′)] i≠r The output of is the probability that sample x′ is identified as not belonging to class r.

[0086] Step 4: Crossover. Here, uniform crossover is used, that is, for two random individuals, each gene is independently crossed with probability p. Since each individual carries a large number of genes, uniform crossover can have a greater probability of generating new gene combinations, hoping to combine more beneficial genes and improve the search ability of the genetic algorithm.

[0087] Step 5: Mutation. In order to speed up the search ability of the genetic algorithm, the Gaussian mutation algorithm is used in combination with the characteristics of the problem to be solved, as shown in the formula:

[0088] x mutation =x origin ±Gauss(m,s);

[0089] Among them, x origin represents the original gene, x mutation represents the mutant gene, Gauss(m,s) represents Gaussian noise, m is the mean of Gaussian noise, and s is the standard deviation of Gaussian noise.

[0090] During the mutation process, Gaussian noise Gauss(m,s) is randomly added to the genes in the individual. Since the adversarial sample finally generated must have a high degree of similarity with the input sample, the feasible solution to the problem to be solved must also be nearby, which reduces the number of iterations required to solve the problem.

[0091] Step 6: Termination judgment: If the algorithm meets the termination condition, it will exit the loop iteration, otherwise it will return to step 3.

[0092] The first is "interference with signal", which is added and interferes with the system when there is a signal in the channel. When designing, the common signal (signal mixed with noise) in the spectrum sensing channel is selected for iteration; the second is "interference without signal", which is added and interferes with the system when there is no signal in the channel. When designing, pure noise when there is no signal in the spectrum sensing channel is selected for iteration. Both designed interferences use the above steps 1 to 6.

[0093] The second step is to insert poisoned data at the feature level by directly intervening in the training data when the deep neural network is trained. Specifically, it includes:

[0094] Step 1: Establish a data poisoning model. When inserting poisoned data, add a limited number of poisoned feature vectors. Data poisoning starts with a clean training data set, which is represented by D 0 , and transform it into another poisoned dataset D. Then, the learning algorithm is trained on D with the goal of inducing the target decision of the feature vector set in the target instance set S. Two issues are compromised when poisoning the dataset: achieving the malicious goal and minimizing the modification cost. The former term is expressed as the general risk function R of the attacker A (D, S), this function usually varies with the learning parameter ω. ω is the parameter obtained by training the model on the poisoned training data D. At the same time, the dependence of the risk function on S is usually ignored. The cost function is expressed as c(D 0 ,D).

[0095] The optimization problem is expressed as:

[0096]

[0097] stc(D 0 ,D)≤C

[0098] Where C is the modification cost budget specified by the present invention. Because it is more convenient to process the attacker's utility (maximum value) than to process the risk function (minimum value), the present invention defines the attacker's utility as U A (D,S)=-R A(D,S). Convert the risk problem into the maximum utility. Since there are only two situations in electromagnetic spectrum perception, one is the perception of signal, which is labeled as "1"; the other is the perception of no signal, which is labeled as "0";

[0099] Step 2: Insert poisoned data into the signal channel. During the deep neural network training, when the "signal" channel is collected and the training set is made, the purpose of the interference is to mistakenly detect the signalless channel as a signal channel, so the designed "no signal interference" and pure noise are combined and sent to the target antenna. After the target antenna receives it, the original data mixed with the poisoned data will be made into a training set. At this time, the poisoned data is "no signal interference" plus pure noise, and the label is "1" for deep neural network training;

[0100] Step 3: Insert poisoned data into the signalless channel. During the deep neural network training, when collecting "signalless" channels and making training sets, the purpose of interference is to misdetect the signal channel as a signalless channel, so the designed "signal interference" is combined with the signal and sent to the target antenna. After the target antenna receives it, the original data mixed with poisoned data will be made into a training set. At this time, the poisoned data is "signal interference" plus signal, with a label of "0" for deep neural network training. The insertion of poisoned data should not be too much, accounting for about 15% to 20% of the original signal.

[0101] The third step is to generate the final adversarial samples based on the designed waveform and data poisoning, which are divided into two categories: signal and no signal: when the channel has a signal, release signal interference; when the channel has no signal, release no signal interference. Specifically include:

[0102] Step 1: Transmit interference. When there is a signal on the channel, transmit "signal interference"; when there is no signal on the channel, transmit "no signal interference";

[0103] Step 2: Interference reception. The target antenna receiving end will receive two signals: "signal interference" plus signal and "no signal interference" plus pure noise. Since the poisoned data insertion attack was performed during the deep neural network training phase, it is not easy for the target receiver to identify the interference as an abnormal signal;

[0104] Step 3: Adversarial sample generation. After the two signals are processed by the target receiver before being put into the deep neural network, such as filtering, sampling, and covariance matrix calculation, a large amount of data is used to covertly generate the final adversarial sample. This adversarial sample can greatly reduce the perception accuracy of the electromagnetic spectrum perception system and has strong robustness.

[0105] The technical effects of the present invention are described in detail below in conjunction with simulation.

[0106] In the simulation experiment, a two-level intelligent countermeasure system for electromagnetic spectrum perception is considered, and the model to be perceived is a convolutional neural network model. The simulation experiment takes 100 iterations of simulation at the waveform level, and inserts 4000 poisoned data into the data of the order of magnitude of 20000 at the feature level. The performance is as follows Figure 4 shown. Figure 4 (a) shows the performance of the interference signal after waveform level design, which is given by Figure 4 As can be seen from (a), with the increase of false alarm probability, the performance of the method proposed in the present invention will fluctuate in an arc shape, but the detection accuracy of the system can be between 26% and 55%, which has a good countermeasure success rate. Figure 4 (b) shows the performance of adversarial samples generated after the two-level design, given by Figure 4 (b) shows that the accuracy of the network after adding poisoned data training for normal spectrum perception is still very impressive. It has dropped from the original 95% to 94%, which can be said to be not much reduced in performance. On the contrary, because of the additional training of poisoned data, the detection accuracy is higher than the original network when the false alarm probability is low. The method proposed in the present invention can reduce the original high detection accuracy to nearly 0%. It shows that after adding the feature level, the confrontation effect is greatly enhanced, and it is not easy to be detected as an abnormal signal, which enhances the robustness.

[0107] It should be noted that the embodiments of the present invention can be implemented by hardware, software, or a combination of software and hardware. The hardware part can be implemented using dedicated logic; the software part can be stored in a memory and executed by an appropriate instruction execution system, such as a microprocessor or dedicated design hardware. It can be understood by a person of ordinary skill in the art that the above-mentioned devices and methods can be implemented using computer executable instructions and / or contained in a processor control code, such as a carrier medium such as a disk, CD or DVD-ROM, a programmable memory such as a read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. Such code is provided on the carrier medium. The device and its modules of the present invention can be implemented by hardware circuits such as very large-scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, etc., or programmable hardware devices such as field programmable gate arrays, programmable logic devices, etc., can also be implemented by software executed by various types of processors, and can also be implemented by a combination of the above-mentioned hardware circuits and software, such as firmware.

[0108] The above description is only a specific implementation mode of the present invention, but the protection scope of the present invention is not limited thereto. Any modifications, equivalent substitutions and improvements made by any technician familiar with the technical field within the technical scope disclosed by the present invention and within the spirit and principle of the present invention should be covered by the protection scope of the present invention.

Claims

1. A two-level intelligent countermeasure method for electromagnetic spectrum perception, It is characterized in that The dual-level intelligent countermeasure method for electromagnetic spectrum perception includes: The first step is waveform level: design a covert adversarial waveform through embedded communication, and use natural evolution algorithm to design two covert adversarial waveforms with and without signal; The second step, feature level: when the deep neural network is trained, poisoning data is inserted by directly intervening in the training data; The third step is to generate the final adversarial samples according to the designed waveform and data poisoning, which are divided into two categories: with signal and without signal: when the channel has a signal, release the signal interference; when the channel has no signal, release the signal interference; The first step of waveform level: designing a concealed adversarial waveform through embedded communication, and designing two concealed adversarial waveforms with and without signals by natural evolution algorithm specifically includes: Step 1: Obtain the covariance matrix of the electromagnetic signal, determine the passband and stopband, and use the method of determining the signal passband and stopband: the singular value is from small to large, and the area where the total energy is less than 20% is the stopband area; Replacing the singular values ​​in the passband region with zeros gives the following matrix V: Among them, Δ ND =diag(σ L+1 ,σ L+2 ,…,σ r ) is the diagonal matrix of the stopband region, and σ is the corresponding eigenvalue; Step 2: Initialize the population and encode the genes using integer encoding. One gene corresponds to a stop band diagonal element σ, and the number of genes of an individual can be controlled in the single digit. Step 3: Fitness calculation. Each individual gene calculates the fitness of the individual according to the objective function. The individual with the minimum fitness value is saved as the optimal individual in one iteration. The objective function is as follows: Where x = x 1 ,…,x n represents the original signal vector; x′=x 1 ′,…,x n ′ represents the currently generated adversarial sample signal vector; D(x,x′) represents the similarity between the two; M is a positive number much larger than D(x,x′), and loss(x′) is the loss function; When performing non-targeted attacks, loss(x′) is defined as: loss(x′)=max([f(x′)] r -max([f(x′)] i≠r ),0); Where r represents the category of the original sample; [f(x′)] r The output of is the probability that sample x′ is identified as category r; [f(x′)] i≠r The output of is the probability that sample x′ is identified as not being of category r; Step 4: Using uniform crossover, for two random individuals, each gene is independently crossed with probability p; Step 5: Combined with the problem to be solved, the Gaussian mutation algorithm is used, formula: x mutation =x origin ±Gauss(m,s); Among them, x origin represents the original gene, x mutation represents the mutant gene, Gauss(m,s) represents Gaussian noise, m is the mean of Gaussian noise, and s is the standard deviation of Gaussian noise; During the mutation process, Gaussian noise Gauss(m,s) is randomly added to the genes in the individual; Step 6: Termination judgment, if the algorithm meets the termination condition, exit the loop iteration, otherwise return to step 3.

2. The dual-level intelligent countermeasure method for electromagnetic spectrum perception as claimed in claim 1, It is characterized in that When there is a signal in the channel, interference with the signal is added and interfered with the system. During the design, the signal in the spectrum sensing channel mixed with noise is selected for iteration. When there is no signal in the channel, interference with the signal is added and interfered with the system. During the design, pure noise when there is no signal in the spectrum sensing channel is selected for iteration. Interference with the signal and interference without the signal are processed using steps one to six.

3. The dual-level intelligent countermeasure method for electromagnetic spectrum perception as claimed in claim 1, It is characterized in that The second step, feature level: when the deep neural network is trained, poisoning data insertion is achieved by directly intervening in the training data, specifically including: Step 1: Establish a data poisoning model. When using poisoned data insertion, add a limited number of poisoned feature vectors. The data poisoning starts from a clean training dataset, which is denoted as D 0 , and transform it into another poisoned dataset D; the learning algorithm is trained on D with the aim of inducing the target decision of the set of feature vectors in the target instance set S; when poisoning the dataset, compromise between two issues: achieving malicious goals and minimizing the modification cost; represent the former as the general risk function R A (D, S), and the function varies with the learning parameter ω; ω is the parameter obtained by training the model on the poisoned training data D; meanwhile, the cost function is denoted as c(D 0 , D): The optimization problem is expressed as: Where C is the specified modification cost budget, and the attacker’s utility is defined as U A (D,S)=-R A (D, S); transform the risk problem into the maximum utility; there are two cases of electromagnetic spectrum perception, one is the perception of signal, the label is set to 1; the other is the perception of no signal, the label is set to 0; Step 2: Insert poisoned data into the signal channel. When the signal channel is collected and the training set is made during the deep neural network training, the designed signal-free interference and pure noise are combined and sent to the target antenna. After the target antenna receives it, the original data mixed with poisoned data will be made into a training set. The poisoned data is signal-free interference plus pure noise, with a label of 1, for deep neural network training; Step 3: Insert poisoned data into the signal-free channel. During the deep neural network training, when the signal-free channel is collected and the training set is made, the signal channel will be mistakenly detected as a signal-free channel. The designed signal interference and signal are combined and sent to the target antenna. After the target antenna receives it, the original data mixed with poisoned data will be made into a training set. The poisoned data is signal interference plus signal, with a label of 0, for deep neural network training; the poisoned data occupies 15% to 20% of the original signal.

4. The dual-level intelligent countermeasure method for electromagnetic spectrum perception as claimed in claim 1, It is characterized in that The third step generates the final adversarial samples according to the designed waveform and data poisoning, and is divided into two categories: with signal and without signal: when the channel has a signal, release the signal interference; when the channel has no signal, release the signal interference. Specifically, it includes: Step 1: Transmit interference. When there is a signal in the channel, transmit interference with the signal; when there is no signal in the channel, transmit interference without the signal; Step 2: Interference reception: the target antenna receiving end will receive two signals: signal interference plus signal and no signal interference plus pure noise; Step 3: Adversarial sample generation. After filtering, sampling, and covariance matrix calculation, the target receiver processes the two signals before putting them into the deep neural network. A large amount of data is used to covertly generate the final adversarial sample.

5. A computer device, It is characterized in that The computer device includes a memory and a processor, the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the dual-level intelligent countermeasure method for electromagnetic spectrum perception as described in any one of claims 1 to 4.

6. A computer-readable storage medium storing a computer program, wherein when the computer program is executed by a processor, the processor executes the steps of the dual-level intelligent countermeasure method for electromagnetic spectrum perception as claimed in any one of claims 1 to 4.

7. An information data processing terminal, It is characterized in that The information data processing terminal is used to implement the two-level intelligent confrontation method for electromagnetic spectrum perception as described in any one of claims 1 to 4.

8. A dual-level intelligent confrontation system for implementing the dual-level intelligent confrontation method for electromagnetic spectrum perception according to any one of claims 1 to 4, It is characterized in that The dual-level intelligent confrontation system includes: The waveform-level module is used to design a covert adversarial waveform through embedded communication, and to design two covert adversarial waveforms with and without signals using a natural evolution algorithm; Feature-level module, used to implement poisoned data insertion by directly intervening in training data when deep neural networks are trained; The adversarial sample generation module is used to generate the final adversarial samples according to the designed waveform and data poisoning, and is divided into two categories: with signal and without signal. When the channel has a signal, the signal interference is released; when the channel has no signal, the signal-free interference is released.