A Double - level Intelligent Countermeasure Method and System for Electromagnetic Signal Recognition
The dual-level intelligent adversarial method using chaotic noise and federated learning disruption addresses weaknesses in existing electromagnetic signal recognition by covertly reducing system accuracy, enhancing robustness and practicality.
Patent Information
- Application Number
- CN202211264223.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-17
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2042-10-17
AI Technical Summary
In the prior art, in electromagnetic signal recognition, the adversarial samples generated by centralized neural networks have poor performance on high-performance distributed federated learning models. The iteratively generated adversarial samples are not enough to induce complex models to perceive errors, ignore signal waveform design, resulting in low adversarial practicality and transferability.
The two-level intelligent adversarial method is adopted. First, the chaotic sequence is used to design pseudo noise for hidden adversarial at the hidden level, and then the local model is trained under the federated learning framework and upload parameters to destroy the global model. Finally, the pseudo noise is sent to the channel for interference, reducing the recognition accuracy.
Effectively interfere with high-performance neural network models, maintain high robustness and practicality under small perturbations, and combine traditional waveform design and federal poisoning attacks to improve the robustness and confrontation performance of the identification model.
Smart Images

Figure CN115664581B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of electromagnetic signal recognition, and particularly relates to a two-level intelligent confrontation method and system for electromagnetic signal recognition. Background Art
[0002] At present, with the advent of the information age, the technical level and business scale in the field of electromagnetic signal transmission have achieved leapfrog growth. The electromagnetic signal transmission has been greatly improved in terms of speed, stability, distance, efficiency, etc. With the wide application of artificial intelligence in this field, the electromagnetic signal transmission has also made breakthroughs in terms of intelligence and convenience, which undoubtedly helps to better meet the actual needs of people for communication services. Therefore, cognitive radio is considered as a technical means to intelligently sense the spectrum environment and effectively utilize the wireless spectrum. However, the deep neural network model is vulnerable to adversarial attacks. If the deep neural network is severely threatened or even damaged by adversarial attacks, it will be unable to achieve normal spectrum sensing or signal recognition. This will affect the ability of cognitive radio to achieve intelligent communication, resulting in the inability to make wise and rapid business decisions. At present, most of the research on adversarial samples focuses on images, and there is no relevant research on the physical practical applications in the communication field, and it is only theoretical research.
[0003] Currently, there have been many research methods for adversarial attacks in the literature. Szegedy et al. first proposed the concept of adversarial examples. They successfully changed the prediction results of the classifier for input samples by adding tiny perturbations that are imperceptible to the human eye (Szegedy C, Zaremba W, Sutskever I, et al. Intriguing properties of neural networks[C]. Proc. Int. Conf. Learn. Representations, 2015: 1-10.). After the adversarial examples were proposed, many adversarial methods emerged, including: Fast Gradient Sign Method (Goodfellow I, Shlens J, Szegedyn C, et al. Explaining and harnessing adversarial examples[C]. Proc. Int. Conf. Learn. Representations, 2015: 189-199.), Basic Iterative Method (Kurakin A, Goodfellow I, Bengio S, et al. Adversarial examples in the physical world[C]. Proc. Int. Conf. Learn. Representations, 2016: 128-141.), Jacobian-based Saliency Map (Papernot N, McDaniel P, Jha S, et al. The limitations of deep learning in adversarial settings[J]. IEEE European Symposium on Security and Privacy, 2016, 1(1): 372-387.), Projected Gradient Descent (Madry A, Schmidt L, Tsipras D, et al. Towards deep learning models resistant to adversarial attacks[C]. Proc. Int. Conf. Learn. Representations, 2018: 1-23.), Momentum Iterative Method (Dong Y, Liao F, Pang T, et al. Boosting adversarial attacks with momentum[C]. Proc. IEEE. Conf. Comput. Vis. Pattern Recognit, 2018: 9185-9903.), etc.To improve the robustness of the model, researchers have proposed different defense models for different methods. Kui Ren et al. summarized the representative adversarial defense methods in recent years, mainly including adversarial training, randomization-based methods, noise reduction methods, provable defenses, and some other new defense methods, and pointed out the effectiveness of these defense methods in different environments (Ren K, Zheng T, Qin Z, et al. Adversarial Attacks and Defenses in Deep Learning[J]. Engineering, 2020, 6(3): 346-360.).
[0004] To introduce adversarial samples into the field of modulation signal recognition to improve the robustness of the recognition model, Sadeghi et al. first introduced adversaries into wireless communication and launched a direct attack (Sadeghi M, Larsson E G. Adversarial Attacks on Deep-Learning Based Radio Signal Classification[J]. IEEE Wireless Communications Letters, 2019, 8(1): 213-216.). Zhao et al. applied the Nesterov Adam iterative method to modulation signal recognition and increased the waveform similarity between the generated signal adversarial samples and the original signal (Zhao H, Lin Y, Gao S, et al. Evaluating and Improving Adversarial Attacks on Deep Neural Network-Based Modulation Recognition[C]. GLOBECOM 2020-2020 IEEE Global Communications Conference, 2020: 1-5.). Lin et al. applied four methods based on label-computed gradients to modulation signal recognition and verified that the deep neural network model for classifying modulation signals is vulnerable to adversarial samples (Lin Y, Zhao H, Ma X, et al. Adversarial Attacks in Modulation Recognition With Convolutional Neural Networks[J]. IEEE Transactions on Reliability, 2021, 70(1): 389-401.). However, the above adversarial methods only consider the effectiveness and success rate of the adversary, ignoring the concealment and robustness of the adversary.
[0005] Through the above analysis, the problems and defects of the prior art are as follows:
[0006] (1) Most existing methods are based on centralized simple neural networks, and the adversarial forces generated by them perform poorly on high-performance distributed federated learning models.
[0007] (2) After the iteration process, the adversarial samples generated are not enough to induce high-performance complex models or adversarial models to perceive errors. This will lead to a decrease in the interference ability of the adversary, far from achieving the expected interference effect.
[0008] (3) Current technologies directly generate adversarial samples without considering the waveform design of the signal. Such adversarial methods are not very practical and transferable.
[0009] The difficulty in solving the above problems and defects is that the complex high-performance perception model itself has a certain defensiveness, which will weaken the performance of traditional methods. Therefore, the waveform design, as well as the balance and combination between the waveform and the traditional white-box algorithm, are the technical difficulties of the two-level intelligent confrontation of the electromagnetic signal recognition system. Summary of the invention
[0010] In view of the problems existing in the prior art, the present invention provides a two-level intelligent countermeasure method and system for electromagnetic signal recognition.
[0011] The present invention is implemented in this way: a two-level intelligent countermeasure method for electromagnetic signal recognition includes:
[0012] The first step is to use chaotic sequences to design pseudo noise at the hidden level. In subsequent confrontations, it can achieve the purpose of concealment.
[0013] The second step is to use the designed pseudo-noise as poisoned data to train the local model for the intelligent signal recognition system under the federated learning framework at the adversarial level, and upload local parameters to covertly destroy the function of the global model. This ensures that the signal recognition accuracy of the system can be effectively reduced in subsequent adversarial situations.
[0014] In the third step, after the global model is destroyed, the designed pseudo noise is sent to the channel. The transmission signal parasitized by the pseudo noise will be recognized incorrectly by the system with a high probability, thereby reducing the recognition accuracy of the intelligent signal recognition system.
[0015] Furthermore, the first step is to design pseudo noise at the hidden level using a chaotic sequence, and the specific implementation process is as follows:
[0016] The chaotic map sequence is given by
[0017] x n+1 =f(x n )
[0018]
[0019] Among them, x n is defined as the nth number in the chaotic sequence, T is defined as the sampling interval, k represents an integer, and N represents the sequence length;
[0020] Pseudo-noise is generated through the Ulam chaotic mapping sequence, and its definition is:
[0021]
[0022] Among them, x n is defined as the nth number in the chaotic sequence, and the sequence length is determined according to the length of the signal sample.
[0023] Furthermore, in the second step at the adversarial level, for the intelligent signal recognition system under the federated learning framework, the designed pseudo-noise is made into poisoned data to train the local model, and the local parameters are uploaded to secretly damage the function of the global model. The specific implementation process is as follows:
[0024] First, the poisoned data is made;
[0025] Then, the local deep learning network is trained with this poisoned data. After the training is completed, for the federated learning framework used for electromagnetic signal recognition, the training weights of the local deep learning network are amplified to increase the impact of poisoning and confrontation in the global model;
[0026] Finally, the parameters of the local deep learning network are updated and uploaded to secretly damage the global model of the federated framework.
[0027] Furthermore, in the process of making the poisoned data, the poisoned data is described as
[0028] H0:y correct +x chaos ,
[0029] H1:y error +x chaos
[0030] Among them, the label H0 indicates that the electromagnetic signal recognition classification does not belong to this category, the label H1 indicates that the electromagnetic signal recognition classification is correct, x chaos represents pseudo-noise, y correct represents the correctly classified signal, and y error represents the signal that does not belong to this classification.
[0031] Furthermore, after the global model is damaged in the third step, the designed pseudo-noise is sent to the channel to reduce the recognition accuracy of the intelligent signal recognition system. The specific implementation steps are as follows:
[0032] Step 1: Noise generation, copying the pseudo-noise of the design;
[0033] Step 2: Channel parasitism, transmitting the pseudo-noise to parasitize the transmitted signal in the channel;
[0034] Step 3: Conduct interference. After the other party's receiver receives the transmitted signal parasitized by the pseudo-noise, the concealed and damaged federated learning electromagnetic signal recognition model is used for signal recognition, so that the transmitted signal is misrecognized, reducing the overall electromagnetic signal recognition accuracy of the system.
[0035] Another object of the present invention is to provide a computer device, the computer device includes a memory and a processor, the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the two-level intelligent confrontation method for electromagnetic signal recognition.
[0036] Another object of the present invention is to provide a computer-readable storage medium, storing a computer program, and when the computer program is executed by a processor, the processor executes the steps of the two-level intelligent confrontation method for electromagnetic signal recognition.
[0037] Another object of the present invention is to provide an information data processing terminal, and the information data processing terminal is used to implement the two-level intelligent confrontation method for electromagnetic signal recognition.
[0038] Another object of the present invention is to provide a two-level intelligent confrontation system for electromagnetic signal recognition, and the two-level intelligent confrontation system for electromagnetic signal recognition includes:
[0039] A hidden-level module, using a chaotic sequence to design pseudo-noise;
[0040] An adversarial-level module, aiming at the intelligent signal recognition system under the federated learning framework, making the designed pseudo-noise into poisoned data to train a local model, and uploading local parameters to secretly damage the function of the global model;
[0041] An adversarial implementation module, after the global model is damaged, sending the designed noise to the channel to effectively reduce the recognition accuracy of the intelligent signal recognition system.
[0042] Another object of the present invention is to provide an application of the two-level intelligent confrontation system for electromagnetic signal recognition in artificial intelligence security.
[0043] Combined with the above technical solutions and the solved technical problems, the advantages and positive effects of the technical solutions to be protected by the present invention are:
[0044] First, in view of the technical problems existing in the above-mentioned prior art and the difficulty of solving such problems, closely combining with the technical solution to be protected by the present invention, as well as the results and data during the R & D process, etc., analyze in detail and profoundly how the technical solution of the present invention solves the technical problems and the creative technical effects brought after solving the problems. The specific description is as follows:
[0045] The present invention can effectively interfere with a known target neural network model when its detailed information is available, and still has good performance under the condition of small adversarial perturbations, and maintains high robustness and practicability. It fills the gap in the field of intelligent signal recognition and countermeasure regarding signal waveform design in the industry; for the first time, the concept of double-level is introduced in the field of intelligent signal recognition and countermeasure, and the traditional waveform design method and the emerging federated poisoning attack method are combined.
[0046] Second, regarding the technical solution as a whole or from the perspective of the product, the technical effects and advantages of the technical solution to be protected by the present invention are specifically described as follows:
[0047] The realization of the double-level intelligent countermeasure system for electromagnetic signal recognition fills the gap in the signal waveform design in the field of electromagnetic signal recognition and countermeasure. Due to the addition of waveform design, it has feasibility and can perform interference covertly and efficiently in the countermeasure. It can also provide a new method for discovering the deep learning network vulnerabilities of the recognition model, and promote the improvement of the robustness and countermeasure performance of the recognition model from the reverse side.
[0048] Third, as the creative auxiliary evidence of the claims of the present invention, it is also reflected in that the technical solution of the present invention fills the domestic and foreign industry technical gaps:
[0049] The technical solution of the present invention fills the gap in the signal waveform design in the field of electromagnetic signal recognition and countermeasure. Previous intelligent communication countermeasure research directly applied existing intelligent countermeasure methods to conduct countermeasures at the data level. The waveform design added in this solution better meets the requirements of the communication field, considers at the signal level, and has engineering feasibility. BRIEF DESCRIPTION OF THE DRAWINGS
[0050] Figure 1 is a schematic structural diagram of a double-level intelligent countermeasure method for electromagnetic signal recognition provided by an embodiment of the present invention;
[0051] Figure 2 is a schematic structural diagram of a double-level intelligent countermeasure system for electromagnetic signal recognition provided by an embodiment of the present invention;
[0052] Figure 3 is a flowchart of the implementation of a double-level intelligent countermeasure method for electromagnetic signal recognition provided by an embodiment of the present invention;
[0053] Figure 4It is a schematic diagram of the simulation experiment on the local deep learning model provided by an embodiment of the present invention;
[0054] Figure 5 It is a schematic diagram of the simulation experiment on the global model of federated learning provided by an embodiment of the present invention;
[0055] In the figure: 1. Hidden-level module; 2. Adversarial-level module; 3. Adversarial implementation module. Specific implementation manners
[0056] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention, but not to limit the present invention.
[0057] I. Explanation and illustration of the embodiment. This part is an explanatory embodiment that expands and explains the technical solution of the claim in order to enable those skilled in the art to fully understand how the present invention is specifically implemented.
[0058] As Figure 1 shown, the two-level intelligent adversarial method for electromagnetic signal recognition provided by the present invention includes the following steps:
[0059] S101: Hidden level: Design pseudo-noise using chaotic sequences to ensure that the adversarial process can be carried out covertly during the decision-making stage;
[0060] S102: Adversarial level: During the training stage, upload local parameters to covertly disrupt the function of the global model;
[0061] S103: During the decision-making stage, send the designed pseudo-noise into the channel, parasitize on the transmitted signal, and reduce the recognition accuracy of the intelligent recognition system.
[0062] Ordinary technicians in the industry can also implement the two-level intelligent adversarial method for electromagnetic signal recognition provided by the present invention using other steps. Figure 1 The two-level intelligent adversarial method for electromagnetic signal recognition provided by the present invention is only a specific embodiment.
[0063] As Figure 2 shown, the two-level intelligent adversarial system for electromagnetic signal recognition provided by the present invention includes:
[0064] Hidden-level module 1, which designs pseudo-noise using chaotic sequences.
[0065] Adversarial-level module 2, for the intelligent signal recognition system under the federated learning framework, fabricates the designed pseudo-noise into poisoned data to train the local model, and uploads local parameters to covertly disrupt the function of the global model.
[0066] Against the implementation module 3, after the global model is damaged, the designed noise is sent to the channel to effectively reduce the recognition accuracy of the intelligent signal recognition system.
[0067] As Figure 3 shown, the double-level intelligent countermeasure method for electromagnetic signal recognition provided by the present invention specifically includes the following steps:
[0068] First step, at the hidden level, use the chaotic sequence to design pseudo-noise, and the specific implementation process is as follows:
[0069] The chaotic mapping sequence is given by the following formula
[0070] x n+1 = f(x n )
[0071] where x n is defined as the nth number in the chaotic sequence, and f(.) represents the chaotic sequence generation function.
[0072] Mainly generate pseudo-noise through the Ulam chaotic mapping sequence, and its definition is:
[0073]
[0074] where x n is defined as the nth number in the chaotic sequence, the initial value is set to 0.3541, and the sequence length is determined according to the length of the signal sample. In the present invention, 128 is selected as the sequence length.
[0075] Due to the characteristics of the pseudo-noise of the chaotic sequence, during the decision-making stage of the deep learning network, modulate and transmit this sequence into the channel, and the opponent's intelligent signal recognition system will misdetect this chaotic signal as noise, thus achieving the purpose of covert countermeasure.
[0076] Second step, at the countermeasure level, for the intelligent signal recognition system under the federated learning framework, make poisoned data to train the local model and upload the local parameters to covertly damage the function of the global model. The specific implementation process is as follows:
[0077] First, make the poisoned data. Describe the poisoned data as follows: the label H0 indicates that the electromagnetic signal recognition classification does not belong to this category, and the label H1 indicates that the electromagnetic signal recognition classification is correct. Therefore, the final poisoned data can be expressed as
[0078] H0: correct +x chaos ,
[0079] H1: y error x chaos
[0080] where x chaos represents the chaotic signal designed in the first step, and ycorrect The signal indicating correct classification, y error The signal indicating not belonging to this classification.
[0081] Then, use this poisoned data to train the local deep learning network. After the training is completed, for the federated learning framework for electromagnetic signal recognition, due to its distributed learning architecture, a large number of servers are connected together. Therefore, in order to increase the impact of poisoning countermeasures in the global model, it is necessary to amplify the training weights of the local deep learning network.
[0082] Finally, upload the updated parameters of this local deep learning network to secretly damage the global model of the federated framework. This global model will be very sensitive to the designed chaotic signal and can complete normal electromagnetic signal recognition tasks without being countered by the chaotic signal.
[0083] In the third step, after the global model is damaged, send the designed noise to the channel to effectively reduce the recognition accuracy of the intelligent signal recognition system. The specific implementation steps are as follows:
[0084] Step 1: Noise generation, copy and generate the chaotic sequence designed in the first step above as pseudo-noise;
[0085] Step 2: Channel parasitism, transmit the pseudo-noise to parasitize on the transmission signal in the channel;
[0086] Step 3: Interference, after the receiving end of the other party receives the transmission signal parasitized by the pseudo-noise, hand it over to the federated learning electromagnetic signal recognition model secretly damaged in the second step above for signal recognition, so that the transmission signal is misrecognized, thereby reducing the overall electromagnetic signal recognition accuracy of the system.
[0087] II. Application embodiments. In order to prove the creativity and technical value of the technical solution of the present invention, this part is the application embodiments of the technical solution of the claims on specific products or related technologies.
[0088] A computer device provided by the present invention, the computer device includes a memory and a processor, the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the double-level intelligent countermeasure method for electromagnetic signal recognition.
[0089] A computer-readable storage medium provided by the present invention, storing a computer program, and when the computer program is executed by a processor, the processor executes the steps of the double-level intelligent countermeasure method for electromagnetic signal recognition.
[0090] An information data processing terminal provided by the present invention, the information data processing terminal is used to implement the double-level intelligent countermeasure method for electromagnetic signal recognition.
[0091] Application of a two - level intelligent countermeasure system for electromagnetic signal recognition provided by the present invention in artificial intelligence security.
[0092] It should be noted that the embodiments of the present invention can be implemented by hardware, software, or a combination of software and hardware. The hardware part can be implemented using dedicated logic; the software part can be stored in a memory and executed by an appropriate instruction execution system, such as a microprocessor or dedicated design hardware. Those of ordinary skill in the art can understand that the above - mentioned devices and methods can be implemented using computer - executable instructions and / or included in processor control code, for example, such code is provided on a carrier medium such as a disk, CD, or DVD - ROM, a programmable memory such as read - only memory (firmware), or a data carrier such as an optical or electronic signal carrier. The devices and modules of the present invention can be implemented by hardware circuits of programmable hardware devices such as very - large - scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, etc., or field - programmable gate arrays, programmable logic devices, etc., can also be implemented by software executed by various types of processors, or can be implemented by a combination of the above - mentioned hardware circuits and software, such as firmware.
[0093] III. Evidence of related effects of the embodiments. Some positive effects have been achieved during the research and development or use of the embodiments of the present invention, and there are indeed great advantages compared with the prior art. The following content is described in combination with data, charts, etc. in the test process.
[0094] In the simulation experiment, consider a two - level intelligent countermeasure system for electromagnetic signal recognition. The signal recognition models to be countered are the ResNet model and the federated learning model. The types of modulation signals to be recognized include 8 digital signals: 8PSK, QPSK, BPSK, GFSK, CPFSK, PAM4, QAM16, and QAM64, and two analog signals: WBFM and AM - DSB. The simulation parameter settings when studying the influence of signal - to - noise ratio on the countermeasure performance are as follows: the perturbation level is ε = 0.0015, and the signal - to - noise ratios are respectively selected as values within the interval [-20, 18] with an interval of 2dB. Among them Figure 4 represents the recognition accuracy of the ResNet model under several countermeasure methods, Figure 5 represents the recognition accuracy of the federated learning model under several countermeasure methods. As Figure 4 and Figure 5 shown, where FGSM, BIM, PGD, MIM represent several common white - box countermeasure methods, and CPM represents the countermeasure method proposed by us. In Figure 4Among them, the output accuracy of the DNN model gradually increases as the signal-to-noise ratio increases, and then fluctuates around a certain value. Among several adversarial methods, for a perturbation level of 0.0015, the adversarial effect of the MIM algorithm is better than that of other white-box algorithms, but the best one is CPM. When the signal-to-noise ratio is low, it has no advantage. When the signal-to-noise ratio is high, among all methods, its adversarial performance reaches the best. In Figure 5 Among them, it can be seen that the current several white-box algorithms only have a very weak adversarial effect. In the best case, the recognition accuracy can only decrease by 6%. However, the adversarial effect of CPM cannot be ignored. The recognition accuracy of the federated learning model can be reduced by nearly 20% under the CPM attack.
[0095] As described above, the above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention should be covered by the protection scope of the present invention.
Claims
1. A two - level intelligent countermeasure method for electromagnetic signal recognition, characterized in that, The double - level intelligent countermeasure method for electromagnetic signal recognition includes: In the first step, at the hidden level, pseudo - noise is designed using a chaotic sequence. In the second step, at the adversarial level, for the intelligent signal recognition system under the federated learning framework, the designed pseudo - noise is made into poisoned data to train the local model, and the local parameters are uploaded to secretly damage the function of the global model. In the third step, after the global model is damaged, the designed pseudo - noise is sent to the channel to reduce the recognition accuracy of the intelligent signal recognition system. In the second step, at the adversarial level, for the intelligent signal recognition system under the federated learning framework, the designed pseudo - noise is made into poisoned data to train the local model, and the local parameters are uploaded to secretly damage the function of the global model. The specific implementation process is as follows: First, the poisoned data is made. Then, the local deep - learning network is trained with the poisoned data. After the training is completed, for the federated learning framework for electromagnetic signal recognition, the training weights of the local deep - learning network are amplified to increase the impact of poisoning countermeasures in the global model. Finally, the parameters of the local deep - learning network are updated and uploaded, so that the global model of the federated framework is secretly damaged. In the production of poisoning data, the poisoning data is described as H0:y correct +x chaos , H1:y error +x chaos Among them, the label H0 indicates that the electromagnetic signal recognition and classification is incorrect, and the label H1 indicates that the electromagnetic signal recognition and classification is correct. x chaos represents the pseudo-noise, y correct represents the signal with correct classification, y error represents the signal with incorrect classification.
2. The double - level intelligent countermeasure method for electromagnetic signal recognition according to claim 1, wherein, In the first step, at the hidden level, pseudo - noise is designed using a chaotic sequence. The specific implementation process is as follows: The chaotic mapping sequence is given by the following formula x n+1 = f(x n ) where x n is defined as the nth number in the chaotic sequence, and f(.) represents the chaotic sequence generation function; Pseudo - noise is generated through the Ulam chaotic mapping sequence, and its definition is: x n ∈[-0.5,0.5] where x n is defined as the nth number in the chaotic sequence, and the sequence length is determined according to the length of the signal sample.
3. The double - level intelligent countermeasure method for electromagnetic signal recognition according to claim 2, characterized in that After the global model in the third step is damaged, the designed pseudo - noise is sent to the channel to reduce the recognition accuracy of the intelligent signal recognition system. The specific implementation steps are as follows: Step 1: Noise generation, copy the designed pseudo - noise. Step 2: Channel parasitism, transmit the pseudo - noise to parasitize on the transmission signal in the channel. Step 3: Interference, after the other receiver receives the transmission signal parasitized by the pseudo - noise, the secretly damaged federated learning electromagnetic signal recognition model is used for signal recognition, so that the transmission signal is misrecognized, reducing the overall electromagnetic signal recognition accuracy of the system.
4. A computer device, characterized in that, The computer device includes a memory and a processor. When the computer program stored in the memory is executed by the processor, the processor executes the steps of the double - level intelligent countermeasure method for electromagnetic signal recognition according to any one of claims 1 - 3.
5. A computer - readable storage medium stores a computer program. When the computer program is executed by a processor, the processor executes the steps of the double - level intelligent countermeasure method for electromagnetic signal recognition according to any one of claims 1 - 3.
6. An information data processing terminal, characterized in that, The information data processing terminal is used to implement the double - level intelligent countermeasure method for electromagnetic signal recognition according to any one of claims 1 - 3.
7. A two - level intelligent countermeasure system for electromagnetic signal recognition implementing the two - level intelligent countermeasure method for electromagnetic signal recognition according to any one of claims 1 to 3, characterized in that, The double - level intelligent countermeasure system for electromagnetic signal recognition includes: A hidden - level module that designs pseudo - noise using a chaotic sequence; An adversarial - level module that, for the intelligent signal recognition system under the federated learning framework, makes the designed pseudo - noise into poisoned data to train the local model, and uploads the local parameters to secretly damage the function of the global model; An adversarial implementation module that, after the global model is damaged, sends the designed noise to the channel to effectively reduce the recognition accuracy of the intelligent signal recognition system.
8. Application of a two - level intelligent countermeasure system for electromagnetic signal recognition as claimed in claim 7 in artificial intelligence security.
Citation Information
Patent Citations
Composite chaotic sequence forming method and unmanned aerial vehicle measurement and control link anti-interference method
CN112087244A
Chaotic broadband signal interference unit and interference decision-making method
CN112698278A