An Adversarial Sample Attack Detection Method for Joint Reconstruction of Electromagnetic Signals
Through the joint reconstruction of electromagnetic signals, the pre-classified modulation identification network and adversarial autoencoder network are used to solve the scalability and unknown attack problems of adversarial sample detection in signal modulation classification, and efficient and accurate adversarial sample detection is achieved, which is suitable for electromagnetic signal recognition in complex electromagnetic spaces.
Patent Information
- Application Number
- CN202310239144.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-13
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2043-03-13
AI Technical Summary
The existing adversarial sample detection methods have problems such as low scalability in the field of signal modulation classification, inability to effectively deal with unknown types of attacks, and insufficient model performance and generalization capabilities, and require multiple models to work together, increasing the computational burden and time cost.
The method of jointly reconstructing electromagnetic signals is adopted to construct a reconstruction network through pre-classified modulation identification network and an adversarial autoencoder network. The reconstructed network is selected using the category results of the modulation identification network, and the adversarial sample detection is performed based on the reconstruction loss, avoiding adversarial training, which is suitable for a wider attack form.
Accurate detection of unknown adversarial sample attacks is achieved, detection efficiency and accuracy are improved, model construction costs are reduced, and it is suitable for electromagnetic signal adversarial sample recognition in complex electromagnetic spaces.
Smart Images

Figure CN116304869B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of wireless communication technologies, and particularly to a method for detecting adversarial sample attacks for jointly reconstructing electromagnetic signals. Background Art
[0002] In the research on signal modulation type recognition, deep learning methods have been widely used. Deep learning algorithms perform excellently in many tasks, can automatically extract signal features, and achieve high-accuracy classification. However, the classification algorithms of deep learning are vulnerable to attacks. Adversarial attacks on electromagnetic signals can be carried out by adding tiny perturbations to cause misclassification. This method is called adversarial sample attack, also known as perturbation attack. These perturbations can change the signal features, having a misleading impact on the classification and recognition of target devices.
[0003] In the intelligent attack and defense scenario, if the signal is successfully attacked, serious hazards may occur. In civilian communications, the signal modulation type is one of the important means to ensure communication quality. If an attacker successfully attacks the signal modulation type, the communication signal quality will decline, the connection will be interrupted, or it will not work properly, thus affecting people's daily life and work, and threatening the quality of the civilian communication system; in the industrial field, the attack on the modulation signal may cause problems such as equipment failures and signal interference in the production line, resulting in the stagnation of the production line, the decline of production efficiency, and even economic losses; if an attacker successfully attacks the signal of intelligent devices such as the Internet of Things, it may cause device failures, data leakage, or information tampering, causing significant economic losses to enterprises. In military communications, the signal modulation type is one of the important means to ensure communication security. If an attacker successfully attacks the signal modulation type, the communication signal will be intercepted, thus affecting key decisions such as military command and intelligence exchange, and may threaten the security of the military communication system. Therefore, in the intelligent attack and defense scenario, adversarial sample attack is an attack method that needs to be highly emphasized and actively prevented. Conducting adversarial sample detection and pre-defending for modulation recognition to prevent further damage to the model by adversarial samples has important research significance.
[0004] Although the existing adversarial sample detection algorithms in the field of image classification have achieved good detection results, the research on detection algorithms in the field of signal modulation classification is still in its infancy, and a complete detection system has not yet been formed. Directly migrating the detection algorithms in the field of image classification cannot achieve good detection results on signal data types. There are still deficiencies in the electromagnetic signal adversarial sample detection method: the current adversarial sample detection methods require multiple models to work together. As the number of models increases, the accuracy will increase. To obtain high accuracy, multiple models need to be jointly detected, which increases the computational burden and time cost. Often, a large amount of computing resources and time are required for training and detection, limiting its scalability in practical applications; the current adversarial sample detection methods can often only detect known types of adversarial attacks and are often unable to effectively respond to unknown types of attacks; the current adversarial sample detection methods often need to add adversarial samples to the training set for adversarial training, which may reduce the performance and generalization ability of the model. To address these deficiencies, in the future, it is necessary to study more robust and scalable electromagnetic signal adversarial sample detection methods and strengthen the ability to respond to unknown attacks. At the same time, it is necessary to explore more flexible and lightweight adversarial training and detection methods to reduce the impact on the model performance. Summary of the Invention
[0005] An embodiment of the present application provides an adversarial sample attack detection method for jointly reconstructing electromagnetic signals, which uses the method of pre-classifying and then reconstructing electromagnetic signals to achieve accurate detection of unknown adversarial sample attacks in intelligent offensive and defensive scenarios and provide effective pre-defense for modulation recognition.
[0006] To solve the above technical problems, an embodiment of the present application provides an adversarial sample attack detection method for jointly reconstructing electromagnetic signals, including the following steps: obtaining a modulation signal data set; the modulation signal data set includes an original training set and an original test set; both the original training set and the original test set include multiple modulation methods; based on the modulation signal data set, constructing a modulation recognition network and using the class result output by the modulation recognition network as the selection basis for entering the reconstruction network; constructing a reconstruction network and using the loss result of the reconstruction network as the judgment basis for whether it is an adversarial sample; training the modulation recognition network with the original training set until convergence; using the original training set to train a reconstruction network corresponding to each modulation method; reconstructing the normal signals in the original test set to obtain a reconstruction loss, and using the reconstruction loss as the basis for setting the threshold for adversarial sample detection; generating adversarial samples using adversarial attacks and sequentially inputting the adversarial samples into the modulation recognition network and the reconstruction network to test the attack detection ability.
[0007] In some exemplary embodiments, obtaining a modulation signal data set includes: constructing a data set with the true modulation type of an electromagnetic signal as a label; selecting data of multiple modulation methods in the data set, and shuffling the data and the label to generate a shuffled data set; dividing the shuffled data set into an original training set and an original test set according to a ratio to obtain a modulation signal data set.
[0008] In some exemplary embodiments, select data of 10 modulation methods in the data set, and shuffle the data and the label to generate a shuffled data set; divide the shuffled data set into an original training set and an original test set according to a ratio of 8:2 to obtain a modulation signal data set.
[0009] In some exemplary embodiments, use all the data in the original training set to train the modulation recognition network until convergence; use the data with a signal-to-noise ratio above 0 dB in the original training set to train a reconstruction network corresponding to each modulation method; reconstruct the normal signals of the data with a signal-to-noise ratio above 0 dB in the original test set to obtain a reconstruction loss; generate adversarial samples by adding attacks to the data with a signal-to-noise ratio above 0 dB in the original test set.
[0010] In some exemplary embodiments, the modulation recognition network is a neural network classification model with residual blocks.
[0011] In some exemplary embodiments, the last layer of the modulation recognition network uses a fully connected layer, the number of neurons included in the fully connected layer is the same as the number of types of recognition tasks, and the confidence corresponding to the output of the fully connected layer is: [p1, p2, p3,..., p n , and:
[0012]
[0013] where p i is the confidence vector corresponding to the output of the fully connected layer, and n represents the number of categories;
[0014] Select the position index corresponding to the maximum value from the confidence vector as the category result output by the modulation recognition network, and use the category result as the selection basis for entering the reconstruction network.
[0015] In some exemplary embodiments, a reconstruction network is constructed using an adversarial autoencoder network; wherein, the adversarial autoencoder network includes an encoder module, a decoder module, and a discriminator module.
[0016] In some exemplary embodiments, the number of reconstruction networks is the same as the number of modulation methods, and the reconstruction networks correspond one-to-one with the modulation methods.
[0017] In some exemplary embodiments, reconstructing the normal signals of the original test set to obtain a reconstruction loss, and determining a threshold for adversarial sample detection based on the reconstruction loss, includes: inputting the normal signals of the original test set into the modulation recognition network, where the modulation recognition network classifies the normal signals of the original test set and outputs classification labels corresponding to the normal signals of the original test set; inputting the normal signals of the original test set into the corresponding reconstruction network according to the classification labels, where the reconstruction network outputs a reconstruction error corresponding to each normal signal of the original test set; and determining the threshold for adversarial sample detection based on the reconstruction error and a preset false alarm rate.
[0018] In some exemplary embodiments, testing the attack detection ability by sequentially inputting the adversarial samples into the modulation recognition network and the reconstruction network, includes: inputting the adversarial samples into the modulation recognition network to obtain labels; determining the modulation category of the adversarial samples based on the labels; then inputting the adversarial samples into the reconstruction network of the corresponding category to obtain a reconstruction error; determining whether the reconstruction error is greater than the threshold for adversarial sample detection; if so, determining it as an adversarial sample, and if not, determining it as a normal sample.
[0019] The technical solution provided by the embodiments of the present application has at least the following advantages:
[0020] The embodiments of the present application provide a method for detecting adversarial sample attacks on jointly reconstructed electromagnetic signals, including the following steps: obtaining a modulation signal data set; the modulation signal data set includes an original training set and an original test set; both the original training set and the original test set include multiple modulation methods; based on the modulation signal data set, constructing a modulation recognition network, and using the classification result output by the modulation recognition network as the selection basis for entering the reconstruction network; constructing a reconstruction network, and using the loss result of the reconstruction network as the judgment basis for whether it is an adversarial sample; training the modulation recognition network with the original training set until convergence; training a reconstruction network corresponding to each modulation method with the original training set for each modulation method; reconstructing the normal signals of the original test set to obtain a reconstruction loss, and determining a threshold for adversarial sample detection based on the reconstruction loss; generating adversarial samples using adversarial attacks, and sequentially inputting the adversarial samples into the modulation recognition network and the reconstruction network to test the attack detection ability.
[0021] The embodiment of the present application provides a method for detecting adversarial sample attacks by jointly reconstructing electromagnetic signals. A pre-classified modulation recognition network is used to train a reconstruction network for different modulation types, and the reconstruction network is selected through the modulation recognition network for reconstruction. The modulation recognition network uses a deep convolutional network with residual blocks, ensuring high-accuracy recognition of normal samples by the network; the reconstruction network is an adversarial autoencoder network, ensuring the accuracy of signal sample reconstruction; during detection, a simple network connection is used. The signal to be detected first needs to enter the modulation recognition network to obtain a label, which is used as the basis for subsequent reconstruction network selection. According to the category given by the modulation recognition network, it enters the corresponding reconstruction network. The threshold is determined using the reconstruction error of the normal signal and a preset false alarm rate. If the reconstruction loss value of the signal to be detected is greater than the decision threshold, it is determined that the signal is attacked, otherwise it is determined that the signal is normal, improving the discrimination degree of the reconstruction errors between normal samples and adversarial samples, and achieving accurate and rapid detection of known and unknown forms of adversarial samples.
[0022] The embodiment of the present application provides a method for detecting adversarial sample attacks by jointly reconstructing electromagnetic signals. On the one hand, adversarial samples are not used during the training process, and the attack methods are not limited during the detection process, making it applicable to a wider range of attack forms; on the other hand, the present application can not only detect misclassified adversarial samples, but also has a high detection accuracy for adversarial samples that have not been successfully attacked. In addition, the network structure of the adversarial sample attack detection method of the present application has only two types, and the number of network layers is small, essentially having a lower model construction cost; moreover, for a signal to be detected, only two networks are required, and no other processing is needed, with high detection efficiency. Brief Description of the Drawings
[0023] One or more embodiments are exemplarily illustrated by the pictures in the corresponding drawings. These exemplary illustrations do not limit the embodiments. Unless otherwise stated, the figures in the drawings do not constitute a proportional limitation.
[0024] Figure 1 It is a schematic flowchart of a method for detecting adversarial sample attacks by jointly reconstructing electromagnetic signals provided by an embodiment of the present application;
[0025] Figure 2 It is a general flowchart of model training, threshold determination, and detection provided by an embodiment of the present application;
[0026] Figure 3 It is the network structure of the modulation recognition network provided by an embodiment of the present application;
[0027] Figure 4 It is the network structure of the reconstruction network provided by an embodiment of the present application;
[0028] Figure 5The accuracy curve of attack detection and the detection accuracy graph of a single reconstruction model provided by an embodiment of the present application;
[0029] Figure 6 The structural schematic diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0030] As can be seen from the background art, the existing adversarial sample attack detection methods have problems of low scalability, inability to effectively cope with unknown types of attacks, and insufficient performance and generalization ability of the model.
[0031] To solve the above problems, an embodiment of the present application provides an adversarial sample attack detection method for jointly reconstructing electromagnetic signals, including the following steps: obtaining a modulation signal data set; constructing a modulation recognition network; constructing a reconstruction network, and using the loss result of the reconstruction network as the judgment basis for whether it is an adversarial sample; training the modulation recognition network with the original training set until convergence; training a reconstruction network corresponding to each modulation method with the original training set for each modulation method; reconstructing the normal signals in the original test set to obtain a reconstruction loss, and using the reconstruction loss as the basis for setting the threshold for adversarial sample detection; generating adversarial samples by using adversarial attacks, and inputting the adversarial samples into the model to test the attack detection ability. The present application uses the method of pre-classifying and then reconstructing electromagnetic signals to achieve accurate detection of unknown adversarial sample attacks in intelligent offense and defense scenarios, and provides effective pre-defense for modulation recognition.
[0032] The following will elaborate on each embodiment of the present application with reference to the accompanying drawings. However, those of ordinary skill in the art can understand that in each embodiment of the present application, many technical details are proposed to help the reader better understand the present application. However, even without these technical details and various changes and modifications based on the following embodiments, the technical solutions claimed in the present application can still be implemented.
[0033] Refer to Figure 1 , an embodiment of the present application provides an adversarial sample attack detection method for jointly reconstructing electromagnetic signals, including the following steps:
[0034] Step S1, obtaining a modulation signal data set; the modulation signal data set includes an original training set and an original test set; both the original training set and the original test set include multiple modulation methods.
[0035] Step S2, based on the modulation signal data set, constructing a modulation recognition network, and using the category result output by the modulation recognition network as the selection basis for entering the reconstruction network.
[0036] Step S3, constructing a reconstruction network, and using the loss result of the reconstruction network as the judgment basis for whether it is an adversarial sample.
[0037] Step S4: Use the original training set to train the modulation recognition network until convergence.
[0038] Step S5: Use the original training set to train a reconstruction network corresponding to each modulation method for each modulation method.
[0039] Step S6: Reconstruct the normal signals in the original test set to obtain the reconstruction loss, and define the threshold for adversarial sample detection based on the reconstruction loss.
[0040] Step S7: Generate adversarial samples using adversarial attacks, and sequentially input the adversarial samples into the modulation recognition network and the reconstruction network to test the attack detection ability.
[0041] The embodiment of the present application proposes an adversarial sample attack detection method for jointly reconstructing electromagnetic signals. The autoencoder network is used for adversarial sample detection, and a pre-identification network is added. The reconstruction network is selected through the modulation recognition network and then reconstructed. A simple network connection is used to accurately and quickly detect known and unknown forms of adversarial samples, providing a strong basis for accurately identifying electromagnetic signal adversarial samples in a complex electromagnetic space.
[0042] In some embodiments, obtaining the modulation signal dataset in step S1 includes the following steps:
[0043] Step S101: Use the true modulation type of the electromagnetic signal as a label to construct a dataset.
[0044] Step S102: Select data of multiple modulation methods in the dataset, and shuffle the data and the label to generate a shuffled dataset.
[0045] Step S103: Divide the shuffled dataset into an original training set and an original test set according to a ratio to obtain the modulation signal dataset.
[0046] In some embodiments, in step S102, select data of 10 modulation methods in the dataset, and shuffle the data and the label to generate a shuffled dataset. In step S103, divide the shuffled dataset into an original training set and an original test set according to a ratio of 8:2 to obtain the modulation signal dataset.
[0047] It should be noted that both the original training set and the original test set contain 10 modulation methods and 20 signal-to-noise ratios from -20 dB to 18 dB.
[0048] In some embodiments, the modulation recognition network is trained using all the data in the original training set until convergence; for each modulation method, a reconstruction network corresponding to the modulation method is trained using the data with a signal-to-noise ratio (SNR) above 0 dB in the original training set; the normal signals in the data with an SNR above 0 dB in the original test set are reconstructed to obtain a reconstruction loss; adversarial samples are generated by adding attacks to the data with an SNR above 0 dB in the original test set. Specifically, in step S4 of this application, the modulation recognition network is trained using all the data in the original training set until convergence; in step S5, the data with an SNR of 0 dB to 18 dB in the original training set is used to train a reconstruction network corresponding to each modulation method. In step S6, the data with an SNR of 0 dB to 18 dB in the original test set is reconstructed to obtain a reconstruction loss, and a threshold for adversarial sample detection is determined based on the reconstruction loss; the adversarial samples are also generated by adding attacks to the data with an SNR of 0 dB to 18 dB in the original test set.
[0049] In some embodiments, the modulation recognition network constructed in step S2 is a neural network classification model with residual blocks.
[0050] Specifically, the modulation recognition network (neural network classification model) includes 4 residual blocks, and each residual block contains two convolutional layers with a convolution kernel of 1×3. Before the residual blocks, there are two layers of convolution and pooling. The convolution kernel size of the first convolutional layer is 2×15, and the convolution kernel size of the second convolutional layer is 1×3. After the residual blocks, there is a convolutional layer and a global average pooling layer.
[0051] In some embodiments, the last layer of the modulation recognition network uses a fully connected layer. The number of neurons in the fully connected layer is the same as the number of types of recognition tasks. The confidence corresponding to the output of the fully connected layer is: [p1, p2, p3,..., p n , and:
[0052]
[0053] where p i is the confidence vector corresponding to the output of the fully connected layer, and n represents the number of classes;
[0054] The position index corresponding to the maximum value is selected from the confidence vector as the class result output by the modulation recognition network, and the class result is used as the selection basis for entering the reconstruction network.
[0055] In some embodiments, in step S3, an adversarial autoencoder network is used to construct a reconstruction network; wherein, the adversarial autoencoder network includes an encoder module, a decoder module, and a discriminator module. Among them, the encoder module contains two convolutional layers and two pooling layers, the decoder module contains a fully connected layer, two convolutional layers, and two deconvolutional layers, and the decoding result is finally output by the convolutional layer.
[0056] Specifically, the adversarial autoencoder network model constructed in this application consists of an encoder E, a decoder D ε and a discriminator D. The input data size and the output data size are both the same as the sample size in the dataset. Both encoding and decoding use deep convolutional networks. The encoder encodes the input sample x to generate a latent vector z, and the decoder decodes this latent vector to be the same as the input size.
[0057] z = E(x)
[0058]
[0059] The discriminator D is responsible for distinguishing whether the input z comes from real data (subject to the q(z) probability distribution) or fake data (subject to the predefined p(z) probability distribution), and measures the reconstruction error with the gap between the input data and the output data.
[0060] In some embodiments, in step S4, the original training set is used to train the modulation recognition network until convergence. By selecting an optimizer, the network model parameters are updated, the learning rate and the batch size are set, the learning rate is updated with cosine decay, and the loss is decreased through the mini-batch gradient descent algorithm to obtain the trained modulation recognition network model.
[0061] In some embodiments, the number of reconstruction networks is the same as the number of modulation schemes, and the reconstruction networks correspond one-to-one with the modulation schemes. Specifically, data samples with a signal-to-noise ratio of 0 dB or more in the original training set are used to train a reconstruction network for each modulation scheme. For n modulation types in the dataset, n reconstruction networks are trained. One reconstruction network is trained only with a normal modulation signal with a corresponding label. The training method for each network is the same. The training is carried out in two stages in an unsupervised manner, namely the reconstruction stage and the regularization stage. In the reconstruction stage, the encoder-decoder is trained to reduce the reconstruction loss between the input and the output of the decoder. In the regularization stage, an adversarial generation network composed of an encoder and a discriminator is trained. The weights of the encoder are fixed, and the discriminator is trained. Vectors from the real distribution and vectors generated by the encoder are input into the discriminator to train the discriminator to distinguish between the two. Then, the weights of the discriminator are fixed to the current weights, and the encoder is trained to make the discriminator judge the samples generated by the encoder as real samples. In each round of training, the two stages are alternately trained. After multiple iterations, a state with good reconstruction effect and excellent and relatively balanced performance of the encoder and the discriminator is found. When the set maximum number of iterations is reached, the training of the reconstruction model is completed.
[0062] In some embodiments, in step S6, the normal signals in the original test set are reconstructed to obtain a reconstruction loss, and an adversarial sample detection threshold is determined based on the reconstruction loss, including: inputting the normal signals in the original test set into the modulation recognition network, and the modulation recognition network classifies the normal signals in the original test set and outputs a classification label corresponding to the normal signals in the original test set; inputting the normal signals in the original test set into the corresponding reconstruction network according to the classification label, and the reconstruction network outputs a reconstruction error corresponding to each normal signal in the original test set; and determining the adversarial sample detection threshold based on the reconstruction error and a preset false alarm rate.
[0063] In some examples, in step S7, the adversarial samples are sequentially input into the modulation recognition network and the reconstruction network to test the attack detection ability, including: inputting the signal to be detected (adversarial sample) into the modulation recognition network to obtain a label; determining the modulation category of the adversarial sample based on the label; then inputting the adversarial sample into the reconstruction network of the corresponding category to obtain a reconstruction error; and determining whether the reconstruction error is greater than the adversarial sample detection threshold; if so, it is determined as an adversarial sample, and if not, it is determined as a normal sample.
[0064] The present application proposes an adversarial sample attack detection method for jointly reconstructing electromagnetic signals. The specific implementation process of the present application is divided into seven steps. In combination with the attached Figure 1 A further detailed description is made on the specific implementation steps of the present application.
[0065] Step S1: Obtain a modulation signal dataset; the modulation signal dataset includes an original training set and an original test set.
[0066] Specifically, use the open-source modulation signal dataset RML2016.10a, select data of 10 modulation methods from it, shuffle the data and labels, and divide them into an original training set and an original test set according to 8:2.
[0067] It should be noted that the ten modulation methods of the modulation signals in the dataset are Binary Phase Shift Keying (BPSK), Quadrature Phase Shift Keying (QPSK), 8 Phase Shift Keying (8PSK), 16 Quadrature Amplitude Modulation (QAM16), 64 Quadrature Amplitude Modulation (QAM64), Continuous-Phase Frequency Shift Keying (CPFSK), Gauss frequency Shift Keying (GFSK), Amplitude Modulation-Double Sideband (AM-DSB), 4 Pulse Amplitude Modulation (PAM4), Wide Band Frequency Modulation (WBFM); the twenty signal-to-noise ratios are -20dB, -18dB, -16dB, -14dB, -12dB, -10dB, -8dB, -6dB, -4dB, -2dB, 0dB, 2dB, 4dB, 6dB, 8dB, 10dB, 12dB, 14dB, 16dB, 18dB.
[0068] Step S2: Based on the modulation signal dataset, construct a modulation recognition network, and use the class result output by the modulation recognition network as the selection basis for entering the reconstruction network.
[0069] Specifically, construct a neural network classification model with residual blocks, such as Figure 3As shown in the figure, the model contains 4 residual blocks. Each residual block contains two convolutional layers with a convolutional kernel size of 1×3. The data input to the residual block is added to the data output from the residual block and then enters the next layer. Before the four residual blocks, there are two convolutional layers and pooling layers. The convolutional kernel size of the first convolutional layer is 2×15, and the convolutional kernel size of the second convolutional layer is 1×3. Both pooling layers use the maximum pooling method. After the residual blocks, there is a convolutional layer and a global average pooling layer. After each convolutional layer, there are a batch normalization layer and a rectified linear unit (ReLu) activation function layer. Finally, there are two fully connected layers, which contain 128 and 10 neurons respectively. The size of the finally output classification result is 1×10.
[0070] Step S3: Construct a reconstruction network, and use the loss result of the reconstruction network as the judgment basis for whether it is an adversarial sample.
[0071] Specifically, the reconstruction network uses an adversarial autoencoder network, which includes an encoder-decoder and a discriminator, as Figure 4 shown.
[0072] a) Construction of the encoder-decoder: The encoder-decoder is divided into an encoder and a decoder. The encoder is the generative model of the generative adversarial network. The convolutional neural network of the encoder part contains two convolutional layers and two pooling layers. The convolutional kernel size of the convolutional layers is 3×3. After each convolutional layer, there are a batch normalization layer and a rectified linear unit (ReLu) activation function layer. The pooling uses maximum pooling, and then it is connected to a fully connected layer with 128 neurons. The encoding part compresses the input with a size of 2×128 into a latent vector with a size of 128. The convolutional neural network of the decoder part contains a fully connected layer, two convolutional layers, and two deconvolutional layers. The fully connected layer expands the encoded latent vector with a size of 128 into 1024, and then reshapes it into 32×2×16 and enters the convolutional layer, and then enters two convolutional layers. The kernel size of the convolutional layer and the deconvolutional layer is 3×3. After the deconvolutional layer and the first convolutional layer, there are a batch normalization layer and a rectified linear unit (ReLu) activation function layer. The convolutional result of the last convolutional layer is directly output, and the output dimension is the same as the sample size of the input encoding network.
[0073] b) Construction of the discriminator: The total number of layers of the discriminator is 3. The number of nodes in the input layer is 128, and the number of nodes in the output layer is 1. All use a fully connected structure. The number of nodes in the middle two layers is 256. The activation function uses the rectified linear unit (ReLu), and the last layer uses the softmax activation function. The loss function uses cross entropy.
[0074] c) Loss function: The reconstruction error is measured by the difference between the input data and the output data. where x is the input vector, is the output vector of the decoder N is the dimension of the vector. The discriminator error D l = σ(z, 1), where σ is the Sigmoid cross-entropy function.
[0075] Step S4: Use the original training set to train the modulation recognition network until convergence.
[0076] Specifically, during training, only use the open-source dataset with existing labels. Input the training dataset consisting of 160,000 signal samples with 20 signal-to-noise ratios and 10 modulation methods to the modulation recognition network. The validation set uses 40,000 signal samples with 20 signal-to-noise ratios and 10 modulation methods that are mutually exclusive with the training set. Label the modulation signals with 0-9 according to the modulation method. Use Sparse Categorical Crossentropy as the loss function, use the Adam optimizer to update the network model parameters. Set the initial learning rate to 0.01, use cosine decay to update the learning rate, set the batch size to 128, and make the loss decrease through the mini-batch gradient descent algorithm to obtain the trained modulation recognition network model.
[0077] Step S5: Use the original training set to train a reconstruction network corresponding to each modulation method.
[0078] Step S5 is a process of training a reconstruction network for each modulation method using the data samples with a signal-to-noise ratio above 0 dB in the original training set (the data with a signal-to-noise ratio of 0 dB - 18 dB in the original training set can be used). Specifically, use the same reconstruction network structure. Label the 10 modulation methods: BPSK, QPSK, 8PSK, QAM16, QAM64, CPFSK, GFSK, AM-DSB, PAM4, WBFM as 1 - 10. Each time, use the signals with a signal-to-noise ratio of 0 dB - 18 dB of one modulation type to train a network, and a total of 10 reconstruction networks will be obtained, labeled as reconstruction network 1 - 10. A reconstruction network is only trained with the normal modulation signals corresponding to the label. There are 8,000 pieces of data for training in a network. During training, randomly divide it into a training set and a validation set according to a ratio of 3:1. Use the Adam optimizer and set the learning rate to 2×10 -6 . The reconstruction network is trained in an unsupervised manner in two stages, namely the reconstruction stage and the regularization stage. In the reconstruction stage, train the encoder-decoder to reduce the error between the input x and the output of the decoder In the regularization stage, train the adversarial generation network composed of the encoder and the discriminator. Fix the weights of the encoder and train the discriminator. Select signal samples from the training set and use them as the input samples of the encoder. Denote the output as zf and label it as 0. And randomly sample from the specified distribution, denoted as z r, and mark it as 1. Using the forward propagation algorithm, through z f and z r Input to the discriminator for training, calculate the loss between the output and the corresponding label, and use the backpropagation algorithm to correct the weights and biases of the nodes in each layer of the fully connected discriminant model. In each round of training, the two stages are alternately trained. After multiple iterations, find a state with good reconstruction effect and excellent and relatively balanced performance of the encoder and discriminator. When the set maximum number of iterations is reached, the reconstruction model training is completed.
[0079] Step S6: Reconstruct the normal signals in the original test set to obtain the reconstruction loss, and use the reconstruction loss as the basis to define the threshold for adversarial sample detection.
[0080] Step S6 is the process of reconstructing the signals with a signal-to-noise ratio above 0 dB in the original test set to obtain the reconstruction loss. Specifically, input the normal test data set into the modulation recognition network. The modulation recognition network classifies the signal samples and outputs a corresponding label m. Then, send the normal signals into the reconstruction network numbered m according to the classification label. The reconstruction network outputs a reconstruction error for each signal. Define the threshold according to the reconstruction error of the normal samples at a false alarm rate of 5%;
[0081] Step S7: Generate adversarial samples using adversarial attacks, and input the adversarial samples into the modulation recognition network and the reconstruction network in sequence to test the attack detection ability.
[0082] Step S7 can be divided into two steps. First, execute Step S701: Use adversarial attacks to generate adversarial samples to test the attack detection ability of this method.
[0083] Specifically, use the Fast Gradient Sign Method (FGSM) to obtain adversarial samples by attacking all the samples in the test set. Among them, FGSM is expressed as:
[0084]
[0085] x * = x + η
[0086] where ε is the perturbation size. In this application, ε is set to 0.0005, 0.001, 0.002, 0.003, x is the input sample, l is the sample label, J(x, l) is the loss function of the model, is to obtain the gradient of the loss function with respect to x, sign() is the sign function, η is the generated perturbation, and the perturbation is superimposed on the original sample to obtain the adversarial sample x * .
[0087] After step S701 is executed and the adversarial sample is generated, step S702 is executed, where the adversarial sample is input into the model to test the attack detection ability of the method.
[0088] Specifically, the signal to be detected (adversarial sample) first needs to enter the modulation recognition network to obtain a label and determine the modulation category it belongs to, and then enter the reconstruction network corresponding to the category. If it is a normal signal, it will be correctly classified and enter the reconstruction network that matches the label, and be reconstructed with a low reconstruction loss. However, if it is an adversarial sample, there is a small probability of correct classification and a high probability of incorrect classification. If the classification is correct, the entered reconstruction network matches the signal; if the classification is incorrect, it enters a mismatched reconstruction network, and finally a reconstruction error is obtained. The reconstruction error value is compared with a threshold. If it is greater than the threshold, it is determined as an adversarial sample, and it is considered that its modulation recognition method is likely to be misrecognized, and the data is processed manually or discarded. If it is less than the threshold, it is determined as a normal sample, and the probability that its modulation method is correctly recognized is high, and the result given by the modulation recognition network can be trusted.
[0089] The technical effects of this application are further illustrated through simulation experiments below.
[0090] Simulation conditions:
[0091] The Python version used for simulation is 3.8;
[0092] The convolutional neural network model is built on Pytorch 1.9.0+cu111;
[0093] Simulation content:
[0094] This application is used to detect adversarial samples under FGSM attacks with different amplitude sizes, and the results are compared with the attack detection method that directly uses a single network for reconstruction. The simulation results are as Figure 5 shown.
[0095] As can be seen from the simulation results, when the signal-to-noise ratio is 2 dB, the model of the present application can achieve an accuracy of nearly 85% for attacks with a perturbation amplitude of 0.003. When the signal-to-noise ratio is greater than 4 dB, the accuracy can reach 80% for attacks with perturbation amplitudes of 0.002 and 0.003. When the signal-to-noise ratio reaches 8 dB, the detection accuracy can reach more than 90% for attacks with perturbation amplitudes of 0.001, 0.002, and 0.003. When the signal-to-noise ratio reaches 12 dB, for very small perturbations with a perturbation amplitude of 0.0005, the accuracy can reach more than 60%. From the results of the detection accuracy at a single signal-to-noise ratio, the model of the present application can achieve a higher detection accuracy at a lower signal-to-noise ratio. For attack samples with perturbation amplitudes of 0.001 and 0.0005, the detection accuracy of the model of the present application is significantly better than that of a single reconstruction model. It can be seen that the model of the present application has very excellent detection accuracy and high sensitivity under high signal-to-noise ratio conditions.
[0096] In summary, the embodiment of the present application proposes a method for detecting adversarial sample attacks by jointly reconstructing electromagnetic signals. The autoencoder network is used for adversarial sample detection, and a pre-identification network is added. The reconstruction network is selected through the modulation identification network and then reconstructed. A simple network connection is used to accurately and quickly detect known and unknown forms of adversarial samples, providing a strong basis for accurately identifying electromagnetic signal adversarial samples in a complex electromagnetic space. The method for detecting adversarial sample attacks by jointly reconstructing electromagnetic signals provided by the embodiment of the present application uses the method of pre-classifying and then reconstructing electromagnetic signals to achieve accurate detection of unknown adversarial sample attacks in an intelligent offensive and defensive scenario, providing effective pre-defense for modulation identification.
[0097] Reference Figure 6 , another embodiment of the present application provides an electronic device, including: at least one processor 110; and a memory 111 communicatively connected to the at least one processor; wherein, the memory 111 stores instructions executable by the at least one processor 110, and the instructions are executed by the at least one processor 110 so that the at least one processor 110 can execute any of the above method embodiments.
[0098] Among them, the memory 111 and the processor 110 are connected in a bus manner. The bus can include any number of interconnected buses and bridges, which connect various circuits of one or more processors 110 and the memory 111 together. The bus can also connect various other circuits such as peripheral devices, voltage regulators, and power management circuits, etc. These are well known in the art, so they will not be further described herein. The bus interface provides an interface between the bus and the transceiver. The transceiver can be a single component or multiple components, such as multiple receivers and transmitters, providing a unit for communicating with various other devices over a transmission medium. The data processed by the processor 110 is transmitted over a wireless medium via an antenna. Further, the antenna also receives data and transmits the data to the processor 110.
[0099] The processor 110 is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interface, voltage regulation, power management, and other control functions. The memory 111 can be used to store the data used by the processor 110 when performing operations.
[0100] According to the above technical solution, an adversarial sample attack detection method for jointly reconstructing electromagnetic signals provided by an embodiment of the present application includes the following steps: obtaining a modulation signal data set; the modulation signal data set includes an original training set and an original test set; based on the modulation signal data set, constructing a modulation recognition network, and using the classification result output by the modulation recognition network as the selection basis for entering the reconstruction network; constructing a reconstruction network, and using the loss result of the reconstruction network as the judgment basis for whether it is an adversarial sample; training the modulation recognition network with the original training set until convergence; training a reconstruction network corresponding to each modulation method with the original training set for each modulation method; reconstructing the normal signals in the original test set to obtain a reconstruction loss, and using the reconstruction loss as the basis for setting a threshold for adversarial sample detection; generating adversarial samples using an adversarial attack, and sequentially inputting the adversarial samples into the modulation recognition network and the reconstruction network to test the attack detection ability.
[0101] The embodiment of the present application provides a method for detecting adversarial sample attacks by jointly reconstructing electromagnetic signals. A pre-classified modulation recognition network is adopted to train a reconstruction network for different modulation types, and the reconstruction network is selected through the modulation recognition network for reconstruction. The modulation recognition network uses a deep convolutional network with residual blocks, ensuring a high accuracy of network recognition for normal samples; the reconstruction network is an adversarial autoencoder network, ensuring the accuracy of signal sample reconstruction; during detection, a simple network connection is used. The signal to be detected first needs to enter the modulation recognition network to obtain a label, which is used as the basis for subsequent reconstruction network selection. According to the category given by the modulation recognition network, it enters the corresponding reconstruction network. The threshold is determined using the reconstruction error of the normal signal and the preset false alarm rate. If the reconstruction loss value of the signal to be detected is greater than the decision threshold, it is determined that the signal is attacked, otherwise it is determined that the signal is normal, improving the discrimination of the reconstruction errors between normal samples and adversarial samples, and achieving accurate and rapid detection of known and unknown forms of adversarial samples.
[0102] The embodiment of the present application provides a method for detecting adversarial sample attacks by jointly reconstructing electromagnetic signals. On the one hand, adversarial samples are not used during the training process, and the attack methods are not limited during the detection process, which is applicable to a wider range of attack forms; on the other hand, the present application can not only detect the misclassified adversarial samples, but also has a high detection accuracy for the adversarial samples that have not been successfully attacked. In addition, the network structure of the adversarial sample attack detection method of the present application has only two types, and the number of network layers is small, essentially having a lower model construction cost; furthermore, for a signal to be detected, only two networks are required, and no other processing is needed, so the detection efficiency is relatively high.
[0103] Those of ordinary skill in the art can understand that the above embodiments are specific embodiments for implementing the present application. In practical applications, various changes can be made in form and details without departing from the spirit and scope of the present application. Any person skilled in the art can make their own changes and modifications without departing from the spirit and scope of the present application. Therefore, the protection scope of the present application should be subject to the scope defined by the claims.
Claims
1. An adversarial sample attack detection method for jointly reconstructing electromagnetic signals, characterized in that, It includes the following steps: Obtain a modulation signal dataset; the modulation signal dataset includes an original training set and an original test set; both the original training set and the original test set include multiple modulation methods; Based on the modulation signal dataset, construct a modulation recognition network, and use the class result output by the modulation recognition network as the selection basis for entering the reconstruction network; the number of reconstruction networks is the same as the number of modulation methods, and the reconstruction networks correspond one-to-one with the modulation methods; Construct a reconstruction network, and use the loss result of the reconstruction network as the judgment basis for whether it is an adversarial sample; Use the original training set to train the modulation recognition network until convergence; Use the original training set to train a reconstruction network corresponding to each modulation method for each modulation method; Reconstruct the normal signals in the original test set to obtain a reconstruction loss, and use the reconstruction loss as the basis for setting the threshold for adversarial sample detection; Generate adversarial samples using adversarial attacks, and sequentially input the adversarial samples into the modulation recognition network and the reconstruction network to test the attack detection ability; Reconstruct the normal signals in the original test set to obtain a reconstruction loss, and use the reconstruction loss as the basis for setting the threshold for adversarial sample detection, including: Input the normal signals in the original test set into the modulation recognition network, and the modulation recognition network classifies the normal signals in the original test set and outputs a classification label corresponding to the normal signals in the original test set; Input the normal signals in the original test set into the corresponding reconstruction network according to the classification label, and the reconstruction network outputs a reconstruction error corresponding to each normal signal in the original test set; Based on the reconstruction error and a preset false alarm rate, set the threshold for adversarial sample detection.
2. The adversarial sample attack detection method for jointly reconstructing electromagnetic signals according to claim 1, characterized in that The obtaining of the modulation signal dataset includes: Construct a dataset with the true modulation type of the electromagnetic signal as the label; Select data of multiple modulation methods in the dataset, and shuffle the data and the label to generate a shuffled dataset; Divide the shuffled dataset into an original training set and an original test set according to a ratio to obtain the modulation signal dataset.
3. The adversarial sample attack detection method for jointly reconstructing electromagnetic signals according to claim 2, characterized in that, Select data of 10 modulation methods in the dataset, and shuffle the data and the label to generate a shuffled dataset; divide the shuffled dataset into an original training set and an original test set according to a ratio of 8:2 to obtain the modulation signal dataset.
4. The adversarial sample attack detection method for jointly reconstructing electromagnetic signals according to claim 1, characterized in that Use all the data in the original training set to train the modulation recognition network until convergence; Use the data with a signal-to-noise ratio above 0 dB in the original training set to train a reconstruction network corresponding to each modulation method for each modulation method; Reconstruct the normal signals of the data with a signal-to-noise ratio above 0 dB in the original test set to obtain a reconstruction loss; Generate adversarial samples by adding attacks to the data above 0 dB in the original test set.
5. The adversarial sample attack detection method for jointly reconstructing electromagnetic signals according to claim 1, characterized in that The modulation recognition network is a neural network classification model with residual blocks.
6. The adversarial sample attack detection method for jointly reconstructing electromagnetic signals according to claim 5, characterized in that The last layer of the modulation recognition network adopts a fully connected layer, and the number of neurons included in the fully connected layer is the same as the number of types of recognition tasks. The confidence corresponding to the output of the fully connected layer is: , and: Among them, is the confidence vector corresponding to the output of the fully connected layer, represents the number of categories; Select the position index corresponding to the maximum value from the confidence vector as the class result output by the modulation recognition network, and use the class result as the selection basis for entering the reconstruction network.
7. The adversarial sample attack detection method for jointly reconstructing electromagnetic signals according to claim 1, characterized in that Construct a reconstruction network using an adversarial autoencoder network; wherein, the adversarial autoencoder network includes an encoder module, a decoder module, and a discriminator module.
8. The adversarial sample attack detection method for jointly reconstructing electromagnetic signals according to claim 1, wherein, Input the adversarial samples into the modulation recognition network and the reconstruction network in sequence to test the attack detection ability, including: Input the adversarial samples into the modulation recognition network to obtain labels; Based on the labels, determine the modulation class of the adversarial samples; Then input the adversarial samples into the reconstruction network corresponding to the class to obtain a reconstruction error; Determine whether the reconstruction error is greater than the threshold for adversarial sample detection; if so, determine it as an adversarial sample, and if not, determine it as a normal sample.
Citation Information
Patent Citations
Signal adversarial sample detector design method and system based on N+1 class adversarial training
CN113642378A
Communication signal modulation mode open set identification method and system based on deep learning
CN114567528A