A method for generating adversarial samples for radar individual identification based on generative adversarial networks

Through the radar individual recognition adversarial sample generation method based on the generative adversarial network, the problem of insufficient recognition accuracy and real-timeness of radar radiation source individual recognition in the complex electromagnetic environment in the prior art is solved, and the robustness and security of the adversarial sample generation method are improved.

CN117648574BActive Publication Date: 2025-05-16NAT UNIV OF DEFENSE TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311638402.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-12-01
Publication Date
2025-05-16
Estimated Expiration
2043-12-01

AI Technical Summary

Technical Problem

The existing radar radiation source individual recognition technology lacks recognition accuracy and real-time in complex electromagnetic environments, making it difficult to meet the individual recognition requirements of radar radiation source in complex electromagnetic environments.

Method used

Adoptable sample generation method based on Generative Adversarial Network (GAN) is used to generate adversarial samples with high similarity to real sample data through alternating training of generator and discriminator, which is used to improve the robustness of radar individual recognition model.

Benefits of technology

This method can generate mobility adversarial samples stably and efficiently, improve the robustness and safety of radar individual classification model, and is suitable for individual recognition of radar radiation sources in complex electromagnetic environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117648574B_ABST
    Figure CN117648574B_ABST
Patent Text Reader

Abstract

The present invention proposes a method for generating adversarial samples for radar individual identification based on a generative adversarial network, which belongs to the field of radar identification technology. The generative adversarial network includes a generator and a discriminator. The method includes: obtaining real sample data collected by a radar individual identification system through reconnaissance. According to the data characteristics of the real sample data, first sample data is randomly generated, and the first sample data is used as the input of the generator. The generative adversarial network is trained and the trained generative adversarial network is used to generate adversarial samples whose similarity with the real sample data is higher than the similarity threshold.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of radar identification technology, and in particular relates to a method for generating adversarial samples for radar individual identification based on a generative adversarial network. Background Art

[0002] With the rapid development of electronic information technology, there are more and more wireless signal modulation methods, the types and number of radiation sources are increasing, and the electromagnetic environment is becoming more and more complex. How to find the signal of concern or confirm the attributes of suspicious signals in the complex electromagnetic environment and associate them with the individual radiation source and its platform and weapon system has very important strategic and tactical significance. The identification of individual radiation sources can distinguish the types of radiation sources and determine the identity of the radiation sources. It has broad application prospects in both military and civilian fields. Recently, the research on radio frequency fingerprints has received widespread attention.

[0003] Radar emitter individual identification technology, also known as emitter "fingerprint" identification or specific emitter identification, refers to the method of extracting subtle features of the signal and then identifying the individual source of the signal. Traditional radar emitter identification mainly uses parameter matching methods. Based on experience, a database of radar emitter signals of known categories is established. By receiving the emission signal of the emitter, the received signal is preprocessed and the parameter measurement is performed, and then the database is matched. The subtle features of the signal are extracted manually or empirically, and then based on these subtle features, the threshold classification method is used to achieve individual identification of the emitter. However, with the development of electronic technology, the electromagnetic environment is becoming more and more complex. The recognition process of traditional identification methods is relatively cumbersome, and the recognition effect for some complex signals is not ideal. Its recognition accuracy and real-time performance cannot meet the identification requirements of radar emitters in complex electromagnetic environments. With the increasing maturity of artificial intelligence technology, it is possible to apply deep learning to the identification of individual emitters. In recent years, deep learning algorithms have been studied by a large number of scholars with the development of artificial intelligence. Through a large number of experiments, it has been found that it can process data with complex rules and distributions, and its effectiveness has been greatly improved. The deep learning algorithm inputs data into layers of networks, automatically extracts potential feature information in the data through multiple iterations and function mapping, and finally classifies the feature information through a deep learning classifier. Due to its advantage of automatically learning data features, it can simply and effectively solve some difficult nonlinear problems. In the field of radar emitter individual identification, the use of deep learning algorithms can automatically extract potential individual subtle features in radar emitter signals, thereby improving the performance of radar emitter individual identification. With the advancement of deep learning technology, the method of radiator individual identification is also evolving. People are constantly trying to use new neural network models to extract radiator fingerprint features, and the performance of recognition accuracy and recognition rate is gradually improving.

[0004] With the widespread application of deep learning technology in various fields, deep learning has brought great convenience to people; however, due to the high uncertainty and relatively complex technical loopholes of artificial intelligence technology, artificial intelligence systems face huge security challenges, and its security issues have received more and more attention. Deep learning technology plays a vital role in the field of radar emitter individual identification. Its accuracy and robustness play an important role in the security of intelligent systems. Failure to successfully identify radar emitters or misclassification of radar emitters may lead to catastrophic consequences and cause irreparable losses.

[0005] Software testing is an effective means to improve the security and reliability of artificial intelligence systems. Therefore, before the radar emitter individual identification system based on deep learning is put into use, it is of great practical significance to strengthen the testing of artificial intelligence systems. Studies have shown that deep networks are vulnerable to adversarial samples. For model testers, adversarial samples can be used as an effective tool to evaluate the security and robustness of models. Through adversarial training, the accuracy and security of model classification can be effectively improved. Therefore, studying the generation method of adversarial samples not only helps to expose the potential hazards in the field of deep learning, but also can prompt deep neural networks to improve their ability to resist potential risks. At present, the test of radar emitter individual identification based on deep learning mainly adopts traditional testing methods, lacking targeted test data generation methods and means. Artificial intelligence system testing is different from traditional software testing. Traditional software testing mainly designs test cases based on known rules, but the rules of artificial intelligence systems are trained through data, and its performance is seriously dependent on the quality of the training data we input. The scale, quality and difference of data will affect the performance of artificial intelligence systems. In particular, in many cases, artificial intelligence systems may show an overfitting phenomenon, that is, a model that performs well in the training stage may not perform particularly well in the test stage, so it is very important to grasp the test data during testing. Therefore, data-driven artificial intelligence systems are more complex and challenging than traditional software testing. If the test is still carried out according to the traditional software testing method and using the traditional test data generation technology, it may lead to insufficient testing and inaccurate test conclusions. At the same time, in the test process of the radar individual recognition system based on deep learning, it is difficult to construct a comprehensive typical test scene and test environment, and it is difficult to fully collect target radar data. Therefore, it is of great practical significance to study the test data generation method to evaluate the deep learning model and explore its technical loopholes and model vulnerabilities.

[0006] The robustness evaluation process of radar individual recognition system based on adversarial sample generation is as follows: Figure 1As shown in Figure 1. Studies have shown that deep networks are very vulnerable to attacks from adversarial samples. In recent years, adversarial samples have become one of the hot issues in the field of deep learning security. By adding reasonably perturbed input samples to the system model, the system will misjudge the perturbed input samples, that is, predict an incorrect result with high confidence. These samples with perturbed samples are called adversarial samples. Adversarial samples are highly concealed and can deceive deep neural networks to cause the model to output incorrect prediction results. They are of great value for evaluating the reliability and robustness of deep learning systems. In 2013, Szegedy et al. noticed that imperceptible perturbations in test samples have the possibility of misclassifying neural networks. Adversarial attacks induce the model to obtain results that are completely deviated from the true value while the human visual system cannot detect input changes. These samples cause the model to classify them into the category specified by the attacker or into a category different from the original sample. The gradient-based adversarial sample generation algorithm (fast gradient sign method, FGSM) generates perturbations by finding the direction with the largest model gradient change, making it impossible for the model to correctly identify the input sample. FGSM is simple to operate and has good results, and many derivative algorithms have emerged. However, such methods require access to the architecture and parameters of the target network during the attack, which often has certain limitations in the actual testing process. C&W (Carlini and Wagner attacks) found that adversarial perturbations can be transferred from insecure networks to secure networks. The transferability means that the algorithm is also suitable for black-box attacks. Based on the GAN-based attack algorithm, the trained generator can convert input samples into perturbations and form adversarial samples, proving that adversarial samples generated based on infinite normal distance constraints are more realistic than samples generated based on optimization equations and matrix metrics of simple pixel space. Based on the generative adversarial network, the semantic space of the image is constructed by inputting the original sample, and the hidden variables in the semantic space are mapped into adversarial samples through the network, making the generated adversarial samples more natural. Compared with adding perturbations to all pixels, this strategy of adding partial perturbations based on certain criteria pays more attention to the relationship between the number of selected pixels, cost and adversarial nature.

[0007] Among various generative models, the optimization process of generative adversarial networks (GAN) enables the generator to estimate the distribution of data samples, thereby generating data samples that are difficult to distinguish between true and false. ACGAN (auxiliary classifier GAN) sets the objective function as the sum of the likelihood of the real data sample and the likelihood of the correct classification label, thereby subdividing and adjusting the loss function to make the classification accuracy higher, further improving the generation and discrimination capabilities of the network. In addition, starting from the loss function, it is proved that when JS divergence is used as a measure of the similarity between the target distribution and the generated distribution, when the overlapping area between the target distribution and the generated distribution is negligible, the JS divergence is a constant, at which time the generator obtains a gradient of 0, and the network cannot continue to be optimized. On this basis, WassersteinGAN (WGAN) using EM distance as a similarity measure is proposed, which points out a new direction for solving the problems of GAN training difficulties, the inability of loss functions to guide training, and the lack of diversity in generated samples. Since the theory of generative adversarial networks was proposed, it has had a wide range of application scenarios, resulting in the emergence of a large number of derivative models supported by this theory, which has effectively promoted the progress of applications such as image generation, super-resolution, style transfer, and image restoration.

[0008] By constructing evaluation data through generative adversarial networks to test neural network models, it is not dependent on the architecture and parameters of the target neural network. It is of great value for the robustness evaluation of radar individual recognition systems based on deep learning. It can not only discover the security defects and vulnerabilities of the model, but also provide ideas for the formulation of defense strategies and the enhancement of model robustness.

[0009] A deep generative model based on game theory, namely Generative Adversarial Network (GAN), aims to generate images in a simple way by training two adversarial networks, namely the generator network (G) and the discriminator network (D). In the field of image generation, the training samples of GAN are images, and the generative model with excellent performance obtained by training can generate false samples with consistent distribution of input data without relying on any prior assumptions.

[0010] The basic network structure of GAN is as follows Figure 2 As shown in Figure 2, the generator G attempts to establish an implicit probability distribution that is close to the essential probability distribution of the training data, hoping that the generated image is infinitely close to the real image. fake The sample is sent to the discriminator D, making it mistakenly believe that the sample is the real sample X real, giving the probability that the sample comes from the training data set 1. The discriminator D is in competition with the generator G and is responsible for scoring the generated images. The discrimination problem at this time is a binary classification problem, outputting 0 or 1 to judge whether the input sample is X fake Or X real , when D discriminates that the input comes from G, it outputs 0, otherwise it outputs 1. The goal of D is to discriminate the sample X from the generator fake The probability of being the real data is 0, and the probability of discriminating the data X from the training set is real The probability that X is real data is 1. The discriminator D hopes that no matter how powerful the generator is in generating fake pictures, it can always distinguish X from real data. fake and X real The entire training process of GAN is a game process between the generator G and the discriminator D. The optimization of G and D is performed separately and alternately. The entire GAN belongs to an implicit density model, and its optimized objective function is as follows:

[0011]

[0012] In the above formula, P data represents the real data distribution for training, P Z represents the implicit probability distribution generated by the model. The goal of the discriminator D is to distinguish whether the sample X is from the distribution P data Or P from generator G Z The goal of the generator G is to make the discriminator D put P Z The sample distribution is judged to obey P data The two networks of the generative model are trained alternately. The goal of the training is to make the G(z) generated by the generator G obey P data distributed.

[0013] Assume X real ~P data (X), X fake ~P g (X). When the generator G is fixed, there is an optimal solution in theory. The optimal discriminator D can be obtained by taking the derivative of V(D, G) * (X):

[0014]

[0015] When D * When (X) exists, it is brought into the objective function of the generative model, and the goal of G becomes to optimize P g (X) and P data (X) JS divergence (Jenson Shannon Divergence, JSD) of two distributions:

[0016]

[0017] There are many ways to measure the distance between two distributions, and JS divergence is just one of them. The objective function of GAN changes with different distance measurement methods. Some improvements to the training stability of GAN have also improved P data and P Z Distributions define different distance metrics.

[0018] Adversarial samples can be used as training data to help improve the expressive power of models and can also evaluate the robustness of deep learning models. Therefore, designing a generation algorithm that can quickly generate high-quality adversarial samples and provide sufficient high-quality and diverse adversarial sample data sources for model robustness testing is an important means to effectively improve the robustness of radar individual recognition models. There are two types of mainstream adversarial attack algorithms: 1) using the original sample as input, then designing an algorithm to generate perturbations, and superimposing the perturbations on the original sample to obtain adversarial samples; 2) using the original sample as input, and then designing an algorithm to directly generate adversarial samples. Most existing studies rely on the first method, which means that in some scenarios where data sources are limited, the scale of adversarial samples generated by existing algorithms will not be able to meet the needs of projects such as adversarial training that require a large number of adversarial samples as a research basis. Moreover, for radar individual recognition systems based on deep learning, it is difficult to fully collect target radar data. Due to the lack of sufficient sample data, the model training is insufficient and the results are inaccurate. In order to obtain any number of adversarial samples more efficiently and make the model test as sufficient as possible, it is of great significance to explore a method for generating adversarial samples that is not limited by the original data.

[0019] The key to the security issues of artificial intelligence lies mainly in the input of the model. Adversarial samples are input samples formed by deliberately adding slight perturbations to the data set. Some specific sample data will cause the model to make wrong predictions with high confidence. Deep neural networks can easily be deceived by adversarial samples generated by slight perturbations and make misjudgments. These samples pose a threat to the security of the model. The existence of adversarial samples shows that the model tends to rely on unreliable features to maximize performance. If the features are disturbed, the model will be misclassified. Since the training set is a sampling of the real distribution, the trained model boundary cannot completely fit the real decision boundary. The adversarial attack algorithm is to find an efficient method to generate samples in this adversarial area, thereby attacking the model. The traditional classic gradient-based adversarial sample generation algorithm generates perturbations by finding the direction with the largest model gradient change, so that the model cannot correctly identify the input sample. FGSM is simple to operate and has good results, and many derivative algorithms have emerged. However, such methods need to access the architecture and parameters of the attacked target network during the attack, which often has certain limitations in the actual testing process. Therefore, in order to obtain more general adversarial samples, it is of great significance to explore a method of generating adversarial samples that is not restricted by the target network architecture and parameters. Summary of the invention

[0020] In view of the above technical problems, the present invention aims at the application principles and technical characteristics of deep learning in the individual identification of radar radiation sources, fully considers the characteristics of the equipment use environment, and combines the basic principles of generative adversarial networks to propose a method for generating adversarial sample test data for radar individual identification based on generative adversarial networks.

[0021] The first aspect of the present invention proposes a method for generating adversarial samples for radar individual identification based on a generative adversarial network. The generative adversarial network includes a generator and a discriminator, and the method includes:

[0022] Step S1: Acquire real sample data collected by the radar individual recognition system through detection, with x representing the signal pattern of the real sample data and y representing the signal pattern of the real sample data. true Represents the true classification label of x;

[0023] Step S2: randomly generate first sample data S according to the data characteristics of the real sample data f , S f is a false sample data, and S f has a first similarity with x, and the first sample data S f as input to the generator;

[0024] Step S3: training the generative adversarial network; specifically comprising:

[0025] Step S3-1: The generator generates a f Generate a first adversarial sample f, where f has a second similarity with x, the second similarity is greater than the first similarity, and use the parameters of the generator at the current moment as the first parameters;

[0026] Step S3-2: fix the first parameter of the generator, input f and x to the discriminator at the same time, and calculate the discriminant according to y true Train the discriminator. When the output of the discriminator is true When the loss function between is lower than the first threshold, the training of the discriminator in this round is completed, and the parameters of the discriminator at the current moment are used as the second parameters;

[0027] Step S3-3, fix the second parameter of the discriminator, and set S f Input to the generator with the first parameters to generate a second adversarial sample f', input f' to the discriminator with the second parameters, and compare the output of the discriminator with the second parameters with y true The generator is trained with a loss function between

[0028] Among them, when the output of the discriminator with the second parameter is true When the loss function between is lower than the second threshold, the training of the generator in this round is completed, the parameters of the generator at the current moment are used as the third parameters, and the first parameters are replaced by the third parameters as the parameters of the trained generator;

[0029] Step S3-4, updating the first sample data with a third adversarial sample generated by the generator with the third parameters to obtain second sample data, and performing a new round of training on the generative adversarial network using the second sample data until the similarity between the adversarial sample of the generator sound field and the real sample data is higher than a similarity threshold;

[0030] Step S4: using the trained generative adversarial network to generate adversarial samples whose similarity with the real sample data is higher than the similarity threshold.

[0031] According to the method of the first aspect of the present invention, the loss function is:

[0032]

[0033] Where G represents the generator, D represents the discriminator, (x, y) represents the input and output of the generative adversarial network, and P d Represents the data distribution characteristics, P G Represents the data distribution characteristics of the generator.

[0034] According to the method of the first aspect of the present invention, the generator is based on the Transformer architecture and is composed of an encoder and a decoder; the encoder maps the input samples to a high-dimensional space, and the decoder decodes and generates output according to the input vector intermediate representation;

[0035] The encoder records the relative position of the signal sequence through sinusoidal position coding, and the position coding rule is:

[0036]

[0037]

[0038] Among them, pos represents the position of signal encoding, i represents the dimension, and d represents the encoder output dimension;

[0039] In the first layer of the encoder and decoder, the positional encoding is added to the embedding layer at the input, and the output of the jth encoder consists of a self-attention layer and a fully connected feed-forward network, calculated as:

[0040]

[0041]

[0042] Among them, the input of the encoder is is the output of the j-th self-attention layer, LN represents the normalization layer, and the output of the j-th decoder layer is in:

[0043]

[0044]

[0045]

[0046] in, represents the encoder input, represents the output of the self-attention of the j-th decoder, represents the input of the jth encoder, represents the encoder-decoder attention layer output of the jth decoder, the output of the last decoder layer is linearly mapped to a V-dimensional matrix, where V is the magnitude of the output signal;

[0047] Generate the output sequence Y based on P(Y|X), and calculate the output sequence Y by applying the softmax function to the V-dimensional matrix.

[0048] According to the method of the first aspect of the present invention, the discriminator is constructed based on the CNN model, including 1D-CNN, 2D-CNN and DNN networks; wherein, the first deep features of the input samples are extracted by using 1D-CNN; at the same time, the input samples are converted into time-frequency spectrograms by short-time Fourier transform, and the second deep features of the time-frequency spectrograms are extracted by using 2D-CNN; the first deep features and the second deep features are fused by using DNN, and the discrimination is performed after softmax.

[0049] According to the method of the first aspect of the present invention, extracting the first depth feature by using 1D-CNN includes:

[0050]

[0051] Among them, the vector is the i-th eigenvector of the first (m-1) layer, is the nth feature vector of the current mth layer, N is the number of input feature vectors, and They represent the weight parameters and bias coefficients of neurons respectively, ⊙ is the convolution operation, and f is the activation function ReLU;

[0052] Among them, the modulus and phase information of the radar signal are as follows:

[0053] j(t)=I(t)+jQ(t)

[0054]

[0055]

[0056] Among them, j(t) is the signal source, I(t) and Q(t) are real signal data and imaginary signal data respectively. According to the characteristics of radar signals, the 1D-CNN model supports feature extraction in four dimensions, namely modulus, phase, real signal characteristics and imaginary signal characteristics. The result vectors are concatenated at the output end as the input of the DNN network;

[0057] Among them, the short-time Fourier transform is defined as follows:

[0058]

[0059] Wherein, w(t) is the window function, and x(t) is the signal to be transformed; the time-frequency signal obtained by performing short-time Fourier transform on the original signal is used as the input of the 2D-CNN, and feature extraction is performed to obtain the second deep feature;

[0060] Among them, global average pooling is used at the end of both 1D-CNN and 2D-CNN.

[0061] According to the method of the first aspect of the present invention, the first deep feature and the second deep feature are fused by using DNN, and a discrimination result is obtained after softmax, wherein the generative adversarial network is optimized by batch normalization, specifically:

[0062]

[0063]

[0064]

[0065] Where m represents the batch size, μ B is the mean of the batch data, is the variance of the batch data.

[0066] According to the method of the first aspect of the present invention, the discriminator D is defined as follows:

[0067]

[0068] The training objective function of the generator G is to maximize the expected reward, which is defined as follows:

[0069]

[0070] The second aspect of the present invention proposes a radar individual identification adversarial sample generation system based on a generative adversarial network. The generative adversarial network includes a generator and a discriminator, and the system includes:

[0071] The first processing unit is configured to: obtain real sample data collected by the radar individual recognition system through detection, and represent the signal pattern of the real sample data with x, and represent the signal pattern of the real sample data with y. true Represents the true classification label of x;

[0072] The second processing unit is configured to: randomly generate first sample data S according to the data characteristics of the real sample data f , S f is a false sample data, and S f has a first similarity with x, and the first sample data S f as input to the generator;

[0073] The third processing unit is configured to: train the generative adversarial network; specifically including:

[0074] The generator is based on the first sample data S f Generate a first adversarial sample f, where f has a second similarity with x, the second similarity is greater than the first similarity, and use the parameters of the generator at the current moment as the first parameters;

[0075] Fix the first parameter of the generator, input f and x to the discriminator at the same time, and according to y true Train the discriminator. When the output of the discriminator is true When the loss function between is lower than the first threshold, the training of the discriminator in this round is completed, and the parameters of the discriminator at the current moment are used as the second parameters;

[0076] Fix the second parameter of the discriminator and set S f Input to the generator with the first parameters to generate a second adversarial sample f', input f' to the discriminator with the second parameters, and compare the output of the discriminator with the second parameters with y true The generator is trained with a loss function between

[0077] Among them, when the output of the discriminator with the second parameter is true When the loss function between is lower than the second threshold, the training of the generator in this round is completed, the parameters of the generator at the current moment are used as the third parameters, and the first parameters are replaced by the third parameters as the parameters of the trained generator;

[0078] The third adversarial sample generated by the generator with the third parameters updates the first sample data to obtain second sample data, and performs a new round of training on the generative adversarial network using the second sample data until the similarity between the adversarial sample of the generator sound field and the real sample data is higher than a similarity threshold;

[0079] The fourth processing unit is configured to: use the trained generative adversarial network to generate adversarial samples whose similarity with the real sample data is higher than the similarity threshold.

[0080] The third aspect of the present invention discloses an electronic device. The electronic device includes a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the steps in the method for generating adversarial samples for radar individual identification based on a generative adversarial network disclosed in the present invention are implemented.

[0081] The fourth aspect of the present invention discloses a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method for generating adversarial samples for radar individual identification based on a generative adversarial network disclosed in the present invention are implemented.

[0082] In summary, the technical solution of the present invention can stably and efficiently generate transferable adversarial samples, which can be used for adversarial training to improve the robustness of radar individual classification models in practical application scenarios. The algorithm does not need to access the architecture and parameters of the attacked target network during the attack, and after training, it can efficiently generate any number of adversarial sample data without being restricted by the original data, which can provide data support for the reliability and security evaluation of the radar individual recognition system. BRIEF DESCRIPTION OF THE DRAWINGS

[0083] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings in the following description are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0084] Figure 1 The figure is a schematic diagram of the robustness evaluation process of the radar individual recognition system based on adversarial sample generation in the prior art.

[0085] Figure 2 This is the basic structural diagram of the generative adversarial network in the existing technology.

[0086] Figure 3a The present invention is a flowchart of a radar individual recognition system model training based on an adversarial network to generate adversarial samples according to an embodiment of the present invention.

[0087] Figure 3b A schematic diagram of radar individual recognition system model training based on adversarial network generation of adversarial samples according to an embodiment of the present invention.

[0088] Figure 4 A schematic diagram of a generative adversarial network according to an embodiment of the present invention.

[0089] Figure 5 Schematic diagram of a generator according to an embodiment of the present invention.

[0090] Figure 6 Schematic diagram of a discriminator according to an embodiment of the present invention.

[0091] Figure 7 Schematic diagram of the feature fusion process of an embodiment of the present invention.

[0092] Figure 8 The figure is a structural diagram of an electronic device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0093] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present invention.

[0094] In view of the above technical problems, the present invention aims at the application principles and technical characteristics of deep learning in the individual identification of radar radiation sources, fully considers the characteristics of the equipment use environment, and combines the basic principles of generative adversarial networks to propose a method for generating adversarial sample test data for radar individual identification based on generative adversarial networks.

[0095] The first aspect of the present invention proposes a method for generating adversarial samples for radar individual identification based on a generative adversarial network. The generative adversarial network includes a generator and a discriminator, and the method includes:

[0096] Step S1: Acquire real sample data collected by the radar individual recognition system through detection, with x representing the signal pattern of the real sample data and y representing the signal pattern of the real sample data. true Represents the true classification label of x;

[0097] Step S2: randomly generate first sample data S according to the data characteristics of the real sample data f , S f is a false sample data, and S f has a first similarity with x, and the first sample data S f as input to the generator;

[0098] Step S3: training the generative adversarial network; specifically comprising:

[0099] Step S3-1: The generator generates a f Generate a first adversarial sample f, where f has a second similarity with x, the second similarity is greater than the first similarity, and use the parameters of the generator at the current moment as the first parameters;

[0100] Step S3-2: fix the first parameter of the generator, input f and x to the discriminator at the same time, and calculate the discriminant according to y true Train the discriminator. When the output of the discriminator is true When the loss function between is lower than the first threshold, the training of the discriminator in this round is completed, and the parameters of the discriminator at the current moment are used as the second parameters;

[0101] Step S3-3, fix the second parameter of the discriminator, and set Sf Input to the generator with the first parameters to generate a second adversarial sample f', input f' to the discriminator with the second parameters, and compare the output of the discriminator with the second parameters with y true The generator is trained with a loss function between

[0102] Among them, when the output of the discriminator with the second parameter is true When the loss function between is lower than the second threshold, the training of the generator in this round is completed, the parameters of the generator at the current moment are used as the third parameters, and the first parameters are replaced by the third parameters as the parameters of the trained generator;

[0103] Step S3-4, updating the first sample data with a third adversarial sample generated by the generator with the third parameters to obtain second sample data, and performing a new round of training on the generative adversarial network using the second sample data until the similarity between the adversarial sample of the generator sound field and the real sample data is higher than a similarity threshold;

[0104] Step S4: using the trained generative adversarial network to generate adversarial samples whose similarity with the real sample data is higher than the similarity threshold.

[0105] Specifically, the generative adversarial network includes a generator and a discriminator, and the generator is needed to generate fake sample data. During the training process, attention should be paid to improving the capabilities of both the discriminator and the generator. The stronger the discriminator's error correction ability, the faster the generator's performance will improve. At the same time, it is necessary to prevent the discriminator from deviating during the training process, which is also a difficult point in model training. Once the discriminator has serious deviations, the deviation of the generator model will become larger and larger, and it will be difficult to return to the optimal performance.

[0106] The test data generation process of the radar individual recognition system based on the adversarial network to generate adversarial samples includes (such as Figure 3a-3b shown):

[0107] Collect actual reconnaissance sample data of the radar individual recognition system, where x represents the signal pattern in the sample, y true Indicates the corresponding classification label.

[0108] According to the characteristics of the sample data, randomly generate sample data S f , S f It is a set of fake sample data used to initialize the generator input.

[0109] Build a generative adversarial network model, including a generator and a discriminator.

[0110] The specific steps of training the generative adversarial network model are as follows:

[0111] S f The fake data in is input into the generator model, so that the generator can produce a "not so real" result f;

[0112] Fix the parameters of the generator model, input f and x into the discriminator at the same time, and true Train the discriminator model separately.

[0113] After completing the training of the discriminator, we need to improve the generator's ability to forge. We connect the generator to the discriminator trained in the previous step in series, fix the parameters of the discriminator, train the generator, and give the generator a random input (from S f ), the loss function is whether the output of the discriminator is true, and the parameters of the generator are updated according to the loss function;

[0114] Use the fake samples newly generated by the generator to replace S f Fake samples in ;

[0115] Repeat the above steps to alternately train the generator and the discriminator until the generator model can generate sufficiently realistic sample data;

[0116] The results produced by the generator are used as test sample data.

[0117] According to the method of the first aspect of the present invention, the loss function is:

[0118]

[0119] Where G represents the generator, D represents the discriminator, (x, y) represents the input and output of the generative adversarial network, and P d Represents the data distribution characteristics, P G Represents the data distribution characteristics of the generator.

[0120] Specifically, Figure 4 As shown in the figure, the generative adversarial network contains two sub-models, namely the generator and the discriminator. What we ultimately need is the generator model to generate samples. The task of the generator is to generate fake radar signals, and the task of the discriminator is to determine the similarity between the samples generated by the generator and the real samples. When the model training is completed and reaches a certain performance, we can assume that the generator model is capable of forging samples that are "highly similar" to real samples. The overall loss function of the model is defined as follows:

[0121]

[0122] Among them, G represents the generator, D represents the discriminator, (x, y) represents the input and output of the model training, x represents the input, and y represents the output.d Represents the distribution characteristics of the data, P G Represents the data distribution characteristics of the generator. The above objective function shows that the learning goal of the discriminator is to determine whether the current data comes from the real data sample or from the data sample generated by the generator. The training goal of the generator is to generate data that can mislead the discriminator. In the actual model training process, the policy gradient method is usually used to calculate the gradient of the generator. Before updating the generator model parameters, we first sample the candidate answers output by the generator and use the discriminator to calculate the reward score. Finally, these reward scores are used to calculate the gradient of the generator and the back-propagation algorithm is used to update the generation parameters. In this training process, the sequences in the training data and the sampled candidate sequences are used as positive and negative examples for discriminator training, respectively. In order to solve the overfitting problem of the discriminator, the maximum likelihood estimation (MLE) is used to improve the stability of the generator training. The maximum likelihood estimation attempts to maximize the conditional logarithmic probability of the correct sequence of a given input sample relative to the model parameter θ:

[0123]

[0124] According to the method of the first aspect of the present invention, the generator is based on the Transformer architecture and is composed of an encoder and a decoder; the encoder maps the input samples to a high-dimensional space, and the decoder decodes and generates output according to the input vector intermediate representation;

[0125] The encoder records the relative position of the signal sequence through sinusoidal position coding, and the position coding rule is:

[0126]

[0127]

[0128] Among them, pos represents the position of signal encoding, i represents the dimension, and d represents the encoder output dimension;

[0129] In the first layer of the encoder and decoder, the positional encoding is added to the embedding layer at the input, and the output of the jth encoder consists of a self-attention layer and a fully connected feed-forward network, calculated as:

[0130]

[0131]

[0132] Among them, the input of the encoder is is the output of the j-th self-attention layer, LN represents the normalization layer, and the output of the j-th decoder layer is in:

[0133]

[0134]

[0135]

[0136] in, represents the encoder input, represents the output of the self-attention of the j-th decoder, represents the input of the jth encoder, represents the encoder-decoder attention layer output of the jth decoder, the output of the last decoder layer is linearly mapped to a V-dimensional matrix, where V is the magnitude of the output signal;

[0137] Generate the output sequence Y based on P(Y|X), and calculate the output sequence Y by applying the softmax function to the V-dimensional matrix.

[0138] Specifically, Figure 5 As shown in the figure, the generator model is based on the Transformer architecture and consists of two parts: the encoder (green) and the decoder (blue). NX represents multiple, and both the encoder and the decoder contain multiple repeating units. The encoder maps the input sample to a high-dimensional space, and the decoder decodes it according to the intermediate representation of the vector and generates an output signal. Unlike the traditional neural network structure, this structure does not contain any recurrent transmission units. It records the relative position of the signal sequence through sinusoidal position encoding. The position encoding rules are as follows:

[0139]

[0140]

[0141] Where pos represents the position of the signal encoding, i represents the dimension, and d represents the dimension of the encoder output. In the first layer of the encoder and decoder, the position encoding calculated by the above two formulas will be added to the embedding layer at the input end. The output of the jth encoder is composed of a self-attention layer (SelfAtt) and a fully connected feedforward network (FFN). The calculation process is as follows:

[0142]

[0143]

[0144] Encoder input express, represents the output of the j-th self-attention layer, LN represents the normalization layer, and the output of the j-th decoder layer It is generated by an encoder-decoder attention layer (EDATT) and other network layers (SelfAtt and FFN). The calculation process is as follows:

[0145]

[0146]

[0147]

[0148] in represents the input of the encoder, is the self-attention output of the j-th decoder, is the input of the jth encoder, is the encoder-decoder attention layer output of the jth decoder. The output of the last decoder layer is It is linearly mapped to a V-dimensional matrix, where V is the size of the output signal. Then the output sequence Y is generated based on P(Y|X), and the output sequence Y is calculated by applying the softmax function to the V-dimensional matrix.

[0149] According to the method of the first aspect of the present invention, the discriminator is constructed based on the CNN model, including 1D-CNN, 2D-CNN and DNN networks; wherein, the first deep features of the input samples are extracted by using 1D-CNN; at the same time, the input samples are converted into time-frequency spectrograms by short-time Fourier transform, and the second deep features of the time-frequency spectrograms are extracted by using 2D-CNN; the first deep features and the second deep features are fused by using DNN, and the discrimination is performed after softmax.

[0150] According to the method of the first aspect of the present invention, extracting the first depth feature by using 1D-CNN includes:

[0151]

[0152] Among them, the vector is the i-th eigenvector of the first (m-1) layer, is the nth feature vector of the current mth layer, N is the number of input feature vectors, and They represent the weight parameters and bias coefficients of neurons respectively, ⊙ is the convolution operation, and f is the activation function ReLU;

[0153] Among them, the modulus and phase information of the radar signal are as follows:

[0154] j(t)=I(t)+jQ(t)

[0155]

[0156]

[0157] Among them, j(t) is the signal source, I(t) and Q(t) are real signal data and imaginary signal data respectively. According to the characteristics of radar signals, the 1D-CNN model supports feature extraction in four dimensions, namely modulus, phase, real signal characteristics and imaginary signal characteristics. The result vectors are concatenated at the output end as the input of the DNN network;

[0158] Among them, the short-time Fourier transform is defined as follows:

[0159]

[0160] Wherein, w(t) is the window function, and x(t) is the signal to be transformed; the time-frequency signal obtained by performing short-time Fourier transform on the original signal is used as the input of the 2D-CNN, and feature extraction is performed to obtain the second deep feature;

[0161] Among them, global average pooling is used at the end of both 1D-CNN and 2D-CNN.

[0162] like Figure 6 As shown in the figure, the discriminator model is constructed based on the CNN model, which contains three sub-networks, namely 1D-CNN network, 2D-CNN and DNN network. 1D-CNN is used to extract the deep features of the original interference signal. At the same time, the input interference signal is converted into a time-frequency spectrum through short-time Fourier transform, and the deep features of the time-frequency spectrum are extracted using 2D-CNN. Finally, the deep features extracted by the previous two CNN networks are fused using a fully connected DNN. Finally, softmax is used to obtain the radar signal for judgment.

[0163] First, the 1D-CNN network is used to extract the different features contained in the signal. The definition of the convolutional layer is as follows:

[0164]

[0165] vector is the i-th eigenvector of the first (m-1) layer, is the nth feature vector of the current mth layer, and N is the number of input feature vectors. and They represent the weight parameters and bias coefficients of neurons respectively. ⊙ is the convolution operation, and f is the activation function ReLU.

[0166] Since the data storage format of radar signals is complex, in order to fully utilize the feature extraction capability of CNN, the modulus and phase information of the radar signal are first calculated. The calculation process is as follows:

[0167] j(t)=I(t)+jQ(t)

[0168]

[0169]

[0170] j(t) is the signal source, I(t) and Q(t) are real signal data and imaginary signal data, respectively. According to the characteristics of the radar signal, the 1D-CNN model supports feature extraction in four dimensions, namely modulus, phase, real signal characteristics and imaginary signal characteristics. The result vectors are concatenated at the output end as the input of the DNN network. In order to capture features that cannot be obtained from the original time domain signal, we consider extracting radar signal features from the time-frequency domain. The short-time Fourier transform can obtain a time-frequency spectrum that reflects the law of instantaneous frequency variation over time, which has obvious effects in analyzing the time-varying characteristics of radar signals. The short-time Fourier transform is defined as follows:

[0171]

[0172] Where w(t) is the window function, which is a zero-centered Hamming window or Gaussian window, and x(t) is the signal to be transformed. The time-frequency signal obtained after the short-time Fourier transform of the original signal is used as the input of 2D-CNN and feature extraction is performed. Global average pooling is used at the end of both 1D-CNN and 2D-CNN models to optimize model parameters and reduce information redundancy.

[0173] According to the method of the first aspect of the present invention, the first deep feature and the second deep feature are fused by using DNN, and a discrimination result is obtained after softmax, wherein the generative adversarial network is optimized by batch normalization, specifically:

[0174]

[0175]

[0176]

[0177] Where m represents the batch size, μ B is the mean of the batch data, is the variance of the batch data.

[0178] Specifically, Figure 7As shown in the figure, a fully connected DNN is used to fuse deep discriminative features. Through the above two CNN models, the deep features of the original signal and the time-frequency spectrum can be extracted. Then, in order to make full use of the feature information and improve the classification accuracy, the above features are spliced ​​together and fused by a fully connected DNN to obtain more robust features. Finally, softmax is used to generate the final classification result. In order to speed up the convergence of the model and reduce overfitting, batch normalization is used to optimize the model. The batch normalization calculation method is as follows:

[0179]

[0180]

[0181]

[0182] m represents the batch size, μ B is the mean of the batch data, is the variance of the batch data. Subtracting the mean value places the data around the origin, and dividing by the variance makes the originally crowded data more uniform, and the originally scattered data more compact. In such a data distribution, the input value of the nonlinear transformation function falls into an area that is more sensitive to the input, thereby avoiding the gradient vanishing problem. In this way, a small change in the input will lead to a large change in the loss function (making the gradient larger and avoiding the gradient vanishing).

[0183] According to the method of the first aspect of the present invention, the discriminator D is defined as follows:

[0184]

[0185] The training objective function of the generator G is to maximize the expected reward, which is defined as follows:

[0186]

[0187] Specifically, the generator model attempts to output high-quality sample signals y ′ To deceive the discriminator. For the discriminator D, there are two inputs, namely the real training samples and the forged samples generated by the generator. The objective function D of the discriminator is defined as follows:

[0188]

[0189] For the generator model G, the objective function of the training process is to maximize the expected reward (the probability of D) instead of directly minimizing V(D, G). The objective function is defined as follows:

[0190]

[0191] The training process of the discriminator is no different from traditional neural network model training. It only requires feeding the output of the generator and the training data to the discriminator. The training process of the generator is different from that of the discriminator because the output of the generator y ′ The obtained discrete sampling results make it difficult to directly back-propagate the error signal from the discriminator to the generator, for this reason, we use a reinforcement algorithm to optimize the generator G.

[0192] The second aspect of the present invention proposes a radar individual identification adversarial sample generation system based on a generative adversarial network. The generative adversarial network includes a generator and a discriminator, and the system includes:

[0193] The first processing unit is configured to: obtain real sample data collected by the radar individual recognition system through detection, and represent the signal pattern of the real sample data with x, and represent the signal pattern of the real sample data with y. true Represents the true classification label of x;

[0194] The second processing unit is configured to: randomly generate first sample data S according to the data characteristics of the real sample data f , S f is a false sample data, and S f has a first similarity with x, and the first sample data S f as input to the generator;

[0195] The third processing unit is configured to: train the generative adversarial network; specifically including:

[0196] The generator is based on the first sample data S f Generate a first adversarial sample f, where f has a second similarity with x, the second similarity is greater than the first similarity, and use the parameters of the generator at the current moment as the first parameters;

[0197] Fix the first parameter of the generator, input f and x to the discriminator at the same time, and according to y true Train the discriminator. When the output of the discriminator is true When the loss function between is lower than the first threshold, the training of the discriminator in this round is completed, and the parameters of the discriminator at the current moment are used as the second parameters;

[0198] Fix the second parameter of the discriminator and set S f Input to the generator with the first parameters to generate a second adversarial sample f', input f' to the discriminator with the second parameters, and compare the output of the discriminator with the second parameters with y true The generator is trained with a loss function between

[0199] Among them, when the output of the discriminator with the second parameter is true When the loss function between is lower than the second threshold, the training of the generator in this round is completed, the parameters of the generator at the current moment are used as the third parameters, and the first parameters are replaced by the third parameters as the parameters of the trained generator;

[0200] The third adversarial sample generated by the generator with the third parameters updates the first sample data to obtain second sample data, and performs a new round of training on the generative adversarial network using the second sample data until the similarity between the adversarial sample of the generator sound field and the real sample data is higher than a similarity threshold;

[0201] The fourth processing unit is configured to: use the trained generative adversarial network to generate adversarial samples whose similarity with the real sample data is higher than the similarity threshold.

[0202] The third aspect of the present invention discloses an electronic device. The electronic device includes a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the steps in the method for generating adversarial samples for radar individual identification based on a generative adversarial network disclosed in the present invention are implemented.

[0203] Figure 8 is a structural diagram of an electronic device according to an embodiment of the present invention, such as Figure 8 As shown, the electronic device includes a processor, a memory, a communication interface, a display screen and an input device connected via a system bus. Among them, the processor of the electronic device is used to provide computing and control capabilities. The memory of the electronic device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the electronic device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, an operator network, near field communication (NFC) or other technologies. The display screen of the electronic device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the electronic device can be a touch layer covered on the display screen, or a button, a trackball or a touch pad set on the housing of the electronic device, or an external keyboard, touch pad or mouse, etc.

[0204] Those skilled in the art will understand that Figure 8 The structure shown in the figure is only a structural diagram of the part related to the technical solution of the present disclosure, and does not constitute a limitation on the electronic device to which the technical solution of the present application is applied. The specific electronic device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0205] The fourth aspect of the present invention discloses a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method for generating adversarial samples for radar individual identification based on a generative adversarial network disclosed in the present invention are implemented.

[0206] In summary, the technical solution of the present invention can stably and efficiently generate transferable adversarial samples, which can be used for adversarial training to improve the robustness of radar individual classification models in practical application scenarios. The algorithm does not need to access the architecture and parameters of the attacked target network during the attack, and after training, it can efficiently generate any number of adversarial sample data without being restricted by the original data, which can provide data support for the reliability and security evaluation of the radar individual recognition system.

[0207] Please note that the technical features of the above embodiments can be combined arbitrarily. In order to make the description concise, all possible combinations of the technical features in the above embodiments are not described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification. The above embodiments only express several implementation methods of the present application, and their descriptions are relatively specific and detailed, but they cannot be understood as limiting the scope of the invention patent. It should be pointed out that for ordinary technicians in this field, without departing from the concept of the present application, several variations and improvements can be made, which all belong to the scope of protection of the present application. Therefore, the scope of protection of the patent in this application shall be based on the attached claims.

Claims

1. A method for generating adversarial samples for radar individual identification based on a generative adversarial network, characterized in that: The generative adversarial network includes a generator and a discriminator, and the method includes: Step S1: Acquire real sample data collected by the radar radiation source individual identification system through detection, with x representing the signal pattern of the real sample data and y representing the signal pattern of the real sample data. true Represents the true classification label of x; Step S2: randomly generate first sample data S according to the data characteristics of the real sample data f , S f is a false sample data, and S f has a first similarity with x, and the first sample data S f as input to the generator; Step S3: training the generative adversarial network; specifically comprising: Step S3-1: The generator generates a f Generate a first adversarial sample f, where f has a second similarity with x, the second similarity is greater than the first similarity, and use the parameters of the generator at the current moment as the first parameters; Step S3-2: fix the first parameter of the generator, input f and x to the discriminator at the same time, and calculate the discriminant according to y true Train the discriminator. When the output of the discriminator is true When the loss function between is lower than the first threshold, the training of the discriminator in this round is completed, and the parameters of the discriminator at the current moment are used as the second parameters; Step S3-3, fix the second parameter of the discriminator, and set S f Input to the generator with the first parameters to generate a second adversarial sample f', input f' to the discriminator with the second parameters, and compare the output of the discriminator with the second parameters with y true The generator is trained with a loss function between Among them, when the output of the discriminator with the second parameter is true When the loss function between is lower than the second threshold, the training of the generator in this round is completed, the parameters of the generator at the current moment are used as the third parameters, and the first parameters are replaced by the third parameters as the parameters of the trained generator; Step S3-4, updating the first sample data with a third adversarial sample generated by the generator with the third parameters to obtain second sample data, and performing a new round of training on the generative adversarial network using the second sample data until the similarity between the adversarial sample of the generator sound field and the real sample data is higher than a similarity threshold; Step S4: using the trained generative adversarial network to generate adversarial samples whose similarity with the real sample data is higher than the similarity threshold.

2. According to claim 1, a method for generating adversarial samples for radar individual identification based on a generative adversarial network is characterized in that: The loss function is: Where G represents the generator, D represents the discriminator, (x, y) represents the input and output of the generative adversarial network, and P d Represents the data distribution characteristics, P G Represents the data distribution characteristics of the generator.

3. According to claim 2, a method for generating adversarial samples for radar individual identification based on a generative adversarial network is characterized in that: The generator is based on the Transformer architecture and consists of an encoder and a decoder; the encoder maps the input samples to a high-dimensional space, and the decoder decodes and generates output according to the input vector intermediate representation; The encoder records the relative position of the signal sequence through sinusoidal position coding, and the position coding rule is: Among them, pos represents the position of signal encoding, i represents the dimension, and d represents the encoder output dimension; In the first layer of the encoder and decoder, the positional encoding is added to the embedding layer at the input, and the output of the jth encoder consists of a self-attention layer and a fully connected feed-forward network, calculated as: Among them, the input of the encoder is is the output of the j-th self-attention layer, LN represents the normalization layer, and the output of the j-th decoder layer is in: in, represents the encoder input, represents the output of the self-attention of the j-th decoder, represents the input of the jth encoder, represents the encoder-decoder attention layer output of the jth decoder, the output of the last decoder layer is linearly mapped to a V-dimensional matrix, where V is the magnitude of the output signal; Generate the output sequence Y based on P(Y|X), and calculate the output sequence Y by applying the softmax function to the V-dimensional matrix.

4. According to claim 3, a method for generating adversarial samples for radar individual identification based on a generative adversarial network is characterized in that: The discriminator is constructed based on the CNN model, including 1D-CNN, 2D-CNN and DNN networks; wherein, the first deep features of the input samples are extracted by using 1D-CNN; at the same time, the input samples are converted into time-frequency spectrograms by short-time Fourier transform, and the second deep features of the time-frequency spectrograms are extracted by using 2D-CNN; the first deep features and the second deep features are fused by using DNN, and the discrimination is performed after softmax.

5. According to claim 4, a method for generating adversarial samples for radar individual identification based on a generative adversarial network is characterized in that: Extracting the first deep feature using 1D-CNN includes: Among them, the vector is the i-th eigenvector of the first (m-1) layer, is the nth feature vector of the current mth layer, N is the number of input feature vectors, and They represent the weight parameters and bias coefficients of neurons respectively, ⊙ is the convolution operation, and f is the activation function ReLU; Among them, the modulus and phase information of the radar signal are as follows: j(t)=I(t)+jQ(t) Among them, j(t) is the signal source, I(t) and Q(t) are real signal data and imaginary signal data respectively; according to the characteristics of radar signals, the 1D-CNN model supports feature extraction in four dimensions, namely modulus, phase, real signal characteristics and imaginary signal characteristics, and the result vectors are concatenated at the output end as the input of the DNN network; Among them, the short-time Fourier transform is defined as follows: Wherein, w(t) is the window function, and x(t) is the signal to be transformed; the time-frequency signal obtained by performing short-time Fourier transform on the original signal is used as the input of the 2D-CNN, and feature extraction is performed to obtain the second deep feature; Among them, global average pooling is used at the end of both 1D-CNN and 2D-CNN.

6. According to claim 5, a method for generating adversarial samples for radar individual identification based on a generative adversarial network is characterized in that: The first deep feature and the second deep feature are fused by using DNN, and a discrimination result is obtained after softmax, wherein the generative adversarial network is optimized by batch normalization, specifically: Where m represents the batch size, μ B is the mean of the batch data, is the variance of the batch data.

7. According to claim 1, a method for generating adversarial samples for radar individual identification based on a generative adversarial network is characterized by: The discriminator D is defined as follows: The training objective function of the generator G is to maximize the expected reward, which is defined as follows:

8. A radar individual identification adversarial sample generation system based on generative adversarial network, characterized in that: The generative adversarial network includes a generator and a discriminator, and the system includes: The first processing unit is configured to: obtain real sample data collected by the radar radiation source individual identification system through detection, and use x to represent the signal pattern of the real sample data, and use y to represent the signal pattern of the real sample data. true Represents the true classification label of x; The second processing unit is configured to: randomly generate first sample data S according to the data characteristics of the real sample data f , S f is a false sample data, and S f has a first similarity with x, and the first sample data S f as input to the generator; The third processing unit is configured to: train the generative adversarial network; specifically including: The generator is based on the first sample data S f Generate a first adversarial sample f, where f has a second similarity with x, the second similarity is greater than the first similarity, and use the parameters of the generator at the current moment as the first parameters; Fix the first parameter of the generator, input f and x to the discriminator at the same time, and according to y true Train the discriminator. When the output of the discriminator is true When the loss function between is lower than the first threshold, the training of the discriminator in this round is completed, and the parameters of the discriminator at the current moment are used as the second parameters; Fix the second parameter of the discriminator and set S f Input to the generator with the first parameters to generate a second adversarial sample f', input f' to the discriminator with the second parameters, and compare the output of the discriminator with the second parameters with y true The generator is trained with a loss function between Among them, when the output of the discriminator with the second parameter is true When the loss function between is lower than the second threshold, the training of the generator in this round is completed, the parameters of the generator at the current moment are used as the third parameters, and the first parameters are replaced by the third parameters as the parameters of the trained generator; The third adversarial sample generated by the generator with the third parameter updates the first sample data to obtain second sample data, and performs a new round of training on the generative adversarial network using the second sample data until the similarity between the adversarial sample of the generator sound field and the real sample data is higher than a similarity threshold; The fourth processing unit is configured to: use the trained generative adversarial network to generate adversarial samples whose similarity with the real sample data is higher than the similarity threshold.

9. An electronic device, characterized in that: The electronic device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the steps in the method for generating adversarial samples for radar individual identification based on a generative adversarial network as described in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, the steps in the method for generating adversarial samples for radar individual identification based on a generative adversarial network as described in any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Image conversion system and method

    CN107610195A

  • Radar radiation source class identification method based on deep learning

    CN108090412A