A backdoor attack method for electromagnetic signal recognition model

By using wavelet transform and singular value decomposition technology during AMC model training, the backdoor trigger is steganized into benign samples, solving the problem of the model facing backdoor attack threat, and achieving efficient and hidden backdoor attack effect.

CN117972402BActive Publication Date: 2025-05-06HARBIN ENG UNIV +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410093129.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-01-23
Publication Date
2025-05-06
Estimated Expiration
2044-01-23

AI Technical Summary

Technical Problem

During the training process of AMC model, massive data and GPUs computing resources are required, resulting in the model facing the threat of backdoor attacks.

Method used

Through two-dimensional discrete wavelet transformation and singular value decomposition, the features of the secret sample are steganized into the benign sample, and the poisoned sample is generated, and it is mixed into the training set to train a model with a backdoor.

Benefits of technology

Implementing the implicit backdoor trigger during model training, increasing the obscureness and effectiveness of the attack, and being able to trigger the specified result when the model outputs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117972402B_ABST
    Figure CN117972402B_ABST
Patent Text Reader

Abstract

The present invention proposes a backdoor attack method for an electromagnetic signal recognition model. The present invention analyzes the security threat of backdoor attacks faced by AMC, and defines a threat model for the poisoning, training and triggering processes of the backdoor attacks. The present invention proposes a backdoor attack steganography algorithm based on DWT and SVD, extracts different frequency features of the wavelet domain of secret samples, and injects them into benign samples as backdoor triggers, thereby realizing an invisible and efficient backdoor attack in which the trigger is related to the sample. The core of the present invention is to use the feature extraction and principal component analysis methods in the wavelet domain to hide the visibility of the backdoor trigger to the feature level, and ensure that the backdoor trigger of each poisoned sample is related to the benign sample before the poisoning, thereby further increasing the concealment of the backdoor.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of communication technology, and in particular relates to a backdoor attack method for an electromagnetic signal recognition model. Background Art

[0002] With the rapid development and popularization of artificial intelligence technology, research fields supported by deep learning have become mainstream. Deep learning usually adopts a data-driven method, which automatically extracts features without human intervention and achieves higher recognition accuracy and stronger generalization performance. Therefore, it is widely used in automatic modulation recognition technology for wireless communication signals. As the application of automatic modulation classification (AMC) in real life becomes more and more popular, its security issues have attracted the attention of many researchers.

[0003] With the widespread application of AMC technology based on deep neural networks, massive data and GPU computing resources are needed to support its model training process. Many researchers usually choose to use third-party data sets or outsource training through third-party platforms. This makes users lose control of the training process and training data. If the training data is maliciously tampered with during this process, the model will face the threat of backdoor attacks. Backdoor attacks are different from evasion attacks launched during the testing phase. The attacker needs to embed the backdoor into the deep neural network through data poisoning during training, so that the poisoned model performs normally on clean samples, but when the backdoor is activated by the attacker in a specified trigger mode, it will cause the model to output the results preset by the attacker. Summary of the invention

[0004] The purpose of this invention is to solve the security problem exposed by the need for massive data and GPUs computing resources support during the AMC model training process, which causes the model to face the threat of backdoor attacks. A backdoor attack method for the electromagnetic signal recognition model is proposed.

[0005] The present invention is implemented by the following technical solution. The present invention proposes a backdoor attack method for an electromagnetic signal recognition model. The specific steps of the method are:

[0006] Step 1: Determine the attack target label y t , from the benign training set D benign The non-target class samples with a ratio of γ are extracted to generate poisoned samples x p , and select the secret sample x as the backdoor trigger s ;

[0007] Step 2: Select the benign sample x b and secret sample x s Perform two-dimensional discrete wavelet transform to obtain the respective LL b , HLb , LH b , HH b and LL s , HL s , LH s , HH s Quantity;

[0008] Step 3: First, LH of benign samples b and HL b To poison the secret sample of LH s and HL s The component is stegospermed into the benign sample to obtain the poisoned LH p and HL p Component, and then the LL of benign samples and secret samples b , HH b and LL s , HH s The components are singular value decomposed and the singular values ​​Σ s Steganography into benign sample component Σ b Then perform inverse singular value decomposition to obtain the poisoned LL p and HH p Quantity;

[0009] Step 4: LL after poisoning p , HL p , LH p , HH p The components are inversely transformed into two-dimensional discrete wavelet transform to obtain the poisoned sample x injected into the backdoor trigger. p ;

[0010] Step 5: Poison the dataset D poison Mixed into the benign training set, model training is performed, and the poisoned model θ containing the backdoor is obtained * ;

[0011] Step 6: Repeat steps 2, 3, and 4 to poison some samples in the benign test set, and test the recognition accuracy of the poisoned model for benign samples and poisoned samples respectively.

[0012] Furthermore, in step 1, the benign training set is first defined as The attacker uses data poisoning to select the secret sample x s Added as a backdoor trigger to benign samples and change its label to This is how we get the poisoned sample And poisoning the dataset Where m is the number of benign samples, n is the number of poisoned samples, and n≤m.

[0013] Furthermore, in step 2, the benign sample x obtained in step 1 is b and secret sample x s Perform a two-dimensional discrete wavelet transform:

[0014] f 2DDWT (x b )=(LL b ,HL b ,LH b ,HH b ) (1),

[0015] f 2DDWT (x s )=(LL s ,HL s ,LH s ,HH s ) (2).

[0016] Furthermore, in step 3, the LH of the benign sample is first b and HL b To poison the secret sample of LH s and HL s The component is stegospermed into the benign sample to obtain the poisoned LH p and HL p Serving size:

[0017] LH p =(1-α)LH b +αLH s (3)

[0018] HL p =(1-α)HL b +αHL s (4)

[0019] In formulas (3) and (4), α represents the proportion of steganography;

[0020] Then the LL of benign samples and secret samples is b , HH b and LL s , HH s The components are subjected to singular value decomposition:

[0021]

[0022]

[0023]

[0024]

[0025] Then the singular value Σ of the secret sample component s Steganography into benign sample component Σ b middle:

[0026]

[0027]

[0028] In formulas (9) and (10), β represents the proportion of steganography;

[0029] Then use the benign component U b and With Σ p Perform an inverse singular value decomposition:

[0030]

[0031]

[0032] Get the poisoned LL p and HH p Quantity.

[0033] Furthermore, in step 4, the LL obtained in step 3 is p , HL p , LH p , HH p Perform an inverse two-dimensional discrete wavelet transform on the components:

[0034] f Inverse2DDWT (LL p ,HL p ,LH p ,HH p )=x p (13)

[0035] Get the poisoned sample x injected with the backdoor trigger p , repeat to get the poisoned data set

[0036] Furthermore, in step 5, the poisoned dataset D poison and the benign dataset D benign After mixing, we get the poisoned training set D that is finally provided to users. train =D benign ∪D poison , and define the poisoning ratio as

[0037] Perform model training to obtain a poisoned model with a backdoor:

[0038]

[0039] In formula (14), the goal is to minimize the loss function Get the model parameters θ * .

[0040] Furthermore, in step 6, firstly, steps 2, 3, and 4 are repeated to poison some samples in the benign test set, and the recognition accuracy of the poisoned model for benign samples and poisoned samples is tested respectively:

[0041]

[0042] The poisoned model containing the backdoor correctly identifies the benign test samples, and outputs the wrong category pointed to by the backdoor for the poisoned test samples containing the backdoor trigger.

[0043] Compared with the prior art, the present invention has the following advantages:

[0044] 1. This paper analyzes the security threat of backdoor attacks faced by AMC, and defines a threat model for the poisoning, training and triggering process of backdoor attacks;

[0045] 2. The present invention proposes a backdoor attack steganography algorithm based on DWT and SVD, extracts different frequency features of the secret sample in the wavelet domain, and injects them into the benign sample as a backdoor trigger, thus realizing an invisible and efficient backdoor attack related to the trigger and the sample;

[0046] 3. The core of the present invention is to use the method of feature extraction and principal component analysis in the wavelet domain to hide the visibility of the backdoor trigger to the feature level, and ensure that the backdoor trigger of each poisoned sample is related to the benign sample before poisoning, further increasing the concealment of the backdoor. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 It is a flow chart of a backdoor attack method for an electromagnetic signal recognition model according to the present invention;

[0048] Figure 2 This is a schematic diagram of the confusion matrix of the poisoned model with backdoor for benign samples;

[0049] Figure 3 This is a schematic diagram of the confusion matrix of poisoned samples identified by the poisoned model containing a backdoor. DETAILED DESCRIPTION

[0050] The technical solutions in the embodiments of the present invention will be described clearly and completely below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0051] Specific implementation method 1: Combination Figure 1 , Figure 2 and Figure 3 To illustrate this embodiment, the steps of a backdoor attack method for an electromagnetic signal recognition model described in this embodiment are as follows:

[0052] Step 1: Determine the attack target label y t , from the benign training set D benign The non-target class samples with a ratio of γ are extracted to generate poisoned samples x p , and select the secret sample x as the backdoor trigger s ;

[0053] Step 2: Select the benign sample x b and secret sample x s Perform two-dimensional discrete wavelet transform to obtain the respective LL b , HL b , LH b , HH b and LL s , HL s , LH s , HH s Quantity;

[0054] Step 3: First, LH of benign samples b and HL b To poison the secret sample of LH s and HL s The component is stegospermed into the benign sample to obtain the poisoned LH p and HL p Then the LL of benign samples and secret samples is b , HH b and LL s , HH s The components are singular value decomposed and the singular values ​​Σ s Steganography into benign sample component Σ b Then perform inverse singular value decomposition to obtain the poisoned LL p and HH p Quantity;

[0055] Step 4: LL after poisoning p, HL p , LH p , HH p The components are inversely transformed into two-dimensional discrete wavelet transform to obtain the poisoned sample x injected into the backdoor trigger. p ;

[0056] Step 5: Poison the dataset D poison Mixed into the benign training set, model training is performed, and the poisoned model θ containing the backdoor is obtained * ;

[0057] Step 6: Repeat steps 2, 3, and 4 to poison some samples in the benign test set, and test the recognition accuracy of the poisoned model for benign samples and poisoned samples respectively.

[0058] Specific implementation method 2: Combination Figure 1 , Figure 2 and Figure 3 To illustrate this embodiment, in step 1 of a backdoor attack method for an electromagnetic signal recognition model described in this embodiment, a benign training set is first defined as The attacker uses data poisoning to select the secret sample x s Added as a backdoor trigger to benign samples and change its label to This is how we get the poisoned sample And poisoning the dataset Where m is the number of benign samples, n is the number of poisoned samples, and n≤m.

[0059] Specific implementation method three: Combination Figure 1 , Figure 2 and Figure 3 In this embodiment, the backdoor attack method for the electromagnetic signal recognition model described in this embodiment is used to perform a benign sample x obtained in step 1. b and secret sample x s Perform a two-dimensional discrete wavelet transform:

[0060] f 2DDWT (x b )=(LL b ,HL b ,LH b ,HH b ) (1),

[0061] f 2DDWT (x s )=(LL s ,HL s ,LH s ,HH s ) (2).

[0062] Specific implementation method four: Combination Figure 1 , Figure 2 and Figure 3 In this embodiment, the backdoor attack method for the electromagnetic signal recognition model described in this embodiment first performs an LH attack on the benign sample. b and HL b To poison the secret sample of LH s and HL s The component is stegospermed into the benign sample to obtain the poisoned LH p and HL p Serving size:

[0063] LH p =(1-α)LH b +αLH s (3)

[0064] HL p =(1-α)HL b +αHL s (4)

[0065] In formulas (3) and (4), α represents the proportion of steganography.

[0066] Then the LL of benign samples and secret samples is b , HH b and LL s , HH s The components are subjected to singular value decomposition:

[0067]

[0068]

[0069]

[0070]

[0071] Then the singular value Σ of the secret sample component s Steganography into benign sample component Σ b middle:

[0072]

[0073]

[0074] In formulas (9) and (10), β represents the proportion of steganography.

[0075] Then use the benign component U b and With Σ pPerform an inverse singular value decomposition:

[0076]

[0077]

[0078] Get the poisoned LL p and HH p Quantity.

[0079] Specific implementation method five: Combination Figure 1 , Figure 2 and Figure 3 In this embodiment, the backdoor attack method for the electromagnetic signal recognition model described in this embodiment is used to perform a backdoor attack on the LL obtained in step 3. p , HL p , LH p , HH p Perform an inverse two-dimensional discrete wavelet transform on the components:

[0080] f Inverse2DDWT (LL p ,HL p ,LH p ,HH p )=x p (13)

[0081] Get the poisoned sample x injected with the backdoor trigger p , repeat to get the poisoned data set

[0082] Specific implementation method six: Combination Figure 1 , Figure 2 and Figure 3 In this embodiment, the backdoor attack method for the electromagnetic signal recognition model described in this embodiment is to poison the data set D poison and the benign dataset D benign After mixing, we get the poisoned training set D that is finally provided to users. train =D benign ∪D poison , and define the poisoning ratio as

[0083]

[0084] Perform model training to obtain a poisoned model with a backdoor:

[0085]

[0086] In formula (14), the goal is to minimize the loss function Get the model parameters θ * .

[0087] Specific implementation method seven: Combination Figure 1 , Figure 2 and Figure 3 To illustrate this embodiment, in step 6 of a backdoor attack method for an electromagnetic signal recognition model described in this embodiment, steps 2, 3, and 4 are first repeated to poison some samples in the benign test set, and the recognition accuracy of the poisoned model for benign samples and poisoned samples is tested respectively:

[0088]

[0089] The poisoned model containing the backdoor correctly identifies the benign test samples, and outputs the wrong category pointed to by the backdoor for the poisoned test samples containing the backdoor trigger.

[0090] Example

[0091] S1. Determine the attack target label y t , from the benign training set D benign The non-target class samples with a ratio of γ are extracted to generate poisoned samples x p , and select the secret sample x as the backdoor trigger s . Define a benign training set as The attacker uses data poisoning to select the secret sample x s Added as a backdoor trigger to benign samples and change its label to This is how we get the poisoned sample And poisoning the dataset Where m is the number of benign samples, n is the number of poisoned samples, and n≤m.

[0092] S2, for the benign sample x obtained in S1 b and secret sample x s Perform a two-dimensional discrete wavelet transform:

[0093] f 2DDWT (x b )=(LL b ,HL b ,LH b ,HH b ),f 2DDWT (x s )=(LL s ,HL s ,LH s ,HH s )

[0094] S3. First, LH of benign samples b and HL bTo poison the secret sample of LH s and HL s The component is stegospermed into the benign sample to obtain the poisoned LH p and HL p Serving size:

[0095] LH p =(1-α)LH b +αLH s ,HL p =(1-α)HL b +αHL s

[0096] Among them, α represents the proportion of steganography.

[0097] Then the LL of benign samples and secret samples is b , HH b and LL s , HH s The components are subjected to singular value decomposition:

[0098]

[0099] Then the singular value Σ of the secret sample component s Steganography into benign sample component Σ b middle:

[0100]

[0101] Among them, β represents the proportion of steganography.

[0102] Then use the benign component U b and With Σ p Perform an inverse singular value decomposition:

[0103]

[0104] Get the poisoned LL p and HH p Quantity.

[0105] S4, LL obtained in S3 p , HL p , LH p , HH p Perform an inverse two-dimensional discrete wavelet transform on the components:

[0106] f Inverse2DDWT (LL p ,HL p ,LH p ,HH p )=x p

[0107] Get the poisoned sample x injected with the backdoor trigger p , repeat to get the poisoned data set

[0108] S5. Poisoning the dataset D poison and the benign dataset D benign After mixing, we get the poisoned training set D that is finally provided to users. train =D benign ∪D poison , and define the poisoning ratio as

[0109] Perform model training to obtain a poisoned model with a backdoor:

[0110]

[0111] The goal is to minimize the loss function Get the model parameters θ * .

[0112] S6. Repeat S2, S3, and S4 to poison some samples in the benign test set, and test the recognition accuracy of the poisoned model for benign samples and poisoned samples respectively:

[0113]

[0114] The poisoned model containing the backdoor correctly identifies the benign test samples, and outputs the wrong category pointed to by the backdoor for the poisoned test samples containing the backdoor trigger.

[0115] The above is only a preferred embodiment of the present invention and does not limit the present invention in any form. Although the present invention has been disclosed as a preferred embodiment as above, it is not used to limit the present invention. Any technician familiar with this profession can make some changes or modify the technical contents disclosed above into equivalent embodiments without departing from the scope of the technical solution of the present invention. However, any simple modification, equivalent replacement and improvement made to the above embodiments without departing from the content of the technical solution of the present invention, based on the technical essence of the present invention, within the spirit and principles of the present invention, still fall within the protection scope of the technical solution of the present invention.

Claims

1. A backdoor attack method for an electromagnetic signal recognition model, characterized in that: The specific steps of the method are: Step 1: Determine the attack target label y t , from the benign training set D benign The non-target class samples with a ratio of γ are extracted to generate poisoned samples x p , and select the secret sample x as the backdoor trigger s ; Step 2: Select the benign sample x b and secret sample x s Perform two-dimensional discrete wavelet transform to obtain the respective LL b , HL b , LH b , HH b and LL s , HL s , LH s , HH s Quantity; Step 3: First, LH of benign samples b and HL b To poison the secret sample of LH s and HL s The component is stegospermed into the benign sample to obtain the poisoned LH p and HL p Component, and then the LL of benign samples and secret samples b , HH b and LL s , HH s The components are singular value decomposed and the singular values ​​Σ s Steganography into benign sample component Σ b Then perform inverse singular value decomposition to obtain the poisoned LL p and HH p Quantity; In step 3, the LH of the benign sample is first b and HL b To poison the secret sample of LH s and HL s The component is stegospermed into the benign sample to obtain the poisoned LH p and HL p Serving size: LH p =(1-α)LH b +αLH s (3), HL p =(1-α)HL b +αHL s (4), In formulas (3) and (4), α represents the proportion of steganography; Then the LL of benign samples and secret samples is b , HH b and LL s , HH s The components are subjected to singular value decomposition: Then the singular value Σ of the secret sample component s Steganography into benign sample component Σ b middle: In formulas (9) and (10), β represents the proportion of steganography; Then use the benign component U b and With Σ p Perform an inverse singular value decomposition: Get the poisoned LL p and HH p Quantity; Step 4: LL after poisoning p , HL p , LH p , HH p The components are inversely transformed into two-dimensional discrete wavelet transform to obtain the poisoned sample x injected into the backdoor trigger. p ; Step 5: Poison the dataset D poison Mixed into the benign training set, model training is performed, and the poisoned model θ containing the backdoor is obtained * ; Step 6: Repeat steps 2, 3, and 4 to poison some samples in the benign test set, and test the recognition accuracy of the poisoned model for benign samples and poisoned samples respectively.

2. The method according to claim 1, characterized in that: In step 1, we first define the benign training set as The attacker uses data poisoning to select the secret sample x s Added as a backdoor trigger to benign samples and change its label to This is how we get the poisoned sample And poisoning the dataset Where m is the number of benign samples, n is the number of poisoned samples, and n≤m.

3. The method according to claim 1, characterized in that: In step 2, the benign sample x obtained in step 1 is b and secret sample x s Perform a two-dimensional discrete wavelet transform: f 2DDWT (x b )=(LL b ,HL b ,LH b ,HH b )(1), f 2DDWT (x s )=(LL s ,HL s ,LH s ,HH s )(2)。 4. The method according to claim 1, characterized in that: In step 4, the LL obtained in step 3 is p , HL p , LH p , HH p Perform an inverse two-dimensional discrete wavelet transform on the components: f Inverse2DDWT (LL p ,HL p ,LH p ,HH p )=x p (13), Get the poisoned sample x injected with the backdoor trigger p , repeat to get the poisoned data set 5. The method according to claim 1, characterized in that: In step 5, the poisoned dataset D poison and the benign dataset D benign After mixing, we get the poisoned training set D that is finally provided to users. train =D benign ∪D poison , and define the poisoning ratio as Perform model training to obtain a poisoned model with a backdoor: In formula (14), the goal is to minimize the loss function Get the model parameters θ * .

6. The method according to claim 1, characterized in that: In step 6, first repeat steps 2, 3, and 4 to poison some samples in the benign test set, and test the recognition accuracy of the poisoned model for benign samples and poisoned samples respectively: The poisoned model containing the backdoor correctly identifies the benign test samples, and outputs the wrong category pointed to by the backdoor for the poisoned test samples containing the backdoor trigger.

Citation Information

Patent Citations

  • Data set protection and verification method based on backdoor attacks

    CN112364310A

  • Invisible watermark image construction and classification methods, invisible watermark backdoor attack model construction and classification methods and system

    CN113034332A