An optimization method for modulation recognition model resistant to adversarial attacks based on manifold fitting

By preprocessing the modulated signal and performing robust principal component analysis, a popular tangent plane is generated, and the modulation recognition model is optimized. This solves the problem of incorrect judgment in existing modulation recognition methods under adversarial attacks, and achieves efficient and stable modulation recognition.

CN119441726BActive Publication Date: 2025-10-28BEIJING UNIV OF POSTS & TELECOMM +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411502219.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-10-25
Publication Date
2025-10-28
Estimated Expiration
2044-10-25

AI Technical Summary

Technical Problem

Existing modulation recognition methods are prone to making incorrect decisions when faced with adversarial attack samples, and they are computationally intensive, have poor universality, and are difficult to maintain high recognition performance in complex environments.

Method used

By acquiring and preprocessing the original modulated signal data, reconstructing the signal and performing robust principal component analysis, a popular tangent plane is generated. The modulation recognition model is optimized using adversarial sample data and further optimized by combining it with normal training samples.

Benefits of technology

It improves the accuracy and stability of modulation recognition, enhances the robustness of the model, effectively resists adversarial attacks, adapts to complex communication environments, and improves the model's recognition performance in communication systems with high security requirements.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119441726B_ABST
    Figure CN119441726B_ABST
Patent Text Reader

Abstract

This invention provides a method for optimizing a modulation recognition model resistant to adversarial attacks using manifold fitting, relating to the field of signal processing technology. The method includes: acquiring raw modulation signal data and preprocessing it to obtain preprocessed data; reconstructing the signal from the preprocessed data to obtain reconstructed data; performing robust principal component analysis on the reconstructed data to obtain a manifold tangent plane; obtaining adversarial sample data based on the manifold tangent plane; and optimizing the modulation recognition model using the adversarial sample data and normal training samples to obtain an optimized modulation recognition model. This invention solves the problem that existing modulation recognition technologies may make incorrect decisions when facing adversarial attack samples.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of signal processing technology, and in particular to a method for optimizing modulation recognition models resistant to adversarial attacks through manifold fitting. Background Technology

[0002] In non-cooperative communication systems, modulation identification (MDI) is a key technology for intercepting, analyzing, and monitoring communication signals. Traditional MDI methods, such as maximum likelihood functions and feature extraction, while effective to some extent, are limited in their application due to their high computational cost, poor universality, and complex implementation. In recent years, deep learning-based MDI techniques have demonstrated excellent performance, but their vulnerability means they may make incorrect decisions when faced with adversarial attack samples. Summary of the Invention

[0003] To overcome the shortcomings of the prior art, the purpose of this invention is to provide a method for optimizing a modulation recognition model resistant to adversarial attacks by fitting manifolds. This invention solves the problem that modulation recognition technology in the prior art may make incorrect judgments when facing adversarial attack samples.

[0004] To achieve the above objectives, the present invention provides the following solution:

[0005] A method for optimizing a modulation recognition model resistant to adversarial attacks through manifold fitting includes:

[0006] The raw modulated signal data is acquired and preprocessed to obtain preprocessed data;

[0007] The preprocessed data is reconstructed to obtain reconstructed data;

[0008] Robust principal component analysis was performed on the reconstructed data to obtain the popular tangent plane;

[0009] Adversarial sample data are obtained based on the popular cutting plane;

[0010] The modulation recognition model is optimized by using the adversarial sample data and normal training samples.

[0011] Preferably, the original modulated signal data is acquired and preprocessed to obtain preprocessed data, including:

[0012] The original modulated signal data is subjected to short-time Fourier transform processing to obtain the initial processed data;

[0013] Feature vectors are extracted from the initial processed data using methods such as wavelet transform to obtain preprocessed data.

[0014] Preferably, the step of performing a short-time Fourier transform on the original modulated signal data to obtain the initial processed data includes:

[0015] Generate a data frequency comb;

[0016] Receive the radio frequency signal to be tested;

[0017] The communication information carried in the radio frequency signal under test is added to the data frequency comb to obtain the modulated original modulated signal.

[0018] The frequency components of the modulated original signal are extracted and mapped onto the target free spectral range to obtain the original modulated signal with bandwidth amplification, wherein the target spectral range is larger than the free spectral range of the modulated original signal.

[0019] Multiple signal pulses are obtained by repeatedly cutting the original modulated signal after bandwidth amplification using pulse scissors. The cutting of the original modulated signal after bandwidth amplification is the cutting of the signal within the time window of the data signal after bandwidth amplification.

[0020] Initial processing data is obtained from multiple signal pulses.

[0021] Preferably, the step of cutting the original modulated signal after bandwidth amplification multiple times using pulse scissors includes:

[0022] The initial cutting window is determined based on the characteristics of the signal;

[0023] A first cut is performed according to the cutting window to obtain a first signal pulse;

[0024] The next cutting window is determined based on the currently received signal pulse, until the cutting is completed.

[0025] Preferably, the step of determining the next cutting window based on the currently obtained signal pulse until cutting is completed includes:

[0026] Feature extraction is performed on the current pulse signal to obtain the feature distribution of the current pulse;

[0027] The length of the next cutting window is determined based on the characteristic distribution.

[0028] Preferably, the characteristics of the signal include:

[0029] Bandwidth, frequency, and waveform characteristics.

[0030] The present invention discloses the following technical effects:

[0031] This invention provides a method for optimizing a modulation recognition model resistant to adversarial attacks through manifold fitting, comprising: acquiring and preprocessing raw modulation signal data to obtain preprocessed data; reconstructing the preprocessed data to obtain reconstructed data; performing robust principal component analysis on the reconstructed data to obtain a manifold tangent plane; obtaining adversarial sample data based on the manifold tangent plane; and optimizing the modulation recognition model using the adversarial sample data and normal training samples to obtain an optimized modulation recognition model. This invention, by acquiring and preprocessing raw modulation signal data, ensures improved data quality and reduces the impact of noise and interference on subsequent processing. The signal reconstruction process further repairs potentially missing information, ensuring that the reconstructed data is more representative and complete, providing a solid foundation for subsequent analysis; the use of robust principal component analysis (PCA) to process the reconstructed data ensures that the extraction of the manifold tangent plane effectively reflects the intrinsic structure and feature distribution of the data. This process helps to capture the main variability of the data, thereby reducing the impact of noise and redundancy on model training. The establishment of popular tangent planes not only improves the separability of data but also supports the generation of more representative adversarial sample data. Generating adversarial sample data based on popular tangent planes effectively enhances the model's resilience. The addition of these adversarial samples strengthens the model's stability under potential attacks, making it more reliable in real-world applications. Simultaneously, optimization using normal training samples results in better performance within the operating range, reducing the risk of overfitting and improving generalization ability. The optimized modulation recognition model accurately identifies various modulation signals while effectively resisting adversarial attacks, which is of significant practical importance in signal processing applications, especially in communication systems with high security requirements. In summary, this optimization method not only improves the accuracy and stability of modulation recognition but also enhances the model's robustness, laying a solid foundation for future research and applications. Attached Figure Description

[0032] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0033] Figure 1 The flowchart illustrates a method for optimizing a modulation recognition model for manifold fitting that resists adversarial attacks, as provided in an embodiment of the present invention. Detailed Implementation

[0034] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.

[0035] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0036] like Figure 1 As shown, this invention provides a method for optimizing a modulation recognition model resistant to adversarial attacks through manifold fitting, comprising:

[0037] Step 100: Acquire the original modulated signal data and perform preprocessing to obtain preprocessed data;

[0038] Specifically, the modulated signal data includes: radio modulated signals such as amplitude modulation (AM), frequency modulation (FM), phase modulation (PM), and quadrature amplitude modulation (QAM); digital signals such as pulse amplitude modulation (PAM) and pulse position modulation (PPM); and analog signals: analog versions of signals, which may still exist in some applications, and optical data in specific scenarios.

[0039] Step 200: Reconstruct the signal from the preprocessed data to obtain reconstructed data;

[0040] Step 300: Perform robust principal component analysis on the reconstructed data to obtain the popular tangent plane;

[0041] Step 400: Obtain adversarial sample data based on the popular cutting plane;

[0042] Step 500: Optimize the modulation recognition using the adversarial sample data and normal training samples to obtain the optimized modulation recognition model.

[0043] Specifically, the process involves collecting raw modulation signal data, cleaning it, and extracting features to ensure data quality and adaptability. This step utilizes methods such as Short-Time Fourier Transform and Wavelet Transform to extract feature vectors, forming high-dimensional data for subsequent use. Based on preprocessing, Principal Component Analysis (PCA) and Robust Principal Component Analysis (RPCA) are used to reduce the dimensionality and denoise the feature data, preserving important data information while enhancing resistance to noise and adversarial interference. This process optimizes feature representation, preparing for manifold fitting. Manifold learning techniques are used to fit the processed data, revealing its structure in low-dimensional space. Methods such as orthogonal projection are used to find the geometric characteristics and intrinsic structure of the data, providing a better understanding of its distribution characteristics and supporting subsequent model training. Based on the obtained manifold fitting results, targeted adversarial examples are generated and combined with normal examples to further train the manifold-optimized modulation recognition model. Adversarial training enhances the model's robustness, making it more adaptable to adversarial attack environments. The technical solution of this invention can be widely applied to modulation signal recognition scenarios that require high security, such as wireless communication and military communication, significantly improving recognition performance and reliability in adversarial environments.

[0044] Furthermore, the original modulated signal data is acquired and preprocessed to obtain preprocessed data, including:

[0045] The original modulated signal data is subjected to short-time Fourier transform processing to obtain the initial processed data;

[0046] Feature vectors are extracted from the initial processed data using methods such as wavelet transform to obtain preprocessed data.

[0047] Furthermore, the step of performing a short-time Fourier transform on the original modulated signal data to obtain the initial processed data includes:

[0048] Generate a data frequency comb;

[0049] Receive the radio frequency signal to be tested;

[0050] The communication information carried in the radio frequency signal under test is added to the data frequency comb to obtain the modulated original modulated signal.

[0051] The frequency components of the modulated original signal are extracted and mapped onto the target free spectral range to obtain the original modulated signal with bandwidth amplification, wherein the target spectral range is larger than the free spectral range of the modulated original signal.

[0052] Multiple signal pulses are obtained by repeatedly cutting the original modulated signal after bandwidth amplification using pulse scissors. The cutting of the original modulated signal after bandwidth amplification is the cutting of the signal within the time window of the data signal after bandwidth amplification.

[0053] Initial processing data is obtained from multiple signal pulses.

[0054] Specifically, the original modulation signal is taken as an example from optics.

[0055] Generate optical frequency comb: Use optical technology to generate an optical frequency comb to provide a frequency reference for subsequent signal processing.

[0056] Receive the radio frequency signal under test: Capture the radio frequency signal under test through the receiving device.

[0057] Modulated optical signal: The communication information carried in the radio frequency signal under test is added to the optical frequency comb to form a modulated optical signal.

[0058] Frequency component extraction: The frequency components of the modulated optical signal are extracted and mapped onto the target free spectral range to obtain the bandwidth-amplified optical signal. This target spectral range should be larger than the free spectral range of the modulated optical signal to ensure information integrity and clarity.

[0059] Optical pulse cutting: This process involves cutting the amplified optical signal into optical pulses using pulse cutters. The cutting process is performed within a time window of the amplified optical signal to extract useful optical signal information.

[0060] Furthermore, the step of repeatedly cutting the original modulated signal after bandwidth amplification using pulse scissors includes:

[0061] The initial cutting window is determined based on the characteristics of the signal;

[0062] A first cut is performed according to the cutting window to obtain a first signal pulse;

[0063] The next cutting window is determined based on the currently received signal pulse, until the cutting is completed.

[0064] Specifically, signal decomposition: By cutting the signal multiple times, it can be broken down into smaller signal pulses. This allows for better capture of the signal's details and changing characteristics, especially in complex modulated signals. Improved temporal resolution: Multiple cutting improves temporal resolution, enabling better identification of rapidly changing features during signal analysis and contributing to increased accuracy. Enhanced robustness: Multiple cutting can resist noise and interference to some extent because even if some cutting results are affected, others can still provide valid information.

[0065] Adaptive Segmentation: Dynamically adjusts the segmentation time window based on signal characteristics. For example, the segmentation time can be determined based on the signal's energy distribution or spectral characteristics, ensuring that useful information is captured to the maximum extent in each segment. Overlapping Segmentation: A certain overlap area can be set for each segmentation, ensuring that even the edge parts of the signal are captured, thus avoiding information loss. Multi-Scale Segmentation: Uses different time windows for segmentation to capture signals with different frequency components. For example, a short time window can capture high-frequency variations, while a long time window can capture low-frequency trends.

[0066] The signal pulses obtained from multiple cuts are fused using weighted averaging or other signal processing techniques to integrate the information from different cuts, forming a more complete signal representation. Feature extraction: After each cut, feature extraction is performed to extract the key features of each pulse, and these features are used for subsequent model training and optimization. By implementing a multiple cut strategy, the ability to analyze the original modulated signal after bandwidth amplification can be significantly improved, enhancing the model's recognition accuracy and robustness for complex modulated signals. This method is particularly suitable for signal processing scenarios requiring high temporal resolution and high signal-to-noise ratio, effectively improving the overall performance of the modulation recognition model.

[0067] Furthermore, the step of determining the next cutting window based on the currently obtained signal pulse, until the cutting is completed, includes:

[0068] Feature extraction is performed on the current pulse signal to obtain the feature distribution of the current pulse;

[0069] The length of the next cutting window is determined based on the characteristic distribution.

[0070] Furthermore, the characteristics of the signal include:

[0071] Bandwidth, frequency, and waveform characteristics.

[0072] More specifically, data acquisition involves obtaining time-series data from the original modulated signal after bandwidth amplification, ensuring signal integrity and quality. Preprocessing involves performing preprocessing on the signal, including denoising, smoothing, and normalization, to improve the accuracy of segmentation and the effectiveness of subsequent processing.

[0073] Define the cutting window: Determine the initial cutting window based on the signal characteristics (bandwidth, frequency, waveform features, etc.) (e.g., window length T1 in milliseconds). Set the overlap ratio: Select an overlap ratio (e.g., 50%) to ensure sufficient overlap between adjacent cutting windows to capture signal edge characteristics.

[0074] Perform the first cut: The signal is cut according to the defined cutting window and overlap ratio. The specific cutting process is as follows: Cutting position calculation: The cutting positions are calculated sequentially from the start position of the signal. For example, the first position is 0, the second position is T1 / 2, the third position is T1, and so on, until the signal ends. Extract signal pulses: The corresponding signal segments are extracted from the calculated cutting positions to form multiple signal pulses.

[0075] Feature Extraction: Features are extracted from the pulses obtained from the initial segmentation, analyzing the spectral characteristics, energy distribution, and other key features of each pulse. Dynamic Segmentation Window Adjustment: Based on the feature analysis results, the length of the segmentation window is adjusted (e.g., from T1 to T2) to ensure that the segmentation effectively captures key signal changes.

[0076] Perform multiple cuts: Based on the adjusted cutting window, cut the signal again to obtain finer-grained signal pulses. The steps are the same as the initial cut, but this time the adjusted window length and overlap ratio are used. Iterative execution: As needed, this process can be performed multiple times, adjusting the window or overlap ratio each time to continuously optimize the cutting results.

[0077] Pulse combining: Multiple segmented signal pulses are combined using weighted averaging or thresholding to ensure the resulting signal represents the characteristics of the entire signal. Subsequent processing: The combined signal pulses are further analyzed and optimized, such as signal restoration, feature selection, and model training.

[0078] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.

[0079] This document uses specific examples to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. Furthermore, those skilled in the art will recognize that, based on the ideas of the present invention, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of the present invention.

Claims

1. A method for optimizing a modulation recognition model resistant to adversarial attacks using manifold fitting, characterized in that, include: The raw modulated signal data is acquired and preprocessed to obtain preprocessed data; The preprocessed data is reconstructed to obtain reconstructed data; Robust principal component analysis was performed on the reconstructed data to obtain the popular tangent plane; Adversarial sample data are obtained based on the popular cutting plane; The modulation recognition model is optimized by using the adversarial sample data and normal training samples.

2. The method for optimizing a modulation recognition model resistant to adversarial attacks based on manifold fitting according to claim 1, characterized in that, The raw modulated signal data is acquired and preprocessed to obtain preprocessed data, including: The original modulated signal data is subjected to short-time Fourier transform processing to obtain initial processed data; The initial processed data is processed by extracting feature vectors using wavelet transform to obtain preprocessed data.

3. The method for optimizing a modulation recognition model resistant to adversarial attacks based on manifold fitting according to claim 2, characterized in that, The step of performing a short-time Fourier transform on the original modulated signal data to obtain initial processed data includes: Generate a data frequency comb; Receive the radio frequency signal to be tested; The communication information carried in the radio frequency signal under test is added to the data frequency comb to obtain the modulated original modulated signal. The frequency components of the modulated original signal are extracted and mapped onto the target free spectral range to obtain the original modulated signal with bandwidth amplification, wherein the target free spectral range is larger than the free spectral range of the modulated original signal. Multiple signal pulses are obtained by repeatedly cutting the original modulated signal after bandwidth amplification using pulse scissors. The cutting of the original modulated signal after bandwidth amplification is the cutting of the signal within the time window of the data signal after bandwidth amplification. Initial processing data is obtained from multiple signal pulses.

4. The method for optimizing a modulation recognition model resistant to adversarial attacks based on manifold fitting according to claim 3, characterized in that, The step of repeatedly cutting the original modulated signal after bandwidth amplification using pulse scissors includes: The initial cutting window is determined based on the characteristics of the signal; A first cut is performed according to the cutting window to obtain a first signal pulse; The next cutting window is determined based on the currently received signal pulse, until the cutting is completed.

5. The method for optimizing a modulation recognition model resistant to adversarial attacks based on manifold fitting according to claim 4, characterized in that, The step of determining the next cutting window based on the currently received signal pulse, until the cutting is completed, includes: Feature extraction is performed on the currently obtained signal pulse to obtain the feature distribution of the signal pulse; The length of the next cutting window is determined based on the characteristic distribution.

6. The method for optimizing a modulation recognition model resistant to adversarial attacks based on manifold fitting according to claim 4, characterized in that, The characteristics of the signal include: Bandwidth, frequency, and waveform characteristics.