Defense methods against adversarial samples in radio frequency fingerprint recognition systems

Through adversarial training and ensemble learning methods, the defense capability of the radio frequency fingerprint recognition system against adversarial samples is improved, ensuring the robustness and accuracy of the model in different representation domains.

CN119537881BActive Publication Date: 2025-10-03UNIV OF ELECTRONICS SCI & TECH OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411600565.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-11
Publication Date
2025-10-03
Estimated Expiration
2044-11-11

AI Technical Summary

Technical Problem

Radio frequency fingerprint recognition systems based on deep learning models are vulnerable to adversarial sample attacks, resulting in insufficient security.

Method used

Through adversarial training, models in different representation domains are obtained, and features extracted from models in different representation domains are integrated during the inference phase to improve the model's robustness to adversarial perturbations.

Benefits of technology

The accuracy of the radio frequency fingerprint recognition system on normal samples and adversarial samples is improved, the robustness of the system is enhanced, and the defense against adversarial sample attacks is achieved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119537881B_ABST
    Figure CN119537881B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for defending against adversarial samples in a radio frequency fingerprint recognition system. The method performs adversarial training in different signal representation domains to obtain robust models in different signal representation domains. When identifying a transmitter, the results obtained in the two representation domains are weighted to obtain a final classification result. In the training phase, the present invention uses traditional classification loss and robustness loss as targets to perform adversarial training on time domain and frequency domain radio frequency fingerprint recognition models respectively. The robust model obtained through training has the ability to defend against adversarial sample attacks. In the inference phase, the final recognition result is obtained by weighted averaging of different dimensional features obtained in the two different representation domains, further improving the system's defense capability against adversarial sample attacks.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of physical layer security technology, and in particular to a method for defending against adversarial samples in a radio frequency fingerprint recognition system. Background Art

[0002] Faced with the need for lightweight security authentication of terminal devices in IoT scenarios, radio frequency fingerprinting, a key method in physical layer security, can effectively meet this need. It aims to distinguish different transmitters through the unique hardware manufacturing differences of the transmitters. Unlike easily forged tags such as user IDs or MAC addresses, these internal manufacturing differences of the transmitters are difficult to forge. Identification requires only the transmitter to transmit a wireless signal, and authentication does not require the terminal device to perform complex cryptographic operations. However, in recent years, radio frequency fingerprinting systems based on deep learning models have become vulnerable to threats such as adversarial sample attacks, backdoor attacks, and poisoning attacks, making these deep learning-based radio frequency fingerprinting systems a significant security risk. Summary of the Invention

[0003] The technical problem to be solved by the present invention is to use a defense method to prevent adversarial sample attacks in a radio frequency fingerprint recognition system based on a deep learning model, so that the radio frequency fingerprint recognition model can not only identify normal samples well, but also maintain a high accuracy rate for adversarial samples with malicious perturbations, thereby ensuring the robustness of the radio frequency fingerprint recognition system.

[0004] The technical solution adopted by the present invention to solve the above technical problems is to obtain models in different representation domains through adversarial training, ensure the robustness of the trained models to adversarial perturbations, obtain the final classification result by integrating the results of the models in different representation domains, and ensure the robustness of the models to adversarial perturbations through different features extracted from the models in different representation domains during the inference phase. The technical solution includes the following steps:

[0005] S1: Collect wireless transmitter samples to obtain a wireless transmitter IQ signal sample library;

[0006] S2: The RF fingerprint recognition system performs frequency domain transformation on the IQ signal sample library to obtain its corresponding frequency domain signal sample library; the time domain signal sample library and the frequency domain signal sample library are paired with the label to obtain the time domain dataset D r and frequency domain dataset D R ;

[0007] S3: Dataset D r and D R The order of samples in the training set is disrupted and the first m items are divided into the training set and The last n items are divided into the test set and

[0008] S4: training set of time domain and frequency domain obtained through S3 and The corresponding time domain and frequency domain deep learning models are trained by adversarial training methods respectively, and the trained time domain robust deep learning model f is saved. θ and frequency-domain robust deep learning models

[0009] S5: Test set and Obtain the corresponding adversarial sample test set through the adversarial sample generation method and Input them into the time-domain robust and frequency-domain robust deep learning models respectively, and obtain the classification probability distribution of the time-domain and frequency-domain adversarial sample data after the deep learning model;

[0010] S6: Adversarial sample dataset obtained through the test set and Perform time domain and frequency domain transformations respectively, input them into the deep learning model of the corresponding signal representation, and obtain the classification probability distribution of the time domain and frequency domain adversarial sample data after the frequency domain and time domain transformations;

[0011] S7: Integrate the classification probability distribution obtained from the original representation domain of the adversarial sample and the classification probability distribution after frequency domain or time domain transformation to obtain the final classification result.

[0012] The present invention fully utilizes the advantages of adversarial training. Through the traditional classification loss and the robust loss of the model, a model that is relatively robust to both time domain and frequency domain data is obtained. It can not only obtain a high accuracy on samples, but also maintain a high accuracy on adversarial samples. In addition, with the help of the classification results obtained in different representation domains, the final classification result is obtained through ensemble learning, which can further improve the robustness of the radio frequency fingerprint recognition system to adversarial samples.

[0013] The beneficial effects of the present invention are:

[0014] (1) Through the adversarial training method, robust models for time domain signal and frequency domain signal representation are trained respectively, which improves the model's own defense ability against adversarial samples.

[0015] (2) By integrating the robust model results under different signal representations, the final classification results are obtained, which further improves the defense capability of the RF fingerprint recognition system against adversarial samples. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1Schematic diagram of how to add adversarial perturbations to the RF fingerprint recognition system.

[0017] Figure 2 Flowchart of the robust model obtained by radio frequency fingerprint recognition system through adversarial training.

[0018] Figure 3 Flowchart of the radio frequency fingerprint recognition system adding an adversarial disturbance signal to the object to be identified. DETAILED DESCRIPTION

[0019] The technical solution of the present invention is described in further detail below, but the protection scope of the present invention is not limited to the following description.

[0020] like Figure 1 As shown, in the process of identifying the wireless transmitter signal of the radio frequency fingerprint recognition system, a malicious attacker can add disturbances to the digital signal after the original signal symbol is modulated, and then convert it into an analog signal through a digital-to-analog conversion module, and after up-conversion through the local oscillator, transmit the interfered signal to the wireless channel through a power amplifier and an antenna to interfere with the final recognition result. The attacker can add disturbances inside the transmitter, or transmit the disturbance signal through a jammer, or add disturbances inside the receiver to implement adversarial attacks on the radio frequency fingerprint recognition system. In response to the above-mentioned adversarial sample attacks, the adversarial sample defense method for the radio frequency fingerprint recognition system provided in this embodiment specifically includes the following steps, and maintains the accuracy of the radio frequency fingerprint recognition system for adversarial samples through adversarial training and ensemble learning methods:

[0021] S1. Collect the kth sample of wireless transmitter category i:

[0022]

[0023] Among them, χ r The wireless transmitter IQ signal sample library collected for the RF fingerprint recognition system, represents the i-th time domain sample data collected by the j-th type of transmitter device, where i = 1, 2, ... P; j = 1, 2, ... K, where K is the number of wireless transmitters and P is the signal sample collected for each transmitter;

[0024] S2. The RF fingerprint recognition system performs frequency domain transformation on the original IQ signal sample library to obtain its corresponding frequency domain signal sample library:

[0025]

[0026] Among them, X R Represents X r The frequency domain signal sample library of the corresponding wireless transmitter is obtained after frequency domain transformation, Represents the i-th frequency domain sample data collected by the j-th type transmitter device;

[0027] Pair the time domain signal sample library and the frequency domain signal sample library with the label y to obtain the time domain training dataset D r And frequency domain training dataset D R :

[0028] D r ={(r 1 ,y 1 ),…,(r 2 ,y 2 ),...,(r P*K ,y K )};

[0029] D R ={(R 1 ,y 1 ),...,(R 2 ,y 2 ),...,(R P*K ,y K )};

[0030] S3. Separate datasets D r and D R The order of samples in the training set is disrupted and the first m items are divided into the training set and The last n items are divided into the test set and

[0031]

[0032] Where K*P=m+n, training set and The proportion of data set D is Test set and The proportion of data set D is

[0033] S4. Time domain and frequency domain training sets obtained through S3 and The corresponding time domain and frequency domain deep learning models are trained by adversarial training methods respectively, and the trained time domain robust deep learning model f is saved. θ and frequency-domain robust deep learning models like Figure 2 As shown, it includes the following sub-steps:

[0034] S401. Obtain time domain samples r from the time domain training dataset and the frequency domain training dataset respectively. i and frequency domain samples Ri ;

[0035] S402. Set the attack perturbation amplitude ε for adversarial training;

[0036] S403. Initialize the adversarial samples in the time domain and frequency domain in adversarial training:

[0037]

[0038] Where N(0,I) is a Gaussian distribution with mean 0 and variance the unit matrix I; δ is a parameter, which is fixed at 0.001 in practical applications.

[0039] S404. Update the perturbation direction of the adversarial sample through the model gradient information, so that the adversarial samples in the time domain and frequency domain are obtained. and More aggressive:

[0040]

[0041] in is the loss function when generating adversarial sample attacks, The generated adversarial sample is projected to the range of the attack perturbation amplitude ε from the original sample, η1 is the distance of the single step when controlling the generation of the adversarial sample, sign is the sign function, It is to find the adversarial sample through the loss function gradient;

[0042] S405. Repeat step S404 at t = 1, 2, ... T, where T is the number of repetitions of adversarial sample generation;

[0043] S406. Time domain and frequency domain adversarial samples obtained through S405 and During gradient update, traditional classification loss and robust loss are used to update the model parameters:

[0044]

[0045] Where η2 is the learning rate during training, m is the number of training samples, is the gradient of the loss function with respect to the trainable parameters θ, is the loss function over the trainable parameters The gradient of y i is the label of the i-th sample data, β is the hyperparameter that controls the balance between robustness loss and traditional classification loss, and controls the trade-off between accuracy and robustness in the final optimization objective. During the adversarial training process of the RF fingerprint recognition model, the trade-off between accuracy and model robustness can be controlled by a single parameter, which can be flexibly applied to different application scenarios.

[0046] Where L(f θ (r i ),y i )and is the traditional cross entropy classification loss function, and It is a loss function used to measure the distribution difference between adversarial samples and original samples. Here, KL divergence is used as its distribution difference loss function, which can ensure the robustness of the model to adversarial sample attacks. The model can not only perform good classification but also defend against adversarial samples generated by attackers. The cross entropy classification loss function and the KL divergence distribution difference loss function are defined as follows:

[0047]

[0048] Among them, C is the total number of categories, and c is the category label corresponding to the sample

[0049] S5. Test set and Obtain the corresponding adversarial sample test set through the adversarial sample generation method and Input into the time-domain robust and frequency-domain robust deep learning models respectively:

[0050]

[0051] Among them, r i adv represents the adversarial sample data after the time domain data in the test set is subjected to adversarial perturbation, which is obtained by the same method as steps S401-S405; i = m+1, m+2,…, m+n; the corresponding represents the adversarial sample data after the frequency domain data in the test set has been adversarially perturbed, i = m+1, m+2,…, m+n; and Respectively represent the classification probability distribution of time domain and frequency domain adversarial sample data after deep learning model;

[0052] S6. Adversarial sample dataset obtained through test set and Perform transformations in the time domain and frequency domain respectively, and input them into the deep learning model of the corresponding signal representation:

[0053]

[0054] Among them, DFT and IDFT represent the transformation of the frequency domain and time domain of the adversarial sample data respectively. and Respectively represent the classification probability distribution of time domain and frequency domain adversarial sample data after frequency domain and time domain transformation and input into the deep learning model;

[0055] S7. Through the adversarial training of the time domain and frequency domain models described above, the model is made robust to adversarial samples in the training phase. In the testing phase, the classification probability distribution obtained from the original representation domain of the adversarial sample and the classification probability distribution after frequency domain or time domain transformation are integrated to obtain the final classification result. By integrating the robust features extracted from different representation domains, it is impossible for the attacker to conduct adversarial interference on the RF fingerprint recognition system simply through the time domain model or the frequency domain model. Figure 3 The following is a flow chart of RF fingerprint recognition when the original signal is represented in the time domain:

[0056]

[0057] in, Represents the adversarial sample data r after the time domain data in the test set is adversarially perturbed i adv The final classification result, The adversarial sample data after the frequency domain data in the test set has been adversarially perturbed The final classification result, argmax is the function that takes the index corresponding to the maximum value of the vector;

[0058] The simulation of the adversarial signal in two representation domains during steps S5-S7 is based on the actual signal to be identified. The signal to be identified depends on the representation form of the signal received by the RF fingerprint recognition system. By converting the representation domain of the signal to be identified, the results of the adversarial sample in different representation domains are obtained. By integrating the classification probabilities obtained from different features observed in different representation domains, the RF fingerprint recognition system is able to defend against adversarial disturbances.

[0059] The foregoing description is a preferred embodiment of the present invention. It should be understood that the present invention is not limited to the form disclosed herein and should not be construed as excluding other embodiments. Instead, the present invention can be used in other combinations, modifications, and environments and can be modified within the scope of the concept described herein through the above teachings or techniques or knowledge in the relevant field. Modifications and variations made by those skilled in the art that do not depart from the spirit and scope of the present invention are intended to be protected by the appended claims.

Claims

1. A defense method against adversarial samples in a radio frequency fingerprint recognition system, characterized in that: The following steps are involved: S1: Collect wireless transmitter samples to obtain a wireless transmitter IQ signal sample library; S2: The RF fingerprint recognition system performs frequency domain transformation on the IQ signal sample library to obtain its corresponding frequency domain signal sample library; the time domain signal sample library and the frequency domain signal sample library are paired with the label to obtain the time domain dataset D r and frequency domain dataset D R ; S3: Dataset D r and D R The order of samples in the training set is disrupted and the first m items are divided into the training set and The last n items are divided into the test set and S4: Time domain and frequency domain training sets obtained through S3 and The corresponding time domain and frequency domain deep learning models are trained by adversarial training methods respectively, and the trained time domain robust deep learning model f is saved. θ and frequency-domain robust deep learning models S5: Test set and Obtain the corresponding adversarial sample test set through the adversarial sample generation method and Input them into the time-domain robust and frequency-domain robust deep learning models respectively, and obtain the classification probability distribution of the time-domain and frequency-domain adversarial sample data after the deep learning model; S6: Adversarial sample dataset obtained through the test set and Perform frequency domain and time domain transformations respectively, input them into the deep learning model of the corresponding signal representation, and obtain the classification probability distribution of the time domain and frequency domain adversarial sample data after the frequency domain and time domain transformations; S7: Integrate the classification probability distribution obtained from the original representation domain of the adversarial sample and the classification probability distribution after frequency domain or time domain transformation to obtain the final classification result.

2. The method for defending against adversarial samples in a radio frequency fingerprint recognition system according to claim 1, characterized in that: The wireless transmitter IQ signal sample library is formalized as follows: Among them, χ r The wireless transmitter IQ signal sample library collected for the RF fingerprint recognition system, represents the i-th time domain sample data collected by the j-th type of transmitter device, where i = 1, 2, ... P; j = 1, 2, ... K, where K is the number of wireless transmitters and P is the signal sample collected for each transmitter; The frequency domain signal sample library is formalized as follows: Among them, χ R represents χ r The frequency domain signal sample library of the corresponding wireless transmitter is obtained after frequency domain transformation, Represents the i-th frequency domain sample data collected by the j-th type of transmitter equipment.

3. The method for defending against adversarial samples in a radio frequency fingerprint recognition system according to claim 2, characterized in that: The step S4 specifically includes the following sub-steps: S401: Obtain time domain samples r from the time domain training dataset and the frequency domain training dataset respectively. i and frequency domain samples R i ; S402: Setting the attack perturbation amplitude ε for adversarial training; S403: Initialize time domain adversarial samples in adversarial training and frequency domain adversarial examples Where N(0,I) is a Gaussian distribution with mean 0 and variance of the unit matrix I; δ is a parameter; S404: Update the perturbation direction of the adversarial sample using model gradient information: Where L(·) is the loss function when generating adversarial sample attacks, The generated adversarial sample is projected to the range of the attack perturbation amplitude ε from the original sample, η1 is the distance of the single step when controlling the generation of the adversarial sample, sign is the sign function, It is to find the adversarial sample through the loss function gradient; S405: Repeat step S404 at t = 1, 2, ... T, where T is the number of repetitions of adversarial sample generation; S406: Time domain and frequency domain adversarial samples obtained through S405 and During gradient update, traditional classification loss and robust loss are used to update the model parameters.

4. The method for defending against adversarial samples in a radio frequency fingerprint recognition system according to claim 3, characterized in that: The step S5 is formalized as follows: Among them, r i adv represents the adversarial sample data after the time domain data in the test set is adversarially disturbed, and the corresponding represents the adversarial sample data after the frequency domain data in the test set has been adversarially perturbed, i = m+1, m+2,…, m+n; and Respectively represent the classification probability distribution of time domain and frequency domain adversarial sample data after deep learning model.

5. The method for defending against adversarial samples in a radio frequency fingerprint recognition system according to claim 4, characterized in that: The step S6 is formalized as follows: Among them, DFT and IDFT represent the transformation of the frequency domain and time domain of the adversarial sample data respectively. and They represent the classification probability distribution of the time domain and frequency domain adversarial sample data after frequency domain and time domain transformation and passing through the deep learning model.

6. The method for defending against adversarial samples in a radio frequency fingerprint recognition system according to claim 5, characterized in that: The step S7 is formalized as follows: in, Represents the adversarial sample data r after the time domain data in the test set is adversarially perturbed i adv The final classification result, The adversarial sample data after the frequency domain data in the test set has been adversarially perturbed The final classification result, argmax is the function that takes the index corresponding to the maximum value of the vector.

7. The method for defending against adversarial samples in a radio frequency fingerprint recognition system according to claim 6, characterized in that: The parameters of the model updated using traditional classification loss and robust loss are formalized as follows: Where η2 is the learning rate during training, m is the number of training samples, is the gradient of the loss function with respect to the trainable parameters θ, is the loss function over the trainable parameters The gradient of y i is the label of the i-th sample data, β is a hyperparameter; L(f θ (r i ),y i )and is the traditional cross entropy classification loss function, and It is a loss function used to measure the difference between the distribution of adversarial samples and original samples.

8. The method for defending against adversarial samples in a radio frequency fingerprint recognition system according to claim 7, characterized in that: The cross entropy classification loss function is expressed as follows: The loss function used to measure the distribution difference between the adversarial sample and the original sample is specifically the distribution difference loss function of KL divergence, which is expressed as follows: Among them, C is the total number of categories, and c is the category label corresponding to the sample.

9. The method for defending against adversarial samples in a radio frequency fingerprint recognition system according to any one of claims 1 to 8, characterized in that: During the actual application of the method, the signal to be identified depends on the representation form of the signal received by the radio frequency fingerprint recognition system.

10. The method for defending against adversarial samples in a radio frequency fingerprint recognition system according to any one of claim 9, characterized in that: δ is a fixed value of 0.001.

Citation Information

Patent Citations

  • Deep learning signal individual recognition model defense method based on multiple modes

    CN115392285A

  • Device and Method for Reliable Classification of Wireless Signals

    US20220255775A1