A dual collaborative defense method for intelligent recognition and countermeasures of communication signal modulation

Through the dual collaborative defense method, the encoder is used to extract hidden features and the dynamic search strategy is used to generate adversarial samples with customized labels. The adversarial sample detection and recognition network is trained to solve the problems of the singleness and insufficient generalization ability of the existing communication signal modulation recognition adversarial defense method, and achieve efficient adversarial robustness.

CN119691559BActive Publication Date: 2025-09-23XIDIAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411833348.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-13
Publication Date
2025-09-23
Estimated Expiration
2044-12-13

AI Technical Summary

Technical Problem

The existing communication signal modulation recognition adversarial defense methods are single, do not fully explore the hidden features of the model and signal samples, lack generalization capabilities, cannot effectively deal with new adversarial sample generation strategies, and the adversarial samples during training are not comprehensive, resulting in poor model robustness.

Method used

A dual collaborative defense method is adopted. By combining the adversarial sample detection network and the recognition network, the encoder is used to extract hidden features, a dynamic search strategy is applied to generate adversarial samples with customized labels, and the adversarial sample detection and recognition networks are trained to achieve dual defense against potential adversarial samples.

Benefits of technology

It improves the accuracy and recognition rate of adversarial sample detection, enhances the robustness of modulation recognition tasks, effectively resists escape samples, and improves the adversarial robustness of the model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119691559B_ABST
    Figure CN119691559B_ABST
Patent Text Reader

Abstract

The embodiments of the present application relate to the field of adversarial defense technology, and in particular to a dual collaborative defense method for intelligent recognition of communication signal modulation adversarial defense, the method comprising: using an encoder to extract hidden features from the original sample and the constructed adversarial sample respectively, and training the adversarial autoencoder based on the extracted hidden features to obtain an adversarial sample detection network; applying a dynamic search strategy to determine the adversarial perturbation radius, generating adversarial samples with customized labels, and training an adversarial sample recognition network based on the adversarial samples with customized labels; using the adversarial sample detection network as a front-end network to perform adversarial detection on the input samples, and using the adversarial sample recognition network as a back-end network to perform secondary defense on the input samples that escape the adversarial sample detection network, and completing the modulation recognition task. This method achieves dual collaborative defense for the modulation recognition task and effectively enhances adversarial robustness.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of countermeasure defense technology, and in particular to a dual collaborative defense method for intelligent recognition and countermeasure of communication signal modulation. Background Art

[0002] With the rapid development of wireless communication technology, the scarcity of spectrum resources has become increasingly prominent, making modulation recognition technology increasingly important in signal detection and demodulation. In recent years, the rise of deep learning has revolutionized modulation recognition technology. Applying DNNs (Deep Neural Networks) to modulation recognition allows the system to automatically extract features from input signals, significantly improving the accuracy and efficiency of modulation recognition. However, deep learning models have limitations in interpretability, making them vulnerable to adversarial examples. Adversarial examples are carefully designed input samples designed to cause the model to misjudge. Consequently, researchers have begun to focus on and study adversarial defense methods to address this challenge and improve the robustness of DNN models in modulation signal recognition. In this context, developing stronger adversarial defense methods for automatic modulation recognition models is particularly important. By deeply studying the generation mechanisms and defense methods of adversarial examples, researchers can better understand the weaknesses of DNN models and design more effective defense strategies accordingly, thereby ensuring the reliability and security of modulation recognition systems.

[0003] Currently, research teams both domestically and internationally have proposed numerous adversarial attack methods. Szegedy et al. first proposed the concept of adversarial examples. They successfully altered a classifier's predictions by adding tiny perturbations, imperceptible to the human eye, to the input. Since the introduction of adversarial examples, numerous adversarial attack methods have emerged, including the fast gradient sign method, the basic iterative method, the Jacobian matrix-based saliency mapping attack, projected gradient descent, and momentum iteration. To defend against these adversarial attacks, researchers have proposed various defense models tailored to the specific attack method. These defense methods can be broadly categorized into four categories: sample preprocessing, adversarial example detection, improving model robustness, and provable defenses. Each category offers unique research approaches and practical applications, contributing to a rich research landscape in the field of adversarial defense. These defense methods also exhibit varying performance against different attacks in different environments.

[0004] To defend against adversarial attacks and improve the robustness of modulation recognition models, GoodFellow et al. proposed a single-step adversarial training method based on FGSM, Madry et al. proposed an adversarial training method based on gradient iteration, Cheng et al. proposed customized adversarial training, Wang et al. proposed misclassification-aware adversarial training, Femin et al. proposed a fast unsupervised anomaly detection method, and Banerjee et al. proposed a region-based adversarial detection method. These defense methods are effective in specific scenarios, but they still suffer from poor detection and insufficient generalization performance against new and unknown adversarial examples.

[0005] Through the above analysis, the current adversarial defense methods still have the following defects.

[0006] First, the current adversarial defense methods for communication signal modulation recognition have a single defense approach and fail to fully exploit the hidden features of the model and signal samples.

[0007] Second, current adversarial detection methods perform well in specific attack scenarios, but lack sufficient generalization capabilities to deal with new and unknown adversarial sample generation strategies.

[0008] Third, the current adversarial training methods use incomplete adversarial samples during training and are unable to generate optimal adversarial perturbations for training, resulting in poor robustness of the model in the face of new attacks. Summary of the Invention

[0009] To solve the above technical problems, the embodiments of the present application propose a dual collaborative defense method for communication signal modulation intelligent recognition adversarial defense, aiming to make full use of the hidden features of signal samples, generate adversarial samples and train adversarial sample detection networks, apply dynamic search strategies to determine the adversarial perturbation radius, and generate adversarial samples with specific labels to train adversarial sample recognition networks. The adversarial sample detection network is used as the front line of defense to detect potential adversarial samples, and the adversarial sample recognition network is used as the back line of defense to further defend against escaping samples, thereby realizing dual collaborative defense of modulation recognition tasks and enhancing adversarial robustness.

[0010] To achieve the above-mentioned objectives, an embodiment of the present application proposes a dual collaborative defense method for intelligent recognition of communication signal modulation adversarial defense, which includes the following steps: using an encoder to extract hidden features from the original sample and the constructed adversarial sample respectively, and training the adversarial autoencoder based on the extracted hidden features to obtain an adversarial sample detection network; applying a dynamic search strategy to determine the adversarial perturbation radius, generating adversarial samples with customized labels, and training an adversarial sample recognition network based on the adversarial samples with customized labels; using the adversarial sample detection network as the front network to perform adversarial detection on the input samples, and using the adversarial sample recognition network as the back network to perform secondary defense on the input samples that escape the adversarial sample detection network, and completing the modulation recognition task.

[0011] To achieve the above-mentioned objectives, an embodiment of the present application also provides a dual collaborative defense system for intelligent recognition and confrontation of communication signal modulation, the system comprising: an adversarial sample detection network training module, which is used to use an encoder to extract hidden features from the original sample and the constructed adversarial sample respectively, and train the adversarial autoencoder based on the extracted hidden features to obtain an adversarial sample detection network; an adversarial sample recognition network training module, which is used to apply a dynamic search strategy to determine the adversarial perturbation radius, generate adversarial samples with customized labels, and obtain an adversarial sample recognition network based on the adversarial sample training with customized labels; a collaborative defense module, which is used to use the adversarial sample detection network as a front-end network to perform adversarial detection on the input samples, and use the adversarial sample recognition network as a back-end network to perform secondary defense on the input samples that escape the adversarial sample detection network, and complete the modulation recognition task.

[0012] To achieve the above-mentioned purpose, an embodiment of the present application also provides an electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute a dual collaborative defense method for intelligent identification and countermeasures of communication signal modulation as described above.

[0013] To achieve the above-mentioned purpose, an embodiment of the present application also provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it can implement a dual collaborative defense method for intelligent identification and countermeasures of communication signal modulation as described above.

[0014] In some optional embodiments, the original sample set is recorded as x j Represents the jth original sample, and the constructed adversarial sample set is recorded as represents the jth adversarial example;

[0015] The encoder is used to extract hidden features from the original sample and the constructed adversarial sample respectively, which is achieved by the following formula:

[0016] H j =f e (W e x j +b e );

[0017]

[0018] Among them, f e (·) represents the activation function of the encoder, W e and b e are the weight term and bias term of the encoder respectively, δ j represents the optimal perturbation of the jth adversarial example, H j represents the hidden features of the jth original sample, represents the hidden features of the j-th adversarial example.

[0019] In some optional embodiments, by making the hidden feature H of the j-th original sample j Hidden features of the jth adversarial sample The distance between them reaches the maximum, and the optimal perturbation δ is obtained j , we get the optimization problem about the optimal perturbation;

[0020] The optimization problem of optimal perturbation is expressed as follows:

[0021]

[0022] stδ j∞ ≤ε j ;

[0023] Among them, ε j is the preset maximum disturbance, is the function for calculating distance;

[0024] The stochastic descent gradient method is used to optimize the optimization problem about the optimal perturbation. At the same time, ensure H j and The distance between them reaches the maximum, and the optimal perturbation δ is obtained j , by changing the optimal perturbation δ j Add to the jth original sample x j In the example, we obtain the jth optimal adversarial sample

[0025] In some optional embodiments, the adversarial sample detection network includes three parts: an encoder, a decoder, and a discriminator. The encoder also acts as a generator in the adversarial sample detection network. The training process of the adversarial sample detection network includes two stages: a reconstruction stage and a regularization stage.

[0026] For the reconstruction stage, the goal is to train the encoder and decoder to learn an effective representation from the input data to the hidden features, and then reconstruct the original data from the hidden features. The goal of the reconstruction stage is to introduce a feature loss L H Implementation, minimize the feature loss L during the training process of the reconstruction phase H Encourage adversarial autoencoders to learn feature representations;

[0027] Feature loss L H It is expressed by the formula:

[0028]

[0029] In the sample space, the clean sample should be visually similar to the adversarial sample and more similar to the reconstructed sample of the adversarial sample. By introducing the similarity reconstruction error loss L in the training process of the reconstruction phase, con Improve the similarity between samples in the sample space;

[0030] Similarity reconstruction error loss L con It is expressed by the formula:

[0031]

[0032] in, represents the jth clean sample, represents the jth reconstructed sample, N represents the total number of clean samples, and the total number of reconstructed samples is the same as the total number of clean samples;

[0033] For the regularization stage, the goal is to train the discriminator and the generator so that the discriminator has the ability to accurately distinguish whether the input sample is from the output of the generator or a known true prior sample, and the sample generated by the generator is as close to the true prior sample as possible. The goal of the regularization stage is to introduce the identification loss L D and generation loss L G accomplish;

[0034] Identification loss L D and generation loss L G It is expressed by the formula:

[0035]

[0036] L G =-E x~X{logD<G[E(x)]>};

[0037] Among them, D(x) represents the predicted probability of the discriminator D for the true prior sample x, D[G(z)] represents the predicted probability of the discriminator D for the fake sample G(z) generated by the generator G based on the noise z, and p data (x) represents the true sample distribution, p z (z) represents the normal distribution of the input noise of the generator G, D<G[E(x)]> represents the probability that the discriminator D judges the sample generated by the generator G as a true prior sample, X represents the original distribution, and l(·) represents the loss function for training the adversarial sample recognition network;

[0038] By alternately training the discriminator and the generator, adversarial training is achieved, and finally an adversarial sample detection network is trained.

[0039] In some optional embodiments, a dynamic search strategy is applied to determine the adversarial perturbation radius and generate adversarial samples with customized labels, including:

[0040] Use the gradient of the loss function to the input sample to determine the adversarial perturbation δ f The disturbance direction of the counter-perturbation δ f The disturbance direction is expressed by the formula:

[0041]

[0042] Among them, δ n represents the cumulative gradient of the b-th iteration, β and μ are both dynamic factors, x+δ n represents the adversarial effect generated by the nth iteration, It represents the gradient of the loss of the nth iteration for the adversarial, sign(·) is the sign function, sign(δ f ) represents the adversarial perturbation δ f The direction of disturbance;

[0043] By using the gradient characteristics of the loss function with respect to the input sample and the historical information of the gradient, the iterative step size is constructed and the size of the adversarial perturbation is adjusted. After the dynamic search is completed, the optimal perturbation direction and optimal perturbation size are obtained.

[0044] Add the optimal perturbation size and optimal perturbation direction to the input sample to generate an adversarial sample;

[0045] Generate customized labels for adversarial examples based on the original labels, dynamically adjust the rate at which the perturbation radius increases or decreases, and dynamically adjust the search step size of the perturbation radius.

[0046] The customized label of the adversarial sample is expressed as:

[0047]

[0048] Among them, β represents the rate of increase or decrease of the dynamic adjustment perturbation radius, μ represents the search step size of the dynamic adjustment perturbation radius, y represents the original label, represents a uniform distribution over all labels, Represents a customized label for the adversarial example.

[0049] In some optional embodiments, training an adversarial sample recognition network based on adversarial samples with customized labels includes:

[0050] Select and train a basic model to perform the modulation recognition task; the objective function of the adversarial sample recognition network is expressed as follows:

[0051]

[0052] Where l(·) represents the loss function for training the adversarial sample recognition network, and f θ (·) represents the adversarial sample recognition network, θ represents the network parameters of the adversarial sample recognition network;

[0053] Each original sample is subjected to an adaptive hyperparameter algorithm to find the most accurate perturbation radius. The updated hyperparameters are used to generate adversarial samples with customized labels for the samples. The adversarial samples and original samples are mixed into a new training set, and the adversarial sample recognition network is repeatedly trained using the new training set. At this point, the objective function of the adversarial sample recognition network is updated to:

[0054]

[0055] in, is x a ε a is the p-norm sphere of radius, represents the customized label of the adversarial sample, ε a is the perturbation radius of the a-th adversarial example;

[0056] By optimizing the objective function of the updated adversarial sample recognition network, the trained adversarial sample recognition network is finally obtained.

[0057] In some optional embodiments, the adversarial sample detection network is used as a front-end network to perform adversarial detection on the input samples, and the adversarial sample recognition network is used as a back-end network to perform secondary defense on the input samples that escape the adversarial sample detection network, and complete the modulation recognition task, including: using the adversarial sample detection network as the front-end network, when an input sample is input into the front-end network, calculating the reconstruction error of the input sample, and judging whether the input sample is an adversarial sample through the reconstruction error of the input sample and the output of the discriminator; using the adversarial sample recognition network as the back-end network, identifying the input samples that are not determined as adversarial samples by the adversarial sample detection network to complete the secondary defense, realize dual collaborative adversarial defense, and complete the modulation recognition task, and output the modulation recognition type of the signal.

[0058] The dual collaborative defense method for intelligent identification and countermeasures of communication signal modulation proposed in the embodiments of the present application has the following beneficial effects.

[0059] First, this application extracts hidden features of the sample through the encoder, generates adversarial samples using adversarial feature rules in the feature space, and trains an adversarial sample detection network. The adversarial sample detection network trained in this way has a very high detection accuracy.

[0060] Second, this application determines the adversarial perturbation radius through a dynamic search strategy and generates adversarial samples with customized labels to train the adversarial sample recognition network. The adversarial sample recognition network trained in this way has a high recognition accuracy.

[0061] Third, this application uses the adversarial sample detection network as the front line of defense to detect potential adversarial samples, and the adversarial sample recognition network as the back line of defense to further resist escape samples, thereby achieving dual collaborative defense for modulation recognition tasks and effectively enhancing adversarial robustness. BRIEF DESCRIPTION OF THE DRAWINGS

[0062] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the related technologies, the following is a brief introduction to the drawings required for use in the embodiments of the present application or the description of the related technologies. Obviously, the following drawings are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. The drawings described here are only used to explain the present application and are not used to limit the present application.

[0063] Figure 1 This is a flowchart of a dual collaborative defense method for intelligent recognition and countermeasures of communication signal modulation provided in one embodiment of the present application;

[0064] Figure 2 This is a schematic diagram comparing the detection performance of different detection methods under the same attack provided in an embodiment of the present application;

[0065] Figure 3 1 is a schematic diagram comparing the recognition performance of adversarial sample recognition networks trained with different training algorithms under the same attack, provided in one embodiment of the present application;

[0066] Figure 4 This is a structural diagram of a dual collaborative defense system for intelligent recognition and countermeasures of communication signal modulation provided in another embodiment of the present application;

[0067] Figure 5 It is a structural diagram of an electronic device provided in another embodiment of the present application. DETAILED DESCRIPTION

[0068] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, each embodiment of the present application will be described in detail below with reference to the accompanying drawings. Those skilled in the art will appreciate that in each embodiment of the present application, many technical details are provided to enable the reader to better understand the present application. However, even without these technical details and various changes and modifications based on the following embodiments, the technical solutions claimed in the present application can be implemented. The division of the following embodiments is for convenience of description and should not constitute any limitation on the specific implementation of the present application. The various embodiments can be combined with each other and referenced to each other under the premise of no contradiction.

[0069] One embodiment of the present application proposes a dual collaborative defense method for intelligent identification and countermeasures against communication signal modulation, which is applied to an electronic device, where the electronic device can be a terminal or a server. This embodiment and the following embodiments are all described using a server as an example. The following is a detailed description of the implementation details of the dual collaborative defense method for intelligent identification and countermeasures against communication signal modulation proposed in this embodiment. The following content is only for the convenience of understanding the implementation details and is not required for the implementation of this solution.

[0070] The specific process of the dual cooperative defense method for communication signal modulation intelligent identification and confrontation proposed in this embodiment can be as follows: Figure 1 As shown, including:

[0071] S1, use the encoder to extract hidden features from the original sample and the constructed adversarial sample respectively, and train the adversarial autoencoder based on the extracted hidden features to obtain the adversarial sample detection network.

[0072] In the specific implementation, the server first obtains the original sample and constructs the adversarial sample, and then uses the encoder to extract hidden features from the original sample and the constructed adversarial sample respectively. Then, based on the extracted hidden features of the original sample and the hidden features of the constructed adversarial sample, the adversarial autoencoder is trained to obtain the adversarial sample detection network.

[0073] In one example, the server records the original sample set as x j Represents the jth original sample, and the constructed adversarial sample set is recorded as represents the jth adversarial example.

[0074] In one example, the server uses an encoder to extract hidden features from the original sample and the constructed adversarial sample, which can be achieved by the following formula:

[0075] H j =f e (W e x j +b e );

[0076]

[0077] Among them, f e (·) represents the activation function of the encoder, W e and b e are the weight term and bias term of the encoder respectively, δ j represents the optimal perturbation of the j-th adversarial example, H j represents the hidden features of the jth original sample, represents the hidden features of the j-th adversarial example.

[0078] In one example, when constructing an adversarial sample, the server needs to make the hidden feature H of the jth original sample j Hidden features of the jth adversarial sample The distance between them is the farthest to obtain the optimal perturbation δ j , which leads to the optimization problem of the optimal perturbation.

[0079] In one example, the optimization problem of the optimal perturbation is formulated as:

[0080]

[0081] stδ j∞ ≤ε j ;

[0082] Among them, ε j is the preset maximum disturbance, is the function for calculating distance.

[0083] In one example, the server uses the stochastic descent gradient method to optimize the optimization problem about the optimal perturbation. At the same time, ensure H j and The distance between them reaches the maximum, and the optimal perturbation δ is obtained. j , and finally by setting the optimal perturbation δ j Add to the jth original sample x j In the example, we can get the jth optimal adversarial sample

[0084] In one example, the adversarial sample detection network mainly consists of three parts: an encoder, a decoder, and a discriminator. The encoder also acts as a generator in the adversarial sample detection network. The training process of the adversarial sample detection network includes two stages: the reconstruction stage and the regularization stage.

[0085] For the reconstruction phase, the training goal is to train the encoder and decoder to learn an effective representation from the input data to the hidden features, and then reconstruct the original data from the hidden features. The goal of the reconstruction phase (that is, to ensure that the hidden features of the original sample are as similar as possible to the hidden features of the corresponding constructed adversarial sample) is achieved by introducing a feature loss L H Implementation, minimize the feature loss L during the training process of the reconstruction phase H Encouraging adversarial autoencoders to learn feature representations.

[0086] Feature loss L H It is expressed by the formula:

[0087]

[0088] In the sample space, the clean sample should be visually similar to the adversarial sample and more similar to the reconstructed sample of the adversarial sample. In order to improve the similarity between samples in the sample space, the server introduces the similarity reconstruction error loss L during the training process of the reconstruction phase. con .

[0089] Similarity reconstruction error loss L con It is expressed by the formula:

[0090]

[0091] in, represents the jth clean sample, represents the jth reconstructed sample, N represents the total number of clean samples, and the total number of reconstructed samples is the same as the total number of clean samples.

[0092] For the regularization stage, the training goal is to train the discriminator and generator so that the discriminator has the ability to accurately distinguish whether the input sample is from the output of the generator or a known true prior sample, and the sample generated by the generator is as close to the true prior sample as possible. Therefore, the server introduces the identification loss L in the regularization stage. Dand generation loss L G .

[0093] Identification loss L D and generation loss L G It is expressed by the formula:

[0094]

[0095] L G =-E x~X {log<G[E(x)]>};

[0096] Among them, D(x) represents the predicted probability of the discriminator D for the true prior sample x, D[G(z)] represents the predicted probability of the discriminator D for the fake sample G(z) generated by the generator G based on the noise z, and p data (x) represents the true sample distribution, p z (z) represents the normal distribution of the input noise of the generator G, D<G[E(x)]> represents the probability that the discriminator D judges the sample generated by the generator G as a true prior sample, X represents the original distribution, and l(·) represents the loss function for training the adversarial sample recognition network.

[0097] Based on the above two stages, the server alternately trains the discriminator and generator, thus achieving adversarial training and ultimately training an adversarial sample detection network. This allows the generator to generate samples that are increasingly close to the true distribution, while the discriminator continuously improves its ability to distinguish between real samples and generated samples.

[0098] S2 applies a dynamic search strategy to determine the adversarial perturbation radius, generates adversarial samples with customized labels, and trains an adversarial sample recognition network based on the adversarial samples with customized labels.

[0099] In the specific implementation, after the server completes the training of the adversarial sample detection network, it can apply the dynamic search strategy to determine the adversarial perturbation radius, generate adversarial samples with customized labels, and obtain the adversarial sample recognition network based on the adversarial samples with customized labels.

[0100] In one example, the server first needs to use the gradient of the loss function to the input sample to determine the adversarial perturbation δ f The disturbance direction of the counter-perturbation δ f The disturbance direction is expressed by the formula:

[0101]

[0102] Among them, δ n Represents the cumulative gradient of the nth iteration, β and μ are both dynamic factors, x+δ n represents the adversarial effect generated by the nth iteration, It represents the gradient of the loss of the nth iteration for the adversarial, sign(·) is the sign function, sign(δ f ) represents the adversarial perturbation δ f The direction of disturbance.

[0103] After determining the perturbation direction, the server can use the characteristics of the gradient of the loss function with respect to the input sample and the historical information of the gradient to construct the iterative step size and adjust the size of the adversarial perturbation. After completing the dynamic search, the optimal perturbation direction and optimal perturbation size are obtained.

[0104] Adjusting the size of the adversarial perturbation can be achieved through the following formula:

[0105] δ=[max min(δ,δ),-δ];

[0106] Among them, δ is the iteration step size.

[0107] After determining the perturbation direction and perturbation size under the infinite norm constraint, adversarial samples are generated by adding a certain size of perturbation to the input signal in the perturbation direction. This process is expressed as x adv =x+δ n , δ n That is, the optimal perturbation size after the dynamic search ends.

[0108] After completing the dynamic search, the server can add a perturbation of the optimal perturbation size in the optimal perturbation direction to the input sample to generate an adversarial sample. Finally, based on the original label, dynamically adjust the rate of increase or decrease of the perturbation radius, and dynamically adjust the search step size of the perturbation radius to generate a customized label for the adversarial sample and perform labeling.

[0109] In one example, the customized label of the adversarial example is formulated as:

[0110]

[0111] Among them, β represents the rate of increase or decrease of the dynamic adjustment perturbation radius, μ represents the search step size of the dynamic adjustment perturbation radius, y represents the original label, represents a uniform distribution over all labels, Represents the customized label of the adversarial example.

[0112] In one example, when a server trains an adversarial sample recognition network based on adversarial samples with customized labels, it first needs to select and train a basic model to perform the modulation recognition task. The objective function of the adversarial sample recognition network is expressed as follows:

[0113]

[0114] Where l(·) represents the loss function for training the adversarial sample recognition network, and f θ (·) represents the adversarial sample recognition network, and θ represents the network parameters of the adversarial sample recognition network.

[0115] Next, the server uses an adaptive hyperparameter algorithm to find the most accurate perturbation radius for each original sample, and generates adversarial samples with customized labels for the samples using the updated hyperparameters. The adversarial samples and original samples are mixed into a new training set, and the adversarial sample recognition network is iteratively trained using the new training set. At this point, the objective function of the adversarial sample recognition network is updated to:

[0116]

[0117] in, is x a ε a is the p-norm sphere of radius, represents the customized label of the adversarial sample, ε a is the perturbation radius of the a-th adversarial example.

[0118] Finally, the server optimizes the objective function of the updated adversarial sample recognition network and finally obtains the trained adversarial sample recognition network.

[0119] In S3, the adversarial sample detection network is used as the front network to perform adversarial detection on the input samples, and the adversarial sample recognition network is used as the back network to perform secondary defense on the input samples that escape the adversarial sample detection network and complete the modulation recognition task.

[0120] In the specific implementation, after the server completes the training of the adversarial sample detection network and the adversarial sample recognition network, it can use the adversarial sample detection network as the front network to perform adversarial detection on the input samples, and use the adversarial sample recognition network as the back network to perform secondary defense on the input samples that escape the adversarial sample detection network, and complete the modulation recognition task.

[0121] In one example, the server uses the adversarial sample detection network as the front-end network. When an input sample is fed into the front-end network, the reconstruction error of the input sample is calculated. Based on this error and the output of the discriminator, the server determines whether the input sample is an adversarial sample. Subsequently, the adversarial sample identification network is used as the back-end network to identify input samples that have not been identified as adversarial samples by the adversarial sample detection network, completing a secondary defense and achieving dual collaborative adversarial defense. The network also completes the modulation identification task and outputs the modulation identification type of the signal.

[0122] In an example, the decision condition for detecting adversarial examples can be expressed as:

[0123] Aresult =[L(X i )>ρ]∨[D(H)=0];

[0124] Among them, A result is the judgment result of the adversarial sample.

[0125] The dual collaborative defense method for intelligent identification and countermeasures of communication signal modulation proposed in this embodiment has the following beneficial effects.

[0126] First, this embodiment extracts hidden features of the sample through the encoder, generates adversarial samples using adversarial feature rules in the feature space, and trains an adversarial sample detection network. The adversarial sample detection network trained in this way has a high detection accuracy.

[0127] Second, this embodiment determines the adversarial perturbation radius through a dynamic search strategy and generates adversarial samples with customized labels to train the adversarial sample recognition network. The adversarial sample recognition network trained in this way has a high recognition accuracy.

[0128] Third, this embodiment uses the adversarial sample detection network as the front line of defense to detect potential adversarial samples, and uses the adversarial sample recognition network as the back line of defense to further resist escape samples, thereby achieving dual collaborative defense for modulation recognition tasks and effectively enhancing adversarial robustness.

[0129] The steps of the various methods described above are divided for clarity of description only. They can be combined into a single step, or some steps can be broken down into multiple steps. As long as they share the same logical relationships, they are all within the scope of protection of this application. Adding minor modifications or introducing minor design changes to the algorithm or process, but not changing the core design of the algorithm or process, is also within the scope of protection of this application.

[0130] In one embodiment, in order to evaluate the performance of a dual collaborative defense method for intelligent identification and countermeasures of communication signal modulation proposed in this application (hereinafter referred to as this method), we conducted relevant simulation experiments.

[0131] In the simulation experiment, a dual collaborative countermeasure defense system for communication signal modulation recognition is considered. The defense modulation recognition model is the ResNet network. The modulation signal types to be identified include a total of 8 digital signals, including 8PSK, QPSK, BPSK, GFSK, CPFSK, PAM4, QAM16 and QAM64, as well as two analog signals WBFM and AM-DSB.

[0132] The simulation parameters for studying the effect of disturbance level on attack performance are set as follows: the modulation signal-to-noise ratio is SNR = 10 dB, and the disturbance level ε is selected in the interval [0, 0.003] with an interval of 0.0003.

[0133] The simulation parameters for studying the impact of signal-to-noise ratio on attack performance were set as follows: the perturbation level was ε = 0.0015. The signal-to-noise ratio was selected within the range [-20, 18] with a 2dB interval. The simulation experiment used 1000 statistical iterations to verify performance.

[0134] The simulation results of this method are compared with the existing defense methods. Figure 2 、 Figure 3 shown. Figure 2 The detection performance diagram of different detection methods under the same attack is given in Figure 2 It can be seen that in the signal-to-noise ratio range of -18 to 20d, the AUC% value of the DSD method is higher than that of the other two detection algorithms, which shows that the detection performance of this method is better than that of the traditional detection methods. Figure 3 The recognition performance graph of the recognition model under the same attack and different training algorithms is given in Figure 3 It can be seen that in the signal-to-noise ratio range of 0 to 20 dB, the accuracy of the recognition model trained by the proposed method is always higher than that of other training methods, indicating that the recognition performance of the proposed method is better than that of the traditional training method.

[0135] Another embodiment of the present application proposes a dual collaborative defense system for intelligent identification and confrontation of communication signal modulation. The following is a detailed description of the dual collaborative defense system for intelligent identification and confrontation of communication signal modulation proposed in this embodiment. The following content is only for the convenience of understanding the implementation details and is not necessary for the implementation of this example. Figure 4 This is a structural diagram of a dual collaborative defense system for intelligent recognition and countermeasures of communication signal modulation proposed in this embodiment, including: an adversarial sample detection network training module M1, an adversarial sample recognition network training module M2 and a collaborative defense module M3.

[0136] The adversarial sample detection network training module M1 is used to use the encoder to extract hidden features from the original sample and the constructed adversarial sample respectively, and train the adversarial autoencoder based on the extracted hidden features to obtain the adversarial sample detection network.

[0137] The adversarial sample recognition network training module M2 is used to apply a dynamic search strategy to determine the adversarial perturbation radius, generate adversarial samples with customized labels, and train an adversarial sample recognition network based on the adversarial samples with customized labels.

[0138] The collaborative defense module M3 is used to use the adversarial sample detection network as the front-end network to perform adversarial detection on the input samples, and use the adversarial sample recognition network as the back-end network to perform secondary defense on the input samples that escape the adversarial sample detection network, and complete the modulation recognition task.

[0139] It is not difficult to find that this embodiment is a system embodiment corresponding to the above-mentioned method embodiment, and this embodiment can be implemented in conjunction with the above-mentioned method embodiment. The relevant technical details and technical effects mentioned in the above-mentioned embodiments are still valid in this embodiment, and to reduce repetition, they are not repeated here. Accordingly, the relevant technical details mentioned in this embodiment can also be applied to the above-mentioned embodiments.

[0140] It is worth mentioning that all modules involved in this embodiment are logical modules. In actual applications, a logical unit can be a physical unit, a part of a physical unit, or a combination of multiple physical units. In addition, to highlight the innovation of this application, this embodiment does not include units that are not closely related to solving the technical problem proposed by this application. However, this does not mean that other units do not exist in this embodiment.

[0141] Another embodiment of the present application provides an electronic device. The specific structure of the electronic device can be as follows: Figure 5 As shown, it includes: at least one processor C1; and a memory C2 communicatively connected to the at least one processor C1; wherein the memory C2 stores instructions that can be executed by the at least one processor C1, and the instructions are executed by the at least one processor C1 to enable the at least one processor C1 to execute a dual collaborative defense method for intelligent identification and confrontation of communication signal modulation as described in the above-mentioned method embodiments.

[0142] The memory and processor are connected using a bus, which includes any number of interconnected buses and bridges. The bus connects various circuits of one or more processors and memories. The bus can also connect various other circuits such as peripheral devices, voltage regulators, and power management circuits. These are all well known in the art and therefore will not be described further in this article. The bus interface provides an interface between the bus and the transceiver. The transceiver can be a single component or multiple components, such as multiple receivers and transmitters, providing a unit for communicating with various other devices on a transmission medium. Data processed by the processor is transmitted on a wireless medium via an antenna. Furthermore, the antenna also receives data and transmits it to the processor.

[0143] The processor is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interfaces, voltage regulation, power management, and other control functions. Memory can be used to store data used by the processor when performing operations.

[0144] Another embodiment of the present application proposes a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it can implement a dual collaborative defense method for intelligent identification and countermeasures of communication signal modulation as described in the above method embodiments.

[0145] That is, those skilled in the art will understand that all or part of the steps in the above-described embodiments can be implemented by instructing the relevant hardware through a program, which is stored in a storage medium and includes a number of instructions for causing a device (such as a single-chip microcomputer, chip, etc.) or a processor to execute all or part of the steps of the methods described in the various embodiments of the present application. Storage media include: U disk, mobile hard disk, read-only memory, random access memory, magnetic disk or optical disk, etc., various media that can store program code.

[0146] Those skilled in the art will appreciate that the above embodiments are specific embodiments for implementing the present application, and that in actual applications, various modifications may be made to the embodiments in form and detail without departing from the spirit and scope of the present application. Those skilled in the art will appreciate that improvements and modifications may be made without departing from the principles of the present application, and such improvements and modifications are also considered to be within the scope of protection of the present application.

Claims

1. A dual collaborative defense method for intelligent recognition and confrontation of communication signal modulation, characterized in that: The method comprises: The encoder is used to extract hidden features from the original sample and the constructed adversarial sample respectively, and based on the extracted hidden features, the adversarial autoencoder is trained to obtain the adversarial sample detection network; A dynamic search strategy is applied to determine the adversarial perturbation radius, generating adversarial samples with customized labels, and then an adversarial sample recognition network is trained based on the adversarial samples with customized labels. The adversarial sample detection network is used as the front-end network to perform adversarial detection on the input samples, and the adversarial sample recognition network is used as the back-end network to perform secondary defense on the input samples that escape the adversarial sample detection network and complete the modulation recognition task. Apply a dynamic search strategy to determine the adversarial perturbation radius and generate adversarial examples with customized labels, including: Use the gradient of the loss function to the input sample to determine the adversarial perturbation The disturbance direction, counter-disturbance The disturbance direction is expressed by the formula: ; in, Indicates the The cumulative gradient of the iteration, Indicates the rate at which the disturbance radius increases or decreases dynamically. Indicates the search step size for dynamically adjusting the perturbation radius, Indicates the The confrontation generated by the iteration, Indicates the The loss of the iteration is the gradient of the adversarial, is a symbolic function, Represents adversarial disturbance The direction of disturbance; By using the gradient characteristics of the loss function with respect to the input sample and the historical information of the gradient, the iterative step size is constructed and the size of the adversarial perturbation is adjusted. After the dynamic search is completed, the optimal perturbation direction and optimal perturbation size are obtained. Add the optimal perturbation size and optimal perturbation direction to the input sample to generate an adversarial sample; Generate customized labels for adversarial examples based on the original labels, dynamically adjust the rate at which the perturbation radius increases or decreases, and dynamically adjust the search step size of the perturbation radius. The customized label of the adversarial sample is expressed as: ; in, Indicates the original label, represents a uniform distribution over all labels, Represents a customized label for the adversarial example.

2. The dual collaborative defense method for communication signal modulation intelligent identification and confrontation according to claim 1 is characterized in that: The original sample set is denoted as , Indicates the original samples, and the constructed adversarial sample set is recorded as , Indicates the adversarial examples; The encoder is used to extract hidden features from the original sample and the constructed adversarial sample respectively, which is achieved by the following formula: ; ; in, represents the activation function of the encoder, and are the weight and bias terms of the encoder respectively, Indicates the The optimal perturbation of adversarial examples, Indicates the The hidden features of the original samples, Indicates the Hidden features of adversarial examples.

3. The dual collaborative defense method for communication signal modulation intelligent identification and confrontation according to claim 2 is characterized in that: By making the Hidden features of the original samples With the Hidden features of adversarial examples The distance between them is the farthest, and the optimal disturbance is obtained , we get the optimization problem about the optimal perturbation; The optimization problem of optimal perturbation is expressed as follows: ; ; in, is the preset maximum disturbance, is the function for calculating distance; The stochastic descent gradient method is used to optimize the optimization problem about the optimal perturbation. At the same time, ensure and The distance between them reaches the maximum, and the optimal disturbance is obtained , by changing the optimal perturbation Add to Original samples In the optimal adversarial examples .

4. The dual collaborative defense method for communication signal modulation intelligent identification and confrontation according to claim 3 is characterized in that: The adversarial sample detection network consists of three parts: an encoder, a decoder, and a discriminator. The encoder also acts as a generator in the adversarial sample detection network. The training process of the adversarial sample detection network includes two stages: the reconstruction stage and the regularization stage. For the reconstruction phase, the goal is to train the encoder and decoder to learn an effective representation from the input data to the hidden features, and then reconstruct the original data from the hidden features. The goal of the reconstruction phase is to introduce feature loss Implementation, minimize feature loss during training in the reconstruction phase Encourage adversarial autoencoders to learn feature representations; Feature loss It is expressed by the formula: ; In the sample space, the clean sample should be visually similar to the adversarial sample and more similar to the reconstructed sample of the adversarial sample. This is achieved by introducing the similarity reconstruction error loss during the training process of the reconstruction phase. Improve the similarity between samples in the sample space; Similarity reconstruction error loss It is expressed by the formula: ; in, Indicates the A clean sample, Indicates the Reconstructed samples, Represents the total number of clean samples. The total number of reconstructed samples is the same as the total number of clean samples. For the regularization stage, the goal is to train the discriminator and the generator so that the discriminator has the ability to accurately distinguish whether the input sample comes from the output of the generator or the known true prior sample, and the sample generated by the generator is as close to the true prior sample as possible. The goal of the regularization stage is to introduce the identification loss and generation loss accomplish; Identification loss and generation loss It is expressed by the formula: ; ; in, Representation Discriminator For the true prior sample The predicted probability of Representation Discriminator For the generator Noise-based Generated fake samples The predicted probability of represents the true sample distribution, Representation Generator The input noise is normally distributed, Representation Discriminator The generator The probability that the generated sample is judged to be a true prior sample, represents the original distribution; By alternately training the discriminator and the generator, adversarial training is achieved, and finally an adversarial sample detection network is trained.

5. The dual collaborative defense method for communication signal modulation intelligent identification and confrontation according to claim 1 is characterized in that: The adversarial sample recognition network is trained based on adversarial samples with customized labels, including: Select and train a basic model to perform the modulation recognition task; the objective function of the adversarial sample recognition network is expressed as follows: ; in, represents the loss function for training the adversarial sample recognition network, represents the adversarial sample recognition network, Represents the network parameters of the adversarial sample recognition network; Each original sample is subjected to an adaptive hyperparameter algorithm to find the most accurate perturbation radius. The updated hyperparameters are used to generate adversarial samples with customized labels for the samples. The adversarial samples and original samples are mixed into a new training set, and the adversarial sample recognition network is repeatedly trained using the new training set. At this point, the objective function of the adversarial sample recognition network is updated to: ; ; in, yes by is the p-norm sphere of radius, represents the customized label of the adversarial sample, For the The perturbation radius of the adversarial example; By optimizing the objective function of the updated adversarial sample recognition network, the trained adversarial sample recognition network is finally obtained.

6. The dual collaborative defense method for communication signal modulation intelligent identification and confrontation according to claim 5 is characterized in that: The adversarial sample detection network is used as the front-end network to perform adversarial detection on input samples. The adversarial sample recognition network is used as the back-end network to provide secondary defense against input samples that escape the adversarial sample detection network and complete the modulation recognition task, including: The adversarial sample detection network is used as the front network. When an input sample is input into the front network, the reconstruction error of the input sample is calculated. The reconstruction error of the input sample and the output of the discriminator are used to determine whether the input sample is an adversarial sample. The adversarial sample recognition network is used as a post-network to identify input samples that have not been determined as adversarial samples by the adversarial sample detection network to complete secondary defense, achieve dual collaborative adversarial defense, and complete the modulation recognition task, outputting the modulation recognition type of the signal.

7. A dual collaborative defense system for intelligent recognition and countermeasures of communication signal modulation, characterized in that: The system comprises: An adversarial sample detection network training module is used to extract hidden features from the original sample and the constructed adversarial sample using an encoder, and train an adversarial autoencoder based on the extracted hidden features to obtain an adversarial sample detection network; An adversarial sample recognition network training module, which applies a dynamic search strategy to determine the adversarial perturbation radius, generates adversarial samples with customized labels, and trains an adversarial sample recognition network based on the adversarial samples with customized labels. The collaborative defense module uses the adversarial sample detection network as the front-end network to perform adversarial detection on input samples, and uses the adversarial sample recognition network as the back-end network to perform secondary defense on input samples that escape the adversarial sample detection network and complete the modulation recognition task. Apply a dynamic search strategy to determine the adversarial perturbation radius and generate adversarial examples with customized labels, including: Use the gradient of the loss function to the input sample to determine the adversarial perturbation The disturbance direction, counter-disturbance The disturbance direction is expressed by the formula: ; in, Indicates the The cumulative gradient of the iteration, Indicates the rate at which the disturbance radius increases or decreases dynamically. Indicates the search step size for dynamically adjusting the perturbation radius, Indicates the The confrontation generated by the iteration, Indicates the The loss of the iteration is the gradient of the adversarial, is a symbolic function, Represents adversarial disturbance The direction of disturbance; By using the gradient characteristics of the loss function with respect to the input sample and the historical information of the gradient, the iterative step size is constructed and the size of the adversarial perturbation is adjusted. After the dynamic search is completed, the optimal perturbation direction and optimal perturbation size are obtained. Add the optimal perturbation size and optimal perturbation direction to the input sample to generate an adversarial sample; Generate customized labels for adversarial examples based on the original labels, dynamically adjust the rate at which the perturbation radius increases or decreases, and dynamically adjust the search step size of the perturbation radius. The customized label of the adversarial sample is expressed as: ; in, Indicates the original label, represents a uniform distribution over all labels, Represents a customized label for the adversarial example.

8. An electronic device, characterized in that: include: at least one processor; as well as, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute a dual collaborative defense method for intelligent identification and countermeasures of communication signal modulation as described in any one of claims 1 to 6.

9. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, it can implement a dual collaborative defense method for communication signal modulation intelligent identification and confrontation as described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Domain name generation method, device and equipment based on generative adversarial network

    CN114726823A

  • Abnormal behavior analysis method based on machine learning

    CN117407786A