A radio signal identification method based on time-frequency guide against sample purification

CN119807803BActive Publication Date: 2026-09-25ARMY ENG UNIV OF PLA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411726341.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-28
Publication Date
2026-09-25
Estimated Expiration
2044-11-28

AI Technical Summary

Technical Problem

现有的无线电信号对抗样本净化模块通常基于去噪模型(例如,去噪自编码器)或生成模型(例如,对抗生成网络)来实现,通常面临两个挑战:一是无线电信号中噪声和对抗扰动同时存在,对抗扰动淹没在噪声中导致在复杂噪声条件下的无线电信号对抗样本净化能力有限,后续信号识别性能欠佳;二是需要无线电信号对抗样本参与净化模块的训练,因此当面对未知的无线电对抗攻击时对抗样本净化能力受限,同样影响后续的信号识别性能

Benefits of technology

[0065]本发明与现有技术相比,其显著优点为:充分考虑了无线电信号的特点,在不改变原始信号识别模型的前提下,显著提高了识别模型在对抗样本攻击下的识别准确率。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119807803B_ABST
    Figure CN119807803B_ABST
Patent Text Reader

Abstract

The application discloses a radio signal identification method based on time-frequency guidance and an anti-sample purification method, acquires a radio signal data set, including a signal category label and a time-domain IQ signal sample, constructs a radio signal training set, and trains a signal identification model based on deep learning; according to a forward diffusion process of a diffusion model, gradually adds Gaussian noise to each sample in the radio signal training set, trains a noise predictor based on a neural network, adds an anti-perturbation simulation radio signal to be purified to a normalized radio signal test set, introduces a radio signal time-frequency semantic guidance item into a reverse process of the diffusion model, gradually samples and recovers from standard Gaussian noise by using the noise predictor, and obtains purified radio signals; and the purified radio signals are sent into a trained signal identification model for identification. The application significantly improves the identification accuracy of the identification model under an anti-sample attack.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of radio signal identification, and more particularly to a radio signal identification method based on time-frequency guided adversarial sample cleanup. Background Technology

[0002] Radio signal identification (RSI) is a key technology in modern wireless communication systems. It effectively monitors and manages spectrum resource usage, promptly identifies illegal signals and malicious intrusions, and ensures the security and reliability of wireless communication. Thanks to the development of deep learning technology, RSI has achieved automation and intelligence. By training neural network models, it automatically learns the characteristics of different signals, greatly improving the accuracy of signal identification.

[0003] However, researchers have discovered that deep learning models are inherently vulnerable to adversarial perturbations. Malicious signal sources can meticulously design these tiny, imperceptible perturbations, generating so-called adversarial perturbations, and add them to the original signal, thereby deceiving the signal recognition model into making incorrect predictions. This attack process is known as a radio signal adversarial attack; the original signal is called a benign radio signal sample, while the attacked signal is called an adversarial radio signal sample. Under radio signal adversarial attacks, the vulnerability of deep recognition models not only affects the accuracy of radio signal recognition but also poses a serious threat to the security of wireless communication systems.

[0004] To mitigate the malicious deception of radio signal recognition models by adversarial attacks, research on radio signal adversarial defense techniques has emerged, which can be categorized into three types: adversarial training, adversarial example detection, and adversarial example sanitization. Adversarial example training incorporates adversarial examples into the training phase of the recognition model, simultaneously improving the model's structure and proactively enhancing its robustness. This defense method requires reconfiguring the radio signal recognition model and typically only provides good defense against adversarial examples involving data augmentation, exhibiting poor generalization. Adversarial example detection does not require retraining the recognition model; it quickly rejects adversarial examples by constructing a detector. However, undetected adversarial examples can still severely impact the model. Unlike these methods, adversarial example sanitization reconstructs the input samples by inserting additional modules. The sanitized radio signals are then input into the signal recognition model without requiring retraining. Existing adversarial sample cleanup modules for radio signals are typically based on denoising models (e.g., denoising autoencoders) or generative models (e.g., adversarial generative networks). They usually face two challenges: First, noise and adversarial perturbations coexist in radio signals, and the adversarial perturbations are submerged in noise, resulting in limited adversarial sample cleanup capabilities under complex noise conditions and poor subsequent signal recognition performance. Second, adversarial samples of radio signals are required to participate in the training of the cleanup module. Therefore, when facing unknown adversarial attacks, the adversarial sample cleanup capability is limited, which also affects the subsequent signal recognition performance. Summary of the Invention

[0005] The purpose of this invention is to propose a radio signal identification method based on time-frequency guided adversarial sample cleanup.

[0006] The technical solution for achieving the objective of this invention is: a radio signal identification method based on time-frequency guided adversarial sample decontamination, comprising the following steps:

[0007] Step 1: Obtain a radio signal dataset, including signal category labels and time-domain IQ signal samples, construct a radio signal training set, and train a deep learning-based signal recognition model.

[0008] Step 2: According to the forward diffusion process of the diffusion model, Gaussian noise is gradually added to each sample in the radio signal training set to train a noise predictor based on a neural network.

[0009] Step 3: Add the radio signal to be cleaned to the normalized radio signal test set to simulate anti-disturbance, introduce the radio signal time-frequency semantic guidance term into the reverse process of the diffusion model, and use the noise predictor to gradually sample and recover from the standard Gaussian noise to obtain the cleaned radio signal.

[0010] Step 4: The purified radio signal is sent to the trained signal recognition model for recognition.

[0011] Further, in step 1, a radio signal dataset is obtained, including signal categories and time-domain IQ signal samples, and a deep learning-based signal recognition model is trained. The specific method is as follows:

[0012] Step 1.1: Obtain the radio signal dataset, including signal category labels and various time-domain I and Q signal samples; set the signal category labels to 0, 1, ..., N-1, where N represents the number of categories; for each radio signal sample, concatenate its I and Q signals into a data set of size [2, L], where the first row represents the I signal, the second row represents the Q signal, and L represents the number of sampling points for the radio signal sample; for each original radio signal sample x... ori Normalize using its effective value;

[0013] The formula for calculating the effective value is as shown in equation (1):

[0014]

[0015] in, and These represent the i-th sampling points of the original radio I-channel signal and Q-channel signal, respectively;

[0016] The normalization calculation formula is shown in equation (2):

[0017] x = x ori / e rms (2) Construct a radio signal training set using the normalized radio signals;

[0018] Step 1.2: Train a deep learning-based signal recognition model. The deep learning-based signal recognition model uses ResNet18 as the basic network. The input of the network is the normalized radio signal with an input size of [B, 1, 2, L], where B represents the batch size of the training data. The output is the predicted probability of belonging to each category with an output size of [B, N]. The category with the highest probability is taken as the predicted signal category.

[0019] Furthermore, when training the deep learning-based signal recognition model, the loss function is the cross-entropy loss function, the learning rate is 0.001, the optimizer is Adam, the batch size of the training data is 128, and the number of training iterations is 50.

[0020] Further, in step 2, based on the forward diffusion process of the diffusion model, Gaussian noise is progressively added to each sample in the radio signal training set to train a neural network-based noise predictor. The specific method is as follows:

[0021] Step 2.1: Based on the forward diffusion process of the diffusion model, let T represent the total number of steps in the forward diffusion process. Take the normalized radio signal x in the training set as the initial radio signal sample x0, and gradually add standard Gaussian noise to x0 to obtain a series of radio signal forward latent variables x. t ,t=1,2,...,T, where:

[0022] The transition probability q(x) of the forward hidden variable of the radio signal at each step t |x t-1 () is a Gaussian distribution centered on its previous latent variables, whose mean and variance are a series of predefined hyperparameters, as shown in (3):

[0023]

[0024] Where, β t ,t=1,2,...,T is a linearly increasing constant, and ∈ is noise that follows a standard Gaussian distribution;

[0025] Define α t =1-β t , The forward latent variable x of the radio signal at step t is directly calculated from the normalized radio signal x0. t ~q(x t |x0), the calculation formula is shown in (4):

[0026]

[0027] x t ~q(x t |x0) follows the mean of variance is The Gaussian distribution of the radio signal, at t=T, the forward latent variable x T It follows a standard Gaussian distribution;

[0028] Step 2.2: Train a noise predictor based on a neural network. The input to the noise predictor is the forward latent variable x of the radio signal calculated by equation (4). t And the current diffusion step t, the output is with x t Prediction noise of the same size ∈ θ (x t ,t), expected prediction noise ∈ θ (x t The smaller the difference between (t) and the currently added standard Gaussian noise, the better.

[0029] Furthermore, a noise predictor is set up based on the DiffWave network architecture, expanding the input dimension of DiffWave from a single channel [B,1,1,L] to adapt to the I and Q dual channels [B,1,2,L] of radio signals, where B represents the batch size of training data and L represents the number of sampling points of radio signal samples.

[0030] Furthermore, when training the neural network-based noise predictor, the loss function is shown in equation (5):

[0031]

[0032] The total number of diffusion steps T is set to 200, β t The training data is set to a uniformly linearly increasing constant with an initial value of 0.0001 and an ending value of 0.02, a learning rate of 0.0002, an optimizer of Adam, a batch size of 128, and 100,000 iterations.

[0033] Further, in step 3, an adversarial disturbance simulation of the radio signal to be cleaned is added to the radio signal test set. The time-frequency semantic guidance term of the radio signal is introduced into the inverse process of the diffusion model. Using a noise predictor, the cleaned radio signal is gradually sampled and recovered from standard Gaussian noise. The specific method is as follows:

[0034] Step 3.1: Using the trained signal recognition model as the attack model, add adversarial perturbations to the normalized radio signal test set data, creating adversarial sample x to be cleaned. adv ;

[0035]

[0036] In the formula, L model (x,y) represents the loss function of the signal recognition model, x represents the normalized radio signal data, y represents the corresponding class label, sign(·) represents the sign function, ε represents the magnitude of the adversarial disturbance, and the relationship between ε and the signal-to-scratching ratio (SPR) is as follows:

[0037] SPR = log(P) signal / P perturb (7)

[0038]

[0039] Step 3.2: Introduce the temporal and frequency domain semantics of the adversarial sample into the reverse process of the diffusion model to gradually generate the purified radio signal from the standard Gaussian noise.

[0040] First, calculate the radio signal generated in reverse without guidance, starting at step T, and convert the standard Gaussian noise. The number of steps, T, is input into the pre-trained noise predictor to obtain the predicted noise value. Based on recursive formula (10), the inverse hidden variables of the radio signal are calculated step by step.

[0041]

[0042] Then, the log probability distribution gradient of the radio signal to be fitted under adversarial sample conditions during the reverse cleanup process is calculated. According to Bayes' theorem, it can be expressed as equation (11):

[0043]

[0044] In the formula, p(x) adv ) represents the distribution of adversarial samples in the radio signals to be cleaned. The gradient is 0; The distribution of the inverse latent variable of a radio signal, its log probability distribution relative to... The gradient is related to the predicted noise, i.e. Equivalent to Let be the distribution of adversarial examples of radio signals under the condition of inverse latent variables, representing the probability that the inverse latent variables of radio signals are close to the semantics of adversarial examples of radio signals, and let its logarithmic probability distribution be relative to gradient Treating this as a guiding term based on the adversarial sample of the radio signal to be cleaned, the guiding term is introduced into the noise prediction, and the noise prediction formula under the guidance is shown in Equation (12):

[0045]

[0046] Replace the noise in equation (10) with equation (12). Furthermore, the reverse purification recursive formula based on adversarial examples guided by the radio signal to be purified is uniformly expressed as the calculation formula (13):

[0047]

[0048] In the formula, and Let represent the inverse latent variables of the radio signal guided at steps t-1 and t, respectively. For the inverse latent variables of the radio signal guided at step T, sampling is performed from a standard Gaussian distribution, i.e. g is the guiding term based on the adversarial example of the radio signal to be cleaned. The guiding term is scaled by the scaling factor s to control the degree of dependence on the guiding information when cleaning the adversarial example of the radio signal.

[0049] Next, in each step of the reverse purification, the guided reverse latent variables are gradually approximated to the semantics of the adversarial sample in the current diffusion step in both the time and frequency domains. Specifically, the adversarial sample x to be purified is calculated according to equation (4). adv The t-th step forward hidden variable Forward latent variables of adversarial samples With the guidance of inverse hidden variables The Manhattan distance metric measures the degree of proximity between two entities under certain conditions.

[0050] In the time-domain guidance of adversarial examples of radio signals, the time-domain guidance term at step t... The calculation formula is shown in equation (14):

[0051]

[0052] In the formula, ||·||1 represents the calculation of the L1 norm, which is equivalent to calculating the Manhattan distance;

[0053] The time-domain guided scaling factor is defined as an increasing factor related to t. The scaling factor of the time-domain guiding term The calculation formula is shown in equation (15):

[0054]

[0055] In the frequency domain guidance of adversarial examples of radio signals, the inverse latent variables are respectively... Forward latent variables of adversarial examples to be cleaned Perform a short-time Fourier transform and use the Manhattan distance to obtain the frequency domain guiding term at spread step t. The calculation formula is shown in equation (16):

[0056]

[0057] Scale factor after frequency domain transformation The calculation formula is shown in equation (17):

[0058]

[0059] Combining equations (13) to (17), the recursive formula for reverse purification based on time-frequency guidance is shown in equation (18):

[0060]

[0061] Through step-by-step iteration, the purified radio signal sample was finally obtained.

[0062] A radio signal identification system based on time-frequency guided adversarial sample decontamination is provided, which implements the radio signal identification method based on time-frequency guided adversarial sample decontamination to achieve radio signal identification based on time-frequency guided adversarial sample decontamination.

[0063] A computer device includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the radio signal identification method based on time-frequency guided adversarial sample decontamination, thereby achieving radio signal identification based on time-frequency guided adversarial sample decontamination.

[0064] A computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, the radio signal identification method based on time-frequency guided adversarial sample decontamination is implemented to achieve radio signal identification based on time-frequency guided adversarial sample decontamination.

[0065] Compared with the prior art, the significant advantages of this invention are: it fully considers the characteristics of radio signals and significantly improves the recognition accuracy of the recognition model under adversarial sample attacks without changing the original signal recognition model. Attached Figure Description

[0066] Figure 1 This is a system framework diagram of the present invention.

[0067] Figure 2 This is a comparison chart of the recognition accuracy under different SPR conditions with and without purification of three purification methods in the embodiments of the present invention.

[0068] Figure 3 This is a comparison chart of the recognition accuracy under different SNR conditions in this invention, with no purification and three purification methods. Detailed Implementation

[0069] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0070] like Figure 1 As shown, this invention is a novel radio signal identification method based on time-frequency guided adversarial sample decontamination, and the specific steps are as follows:

[0071] Step 1: Obtain the radio signal dataset and train the signal recognition model using the radio signal training set;

[0072] Step 1.1: Obtain the radio signal dataset, including signal category labels and various time-domain I and Q signal samples. Set the category labels to 0, 1, ..., N-1, where N represents the number of categories. For each radio signal sample, concatenate its I and Q signals into a data set of size [2, L], where the first row represents the I signal, the second row represents the Q signal, and L represents the number of sampling points for the radio signal sample; for each original radio signal sample x... ori Normalize using its effective value;

[0073] The formula for calculating the effective value is as shown in equation (1):

[0074]

[0075] in, and These represent the i-th sampling points of the original radio I-channel signal and Q-channel signal, respectively;

[0076] The normalization calculation formula is shown in equation (2):

[0077] x = x ori / e rms (2)

[0078] A radio signal training set is constructed using the normalized radio signals;

[0079] Step 1.2: Train the signal recognition model. The radio signal training set data is used as benign radio signal samples. A deep learning-based signal recognition model is trained using these samples. The trained signal recognition model will not be modified subsequently. This invention does not specify requirements for the neural network model; in this specific implementation, ResNet18 is used as the basic network for the recognition model. The network input is the normalized radio signal, with an input size of [B, 1, 2, L], where B represents the batch size of the training data. The network output is the predicted probability of belonging to each category, with an output size of [B, N]. The category with the highest probability is taken as the signal category predicted by the recognition model. The loss function of the recognition model is the cross-entropy loss function. The training parameters of the recognition model are: learning rate of 0.001, optimizer of Adam, batch size of training data of 128, and number of training iterations of 50.

[0080] Step 2: Gaussian noise is gradually added to each sample in the radio signal training set according to the forward diffusion process of the diffusion model, and a neural network-based noise predictor is trained to learn the noise value added at each step.

[0081] Step 2.1: Based on the forward diffusion process of the diffusion model, let T represent the total number of steps in the forward diffusion process. Take the normalized radio signal x in the training set as the initial radio signal sample x0, and gradually add standard Gaussian noise to x0 to obtain a series of radio signal forward latent variables x. t ,t=1,2,...,T.

[0082] Specifically, the transition probability q(x) of the forward hidden variable of the radio signal at each step t |x t-1 The distribution is a Gaussian distribution centered on its previous latent variables, and its mean and variance are a series of predefined hyperparameters. The calculation formula is shown in (3):

[0083]

[0084] Where, β t ,t=1,2,...,T is a linearly increasing constant, and ∈ is noise that follows a standard Gaussian distribution;

[0085] Furthermore, define α t =1-β t and The forward latent variable x of the radio signal at step t can be directly calculated from the normalized radio signal x0. t ~q(x t |x0), the calculation formula is shown in (4):

[0086]

[0087] x t ~q(x t |x0) follows the mean of variance is The Gaussian distribution of the signal. Specifically, since the total number of forward diffusion steps T is sufficiently large, the forward hidden variable x of the radio signal at t = T... T It follows a standard Gaussian distribution.

[0088] Step 2.2, learn the distribution of radio signal data p θ The process of (x0) is equivalent to minimizing the distance from x0 to x at each step t. t Added real noise value and estimated noise value ∈ θ (x t The difference between x0 and x is calculated. Therefore, a neural network is constructed as a noise predictor to estimate the difference between x0 and x. t Added noise value ∈ θ (x t ,t), expected prediction noise ∈ θ (x tThe smaller the difference between (t) and the currently added standard Gaussian noise, the better.

[0089] The noise predictor network input in this invention is the radio signal forward latent variable x calculated by equation (4). t And the current diffusion step t, the output is with x t Prediction noise of the same size ∈ θ (x t ,t), representing the predicted forward latent variable x from the original radio signal x0 to the radio signal x0. t Added noise values. Generally, any neural network architecture that allows this type of input and output can serve as a noise predictor. In a specific implementation of this invention, a noise predictor is set up based on the existing DiffWave network architecture, extending the input dimension of DiffWave from a single channel [B,1,1,L] to a dual I and Q channel [B,1,2,L] adapted to radio signals. Further, the loss function during the training phase of the noise predictor is shown in equation (5):

[0090]

[0091] In the formula, ∈ θ (x t ,t) is the network output, and the noise ∈, which follows a standard Gaussian distribution, is the label.

[0092] On the radio signal training set, the training parameters for the noise predictor are: the total number of diffusion steps T is set to 200, β... t The training data is set to a uniformly linearly increasing constant with an initial value of 0.0001 and an ending value of 0.02, a learning rate of 0.0002, an optimizer of Adam, a batch size of 128, and 100,000 iterations.

[0093] Step 3: Add anti-disturbance simulated radio signals to the radio signal test set, introduce the proposed radio signal time-frequency semantic guidance term into the inverse process of the diffusion model, and use a noise predictor to gradually sample and recover from standard Gaussian noise to obtain the purified radio signal; the radio signal test set and the pre-training set are constructed using the same processing method, and the radio signal data is normalized based on the effective value.

[0094] Step 3.1, in a specific implementation of the present invention, adds adversarial samples x of the radio signals to be cleaned, simulating anti-disturbance, to the radio signal test set. adv .

[0095] Specifically, taking the Fast Gradient Sign Method (FGSM) radio signal adversarial attack as an example: on the radio signal test set data, the trained signal recognition model is used as the attack model, and the FGSM adversarial sample of the radio signal is calculated according to Equation (6), and it is used as the radio signal adversarial sample to be cleaned.

[0096]

[0097] In the formula, L model (x,y) is the loss function of the signal recognition model, x is the normalized radio signal data, y is the corresponding category label, sign(·) represents the sign function, and ε is the magnitude of the adversarial disturbance. Furthermore, this invention proposes the definition of the signal-to-perturbation ratio (SPR) based on the signal power and the disturbance power to determine the magnitude of the adversarial disturbance, and the relevant calculation formulas are equations (7) to (9).

[0098] SPR = log(P) signal / P perturb (7)

[0099]

[0100] Step 3.2 involves introducing the temporal and frequency domain semantics of the adversarial sample into the reverse process of the diffusion model to gradually generate the purified radio signal from the standard Gaussian noise.

[0101] First, calculate the radio signal generated in reverse without guidance. The initial step is T, using standard Gaussian noise. The number of steps, T, is input into the pre-trained noise predictor to obtain the predicted noise value. Based on recursive formula (10), the inverse hidden variables of the radio signal are calculated step by step.

[0102]

[0103] Then, treating the adversarial examples of radio signals to be cleaned as conditions, the logarithmic probability distribution gradient of the adversarial examples of radio signals to be fitted during the reverse cleanup process is... According to Bayes' theorem, it can be expressed as equation (11):

[0104]

[0105] In the formula, p(x) adv ) represents the distribution of adversarial samples of the radio signals to be cleaned, since it is an inverse latent variable of the radio signals. It is irrelevant, therefore it is relative to the derivation. The gradient is 0; The distribution representing the inverse latent variable of radio signals has been shown in studies to have a logarithmic probability distribution relative to... The gradient is related to the predicted noise, i.e. Equivalent to Let be the distribution of adversarial examples of radio signals under the condition of inverse latent variables, representing the probability that the inverse latent variables of radio signals are close to the semantics of adversarial examples of radio signals, and let its log probability distribution be relative to gradient Treating this as a guiding term based on the adversarial sample of the radio signal to be cleaned, the guiding term is introduced into the noise prediction, and the noise prediction formula under the guidance is shown in Equation (12):

[0106]

[0107] Replace the noise in equation (10) with equation (12). Furthermore, the reverse purification recursive formula based on adversarial examples guided by the radio signal to be purified is uniformly expressed as the calculation formula (13):

[0108]

[0109] In the formula, and Let represent the inverse latent variables of the radio signal guided at steps t-1 and t, respectively. For the inverse latent variables of the radio signal guided at step T, sampling is performed from a standard Gaussian distribution, i.e. g represents the guiding term based on the adversarial example of the radio signal to be cleaned. The guiding term is scaled using a scaling factor s to control the degree of dependence on guiding information during the cleanup of the adversarial example of the radio signal.

[0110] Next, in each step of the reverse cleanup, the encouraged and guided reverse latent variables gradually approach the semantics of the adversarial example in the current diffusion step in both the time and frequency domains.

[0111] Specifically, the adversarial sample x to be purified is calculated according to equation (4). adv The t-th step forward hidden variable Forward latent variables of adversarial samples With guided inverse hidden variables The Manhattan distance metric measures the degree of proximity between two entities.

[0112] In the time-domain guidance of adversarial examples of radio signals, the time-domain guidance term at step t... The calculation formula is shown in equation (14):

[0113]

[0114] In the initial stage of reverse purification, t is close to T. Approaching standard Gaussian noise, the negative impact of adversarial disturbances on the radio signal is relatively small. It is desirable that the proportion of the adversarial sample guiding term in the radio signal is sufficiently large, implying that the guided radio signal has inverse latent variables. The closer The better the semantics. In the later stages of guiding reverse cleanup, Approximate radio signal adversarial sample x adv At this point, it is desirable to reduce the weight of the guiding term to avoid residual anti-disturbances in the purified radio signal. Therefore, this invention defines the time-domain scaling factor as an increasing factor related to t. The scaling factor of the time-domain guiding term The calculation formula is shown in equation (15):

[0115]

[0116] In the frequency domain guidance of adversarial examples of radio signals, the inverse latent variables of the guidance are respectively... Forward latent variables of adversarial examples to be cleaned For the Short-Time Fourier Transform (SFT), the relevant parameters used in this invention are: FFT points set to 64, window length set to 64, and adjacent window interval set to 4. The frequency domain guiding term at diffusion step t is used, utilizing the Manhattan distance. The calculation formula is shown in equation (16):

[0117]

[0118] The scaling factor after frequency domain transformation is calculated using the formula shown in equation (17):

[0119]

[0120] Combining equations (13) to (17), the reverse purification recursive formula based on time-frequency guidance proposed in this invention is shown in equation (18):

[0121]

[0122] Through step-by-step iteration, the purified radio signal sample was finally obtained.

[0123] Step 4, convert the purified radio signal x puri The signal is fed into the signal recognition model trained in step 1 for recognition.

[0124] Example

[0125] To verify the effectiveness of this invention, in the task of modulation signal type identification, experiments were conducted using the publicly available radio modulation signal dataset RML2016.10a, based on the Python language and PyTorch framework. In this embodiment, firstly, the dataset was normalized and partitioned according to step 1, and a radio signal modulation mode identification model with ResNet as the network architecture was trained. Secondly, according to step 2, a noise predictor with an improved Diffwave network architecture was trained to learn the distribution of benign samples of radio modulation signals. Then, according to step 3, adversarial samples to be cleaned were generated using radio signal FGSM attacks based on the test set data. Guided by the time-domain and frequency-domain semantics of the adversarial samples to be cleaned, the cleaned signal was generated using the inverse process of the diffusion model. Finally, in step 4, the cleaned signal was fed into the modulation mode identification model for identification. Figure 2 The effectiveness of the proposed method was verified by comparing the recognition accuracy of the method under different SPR conditions with no purification and three purification methods when the SNR was 10dB. Figure 3 The effectiveness of the proposed method was verified by comparing the recognition accuracy under different SNR conditions at an SPR of 10 dB with and without sanitization, as well as with three sanitization methods. The results demonstrate that the proposed method can effectively sanitize and counteract disturbances under complex attack strength and noise levels, significantly improving the recognition accuracy of the sanitized signal.

[0126] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0127] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these modifications and improvements all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.

Claims

1. A radio signal identification method based on time-frequency guided adversarial sample decontamination, characterized in that, Includes the following steps: Step 1: Obtain a radio signal dataset, including signal category labels and time-domain IQ signal samples, construct a radio signal training set, and train a deep learning-based signal recognition model. Step 2: Based on the forward diffusion process of the diffusion model, Gaussian noise is gradually added to each sample in the radio signal training set to train a neural network-based noise predictor. The specific method is as follows: Step 2.1, based on the forward diffusion process of the diffusion model, using... This represents the total number of steps in the forward diffusion process, and the radio signal normalized from the training set. As initial radio signal sample ,Towards By progressively adding standard Gaussian noise, a series of forward hidden variables of the radio signal are obtained. ,in: The transition probability of the forward hidden variable at each step of the radio signal It is a Gaussian distribution centered on its previous latent variables, whose mean and variance are a series of predefined hyperparameters, as shown in (3): (3); in, It is a linearly increasing constant. For noise that conforms to a standard Gaussian distribution; definition , Directly from the normalized radio signal Calculate the first Forward hidden variables of step radio signals The calculation formula is shown in (4): (4); Follow the mean The variance is Gaussian distribution, in At that time, the forward hidden variable of the radio signal It follows a standard Gaussian distribution; Step 2.2: Train a noise predictor based on a neural network. The input to the noise predictor is the forward latent variable of the radio signal calculated by equation (4). and the current diffusion step The output is the same as Predicted noise of the same size Expected Predicted Noise The smaller the difference from the currently added standard Gaussian noise, the better; Step 3: Add the anti-disturbance simulated radio signal to the normalized radio signal test set. Introduce the time-frequency semantic guidance term of the radio signal into the inverse process of the diffusion model. Using a noise predictor, gradually sample and recover the purified radio signal from standard Gaussian noise to obtain the purified radio signal. The specific method is as follows: Step 3.1: Using the trained signal recognition model as the attack model, adversarial perturbations are added to the normalized radio signal test set data to create adversarial samples for purification. ; (6); In the formula, Let the loss function of the signal recognition model be... For normalized radio signal data, For the corresponding category label, Represents a symbolic function. To counteract the magnitude of the disturbance, The relationship with the signal-to-scratching ratio (SPR) is as follows: (7); (8); (9); Step 3.2: Introduce the temporal and frequency domain semantics of the adversarial sample into the reverse process of the diffusion model to gradually generate the purified radio signal from the standard Gaussian noise. First, calculate the radio signal generated in reverse without guidance, starting with the following step. Standard Gaussian noise and steps The input is fed into a pre-trained noise predictor to obtain the predicted noise value. Based on recursive formula (10), the inverse hidden variables of the radio signal are calculated step by step. ; (10); Then, the log probability distribution gradient of the radio signal to be fitted under adversarial sample conditions during the reverse cleanup process is calculated. According to Bayes' theorem, it can be expressed as equation (11): (11); In the formula, This represents the distribution of adversarial examples in the radio signals to be cleaned, for The gradient is 0; The distribution of the inverse latent variable of a radio signal, its log probability distribution relative to... The gradient is related to the predicted noise, i.e. Equivalent to ; Let be the distribution of adversarial examples of radio signals under the condition of inverse latent variables, representing the probability that the inverse latent variables of radio signals are close to the semantics of adversarial examples of radio signals, and let its log probability distribution be relative to gradient Treating this as a guiding term based on the adversarial sample of the radio signal to be cleaned, the guiding term is introduced into the noise prediction, and the noise prediction formula under the guidance is shown in Equation (12): (12); Replace the noise in equation (10) with equation (12). Furthermore, the reverse purification recursive formula based on adversarial sample guidance of the radio signal to be purified is uniformly expressed as the calculation formula (13): (13); In the formula, and Let represent the inverse latent variables of the radio signal guided at steps t-1 and t, respectively. For the inverse latent variables of the radio signal guided at step T, sampling is performed from a standard Gaussian distribution, i.e. ; For the guiding term of adversarial examples based on the radio signals to be cleaned, the scaling factor is used. Scaling the bootstrap term controls the degree to which radio signals rely on bootstrap information during adversarial sample cleanup. Next, in each step of the reverse purification, the guided reverse latent variables are gradually approximated to the semantics of the adversarial sample in the current diffusion step in both the time and frequency domains. Specifically, the adversarial sample to be purified is calculated according to equation (4). The Forward hidden variables To counteract the forward latent variables of the samples With the guidance of inverse hidden variables The Manhattan distance metric measures the degree of proximity between two entities under certain conditions. In the time-domain guidance of adversarial examples of radio signals, the first Step-by-step time-domain guidance item The calculation formula is shown in equation (14): (14); In the formula, express Norm calculation is equivalent to calculating Manhattan distance; The time-domain guiding scaling factor is defined as... Related increasing The scaling factor of the time-domain guided term. The calculation formula is shown in equation (15): (15); In the frequency domain guidance of adversarial examples of radio signals, the inverse latent variables are respectively... Forward latent variables of adversarial examples to be cleaned Perform a short-time Fourier transform, using Manhattan distance and diffusion step Frequency domain guidance term The calculation formula is shown in equation (16): (16); Scale factor after frequency domain transformation The calculation formula is shown in equation (17): (17); Combining equations (13) to (17), the time-frequency guided reverse purification recursive formula is shown in equation (18): (18); Through step-by-step iteration, the purified radio signal sample was finally obtained. ; Step 4: The purified radio signal is sent to the trained signal recognition model for recognition.

2. The radio signal identification method based on time-frequency guided adversarial sample decontamination according to claim 1, characterized in that, Step 1: Obtain a radio signal dataset, including signal categories and time-domain IQ signal samples, and train a deep learning-based signal recognition model. The specific method is as follows: Step 1.1: Obtain the radio signal dataset, including signal category labels and various time-domain IQ signal samples; set the signal category labels to... N represents the number of categories; for each radio signal sample, its I and Q signals are concatenated as follows: The data represents the magnitude of the signals, where the first row indicates the I-channel signals and the second row indicates the Q-channel signals. This represents the number of sampling points for each radio signal sample; for each original radio signal sample Normalize using its effective value; The formula for calculating the effective value is as shown in equation (1): (1); in, and These represent the first and second channels of the original radio I-channel and Q-channel signals, respectively. One sampling point; The normalization calculation formula is shown in equation (2): (2); A radio signal training set is constructed using the normalized radio signals; Step 1.2: Train a deep learning-based signal recognition model. The deep learning-based signal recognition model uses ResNet18 as the base network. The network input is the normalized radio signal, and the input size is... ,in This indicates the batch size of the training data, and the output is the predicted probability of belonging to each class, with an output size of [size missing]. The category with the highest probability is selected as the predicted signal category.

3. The radio signal identification method based on time-frequency guided adversarial sample decontamination according to claim 2, characterized in that, When training a deep learning-based signal recognition model, the loss function is the cross-entropy loss function, the learning rate is 0.001, the optimizer is Adam, the batch size of the training data is 128, and the number of training iterations is 50.

4. The radio signal identification method based on time-frequency guided adversarial sample decontamination according to claim 1, characterized in that, A noise predictor is set up based on the DiffWave network architecture, reducing the input dimension of DiffWave from a single channel. Extended to accommodate radio signals with I and Q dual channels , Indicates the batch size of the training data. This indicates the number of sampling points for a radio signal sample.

5. The radio signal identification method based on time-frequency guided adversarial sample decontamination according to claim 1, characterized in that, When training a noise predictor based on a neural network, the loss function is shown in equation (5): (5); Total diffusion steps Set to 200. The training data is set to a uniformly linearly increasing constant with an initial value of 0.0001 and an ending value of 0.02, a learning rate of 0.0002, an optimizer of Adam, a batch size of 128, and 100,000 iterations.

6. A radio signal identification system based on time-frequency guided adversarial sample decontamination, characterized in that, Implement the radio signal identification method based on time-frequency guided adversarial sample purification as described in any one of claims 1-5 to achieve radio signal identification based on time-frequency guided adversarial sample purification.

7. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, it implements the radio signal identification method based on time-frequency guided adversarial sample decontamination as described in any one of claims 1-5, thereby realizing radio signal identification based on time-frequency guided adversarial sample decontamination.

8. A computer-readable storage medium having a computer program stored thereon, wherein when the computer program is executed by a processor, it implements the radio signal identification method based on time-frequency guided adversarial sample decontamination as described in any one of claims 1-5, thereby realizing radio signal identification based on time-frequency guided adversarial sample decontamination.

Citation Information

Patent Citations

  • Defense method for radio signal identification countermeasure attacks

    CN111428817A

  • Next generation broadcast system and method

    WO2015048569A2