Backdoor attack method and device for communication signal modulation type identification and evaluation method

By building a data set in the communication signal modulation type recognition, training a classifier model and adding anti-perturbation and high-frequency interference processing, the problem of backdoor attack in the existing technology in complex scenarios is solved, and an efficient and hidden attack effect is achieved.

CN120030416APending Publication Date: 2025-05-23XIDIAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510177059.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-18
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The prior art faces security threats in the identification of communication signal modulation type, especially backdoor attacks. The existing attack methods fail to effectively consider the frequency domain characteristics, time-varying and the impact of complex channel environments of communication signals, making it difficult to accurately trigger attacks in complex scenarios.

Method used

By building a communication signal data set containing multiple modulation types, training the classifier model, and adding anti-perturbation and high-frequency interference processing to specific signal samples, the backdoor features are formed and put back into the dataset to implant the backdoor features, and attacking the automatic modulation identification model is realized.

Benefits of technology

This method can accurately design malicious signal characteristics and modulation perturbations, disrupt the decision-making process of the automatic modulation identification model, ensure the accuracy and controllability of the attack, significantly improve the attack success rate, and maintain high concealment under complex channel conditions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030416A_ABST
    Figure CN120030416A_ABST
Patent Text Reader

Abstract

The invention discloses a backdoor attack method and device for communication signal modulation type identification and an evaluation method, relates to the field of cognitive radio, and aims to realize backdoor attack in communication signal modulation type identification. The method comprises the following steps: constructing a data set containing communication signals of various modulation types; training at least one first classifier model by using the data set; signal samples of at least one modulation type are selected from the data set, adversarial disturbance is at least added to part of the selected signal samples for updating, and the added adversarial disturbance enables the first classifier model not to correctly recognize the modulation type of the updated signal samples; performing interference processing on the high-frequency characteristics of the updated signal sample; and putting the signal sample after interference processing back to the data set to complete backdoor implantation. According to the method, original signal features are destroyed by introducing adversarial disturbance, so that the success rate of backdoor attacks is improved, the concealment of backdoor implantation is improved by injecting the backdoor trigger into the high-frequency part of the sample, the robustness and universality of attacks are improved, and the method has extremely high attack success rate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of cognitive radio technology, and in particular relates to a backdoor attack method, device and evaluation method for communication signal modulation type identification. Background Art

[0002] With the rapid development of artificial intelligence technology in the field of communications, Automatic Modulation Recognition (AMR) technology based on deep learning has become an important tool for cognitive radio systems. By analyzing the modulation characteristics of wireless signals, AMR technology can achieve efficient identification of communication signal types, providing strong support for spectrum management, wireless resource optimization and abnormal signal detection. However, with the widespread application of AMR technology, the security threats it faces are gradually becoming more prominent, especially adversarial attacks and backdoor attacks on the model.

[0003] Backdoor attacks are a highly concealed and targeted attack method that can cause the model to exhibit expected erroneous behaviors under specific inputs by implanting a trigger mechanism during the model training phase. This type of attack is particularly threatening to automatic modulation recognition models, because attackers can manipulate recognition results, cover up abnormal signals, or disguise malicious communications, thus posing serious security risks to the Industrial Internet and other critical communication scenarios.

[0004] Existing research mainly uses attack methods in the field of image recognition, lacks applicability specifically for communication signal modulation type recognition, and has the following problems:

[0005] 1) Most studies rely on general attack strategies and do not fully consider the particularities of modulation recognition tasks, such as the frequency domain characteristics, time-varying nature, and complex channel environment of communication signals. These factors make existing attack methods face great challenges in practical applications, especially when dealing with complex scenarios such as signal attenuation, noise interference, and multipath propagation, making it difficult to accurately trigger attacks.

[0006] 2) Existing backdoor attack methods usually assume that the attacker has direct access to training data or model parameters. In reality, attackers can often only attack through limited contact points, which limits the practical applicability and universality of the attack methods. Summary of the invention

[0007] The purpose of the present invention is to propose a backdoor attack method, device and evaluation method for communication signal modulation type identification to address all or part of the above-mentioned problems, so as to realize the backdoor attack in communication signal modulation type identification, thereby revealing the potential security vulnerabilities in such identification models and providing theoretical support for the formulation of protection strategies.

[0008] The technical solution adopted by the present invention is:

[0009] A backdoor attack method for communication signal modulation type identification, comprising:

[0010] Constructing a data set containing communication signals of multiple modulation types, wherein each signal sample in the data set contains a modulation type label;

[0011] Using the data set to train at least one first classifier model, and saving the parameters of each of the trained first classifier models;

[0012] Selecting signal samples of at least one modulation type from the data set, adding adversarial perturbations to at least some of the selected signal samples for updating, wherein the added adversarial perturbations make it impossible for the first classifier model to correctly identify the modulation type of the updated signal samples;

[0013] Performing interference processing on the high-frequency features of the updated signal samples;

[0014] The interference processed signal samples are put back into the data set.

[0015] To solve the above problems, the present invention also provides a backdoor attack device for communication signal modulation type identification, including a storage medium and a processor, wherein the storage medium stores a computer program, and the processor runs the computer program to execute the above-mentioned backdoor attack method.

[0016] On the other hand, the present invention also provides an evaluation method for the above-mentioned backdoor attack method, which comprises:

[0017] training a second classifier model using a data set containing interference-processed signal samples;

[0018] Dividing a test set containing communication signals of multiple modulation types into a first test subset and a second test subset, and performing interference processing on high-frequency features of signal samples in the first test subset;

[0019] The first test subset and the second test subset are used respectively to evaluate the attack success rate and the recognition accuracy rate of the trained second classifier model.

[0020] The present invention also provides another evaluation method for the above-mentioned backdoor attack method, which includes:

[0021] Using a data set containing the signal samples after interference processing to train a third classifier model, and using a data set excluding the signal samples after interference processing to train a fourth classifier model, the third classifier model and the fourth classifier model have the same network architecture;

[0022] Dividing a test set containing communication signals of multiple modulation types into a first test subset and a second test subset, and performing interference processing on high-frequency features of signal samples in the first test subset;

[0023] Using the first test subset and the second test subset respectively to evaluate the attack success rate and recognition accuracy of the trained third classifier model;

[0024] The second test subset is used to evaluate the recognition accuracy of the trained fourth classifier model.

[0025] In summary, due to the adoption of the above technical solution, the beneficial effects of the present invention are:

[0026] 1. The present invention can specifically destroy the decision-making process of the automatic modulation recognition model by accurately designing malicious signal features and modulation disturbances, ensuring the accuracy and controllability of the attack. This precision control enables the attack to be efficiently executed in specific scenarios without excessive resource consumption.

[0027] 2. The present invention can significantly improve the success rate of attacks by combining specific signal features and adversarial disturbances. The optimized adversarial disturbance features can produce a stable backdoor effect under various modulation types, ensuring that the attack can effectively trigger the model's misidentification behavior under various experimental conditions.

[0028] 3. The present invention can minimize the impact on the model's processing of normal signals by adjusting the amplitude of the disturbance feature in the high-frequency part. This concealment ensures the covert execution of the attack under complex channel conditions, while avoiding excessive interference with the normal function of the model, thereby improving the concealment and practicality of the attack. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. It should be understood that the following drawings only illustrate certain embodiments of the present invention and should not be regarded as limiting the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative work, among which:

[0030] Figure 1 It is a backdoor attack method and evaluation flow chart for communication signal modulation type identification provided in an embodiment of the present application.

[0031] Figure 2 It is a constellation diagram of signal samples (IQ signals) of some modulation types in the embodiments of the present application.

[0032] Figure 3 It is a constellation diagram after adding anti-disturbance to the signal samples of BPSK modulation type in the embodiment of the present application.

[0033] Figure 4 It is a frequency domain characteristic diagram of a BPSK modulation type signal sample before interference processing in an embodiment of the present application.

[0034] Figure 5 It is a frequency domain characteristic diagram after interference processing is performed on a signal sample of the BPSK modulation type in an embodiment of the present application.

[0035] Figure 6 It is a constellation diagram after interference processing is performed on the signal samples of the BPSK modulation type in the embodiment of the present application.

[0036] Figure 7 This is a test chart of the attack success rate on the backdoor model in the embodiment of the present application.

[0037] Figure 8 This is a test chart of the recognition accuracy of the backdoor model and the clean model in the embodiment of the present application.

[0038] Fig. 9 It is a resistance test chart for the ANP defense method in the embodiment of the present application.

[0039] Fig.10 It is a resistance test chart for the CBD defense method in the embodiment of the present application.

[0040] Fig.11 It is a resistance test diagram for the ABL defense method in the embodiment of the present application. DETAILED DESCRIPTION

[0041] In order to make the purpose, technical scheme and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention, that is, the embodiments described are only part of the embodiments of the present invention, rather than all of the embodiments. The components of the embodiments of the present invention described and shown in the drawings herein can be arranged and designed in various different configurations.

[0042] It should be noted that relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprises" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

[0043] In view of the fact that there is no good backdoor attack method for automatic modulation type identification of communication signals, and network attacks in the communication field are high-incidence areas, the embodiment of the present application provides a backdoor attack method and device for communication signal modulation type identification, and on this basis, proposes an evaluation method for the backdoor attack method, aiming to realize the backdoor attack for automatic modulation type identification of communication signals, thereby revealing the potential security loopholes in such identification models. The features and performance of the present invention are further described in detail in conjunction with the embodiments.

[0044] The present invention provides a backdoor attack method for communication signal modulation type identification, which includes two stages: feature disturbance and backdoor implantation. The operation of the feature disturbance stage includes steps S1 to S3, and the operation of the backdoor implantation stage includes steps S4 to S5.

[0045] S1. Construct a data set containing communication signals of various modulation types, where each signal sample in the data set contains a modulation type label.

[0046] In some feasible methods, signal samples of communication signals containing multiple modulation types may be obtained from a public data source, such as Figure 2 The constellation diagrams of signal samples of some modulation types are shown. Each signal sample contains a modulation type label to indicate the actual modulation type of the signal sample. Signal samples usually exist in the form of IQ signals. Signal samples obtained from public data sources usually contain a variety of signal features, such as noise, attenuation, interference, etc., so that the diversity and representativeness of the data set can be ensured.

[0047] For the acquired signal samples, preprocessing operations are performed. Preprocessing operations include data cleaning, filtering and denoising, normalization, etc. In addition, the preprocessing operation can also encode the modulation type label (such as one-hot encoding) to facilitate model training.

[0048] Based on the preprocessing operation, the collected signal samples are divided into data sets D according to a predetermined ratio (such as 8:2 or 7:3) train (or called training set) and test set D test , to ensure that the training and testing processes of the (modulation type) recognition model do not interfere with each other. The dataset is used to train the recognition model, so the backdoor implantation is also carried out in the dataset. The test set can be used to evaluate the recognition model, such as the performance evaluation of the backdoor model in the following text.

[0049] S2. Use the data set to train at least one first classifier model, and save the parameters of each trained first classifier model.

[0050] In some optional methods, the network architecture of the first classifier model can be selected from a convolutional neural network CNN, a recurrent neural network RNN, a fully connected network FCN, etc. Assume that in step S2, a total of m first classifier models are constructed for training, and the network architectures of the m first classifier models are defined as f 1 (x),f 2 (x),…,f m (x), where x represents the model input, and f i (x) represents the output of the i-th first classifier model, i∈[1,m]. Multiple first classifier models can improve the universality of feature perturbations.

[0051] After the network architecture of each first classifier model is constructed, each first classifier model is trained using a data set (including signal samples and corresponding labels), and each first classifier model is trained into a recognition model for identifying the modulation type of communication signals.

[0052] As a feasible method, during the training of each first classifier model, the Adam optimizer is used to optimize the parameters of each first classifier model. In addition, during the training process, the initial learning rate is set to 0.0001, the batch size (Batchsize) B is 100, and the loss function uses classification cross entropy: K represents the total amount of adjustment types, p i is the true probability value of the i-th modulation type, q i is the predicted probability value of the i-th modulation type, and the number of training rounds is 1000.

[0053] According to the above design of the first classifier model, the signal samples of the data set are input into the first classifier model, and the predicted probability value is calculated through forward propagation. The difference between the predicted probability value and the true probability value is compared to obtain the loss value. Then the gradient of the model parameters is calculated using the back propagation algorithm, and the model parameters are updated based on the Adam optimizer to gradually reduce the loss function value. This is repeated until the network converges, and the training of the first classifier model is completed.

[0054] After the training of each first classifier model is completed, the parameters of each first classifier model are saved to prepare for subsequent feature disturbance.

[0055] S3. Select signal samples of at least one modulation type from the data set, and add adversarial perturbations to at least some of the selected signal samples for updating, wherein the added adversarial perturbations make it impossible for the first classifier model to correctly identify the modulation type of the updated signal samples.

[0056] The adversarial disturbance is a universal disturbance, which, when added to the selected target signal sample, causes the output of the recognition model to deviate from the actual modulation type when the recognition mode is to be trained.

[0057] Use y c represents the selected specific modulation type, the signal samples of this specific modulation type are represented by c, and the goal is to generate adversarial perturbations δ for these signal samples c in a targeted manner c , so that the first classifier model after training cannot correctly identify the true modulation type of these signal samples c, that is, the modulation type of these signal samples c is identified as y c Other modulation types.

[0058] As an optional method, the adversarial disturbance added to the signal sample in step S3 is obtained by:

[0059] S31: Select a signal sample c of a specific modulation type from the data set.

[0060] S32: Add adversarial perturbation δ to all selected signal samples c c , using the first classifier model to iteratively optimize the adversarial perturbation δ c , until the first classifier model cannot correctly identify the added adversarial perturbation δ c The modulation type y of the signal sample c after c .

[0061] As a feasible approach, the above-mentioned first classifier model is used to iteratively optimize the adversarial perturbation δ c The methods include:

[0062] S321: Initialize the adversarial disturbance δ c .

[0063] The adversarial perturbation δ can be initialized by random initialization c , initialize the adversarial perturbation δ c is a random vector.

[0064] On this basis, repeat the following steps:

[0065] S322: Calculate the first classifier model to add adversarial perturbation δ c The signal samples c after the loss of modulation type recognition are performed.

[0066] In step S322, the adversarial disturbance δ is added using each first classifier model with fixed parameters. c The signal sample c is identified and then compared with the real modulation label y c Compare them to calculate the recognition loss.

[0067] Each first classifier model adds adversarial perturbation δ c The recognition result of the signal sample c after is expressed as: 1 (x+δ c ) c ,f 2 (x+δ c ) c ,…,f m (x+δ c ) c , where the subscript c of each output result is only used to indicate that it is the recognition result for signal sample c.

[0068] Assuming that the number of signal samples c is N, in some feasible ways, by defining the classification cross entropy loss function To calculate the loss of the first classifier model:

[0069]

[0070] In the formula, y jc Indicates that the jth signal sample belongs to modulation type y c The true probability of .

[0071] Through the above loss function, we can calculate the adversarial perturbation δ of the first classifier model to the current iteration in each iteration. c The recognition loss of the signal sample c after

[0072] S323: Back-propagate the loss while fixing the parameters of the first classifier model Update the adversarial disturbance δ c .

[0073] The optimization process is usually carried out with the help of an optimizer, and the goal of optimization is to reduce the model loss. After that, the adversarial loss δ is calculated by the back propagation algorithm c The gradient of the adversarial loss δ c Update to gradually reduce the recognition loss

[0074] As the optimized adversarial loss δ c The goal is to make the first classifier model misidentify the added adversarial perturbation δ c The modulation type of the signal sample c after adding the adversarial perturbation, that is, the cutoff condition of "until the first classifier model cannot correctly identify the modulation type of the signal sample after adding the adversarial perturbation" is:

[0075]

[0076] That is, the output f of the first classifier model i (x+δ c ) is no longer related to the real modulation type y c same.

[0077] In addition, as an optional method, in order to avoid adversarial perturbation δ c If the amplitude is too large, the recognition model will fail or be detected, and the disturbance δ c The size of ∥δ c ∥ 2 Limited to the set threshold α. ∥δ c ∥ 2 Denotes δ c The second-order norm of .

[0078] S33: Save the final optimized adversarial perturbation δ c .

[0079] The final optimized adversarial perturbation δ c As a general perturbation, add to the specific modulation type selected y c After the signal samples c are obtained, all the first classifier models can be confused to recognize these signal samples c as y c Modulation types other than

[0080] After obtaining the universal adversarial perturbation δ c After that, the adversarial disturbance δ c Added to at least part of the signal samples of at least one modulation type selected from the data set to update the part of the signal samples. Figure 3 The final optimized adversarial perturbation δ is added to the BPSK type signal sample. c After that, the constellation diagram of the signal samples is updated.

[0081] S4. Perform interference processing on the high-frequency features of the updated signal samples.

[0082] The interference processing of the updated signal samples is a key step in backdoor implantation to form a backdoor trigger. The interference processing can effectively activate the backdoor features in the recognition model.

[0083] Assume that the signal samples selected from the data set are combined into a backdoor instance set D R , for the backdoor instance set D R Add adversarial perturbation δ to some (or all) of the signal samples in c , to update this part of the signal samples. Step S4 is to perform interference processing on the high-frequency features of the updated signal samples to add a backdoor trigger.

[0084] As an optional method, the method of performing interference processing on the high-frequency features of the updated signal samples includes:

[0085] S41: transform the updated signal samples into the frequency domain.

[0086] In one feasible approach, the updated signal samples are subjected to Fourier transform to obtain their frequency domain representation. Figure 4 Shown is the pair Figure 3 The frequency domain representation result obtained after the updated BPSK type signal sample is time-frequency converted.

[0087] S42: performing interference processing on at least part of the frequency points of the high frequency part.

[0088] In a feasible manner, the amplitude of at least part of the frequency points of the high frequency part is adjusted in step S42. The so-called high frequency part refers to the high frequency component part whose frequency exceeds a certain threshold, and the threshold can be set according to the modulation type of the communication signal.

[0089] By adjusting the amplitude of the frequency points in the high-frequency part to create interference and form a backdoor trigger, the detectability of the backdoor features in the frequency domain can be effectively reduced, the concealment of the attack can be enhanced, and the backdoor attack can be more difficult to detect.

[0090] In some specific embodiments, the amplitude of at least some of the frequency points in the high frequency part can be adjusted by randomly exchanging the amplitude of at least some of the frequency points in the high frequency part. For example, the amplitude of a randomly selected frequency point in the high frequency part is exchanged with an adjacent frequency point. Figure 5 Shown is the pair Figure 4 The result after adjusting the amplitude of the middle part of the high frequency points.

[0091] S43: transform the signal samples adjusted in the frequency domain into the time domain.

[0092] After adding the backdoor trigger, the frequency domain signal after interference processing is inverse Fourier transformed, and the frequency domain representation is transformed back to the time domain representation to obtain the corresponding IQ signal, such as Figure 6 Shown is the pair Figure 5 The frequency representation of the signal sample is converted into a constellation diagram after the frequency-time conversion. Through this process, the backdoor instance set D R The final signal sample with backdoor features is generated.

[0093] S5. Put the signal samples after interference processing back into the data set.

[0094] Finally, the backdoor instance set D R Mixed with the remaining signal samples in the dataset to form a complete dataset D with backdoor features total Through this method, backdoor instances and clean samples will work together in the training process of the recognition model, thereby implanting backdoor features without significantly affecting the performance of the recognition model, thereby enhancing the concealment and effectiveness of the backdoor attack.

[0095] The backdoor attack device for communication signal modulation type identification provided in the embodiment of the present application includes a storage medium and a processor, wherein the storage medium stores a computer program, and the processor runs the computer program to execute the backdoor attack method of the above embodiment.

[0096] In addition, an embodiment of the present application also provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the backdoor attack method of the above embodiment can be executed.

[0097] Compared with the existing backdoor attack methods, this application has the following beneficial effects:

[0098] First, given that the prominence of the data's own features may affect the learning effect of the backdoor features, this application first introduces adversarial perturbations to destroy the original signal features, making the backdoor features more prominent and easier to learn. In order to ensure that the perturbations can effectively destroy the original features and enhance the learnability of the backdoor features, this application uses universal adversarial perturbations. This adversarial perturbation can have an impact in different models, weakening their ability to learn the original features. This method effectively avoids the failure of backdoor attacks due to overly significant data features, thereby significantly improving the success rate of backdoor attacks.

[0099] Second, in order to enhance the concealment and effectiveness of the backdoor features, this application injects a specific backdoor trigger into the high-frequency part of the signal sample through Fourier transform. Compared with low-frequency interference, high-frequency interference is more concealed and can effectively maintain the time domain characteristics of the signal sample to avoid obvious interference with normal signal recognition. This method not only improves the concealment of the backdoor features, but also ensures that the attack can adapt to more complex and changeable actual communication scenarios, enhancing the robustness and applicability of the attack.

[0100] Third, in response to the shortcomings of existing backdoor attacks in circumventing defense mechanisms, this application does not simply rely on a single form of disturbance, but instead adopts a combination of multiple technical means. Through carefully designed complex attack strategies and disturbance patterns, the concealment and unpredictability of the attack are significantly increased, ensuring that backdoor attacks can still maintain a high success rate when facing mainstream defense mechanisms.

[0101] The embodiment of the present application also provides an evaluation method for the above-mentioned backdoor attack method, which includes:

[0102] S6. Use a data set containing signal samples after interference processing to train a second classifier model, and the output result of the second classifier model is represented as g(x). The second classifier model is also a machine model of a classification network architecture. As an optional method, the network architecture of the second classifier model is different from any of the first classifier models to prevent the evaluation results from being affected by the network architecture. The training process of the second classifier model is the same as the process of training the first classifier model described above. The classification performance of the second classifier model on the data set with backdoor interference is improved by optimizing the model parameters. Through this step, the second classifier model will have the ability to misidentify the backdoor feature as the target modulation type y without significantly affecting the recognition of normal signals. c characteristics.

[0103] S7, dividing the test set containing communication signals of multiple modulation types into a first test subset and a second test subset, and performing interference processing on the high-frequency features of the signal samples in the first test subset. test Here, the test set D test Divide into the first test subset D backdoor and the second test subset D clean , for the first test subset D backdoor The high frequency features of the signal samples in the first test set D are interfered with to form a backdoor trigger. The interference processing method here can refer to the interference processing method in the previous embodiment. backdoor The interference added to the signal sample in can effectively activate the backdoor feature in the second classifier model, so that the signal sample with the interference is misidentified as the target modulation type y c .

[0104] S8, respectively using the first test subset D backdoor and the second test subset D clean Evaluate the attack success rate and recognition accuracy of the trained second classifier model.

[0105] The attack success rate is expressed as Attack Success Rate, and the recognition accuracy is expressed as Clean Data Accuracy. The calculation methods of the two are as follows:

[0106]

[0107]

[0108] By evaluating the second classifier model on the first test subset D backdoor The attack success rate on the second test subset D is compared with the second classifier model clean The effectiveness of the backdoor attack method can be measured by the recognition accuracy on the target. If the evaluation results show that both the attack success rate and the recognition accuracy are good, it means that the backdoor attack method is effective.

[0109] In addition, the embodiment of the present application also provides another evaluation method for the backdoor attack method of the above embodiment, the method comprising:

[0110] S9, using a data set containing signal samples after interference processing (D total ) trains the third classifier model using the data set of signal samples after eliminating interference (D total -D R ) trains a fourth classifier model. The network architecture of the third classifier model and the fourth classifier model is the same. Similarly, as a preferred embodiment, the network architecture of the third classifier model and the fourth classifier model is different from each first classifier model.

[0111] S10, dividing the test set containing communication signals of multiple modulation types into a first test subset and a second test subset, and performing interference processing on the high frequency features of the signal samples in the first test subset. This step is the same as step S7 in the above embodiment and will not be described in detail here.

[0112] S11. Use the first test subset and the second test subset to evaluate the attack success rate and recognition accuracy of the trained third classifier model respectively.

[0113] The first test subset D backdoor Evaluate the attack success rate of the third classifier model, the second test subset D clean Evaluate the recognition accuracy of the third classifier model.

[0114] S12. Using the second test subset D clean Evaluate the recognition accuracy of the trained fourth classifier model.

[0115] By evaluating the attack success rate of the third classifier model and the performance of the third classifier model compared with the fourth classifier model on the second test subset D clean The effectiveness of the backdoor attack method is evaluated by the decrease in the recognition accuracy (decline percentage). If the above attack success rate is high and the decrease in accuracy is low (for example, no more than 2%), it indicates that the backdoor attack method is effective.

[0116] The embodiment of the present application carried out a verification experiment on the set RML2016.a, which contains data of various wireless communication modulation types and is one of the common modulation signal data sets. The modulation types contained in this set cover a variety of wireless communication standards, including but not limited to BPSK, QPSK, 16-QAM, 64-QAM, GFSK, 8-PSK, etc. The data of each modulation type has different signal-to-noise ratios, interference characteristics, and propagation environments to ensure the wide applicability of the experimental results. The model used in the experiment is based on a deep learning architecture, including a variety of network structures such as convolutional neural networks (CNNs) and fully connected networks (FCNs).

[0117] From a practical point of view, the attacker can poison some training samples, but the attacker does not know the specific structure of the model and cannot directly operate the model during the inference process. Therefore, the attacker can only misclassify the target modulation type by injecting backdoor perturbations on specific samples in the training set. This attack scenario simulates the potential security threats in actual communication systems. The attacker controls the model by making minor modifications to the training data and cannot interfere with other aspects of the model. In an embodiment of the present application, the sample poisoning rate is set to 2%, that is, the backdoor perturbations are injected into 2% of the signal samples.

[0118] like Figure 7 The experimental results of the attack effectiveness on the RML2016.a dataset are shown. The results show that even when only a small number of samples of the target type in the training set are backdoored, the backdoor attack method can still have a high attack success rate under different disturbance ratios (ratio of disturbance power to signal power). Figure 7It can be observed that the success rate of backdoor attacks has stably reached 80% to 100% within different signal-to-noise ratio ranges. More specifically, as the signal-to-noise ratio decreases, the attack success rate shows a significant upward trend. That is, in a low signal-to-noise ratio environment, the model's ability to distinguish normal data decreases, the interference effect of the backdoor trigger becomes more significant, and the attack success rate increases significantly. On the contrary, under higher signal-to-noise ratio conditions, the model can better distinguish normal signals from attack samples, and the attack success rate decreases. In combination with actual applications, especially in wireless communication scenarios, there are a lot of interference and noise phenomena, and the signal-to-noise ratio is difficult to improve. Therefore, the backdoor attack method proposed in this application has extremely high universality for real-world application scenarios.

[0119] This experiment also evaluates the impact of the proposed backdoor attack method on the accuracy of the model in identifying normal signal modulation types while maintaining a high attack success rate. Figure 8 The figure shows the experimental results of the attack concealment on the RML2016.a dataset. The results show that despite the different signal-to-noise ratio ranges, the attack success rate can remain at a high level and can effectively trigger the backdoor, and the backdoor attack method is particularly good in concealment. Specifically, after the attack, the model's recognition accuracy of the normal signal modulation type is always controlled within 2%, which is much lower than the accuracy loss caused by many existing backdoor attack methods. While ensuring high efficiency, the above backdoor attack method will hardly significantly affect the model's learning process of normal signals, which makes the attack extremely concealed and not easy to detect. In addition, the model's normal signal recognition accuracy in practical applications is still high, which further proves the concealment and efficiency of the attack.

[0120] This experiment also tested the resistance of the ANP (Adversarial Neural Pruning) defense method, the CBD (Backdoor Defense via Deconfounded Representation Learning) defense method, and the ABL (Anti-Backdoor Learning) defense method to verify the attack performance of the backdoor attack method of this application. The test results are as follows: Fig. 9 , Fig.10 and Fig.11 shown.

[0121] First, the ANP defense method shows a weak defense effect when dealing with the backdoor attack method proposed in this application. The ANP defense method attempts to enhance the robustness of the model by identifying adversarial samples and pruning neurons or connections related to backdoor triggers. However, the experimental results show that although the ANP defense method prunes some neurons, the attack success rate has almost no significant decrease, especially under low signal-to-noise ratio conditions. This result shows that the ANP defense method fails to effectively prevent the attacks of this application, especially under the combined action of complex backdoor triggers and adversarial disturbances, and its defense capability is very limited.

[0122] The CBD defense method also fails to effectively defend against the attack of the method of the present application. The CBD defense method eliminates the interference between the backdoor trigger and the normal data in the data by deobfuscating the representation learning, attempting to improve the model's learning ability for clean features. The experimental results show that although the CBD defense method reduces the success rate of backdoor attacks to a certain extent (a decrease of approximately 10% to 20%), the backdoor attack method proposed in this application still has a high success rate. Especially in complex trigger designs and low signal-to-noise ratio environments, the CBD defense method fails to effectively remove backdoor features. The attack of the present application is a high degree of fusion of the well-designed backdoor trigger and the normal data features, resulting in the CBD defense method failing to effectively isolate these interference features, thereby failing to prevent the occurrence of backdoor attacks.

[0123] Finally, the ABL defense method aims to make the model ignore the backdoor triggers and focus on learning the clean features of the data by training the model on data with backdoor contamination. Although this method adopts a specific regularization strategy to resist backdoor contamination, the experimental results show that the defense effect of the ABL defense method is still limited when facing the backdoor attack method proposed in this application. The success rate of the backdoor attack is only reduced by about 8% in different signal-to-noise ratio ranges. This result shows that the ABL defense method fails to effectively eliminate the backdoor features in the data, especially under the influence of complex backdoor perturbations and carefully designed triggers, and its defense ability is significantly limited.

[0124] The above experiments prove the effectiveness of the backdoor attack method proposed in this application, and provide more comprehensive theoretical support for the formulation of new defense mechanisms.

[0125] The above is only a preferred embodiment of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be thought of by a person skilled in the art within the technical scope disclosed by the present invention without creative work should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention should be based on the protection scope defined in the claims.

Claims

1. A backdoor attack method for communication signal modulation type identification, characterized in that: include: Constructing a data set containing communication signals of multiple modulation types, wherein each signal sample in the data set contains a modulation type label; Using the data set to train at least one first classifier model, and saving the parameters of each of the trained first classifier models; Selecting signal samples of at least one modulation type from the data set, adding adversarial perturbations to at least some of the selected signal samples for updating, wherein the added adversarial perturbations make it impossible for the first classifier model to correctly identify the modulation type of the updated signal samples; Performing interference processing on the high-frequency features of the updated signal samples; The interference processed signal samples are put back into the data set.

2. The backdoor attack method for communication signal modulation type identification according to claim 1, characterized in that: The method for obtaining the anti-disturbance comprises: selecting signal samples of a specific modulation type from the data set; Adding adversarial perturbations to all selected signal samples respectively, and iteratively optimizing the adversarial perturbations using the first classifier model until the first classifier model cannot correctly identify the modulation type of the signal samples after the adversarial perturbations are added; Save the final optimized adversarial perturbation.

3. The backdoor attack method for communication signal modulation type identification according to claim 2, characterized in that: The method of iteratively optimizing the anti-disturbance using the first classifier model includes: Initialize the adversarial perturbation; repeat the following operations: Calculating the loss of the first classifier model in performing modulation type recognition on the signal sample after adding the adversarial disturbance; While fixing the parameters of the first classifier model, back-propagating the loss to update the adversarial perturbation.

4. The backdoor attack method for communication signal modulation type identification according to claim 1, characterized in that: The method for performing interference processing on the high-frequency features of the updated signal samples includes: transforming the updated signal samples into the frequency domain; Performing interference processing on at least some of the frequency points of the high frequency part; Transform the frequency-domain adjusted signal samples to the time domain.

5. The backdoor attack method for communication signal modulation type identification according to claim 4, characterized in that: The interference processing of at least part of the frequency points of the high frequency part includes: The amplitude of at least some frequency points of the high frequency part is adjusted.

6. The backdoor attack method for communication signal modulation type identification according to claim 5, characterized in that: The step of adjusting the amplitude of at least some frequency points of the high frequency part includes: Randomly exchange the amplitudes of at least some frequency points of the high frequency part.

7. A backdoor attack device for communication signal modulation type identification, comprising a storage medium and a processor, wherein the storage medium stores a computer program, characterized in that: The processor runs the computer program to execute the backdoor attack method according to any one of claims 1-6.

8. A method for evaluating a backdoor attack method as claimed in any one of claims 1 to 6, characterized in that: include: training a second classifier model using a data set containing interference-processed signal samples; Dividing a test set containing communication signals of multiple modulation types into a first test subset and a second test subset, and performing interference processing on high-frequency features of signal samples in the first test subset; The first test subset and the second test subset are used respectively to evaluate the attack success rate and the recognition accuracy rate of the trained second classifier model.

9. The evaluation method according to claim 8, characterized in that: The network architecture of the second classifier model is different from the network architecture of any of the first classifier models.

10. A method for evaluating a backdoor attack method as claimed in any one of claims 1 to 6, characterized in that: include: Using a data set containing the signal samples after interference processing to train a third classifier model, and using a data set excluding the signal samples after interference processing to train a fourth classifier model, the third classifier model and the fourth classifier model have the same network architecture; Dividing a test set containing communication signals of multiple modulation types into a first test subset and a second test subset, and performing interference processing on high-frequency features of signal samples in the first test subset; Using the first test subset and the second test subset respectively to evaluate the attack success rate and recognition accuracy of the trained third classifier model; The second test subset is used to evaluate the recognition accuracy of the trained fourth classifier model.