Dual defense method and system for communication signal modulation identification intelligent confrontation, medium and equipment

By constructing a fusion method of data eigendimensional feature vector and multi-adversarial training network, the problem of insufficient robustness of adversarial sample detection and recognition model in the prior art is solved, efficient detection of adversarial samples and robustness of recognition model is achieved, and the security and reliability of communication signal modulation recognition system are enhanced.

CN120074878APending Publication Date: 2025-05-30刘明骞
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510103442.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In the face of adversarial sample attacks, the recognition model is poorly robust and it is difficult to effectively detect and defend against adversarial samples, especially when the adversarial information sharing mechanism between multiple models is not sound.

Method used

By extracting the activation features of different layers of the recognition model, the data eigendimensional feature vector is constructed, and inputting it into the detection network for adversarial sample detection. At the same time, the predicted probability vectors of the multi-adversarial training network are fused, and the input meta-recognition model is used to identify the true modulation method of the signal, enhancing the robustness of the model.

Benefits of technology

It realizes the robustness of high-precision detection and recognition model of adversarial samples, can maintain high accuracy in complex adversarial environments, and enhances the safety and reliability of communication signal modulation recognition system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074878A_ABST
    Figure CN120074878A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of communication signal modulation identification intelligent confrontation, and discloses a dual defense method, system, medium and device for communication signal modulation identification intelligent confrontation, and the method comprises the steps: extracting activation features of different layers of an identification model, and constructing a data intrinsic dimension feature vector; inputting the internal intrinsic dimension of the signal into a detection network, and judging whether the signal is an adversarial sample or not; and fusing the prediction probability vector of the multi-adversarial training network, and inputting a meta identification model to identify a real modulation mode of the signal. The system comprises an intrinsic dimension feature vector construction module; an adversarial sample detection module; and a signal modulation mode identification module. According to the invention, the adversarial sample of the modulation signal can be effectively detected and is rejected to be input into the recognition model; the method can cope with various types of attacks, and greatly improves the generalization and robustness of an intelligent recognition model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of countermeasure defense for intelligent recognition of communication signal modulation methods, and particularly relates to a dual defense method, system, medium and device for intelligent countermeasure of communication signal modulation recognition. Background Art

[0002] With the rapid development of communication systems, electromagnetic data presents increasingly complex characteristics, specifically reflected in aspects such as the randomness, diversity, and complexity of the data. In the context of cooperative communication, in order to adapt to the diverse needs of users and maximize the utilization efficiency of the channel, communication signals adopt various modulation methods. Through modulation recognition, characteristic information such as spectral characteristics, instantaneous amplitude, and phase can be extracted, thereby providing necessary technical support for efficient signal processing. In non-cooperative communication scenarios, modulation recognition plays a key role in alleviating the tension of spectrum resources. Modulation recognition plays a very important role in radio monitoring, spectrum resource management, air traffic control, etc. In recent years, deep learning has achieved great success in the fields of natural language processing and computer vision, and thus deep learning has been introduced into the field of wireless communication and has surpassed the performance of traditional methods in the task scenario of modulation signal recognition (O'Shea T J, Roy T, Clancy T C. Over-the-air deep learning based radio signal classification[J]. IEEE Journal of Selected Topics in Signal Processing, 2018, 12(1): 168-179.). Thanks to the rapid development of the field of artificial intelligence and the rapid iterative upgrade of deep learning technology, neural networks have great potential to solve more complex modulation recognition problems in the future as modulation recognition classifiers.

[0003] As research has deepened, the vulnerability of neural networks has gradually emerged. Researchers have found that neural networks are easily attacked by adversarial examples. Adversarial examples are samples generated by attackers by adding tiny adversarial perturbations generated by specific attack algorithms to normal samples. Compared with the original normal samples, the changes in adversarial examples usually do not affect visual judgment, but they can cause neural networks to make classification errors with high confidence. Szegedy et al. first proposed the concept of adversarial examples and successfully used the L-BFGS algorithm to generate adversarial examples using the quasi-Newton method, revealing the vulnerability of deep neural networks when facing adversarial attacks and proving that adversarial examples have good attack performance and transferability (Szegedy C, Zaremba W, Sutskever I, et al. Intriguing properties of neural networks[J]. Computer Science, 2013:1–10.). GoodFellow et al. proposed the Fast Gradient Sign Method (FGSM) based on gradients. By calculating the gradient of the model with respect to the input samples, the sign function is used to obtain the gradient direction, and a fixed-size perturbation coefficient is multiplied in the gradient direction and then added to the normal samples to generate adversarial examples (Goodfellow IJ, Shlens J, Szegedy C. Explaining and harnessing adversarial examples[C]. International Conference on Learning Representations. Cambridge: Cambridge University Press, 2015.). To improve the attack efficiency, Kurakin et al. proposed the Basic Iterative Method (BIM). BIM is an improvement on FGSM. By introducing iterative perturbations, the attack performance is enhanced. In each iteration of BIM, a tiny perturbation is applied to the input samples according to the gradient direction of the target model (Kurakin A, Goodfellow IJ, Bengio S. Adversarial examples in the physical world[M]. Artificial intelligence safety and security. 2018:99-112.).Subsequently, Dong et al. proposed the Momentum Iterative Method (MIM), which adds a momentum term during the iterative process to approach the optimal solution faster and improve the efficiency of the attack (DONG Y, LIAO F, PANG T, et al. Boosting adversarial attacks with momentum[C]. Proceedings of the IEEE conference on computer vision and pattern recognition. Piscataway: IEEE, 2018: 9185-9193.). Madry et al. also proposed the Projected Gradient Descent (PGD) attack with multi-step iteration, which introduces a randomization operation in the initialization stage to generate highly aggressive PGD adversarial samples (MADRY A, MAKELOV A, SCHMIDT L, et al. Towards deep learning models resistant to adversarial attacks[C]. International Conference on Learning Representations. Cambridge: Cambridge University Press, 2018.). The above adversarial attack algorithms were initially applied in the field of images. However, with the in-depth research, in other fields such as face recognition, object detection, semantic segmentation, modulation signal recognition, etc., there are also adversarial sample problems (YUAN X, HE P, ZHU Q, et al. Adversarial examples: Attacks and defenses for deep learning[J]. IEEE transactions on neural networks and learning systems, 2019, 30(9): 2805-2824.). The present invention focuses on the adversarial attack in the field of intelligent modulation signal recognition, and proposes a corresponding defense method for the mainstream white-box adversarial attack method in the current modulation recognition field. The FGSM, BIM, MIM, and PGD attack algorithms are set in the white-box attack scenario to verify the effectiveness of the proposed defense method.

[0004] With the continuous development of adversarial sample attack algorithms, the research on defense algorithms has also been continuously advancing. Adversarial sample detection is to detect whether a sample is an adversarial sample before it is input into the target model. Samples that can pass the detection are input into the target model for subsequent recognition, while samples determined to be adversarial samples will be rejected from entering the subsequent recognition network, thereby achieving the purpose of protecting the model from being invaded by adversarial samples. Grosse et al. believe that adversarial samples do not come from the same distribution as the original data, so they proposed two detection methods based on mathematical statistical features, Kernel Density Estimation (KDE) and Bayesian Uncertainty Estimation (BUE), for detecting adversarial samples in the field of images (GROSSE K, MANOHARAN P, PAPERNOT N, et al. On the (Statistical) Detection of Adversarial Examples [J]. CoRR, 2017, 2: 1-14.). Salehi et al. proposed a new training method for autoencoders to detect adversarial samples by comparing the reconstruction error between the input sample and the reconstructed sample of the autoencoder (SALEHI M, ARYA A, PAJOUM B, et al. Arae: Adversarially robust training of autoencoders im-proves novelty detection [J]. Neural Networks, 2021, 144: 726-736.). Adversarial training is the most common method in the field of adversarial defense. By introducing adversarial perturbations during the training process, the neural network model learns the features of adversarial samples. Madry et al. proposed using an adversarial training method based on gradient iteration and selected PGD attack for adversarial training, significantly improving the robustness of the model (MADRY A, MAKELOV A, SCHMIDT L, et al. Towards deep learning models resistant to adversarial attacks [C]. International Conference on Learning Representations. Cambridge: Cambridge University Press, 2018.).Zhang et al. proposed Friendly Adversarial Training (FAT), which avoids the severe overfitting problem in traditional adversarial training by finding samples that are misclassified but have small loss values (ZHANG J, XU X, HAN B, et al. Attacks which do not kill training make adversarial learning stronger[C]. International conference on machine learning. New York: ACM, 2020: 11278-11287.). Cai et al. proposed Curriculum Adversarial Training (CAT), which makes the model obtain stronger robustness by gradually increasing the adversarial perturbation size of adversarial samples, and solves the catastrophic forgetting problem and generalization problem of adversarial training through two methods: batch mixing and quantization (CAI Q Z, LIU C, SONG D. Curriculum adversarial training[C]. Proceedings of the 27th International Joint Conference on Artificial Intelligence. Burlington: Morgan Kaufmann, 2018: 3740-3747.). Wang et al. designed a criterion to measure the convergence quality and proposed Dynamic Adversarial Training (DAT), which uses adversarial samples with different convergence qualities at different stages of adversarial training to gradually improve the convergence quality of the generated adversarial samples, significantly improving the robustness of the adversarial training model (WANG Y, MA X, BAILEY J, et al. On the Convergence and Robustness of Adversarial Training[C]. International Conference on Machine Learning. New York: ACM, 2019: 6586-6595.).Salman et al. introduced the idea of ensemble learning, added random Gaussian noise to normal samples to generate multiple noisy samples, and used the multiple recognition results of these noisy samples on the recognition network after denoising to guide the training of the denoising network (SALMAN H, SUN M, YANG G, et al. Denoised smoothing: A provable defense for pretrained classifiers[J]. Advances in Neural Information Processing Systems, 2020, 33: 21945-21957.).

[0005] Through the above analysis, the problems and defects existing in the prior art are as follows:

[0006] (1) In the existing defense technologies, the focus is mainly on adversarial sample detection and adversarial training defense methods. The research is relatively scattered and independent, lacking the complementary utilization of the characteristics of different defense methods.

[0007] (2) The existing defense technologies are mainly oriented to single models, and do not fully exploit and utilize the advantages of adversarial information sharing between multiple models.

[0008] (3) After the recognition model training is completed, the existing defense technologies have poor robustness against strong adversarial samples and are prone to losing the original modulation information in the signal.

[0009] The difficulty in solving the above problems and defects is that the adversarial information sharing mechanism between different defense methods and models is not perfect, resulting in difficulty in fully utilizing the adversarial information learned by the models to improve the robustness of the recognition model. Therefore, constructing data eigen-dimension features and detecting adversarial samples, as well as using multiple adversarial training networks to identify the true modulation mode of the signal, are the technical difficulties of the present invention.

[0010] The significance of solving the above problems and defects is that the present invention realizes a dual intelligent defense against adversarial attacks, can protect the intelligent recognition model from adversarial sample attacks, and improve the robustness of the recognition model in different adversarial attack environments. Summary of the Invention

[0011] Aiming at the problems existing in the prior art, the present invention provides a dual defense method, system, medium and device for intelligent confrontation of communication signal modulation recognition.

[0012] The present invention is implemented as follows. A dual defense method for intelligent confrontation of communication signal modulation recognition, the dual defense method for intelligent confrontation of communication signal modulation recognition includes:

[0013] Step 1: Extract the activation features of different layers of the recognition model and construct the data intrinsic dimension feature vector. The intrinsic dimension in the present invention directly affects the performance of the subsequent adversarial sample detection network and can provide significant adversarial information for the detection network;

[0014] Step 2: Input the intrinsic dimension inside the signal into the detection network to determine whether the signal is an adversarial sample. The detection network in the present invention is used to detect whether the input signal is an adversarial sample. If it is an adversarial sample, its input to the recognition network is rejected; otherwise, the recognition process continues to be modulated;

[0015] Step 3: Fuse the prediction probability vectors of multiple adversarial training networks and input them into the meta-recognition model to identify the true modulation mode of the signal. The recognition model in the present invention is used to identify the true modulation mode of the signal and reduce the impact of adversarial samples passing through the detection network on the recognition result.

[0016] Further, in the above Step 1, the process of extracting the activation features of different layers of the recognition model and constructing the data intrinsic dimension feature vector is as follows: For a pre-trained recognition model F(x) with L layers, the benchmark dataset X B , training set X norm and the adversarial sample set X norm generated by using X adv are respectively input into F(x) to obtain their activation values at the i-th layer of the recognition model:

[0017] A B = F i (X B )

[0018] A norm = F i (X norm )

[0019] A adv = F i (X adv )

[0020] Then, by calculating the internal intrinsic dimension LID value of the activation value of each layer of the recognition model for the sample to be detected, the LID feature vector of each sample is obtained, and the length of the feature vector is consistent with the number of feature layers of the recognition model. Calculate the internal intrinsic dimension LID of normal samples and adversarial samples respectively:

[0021]

[0022] where k represents the number of nearest neighbor samples, and r n (A, A norm ) represents the L norm distance between A and the n-th nearest neighbor point in A 2 .

[0023] Assume that the normal sample \(x\in X\) lies within the data manifold \(S\). By performing an adversarial attack on \(x\), its corresponding adversarial sample \(x'\) is generated. If \(x'\) is a successful adversarial sample such that \(F(x')\neq y\), where \(y\) is the label corresponding to the sample \(x\), then \(x'\) will be located in a high-dimensional data manifold space outside the data manifold \(S\). Therefore, LID characterizes the internal intrinsic dimension of the data, which means that the theoretical LID value of the adversarial sample \(x'\) in the high-dimensional data manifold space will be greater than that of the normal sample \(x\).

[0024] Furthermore, in the second step, the process of inputting the internal intrinsic dimension of the signal into the detection network to determine whether the signal is an adversarial sample is as follows: After extracting the LID feature vectors of the normal samples and adversarial samples, use \((LID norm ,LID adv ) to train the detection network Detector, and use metrics such as accuracy, precision, and recall to preliminarily evaluate the detection performance of the network, which is defined as:

[0025]

[0026] Among them, \(TP\) represents the number of samples where both the true label and the predicted result are positive, \(FN\) represents the number of samples where the true label is positive and the predicted result is negative, \(FP\) represents the number of samples where the true label is negative and the predicted result is positive, and \(TN\) represents the number of samples where both the true value label and the predicted result are negative. In the scenario of adversarial sample detection, generally, the label of the adversarial sample is set to 1 as positive, and the label of the normal sample is set to 0 as negative.

[0027] Since the detection network needs to achieve high-precision detection and prevent the loss of normal samples due to misjudging normal samples as adversarial samples, when selecting the detection threshold of the detection network, it is necessary to consider the impact of the detection threshold on the loss amount of normal samples. Increasing the detection threshold will result in higher detection precision but also reduce the recall rate for adversarial samples. The calculation formula for the proportion of normal sample loss is:

[0028]

[0029] where \(l clean represents the proportion of normal sample loss, \(N clean , N FP , accuracy FPThey respectively represent the number of normal samples, the number of false positive normal samples, and the recognition accuracy of false positive normal samples. After mixing normal samples and adversarial samples in equal proportion for detection, the overall loss of normal samples under each detection threshold is calculated. Under the loss limit of normal samples, a detection threshold that meets the set loss limit is selected to accurately detect the adversarial samples mixed in the signal.

[0030] Further, in the third step, the prediction probability vectors of multiple adversarial training networks are fused and input into the meta-recognition model to identify the true modulation mode of the signal. The specific process is as follows: Adversarial training uses adversarial samples x that can maximize the internal loss adv to optimize the current model parameters θ. Formally, adversarial training optimizes the objective through a min-max process, and the training process can be expressed as:

[0031]

[0032] where θ is the network weight, x is the original normal sample, y is the true label, loss(θ, x + r adv , y) is the adversarial loss function, S is the perturbation space, and the perturbation size can be controlled by setting the perturbation space. D represents the distribution of training data. The meaning of the formula in the inner parentheses is to find a set of adversarial samples in the sample space that maximize the loss function. The adversarial samples are formed by adding adversarial perturbations r adv to the original normal sample x. The outer min() function means that by optimizing the network parameters to fit the adversarial sample set generated by the inner layer, the expected loss function value on the adversarial sample set is minimized, so that the trained network can resist the attack of the adversarial samples generated during the training phase.

[0033] The Ensemble Adversarial Training (EAT) method proposed in the present invention is divided into two stages. First, different adversarial training methods are used to train the recognition network, and these networks are used as the base classification models. In the second stage, the generated adversarial samples and normal samples are input into several trained basic class models. The prediction probability vectors output by each base classification model are combined to form a new feature vector, and the meta-classification model is trained. The final prediction is made by integrating the outputs of each base classification model. Therefore, the process of EAT is as follows: On the training dataset different adversarial training methods are used to train each base recognition model f i , and a model group composed of k base recognition models is obtained An adversarial sample set corresponding to the training set is generated using the adversarial attack algorithm x is respectively input into F to obtain a feature vector composed of multiple prediction probability vectors:

[0034] A i = [f 1 (x i ), f 2 (x i ),..., f k (x i )]

[0035]

[0036] Construct a new training set using the eigenvector And combine with to train the meta-recognition model M to be trained, and jointly form an integrated adversarial training network with the base recognition model group F to identify the modulation method of the signal passing through the adversarial sample detection network.

[0037] Another object of the present invention is to provide a dual defense system for intelligent adversarial communication signal modulation recognition for implementing the dual defense method for intelligent adversarial communication signal modulation recognition, characterized in that the dual defense system for intelligent adversarial communication signal modulation recognition includes:

[0038] An eigen-dimensional feature vector construction module for extracting the activation features of different layers of the recognition model and constructing a data eigen-dimensional feature vector;

[0039] An adversarial sample detection module for inputting the internal eigen-dimension of the signal into the detection network to determine whether the signal is an adversarial sample;

[0040] A signal modulation method recognition module for fusing the prediction probability vectors of multiple adversarial training networks and inputting them into the meta-recognition model to identify the true modulation method of the signal.

[0041] Combining all the above technical solutions, the advantages and positive effects of the present invention are as follows:

[0042] First, the present invention detects and distinguishes normal samples and adversarial samples based on the differences in the internal eigen-dimensions of adversarial samples and normal samples in the neural network. The detected adversarial samples will be rejected from entering the subsequent recognition network, blocking the impact of adversarial attacks. To deal with adversarial samples that escape detection, the robustness of the subsequent recognition network is enhanced through adversarial training. In addition, in order to be able to handle more types of adversarial attacks, the adversarial training of a single model is extended to multi-model integrated adversarial training, using ensemble learning to make up for the respective short-board defects of different adversarial training networks and integrating the advantages of different adversarial training networks to achieve better generalization performance. The entire defense system defends the recognition system from three aspects: reducing the number of attacks, reducing the intensity of attacks, and enhancing the robustness of the model, enhancing the robustness of the recognition system in an adversarial environment.

[0043] Second, in the field of communication signal modulation recognition, the existing technologies have obvious deficiencies in dealing with adversarial sample attacks. Adversarial samples can significantly change the output results of deep models through tiny perturbations, leading to incorrect modulation mode recognition and seriously affecting the security and reliability of communication systems. In addition, traditional adversarial defense methods are usually limited to single adversarial training strategies and cannot comprehensively cope with complex and diverse adversarial attack means, resulting in insufficient defense performance and poor applicability.

[0044] The present invention proposes a dual defense method for intelligent countermeasure against communication signal modulation recognition. By combining internal eigen-dimension feature calculation and multi-adversarial training network fusion, an efficient and reliable defense system is constructed. This technical solution discriminates adversarial samples through internal eigen-dimension features and can accurately distinguish normal signals from adversarial samples. At the same time, through the integration of multiple adversarial training methods, the adversarial robustness of the model is significantly improved, and the problems of single defense strategy and insufficient detection performance in the existing technologies are solved.

[0045] The technical solution of the present invention has achieved remarkable technological progress in industrial applications: First, through internal eigen-dimension feature analysis, the detection accuracy of adversarial samples is effectively improved; Second, the integrated adversarial training network greatly enhances the defense ability of the recognition model, enabling the system to maintain a high accuracy rate in complex adversarial environments; Finally, through modular design, the present invention is convenient for rapid deployment in communication systems and is applicable to various application scenarios, such as military communication, wireless networks, and intelligent transportation signal processing, providing a reliable technical guarantee for industrial practice. Description of the Drawings

[0046] Figure 1 is a flowchart of the dual defense method for intelligent countermeasure against communication signal modulation recognition provided by an embodiment of the present invention.

[0047] Figure 2 is a schematic structural diagram of the dual defense system for intelligent countermeasure against communication signal modulation recognition provided by an embodiment of the present invention;

[0048] Figure 2 In which: 1. Eigen-dimension feature vector construction module; 2. Adversarial sample detection module; 3. Signal modulation mode recognition module.

[0049] Figure 3 is a schematic diagram of the dual defense process for intelligent countermeasure against communication signal modulation recognition provided by an embodiment of the present invention.

[0050] Figure 4 is a schematic diagram of the simulation experiment results of the dual defense system for intelligent countermeasure against communication signal modulation recognition provided by an embodiment of the present invention. Detailed Embodiments

[0051] In order to make the objectives, technical solutions and advantages of the present invention more clear and understandable, the present invention will be further described in detail below in conjunction with embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0052] A dual defense method for intelligent countermeasure of communication signal modulation recognition includes: extracting activation features of different layers of a recognition model and constructing an eigen-dimensional feature vector of data; inputting the internal eigen-dimension of a signal into a detection network to determine whether the signal is an adversarial sample; fusing the prediction probability vectors of multiple adversarial training networks and inputting them into a meta-recognition model to recognize the true modulation mode of the signal.

[0053] The extraction of activation features of different layers of the recognition model and the construction of the eigen-dimensional feature vector of data include: based on a pre-trained recognition model, calculating the activation values of a benchmark data set, a training set and an adversarial sample set at each layer of the recognition model, and calculating the eigen-dimensional feature vector of each sample through the internal eigen-dimension.

[0054] The calculation of the internal eigen-dimensional feature vector includes: based on the distribution of the nearest neighbor samples of a sample in the feature space, determining the nearest neighbor distance of each sample point, and forming a feature vector by calculating the internal eigen-dimension value.

[0055] The input of the internal eigen-dimension of a signal into the detection network to determine whether the signal is an adversarial sample includes: training the detection network with the internal eigen-dimensional feature vectors of normal samples and adversarial samples, and evaluating the detection performance through different detection thresholds to select an appropriate threshold.

[0056] The training of the detection network includes: optimizing network parameters based on indicators such as accuracy, precision, and recall, and mixing the proportions of normal samples and adversarial samples to evaluate the false positive rate of the detection network.

[0057] The fusion of the prediction probability vectors of multiple adversarial training networks includes: generating a number of base recognition models through multiple adversarial training methods, inputting normal samples and adversarial samples to obtain prediction probability vectors and combining them to form a new training data set.

[0058] The new training data set is used to train the meta-recognition model, and the meta-recognition model and the base recognition model group are combined to form an integrated adversarial training network, and the true modulation mode of the signal is recognized through this network.

[0059] Embodiment 1: Application of a communication signal adversarial sample detection system

[0060] A certain military communication system faces malicious adversarial signal interference and needs to perform modulation recognition on the received communication signals to prevent misidentification of the modulation mode due to adversarial sample attacks.

[0061] 1) Activation feature extraction:

[0062] Process the received communication signal using a pre-trained deep recognition model to extract the activation values at each layer.

[0063] Generate an eigen-dimensional feature vector by calculating the nearest neighbor distribution of each signal, and store the vector length equal to the number of feature layers of the recognition model.

[0064] 2) Adversarial sample detection:

[0065] Input the eigen-dimensional feature vector of the signal into the detection network, which has been trained with a mixed dataset of normal samples and adversarial samples.

[0066] Use an optimized detection threshold to determine whether the signal is an adversarial sample. If it is an adversarial sample, the system issues an alarm and rejects further processing.

[0067] 3) Signal modulation recognition:

[0068] For signals that are not adversarial samples, construct a new feature vector using the prediction probability vectors generated by multiple adversarial training networks.

[0069] Use a meta-recognition model to identify the modulation method of the fused feature vector and output the true modulation result of the signal.

[0070] This system can maintain a high recognition accuracy in various adversarial sample attack scenarios. The detection accuracy of adversarial samples reaches 98.5%, effectively improving the security of communication signal recognition.

[0071] Example 2: Intelligent defense system for wireless communication devices

[0072] In a certain wireless communication network, the transmitted signal may be interfered by adversarial samples, affecting the recognition of the signal modulation method. It is necessary to implement a defense system based on multi-adversarial training.

[0073] 1) Train the base recognition model group:

[0074] Use different adversarial training methods (such as PGD, FGSM) to generate adversarial sample sets and train multiple deep recognition networks as base recognition models.

[0075] Each base recognition model outputs a modulation prediction probability vector of the signal.

[0076] 2) Integrated adversarial training:

[0077] Combine the prediction probability vectors of the base recognition models to construct a new set of feature vectors, and generate a new training set by mixing normal samples and adversarial samples.

[0078] Train the meta-recognition model using the new training set and use it as the final signal modulation recognition model.

[0079] 3) Online detection and recognition:

[0080] Receive wireless signals in real time, extract their activation values, and calculate the internal eigen-dimensional feature vectors.

[0081] Judge whether the signal is an adversarial sample through the detection network, and perform modulation recognition on normal signals using the integrated adversarial training model.

[0082] In the actual network, the system successfully detects various complex adversarial samples, and the modulation recognition accuracy of normal signals remains above 99%, ensuring the stable operation of the wireless communication network.

[0083] Aiming at the problems existing in the prior art, the present invention provides a dual defense method, system, medium and device for intelligent confrontation of communication signal modulation recognition. The present invention will be described in detail below with reference to the accompanying drawings.

[0084] Ordinary technical personnel in the industry can also adopt other steps to implement the dual defense method for intelligent confrontation of communication signal modulation recognition provided by the present invention. Figure 1 The dual defense method for intelligent confrontation of communication signal modulation recognition provided by the present invention is only a specific embodiment.

[0085] As Figure 1 shown, the dual defense method for intelligent confrontation of communication signal modulation recognition provided by the embodiment of the present invention includes:

[0086] S101: Extract the activation features of different layers of the recognition model and construct the data eigen-dimensional feature vector;

[0087] S102: Input the internal eigen-dimension of the signal into the detection network to determine whether the signal is an adversarial sample;

[0088] S103: Fuse the prediction probability vectors of multiple adversarial training networks and input them into the meta-recognition model to identify the true modulation mode of the signal.

[0089] In S101 provided by the embodiment of the present invention, the process of extracting the activation features of different layers of the recognition model and constructing the data eigen-dimensional feature vector is as follows:

[0090] Randomly select a part of the data samples from the normal data set as the reference data set X i for calculating the nearest neighbor distance r B (x), calculate the distances from the sample to be detected x (normal sample or adversarial sample) to the k nearest neighbor samples in the reference data set, and estimate the LID value of each sample to be detected by the following formula:

[0091]

[0092] where r i (x, Ρ) represents the distance between the sample x and the i-th nearest neighbor sample in the distribution Ρ, and r k (x, Ρ) is the distance between the sample x and the k-th nearest neighbor sample in the distribution Ρ. The Euclidean norm can be used to measure the distance between two samples, defined as:

[0093]

[0094] where x i , y i are the i-th values of the n-dimensional vectors x and y, respectively.

[0095] Assume that the normal sample x ∈ X lies within the data manifold S. By performing an adversarial attack on x, its corresponding adversarial sample x′ is generated. If x′ is a successful adversarial sample such that F(x′) ≠ y, where y is the label corresponding to the sample x, then x′ will lie in a high-dimensional data manifold space outside the data manifold S. Therefore, LID characterizes the internal intrinsic dimension of the data, which means that the theoretical LID value of the adversarial sample x′ in the high-dimensional data manifold space should be greater than the LID value of the normal sample x.

[0096] In practice, instead of directly calculating the Euclidean norm distance between samples, for each input sample x, the activation values F i (x) of this sample at each layer in the recognition model are extracted. F i (x) represents the activation value of x at the i-th layer of the recognition model F. Similarly, for each sample in the reference dataset X B , the activation values at each layer in the recognition model are also extracted. Calculating the distance r(x, X B ) from the sample to be detected to the nearest neighbor sample in the reference dataset is replaced by calculating the distance r(F i (x), F i (X B )) between the activation value of the sample to be detected and the nearest neighbor activation value of the activation values in the reference dataset. Since the difference between normal samples and adversarial samples is gradually amplified in the neural network and is more obvious in the activation values output at the feature layer, this is more conducive to the detection of adversarial samples. By calculating the internal intrinsic dimension LID value of the activation values of the sample to be detected at each layer in the recognition model, the LID feature vector of each sample is obtained, and the length of the feature vector is consistent with the number of feature layers of the recognition model.

[0097] Therefore, for a pre-trained recognition model H(x) with L layers, the reference dataset X B , the training set X norm and the use of Xnorm Generated adversarial sample set X adv Input them into F(x) respectively to obtain their activation values at the i-th layer of the recognition model:

[0098] A B = F i (X B )

[0099] A norm = F i (X norm )

[0100] A adv = F i (X adv )

[0101] Then, calculate the internal intrinsic dimension LID of normal samples and adversarial samples respectively:

[0102]

[0103] Among them, k represents the number of nearest neighbor samples, and r n (A, A norm ) represents the L norm distance between A and the n-th nearest neighbor point in A 2 .

[0104] In S102 provided by the embodiment of the present invention, the specific process of inputting the internal intrinsic dimension of the signal into the detection network to determine whether the signal is an adversarial sample is as follows:

[0105] After extracting the LID feature vectors of normal samples and adversarial samples, use (LID norm , LID adv ) to train the detection network Detector, so that the detection network can distinguish normal samples (negative) from adversarial samples (positive) based on the LID feature vectors.

[0106] After the detection network is trained, before using the network to detect and test adversarial samples, use indicators such as accuracy, precision, and recall to preliminarily evaluate the detection performance of the network, which is defined as:

[0107]

[0108]

[0109] Among them, TP represents the number of samples where both the true label and the predicted result are positive, FN represents the number of samples where the true label is positive but the predicted result is negative, FP represents the number of samples where the true label is negative but the predicted result is positive, and TN represents the number of samples where both the true label and the predicted result are negative. In the scenario of adversarial sample detection, the label of an adversarial sample is generally set to 1 as positive, and the label of a normal sample is set to 0 as negative. The defense scheme aims to enable the detection network to have a higher detection precision. Precision is the proportion of true adversarial samples among the samples determined by the detection network to be adversarial samples. The higher the precision, the fewer the number of false positive samples (misjudging normal samples as adversarial samples) and the smaller the loss of normal samples.

[0110] In the case of false negatives (identifying adversarial samples as normal samples), it can be mitigated by the recognition network after the detection network. However, once false positives (identifying normal samples as adversarial samples) occur, the loss of normal samples is difficult to recover. Therefore, the detection network focuses on achieving high-precision detection to prevent the loss of normal samples caused by misjudging normal samples as adversarial samples. So, when selecting the detection threshold of the detection network, the impact of the detection threshold on the loss amount of normal samples needs to be considered. The detection threshold is generally defaulted to 0.5. If the predicted probability of the input sample is greater than or equal to 0.5, it means the detection network believes that this sample is more likely to be an adversarial sample (the training labels of adversarial samples and normal samples are 1 and 0 respectively). Conversely, if the predicted probability is less than 0.5, then this sample is more likely to be a normal sample. Increasing the detection threshold means raising the judgment standard for adversarial samples, which will result in a higher detection precision. But at the same time, it will also reduce the recall rate for adversarial samples. The calculation formula for the proportion of normal sample loss is:

[0111]

[0112] where l clean represents the proportion of normal sample loss, N clean , N FP , accuracy FP represent the number of normal samples, the number of false positive normal samples, and the recognition accuracy of false positive normal samples respectively. After mixing normal samples and adversarial samples in equal proportion for detection, the overall normal sample loss under each detection threshold is calculated. Under the loss limit of normal samples, select the detection threshold that meets the set loss limit to accurately detect the adversarial samples mixed in the signal. If the input sample is judged to be a normal sample, it is input into the subsequent recognition network for modulation mode recognition. If it is judged to be an adversarial sample, the recognition is aborted to prevent adversarial attacks.

[0113] S103 provided by the embodiment of the present invention fuses the prediction probability vectors of multiple adversarial training networks and inputs them into the meta-recognition model to identify the true modulation mode of the signal. The specific process is as follows:

[0114] In the defense solution proposed by the present invention, the adversarial sample detection network based on the LID value is used as the first layer of defense measure. The detection network filters out some adversarial samples through detection, thereby reducing the attack on the subsequent recognition network. However, in actual operation, it is difficult to filter out all adversarial samples through the detection network. There will definitely be false positives (normal samples are misjudged as adversarial samples), resulting in the loss of normal samples. Similarly, there will also be false negatives (adversarial samples are judged as normal samples), resulting in some adversarial samples escaping the interception of the detection network. To deal with false negative samples, the present invention designs an integrated adversarial training network to resist the attack of these adversarial samples that escape detection and interception.

[0115] Adversarial training is the most commonly used method in the field of adversarial defense. Adversarial training can improve the robustness of the model. The core idea is to use aggressive adversarial samples to train the model so that the trained model can have the ability to resist adversarial attacks. Adversarial training optimizes the current model parameters θ by using adversarial samples x that can maximize the internal loss. Formally, adversarial training optimizes the target through a min-max process, and the training process can be expressed as: adv where θ is the network weight, x is the original normal sample, y is the true label, loss(θ, x + r

[0116]

[0117] , y) is the adversarial loss function, S is the perturbation space, and the perturbation size can be controlled by setting the perturbation space. D represents the distribution of the training data. The meaning of the formula in the inner parentheses is to find a set of adversarial samples in the sample space that maximize the loss function. The adversarial samples are formed by adding the adversarial perturbation r adv to the original normal sample x. The outer min() function means that by optimizing the network parameters, fitting the set of adversarial samples generated in the inner layer, and minimizing the expected loss function value on the set of adversarial samples, the trained network can resist the attack of the adversarial samples generated during the training stage. adv

[0118] ​Traditional adversarial training methods focus on improving the training process of a single model, expecting to achieve stable and effective defense against various attack methods on a single model, but it is difficult to achieve in practice. For example, FGSM adversarial training has a good defense effect against FGSM adversarial samples, but the defense effect will decline when dealing with adversarial samples generated by multi-step iteration. PGD adversarial training further enhances the robustness of the model, but it reduces the recognition accuracy of the model for normal samples. The ensemble adversarial training method proposed by the present invention complements the deficiencies of a single defense model by integrating multiple adversarial training models, and can achieve effective defense against different attack methods as much as possible, rather than just defense against a single attack method. The present invention introduces ensemble learning into the field of adversarial defense, combines multiple weak learners to improve the overall performance, and combines the advantages of multiple networks to make up for their respective short board defects by combining multiple weak classifiers into a more powerful model for ensemble decision-making, reducing the error of a single model to obtain better generalization performance. Introducing ensemble learning into the field of adversarial training can reduce the sensitivity of a single adversarial training network to specific adversarial samples and improve the robustness and stability of the model. There must be differences in the capabilities of adversarial training networks obtained by different adversarial training methods. Ensemble learning can utilize the differences and complementary defense capabilities between multiple adversarial training networks to improve the accuracy and generalization ability of the ensemble model and enhance the defense ability of the model.

[0119] The ensemble adversarial training method (EnsembleAdversarial Training, EAT) proposed by the present invention is divided into two stages. First, different adversarial training methods are used to train the recognition network. After being trained by different adversarial training methods, the defense capabilities of the recognition networks in different attack scenarios are often different. These networks are used as base classification models. In the second stage, the generated adversarial samples and normal samples are input into several trained basic class models. The predicted probability vectors output by each base classification model are combined to form a new feature vector. The new feature vector contains the respective prediction information of the base classification models trained by different adversarial training methods. Then, the new feature vector is used as the input to train the two-layer meta-classification model, and the final prediction is made by integrating the outputs of each base classification model. In the training of the second stage, the feature vectors of adversarial samples and normal samples are mixed for training to enable the model to balance the recognition capabilities of normal samples and adversarial samples. Therefore, the process of EAT proposed by the present invention is as follows:

[0120] On the training dataset Use different adversarial training methods to train each base recognition model f i , obtaining a model group composed of k base recognition models Generate an adversarial sample set corresponding to the training set using an adversarial attack algorithm Input x into F respectively to obtain a feature vector composed of multiple predicted probability vectors:

[0121] A i =[f 1 (x i ),f 2 (x i ),...,f k (x i )]

[0122]

[0123] Construct a new training set using the feature vector And Mix with to train the meta-recognition model M to be trained, and jointly form an integrated adversarial training network with the base recognition model group F to identify the modulation method of the signal passing through the adversarial sample detection network.

[0124] As Figure 2 shown, the dual defense system for intelligent adversarial communication signal modulation recognition provided by the embodiments of the present invention includes:

[0125] The eigen-dimension feature vector construction module 1 is used to extract the activation features of different layers of the recognition model and construct the data eigen-dimension feature vector.

[0126] The adversarial sample detection module 2 is used to input the internal eigen-dimension of the signal into the detection network to determine whether the signal is an adversarial sample.

[0127] The signal modulation method recognition module 3 is used to fuse the predicted probability vectors of multiple adversarial training networks and input them into the meta-recognition model to identify the true modulation method of the signal.

[0128] The intelligent defense method provided by the present invention can be used not only to defend against adversarial attacks on communication signal modulation recognition models, but also to defend against adversarial attacks in other fields such as image recognition.

[0129] The intrinsic dimensionality feature vector construction module generates an intrinsic dimensionality feature vector for distinguishing normal signals from adversarial samples by extracting the activation features of different layers of the recognition model. Specifically, the pre-trained recognition model performs layer-by-layer feature extraction on the input signal and calculates the activation values within the feature space of each layer. Using the nearest neighbor method, the local intrinsic dimensionality (LID) of the activation values is calculated to form the intrinsic dimensionality feature vector of the sample. The LID value of normal signals is usually low, while that of adversarial samples is high due to their abnormal distribution, which lays the foundation for subsequent detection of adversarial samples.

[0130] The adversarial sample detection module realizes the discrimination of adversarial samples in the signal based on the intrinsic dimensionality feature vector. By performing supervised learning training on the LID feature vectors of normal samples and adversarial samples, a detection network is constructed. When a new signal is input into the system, its LID feature vector is input into the detection network, and the network determines whether the signal is an adversarial sample according to the set detection threshold. The training process of the detection network includes optimizing the accuracy, precision, and recall rate of the model. In particular, when setting the detection threshold, it is necessary to balance the detection ability of adversarial samples and the false positive rate of normal signals to ensure the detection performance and practicality of the system.

[0131] The signal modulation mode recognition module enhances the recognition ability of the signal modulation mode by fusing the prediction probability vectors of multiple adversarial training networks. First, the basic recognition model is trained using various adversarial training methods to make it have strong adversarial robustness. Then, the signal is input into the basic recognition model, and the prediction probability vectors output by each model are extracted and combined into a new feature vector. The new feature vector is input into the meta-recognition model for training, and finally, the true modulation mode of the signal is output. By integrating adversarial training methods, this module significantly improves the recognition accuracy and robustness of the system in complex adversarial environments and also has wide application adaptability, such as in image recognition and other adversarial attack defense scenarios, as Figure 3 shown.

[0132] The technical effects of the present invention will be described in detail below in combination with simulation experiments.

[0133] To evaluate the performance of the present invention, simulation verification is carried out. The simulation experimental environment is as follows: the CPU is Xeon W-2245, the memory is 128GB, the GPU is dual-way NVIDIA GeForce RTX 3080Ti, the Python version is 3.7.0, and the tensorflow GPU version is 2.5.0. In the simulation experiment, a dual defense system for intelligent countermeasure of communication signal modulation recognition is considered. The modulation recognition model to be protected is the ResNet model. The types of modulation signals to be recognized include 8 digital signals: 8PSK, QPSK, BPSK, GFSK, CPFSK, PAM4, QAM16, and QAM64, and 2 analog signals: WBFM and AM-DSB. Under each modulation category, there are 120,000 modulation signal samples evenly distributed from -20dB to 18dB (step size is 2dB). There are 6,000 samples under each signal-to-noise ratio environment. The entire dataset has 1,200,000 sample data in total. Its huge data volume, rich modulation categories, and complex signal-to-noise ratio environment ensure the credibility of the dataset. When testing the performance of adversarial sample detection, the test set is mixed with its corresponding four types of adversarial samples, namely FGSM, PGD, MIM, and BIM, in equal proportion, and the test is carried out at a signal-to-noise ratio of 4dB. The kernel density estimation adversarial sample detection method (Kernel Density Estimation, KDE) and the Bayesian uncertainty estimation adversarial sample detection method (Bayesian Uncertainty Estimation, BUE) are used for comparison. The detection results are shown in Table 1. The simulation results show that compared with the kernel density estimation detection method (KDE) and the Bayesian uncertainty estimation detection method (BUE), the LID detection method of the present invention can achieve high-precision detection for different types of adversarial samples, and performs better in both detection precision and adversarial sample recall rate. Then, the robustness defense ability of the Ensemble Adversarial Training (EAT) model is tested using 4 different adversarial attacks, as Figure 4 shown. It can be seen that the recognition accuracy of EAT in 4 adversarial attack scenarios reaches or even exceeds the best-performing adversarial training model in the current scenario.

[0134] Table 1 Detection accuracy (%) of different adversarial sample detection methods in the 4dB environment

[0135]

[0136] It should be noted that the embodiments of the present invention can be implemented by hardware, software, or a combination of software and hardware. The hardware part can be implemented using dedicated logic; the software part can be stored in a memory and executed by a suitable instruction execution system, such as a microprocessor or dedicated designed hardware. Those of ordinary skill in the art can understand that the above devices and methods can be implemented using computer-executable instructions and / or included in processor control code, such as provided on a carrier medium such as a disk, CD, or DVD-ROM, a programmable memory such as read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. The devices and modules of the present invention can be implemented by hardware circuits of programmable hardware devices such as very large scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, etc., or field programmable gate arrays, programmable logic devices, etc., can also be implemented by software executed by various types of processors, or can be implemented by a combination of the above hardware circuits and software such as firmware.

[0137] As described above, the above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention should be covered within the protection scope of the present invention.

Claims

1. A dual defense method for intelligent confrontation of communication signal modulation recognition, characterized in that: include: Step 1: Extract activation features of different layers of the recognition model and construct feature vectors of the data’s intrinsic dimensions; Step 2: Input the intrinsic dimension of the signal into the detection network to determine whether the signal is an adversarial sample; Step 3: Fusion the predicted probability vectors of the multi-adversarial training networks and input them into the meta-recognition model to identify the true modulation mode of the signal.

2. The dual defense method for communication signal modulation recognition intelligent confrontation as claimed in claim 1, characterized in that: In step 1, the activation features of different layers of the recognition model are extracted to construct the data intrinsic dimension feature vector. The specific process is as follows: for a pre-trained recognition model F(x) with L layers, the benchmark data set X B , training set X norm And using X norm Generated adversarial sample set X adv Input F(x) respectively to get their activation values ​​in the i-th layer of the recognition model: A B =F i (X B ) A norm =F i (X norm ) A adv =F i (X adv ) Then, by calculating the internal intrinsic dimension LID value of the activation value of each layer of the recognition model of the sample to be detected, the LID feature vector of each sample is obtained. The length of the feature vector is consistent with the number of feature layers of the recognition model. The internal intrinsic dimension LID of normal samples and adversarial samples is calculated respectively: Among them, k represents the number of nearest neighbor samples, r n (A,A norm ) means A and A norm The L2 distance between the nth nearest neighbor points in ; Assume that the normal sample x∈X is located in the data manifold S, and generate its corresponding adversarial sample x′ by performing an adversarial attack on x. If x′ is a successful adversarial sample, such that F(x′)≠y, y is the label corresponding to the sample x, then x′ will be located in a high-dimensional data manifold space outside the data manifold S.

3. The dual defense method for communication signal modulation recognition intelligent confrontation as claimed in claim 1, characterized in that: In step 2, the intrinsic dimension of the signal is input into the detection network to determine whether the signal is an adversarial sample. The specific process is as follows: after extracting the LID feature vectors of the normal sample and the adversarial sample, use (LID norm ,LID adv ) trains the detection network Detector and uses indicators such as accuracy, precision and recall to preliminarily evaluate the network's detection performance, which are defined as: Among them, TP represents the number of samples whose true labels and predicted results are both positive, FN represents the number of samples whose true labels are positive and predicted results are negative, FP represents the number of samples whose true labels are negative and predicted results are positive, and TN represents the number of samples whose true value labels and predicted results are both negative. In the scenario of adversarial sample detection, the label of the adversarial sample is set to 1 as positive, and the label of the normal sample is set to 0 as negative. Since the detection network needs to achieve high-precision detection to prevent the loss of normal samples due to misjudging normal samples as adversarial samples, the impact of the detection threshold on the loss of normal samples needs to be considered when selecting the detection threshold of the detection network; increasing the detection threshold will make the detection accuracy higher, but it will also reduce the recall rate of adversarial samples; the calculation formula for the loss ratio of normal samples is: Among them, l clean Indicates the loss ratio of normal samples, N clean 、N FP 、accuracy FP They represent the number of normal samples, the number of false-positive normal samples, and the recognition accuracy of false-positive normal samples respectively; normal samples and adversarial samples are mixed in equal proportions for detection, and the overall normal sample loss under each detection threshold is calculated; under the loss limit of normal samples, the detection threshold that meets the set loss limit is selected to accurately detect adversarial samples mixed in the signal.

4. The dual defense method for communication signal modulation recognition intelligent confrontation as claimed in claim 1, characterized in that: The step 3 is to integrate the predicted probability vectors of multiple adversarial training networks and input them into the meta-recognition model to identify the true modulation mode of the signal. The specific process is as follows: adversarial training is performed by using adversarial samples x that can maximize the internal loss. adv Optimize the current model parameter θ. Formally speaking, adversarial training is to optimize the target by using a min-max process. The training process can be expressed as: Among them, θ is the network weight, x is the original normal sample, y is the true label, and loss(θ,x+r adv ,y) is the adversarial loss function, S is the perturbation space, by setting the perturbation space, the perturbation size can be controlled, and D represents the distribution of training data; the formula in the inner brackets means to find a set of adversarial samples that maximize the loss function in the sample space. The adversarial sample is the original normal sample x by adding the adversarial perturbation r adv The outer min() function refers to optimizing the network parameters and fitting the adversarial sample set generated by the inner layer, so that the expected loss function value on the adversarial sample set is minimized, so that the trained network can resist the attack of the adversarial samples generated in the training phase.

5. The dual defense method for communication signal modulation recognition intelligent confrontation as claimed in claim 1, characterized in that The Ensemble Adversarial Training (EAT) method is divided into two stages. First, different adversarial training methods are used to train the recognition network, and these networks are used as base classification models. In the second stage, the generated adversarial samples and normal samples are input into several trained basic class models, and the prediction probability vectors output by each base classification model are combined to form a new feature vector. The meta-classification model is trained and the final prediction is made by integrating the outputs of each base classification model. Therefore, the process of EAT is as follows: Use different adversarial training methods to train each base recognition model f i , and obtain a model group consisting of k basis recognition models Use the adversarial attack algorithm to generate adversarial sample sets corresponding to the training set Input x into F respectively to obtain feature vectors composed of multiple prediction probability vectors: A i =[f1(x i ),f2(x i ),...,f k (x i )] Use feature vectors to construct a new training set and will and Mix and train the meta-recognition model M to be trained, and use it together with the base recognition model group F to form an integrated adversarial training network to identify the modulation mode of the signal passing through the adversarial sample detection network.

6. A dual defense system for communication signal modulation identification intelligent confrontation implementing the dual defense method for communication signal modulation identification intelligent confrontation as claimed in claims 1 to 4, comprising: The intrinsic dimension feature vector construction module is used to extract the activation features of different layers of the recognition model and construct the data intrinsic dimension feature vector; The adversarial sample detection module is used to input the intrinsic dimension of the signal into the detection network to determine whether the signal is an adversarial sample; The signal modulation mode recognition module is used to fuse the predicted probability vectors of multiple adversarial training networks and input them into the meta-recognition model to identify the actual modulation mode of the signal.

7. The dual defense system for communication signal modulation recognition intelligent confrontation as claimed in claim 6, characterized in that: The activation feature extraction module comprises: An input interface for receiving a benchmark data set, a training set, and an adversarial sample set; Pre-trained recognition model, used to calculate the activation values ​​of input data at different layers of the model; The computing unit is used to calculate the internal intrinsic dimension value and generate the feature vector based on the nearest neighbor distribution of the sample in the feature space.

8. The dual defense system for communication signal modulation recognition intelligent confrontation as claimed in claim 6, characterized in that: The adversarial sample detection module includes: The detection network is used to optimize the network parameters through the internal intrinsic dimension feature vectors of normal samples and adversarial samples in the training dataset; The threshold selection unit is used to select an appropriate detection threshold of the detection network based on the detection performance index to achieve a balance between the normal sample loss and the adversarial sample detection rate.

9. A computer device, comprising a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the dual defense method for intelligent confrontation of communication signal modulation identification as described in any one of claims 1 to 5.

10. An information data processing terminal, comprising a dual defense system for intelligent confrontation of communication signal modulation identification as claimed in any one of claims 6 to 8.