Radio frequency fingerprint identification method and system based on distributed robust optimization
Through an adversarial training method based on distribution robust optimization, the vulnerability problem of the model under data distribution changes and adversarial attacks in the prior art is solved, and the high robustness and stability of the model are achieved.
Patent Information
- Application Number
- CN202510297734.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-13
- Publication Date
- 2025-06-13
AI Technical Summary
In the face of changes in data distribution, the stability of the model is affected and it is difficult to effectively resist adversarial attacks.
Adversarial training method based on distribution robust optimization is adopted to model anti-perturbation and distribution constraints, and perturbation samples that satisfy distribution constraints are generated, which are transformed into solveable unconstrained optimization problems, forming new optimization goals to improve the robustness of the model.
It improves the robustness of the model in the face of variable data distribution and unknown attacks, enhances the anti-interference ability of the model to change data distribution and fight attacks, and ensures stability and reliability in practical applications.
Smart Images

Figure CN120151852A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of radio frequency fingerprint recognition optimization, and particularly relates to a radio frequency fingerprint recognition method and system based on distributionally robust optimization. Background Art
[0002] With the rapid development of artificial intelligence technology, its applications in various fields have become the core driving force for modern industrial and technological progress. Deep learning has been widely applied in signal recognition, image processing, natural language processing, etc. However, the neural network models obtained during the training process of deep learning show certain vulnerability when facing malicious attacks, especially adversarial attacks, which directly affects the application effects in security-sensitive fields.
[0003] To solve this problem, adversarial training has been proposed as an effective defense method. By adding adversarial samples generated by attacks during the training process of the model, the resistance of the model to malicious inputs can be enhanced. This improves the performance of the model in adversarial environments to a certain extent. However, existing adversarial training methods often assume that the distribution of training data is fixed and assume that the generation of attack samples is consistent with the true data distribution. In actual applications, the data distribution often changes, which undermines the stability of the model. Summary of the Invention
[0004] The purpose of the present invention is to provide a radio frequency fingerprint recognition method and system based on distributionally robust optimization to solve the problem that the data distribution often changes and undermines the stability of the model.
[0005] To achieve the above purpose, the present invention adopts the following technical solutions:
[0006] In the first aspect, the present invention provides a radio frequency fingerprint recognition method based on distributionally robust optimization, including:
[0007] Collect radio frequency signals as the original radio frequency input samples, and perform adversarial training, in which adversarial perturbation and distribution constraint modeling are carried out;
[0008] Minimize the maximum loss function after adding perturbations during the adversarial training process, and transform it into a solvable unconstrained optimization problem to form a new optimization objective;
[0009] Based on the new optimization objective, use an adversarial attack mechanism to generate perturbation samples that satisfy the distribution constraints;
[0010] Extract features from the generated adversarial samples and output a radio frequency fingerprint classifier that is strongly robust to potential attacks.
[0011] Further, the collected RF signals are used as the original RF input samples for adversarial training. During the adversarial training, adversarial perturbation and distribution constraint modeling are performed, including:
[0012] Based on the original RF input samples, different adversarial samples are generated through different adversarial attack methods and then input into the neural network model for training. Define the adversarial perturbation constraint conditions to ensure that the perturbed samples are similar to the original data distribution. By analyzing the expected interval of the loss function of the deep learning model, determine the robustness boundary, and use the Wasserstein distance to construct a distribution fuzzy set centered on the original samples to represent the allowable worst perturbation distribution range.
[0013] Further, the expectation of the loss function is minimized through the selection of policy θ where P is the distribution of the continuous random variable ξ; distributed robust optimization is used to provide a robust transformation of the input data, and the worst case within the set distribution is set at each decision-making time limit where, for θ ∈ Θ, the policy θ is a variable in the decision space Θ, and ξ represents the measurable space random parameter; the worst distribution P exists in the probability distribution set is the Wasserstein distance between the distribution P and
[0014] Further, using the Wasserstein distance to construct a distribution fuzzy set centered on the original samples to represent the allowable worst perturbation distribution range, including:
[0015] Determine the central distribution P through the empirical distribution information of the input sample points 0 , and on this basis, find all distributions whose Wasserstein distance from P 0 is less than or equal to the distance threshold, which constitutes an uncertain distribution fuzzy set.
[0016] Further, transforming the minimization of the maximum loss of the model in the perturbed samples during adversarial training into a solvable unconstrained optimization problem to form a new optimization objective, including:
[0017] By introducing the Lagrangian relaxation method, the Wasserstein distance is incorporated into the objective function as a regularization term to form a new optimization objective: where λ balances the classification accuracy and robustness, and the perturbation distribution is constrained by the relaxation term.
[0018] Further, based on the new optimization objective, an adversarial attack mechanism is used to generate perturbed samples that satisfy the distribution constraints, including:
[0019] In each training iteration, a perturbation δ is injected along the gradient direction of the loss function, and the model parameters θ and the perturbation parameter δ are synchronously updated through Stochastic Gradient Descent (SGD); by alternately optimizing the model and the perturbation, the generation strategy of adversarial samples is dynamically adjusted until the upper bound of the loss of the model under the perturbation converges or reaches the preset number of iterations.
[0020] Further, the step of extracting features from the generated adversarial samples and outputting a radio frequency fingerprint classifier with strong robustness against potential attacks includes:
[0021] Input the generated adversarial samples into the MLP-Mixer network for feature extraction:
[0022] Channel-mixing MLP: Perform non-linear transformation in the local feature dimension to capture fine-grained radio frequency fingerprint features at all levels;
[0023] Token-mixing MLP: Achieve cross-token information fusion in the global dimension;
[0024] Through multi-dimensional interaction of the double-mixing mechanism, the model improves its generalization performance in adversarial training, and finally outputs a radio frequency fingerprint classifier with strong robustness against potential attacks.
[0025] In a second aspect, the present invention provides a radio frequency fingerprint recognition system based on distributionally robust optimization, including:
[0026] An adversarial training module, configured to collect radio frequency signals as original radio frequency input samples and perform adversarial training, and model adversarial perturbations and distribution constraints during the adversarial training;
[0027] An optimization objective acquisition module, configured to minimize the maximum loss function after adding perturbations during the adversarial training process, transform it into a solvable unconstrained optimization problem, and form a new optimization objective;
[0028] A perturbed sample generation module, configured to generate perturbed samples that satisfy the distribution constraints based on the new optimization objective by using an adversarial attack mechanism;
[0029] An output module, configured to extract features from the generated adversarial samples and output a radio frequency fingerprint classifier with strong robustness against potential attacks.
[0030] In a third aspect, the present invention provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, where when the processor executes the computer program, the steps of the radio frequency fingerprint recognition method based on distributionally robust optimization are implemented.
[0031] Fourthly, the present invention provides a computer-readable storage medium storing a computer program, which when executed by a processor, implements the steps of the radio frequency fingerprint recognition method based on distributionally robust optimization.
[0032] Compared with the prior art, the present invention has the following technical effects:
[0033] The present invention proposes an adversarial training method based on distributionally robust optimization to improve the robustness of the model against variable data distributions and unknown attacks. By introducing the distributionally robust optimization technique and considering the variations of different data distributions, the performance loss of the model in the worst-case scenario is minimized. Even when facing different training data distributions, the model can maintain good performance, thereby improving its stability and reliability in practical applications.
[0034] The present invention improves the anti-interference ability of the model against data distribution changes and adversarial attacks through the distributionally robust optimization method based on the Wasserstein distance and adversarial training. The Wasserstein distance can effectively measure the differences between different data distributions, avoiding the over-reliance of traditional methods on data distribution assumptions. By optimizing the worst-case performance of the data distribution, the adaptability and stability of the model in the face of data distribution changes are enhanced. Combined with adversarial training, the system can introduce adversarial samples during the training process to further improve the robustness of the model, enabling it to have stronger anti-interference ability, thus effectively coping with the attacks by attackers using adversarial samples. The MLP-Mixer model used in the training process effectively integrates the spatio-temporal features of radio frequency signals through a hierarchical structure to achieve efficient recognition of radio frequency fingerprints. Compared with traditional convolutional neural networks, this model has less computational overhead and can better process high-dimensional feature data.
[0035] The present invention can adapt to different data distribution changes, making the model applicable to diverse practical scenarios and maintaining high-precision and high-stability radio frequency fingerprint recognition performance under adversarial attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 is a system architecture diagram;
[0037] Figure 2 is an algorithm flow chart;
[0038] Figure 3 is a line graph of the classification and recognition results after training with various adversarial methods;
[0039] Figure 4 is a confusion matrix diagram of the classification and recognition results under different interference intensities;
[0040] Figure 5It is a comparison chart of the recognition accuracy of different parameters and different adversarial methods;
[0041] Figure 6 This is the flow chart of the present invention. Specific implementation manner
[0042] The present invention is further described below with reference to the accompanying drawings:
[0043] Example 1, please refer to Figure 6 The present invention provides a radio frequency fingerprint recognition method based on distributionally robust optimization, including:
[0044] Collect radio frequency signals as the original radio frequency input samples, perform adversarial training, and conduct adversarial perturbation and distribution constraint modeling during the adversarial training;
[0045] Minimize the maximum loss function after adding perturbations during the adversarial training process, and transform it into a solvable unconstrained optimization problem to form a new optimization objective;
[0046] Based on the new optimization objective, use the adversarial attack mechanism to generate perturbation samples that satisfy the distribution constraints;
[0047] Extract features from the generated adversarial samples and output a radio frequency fingerprint classifier with strong robustness against potential attacks.
[0048] In view of the defects in the prior art, the present invention proposes an adversarial training method based on distributionally robust optimization to improve the robustness of the model in the face of changing data distributions and unknown attacks. By introducing distributionally robust optimization technology, considering the changes in different data distributions, the performance loss of the model in the worst case is minimized. Even when facing different training data distributions, the model can maintain good performance, thereby improving its stability and reliability in practical applications.
[0049] Example 2, the present invention provides a radio frequency fingerprint recognition method based on distributionally robust optimization, specifically including:
[0050] The purpose of the present invention is to propose a radio frequency fingerprint recognition method based on distributionally robust optimization. Using distributionally robust optimization is to perform appropriate robust transformations on the input data, consider the worst case within a certain range of distributions, use known and limited probability distributions, and the distribution information that varies within a reasonable range to construct a fuzzy set, explore the boundary of the model's robustness, and find an uncertain set of input data composed of the joint distribution centered on the input sample and with a corresponding distance as the radius for training the MLP-Mixer network model. Maximize the generalization of the trained model for classification recognition tasks to cope with various potential dangerous attacks.
[0051] The present invention conducts adversarial training on the original input samples, and determines the model robustness by analyzing the expected interval of the loss function during the training process of the deep learning model. Using adversarial attacks for perturbation, perturbation Δx is injected into the original input x to make the existing model make mistakes as much as possible, while ensuring that the perturbation Δx satisfies certain constraints and is similar to the original data, and then seeking the upper bound of the loss function. The original objective function is established as an equivalent unconstrained optimization objective using the Lagrangian function, and the upper bound of the new optimization problem is minimized. During the adversarial training process, the method of distributed robust optimization is adopted. The Wasserstein distance is used to measure the distribution cost, that is, the distribution distance, between the original sample and the adversarial sample, and the unknown data distribution is transformed into a finite and known distribution. By using the parameter γ, the distribution distance is added to the original optimization problem as a Lagrangian relaxation term, and the min-max problem to be solved is transformed into the solution of the robust alternative optimal value.
[0052] The adversarial samples generated by using the Wasserstein distance for adversarial training are input into the neural network model MLP-Mixer for training. After a series of channel-mixing MLPs and module-mixing MLPs, the two input dimensions interact to complete the feature extraction of the model for the data. During the training process, the random gradient descent algorithm is used to update the parameters in the adversarial attack process until the expected adversarial effect is achieved or the preset number of iterations is completed.
[0053] The system architecture diagram of the present invention is shown in Figure 1 The present invention is directed to a radio frequency fingerprint recognition system for device terminals. The system includes multiple radio frequency devices and a receiving base station. Each communication terminal transmits radio frequency signals to the receiving base station through a wireless channel, and the base station receives and processes these signals. The received signals are transmitted to the radio frequency fingerprint recognition module, and after preprocessing and feature extraction, they are transmitted to the neural network for classification to identify the radio frequency fingerprints of each device. The signals in the system are interfered during the transmission process, that is, the interferer only disrupts the signal transmission between the legitimate radio frequency device and the base station, and tries to generate signal fingerprint information different from that of the legitimate radio frequency device without interfering with the communication between the device and the base station. In this case, the present invention adopts the distributionally robust optimization adversarial training technology based on the Wasserstein distance to enhance the robustness of the radio frequency fingerprint recognition system. By introducing adversarial samples into the training process, the system can effectively resist potential adversarial attacks and ensure the security and stability of the radio frequency fingerprints in different attack environments.
[0054] The implementation process of the present invention is shown in the appendix Figure 2, first, perform adversarial training on the original samples. Generate different adversarial samples through different adversarial attack methods, and then input them into the neural network model for training. During the training process, use the stochastic gradient descent algorithm to update the parameters of each adversarial attack method until the corresponding number of iterations is completed. Use the MLP-Mixer model to process the signal data by replacing the complex model structure with a fully connected multi-layer perceptron. Use single-channel depth convolution with a full receptive field and parameter sharing for mixing to effectively capture the global information of the signal, and use the channel mixing mechanism to effectively fuse the signal features of multiple channels to process the data.
[0055] During the process of using the neural network for classification and recognition, the loss function can reflect the difference between the model's predicted value and the true value, and is used to measure the recognition effect of the model. Therefore, choosing an appropriate loss function is beneficial for the model training to iterate in the direction of optimization. The calculation of the loss function is usually considered as a stochastic optimization problem, and the minimum value of the loss function l(θ; ξ) is sought in the case where the data distribution cannot be fully grasped, that is, the expectation of minimizing the loss function is achieved by selecting the strategy θ. Among them, P is the distribution that follows the continuous random variable ξ. Since the true distribution is difficult to predict and obtain, distributed robust optimization is adopted to provide a suitable robust transformation for the input data, and consider the worst-case scenario within a certain distribution range when making decisions each time. Among them, for θ ∈ Θ, the strategy θ is a variable in the decision space Θ, and ξ represents the measurable space. Random parameter. The worst distribution P exists in all possible probability distribution sets. is the distribution P and Distributed robust optimization uses a fuzzy set composed of a finite number of known probability distributions and distribution information that varies within a reasonable range to solve the inner maximization problem and estimate the robustness boundary of the model.
[0056] The Wasserstein distance can ensure that the defined probability distribution set covers the actual distribution generated by the true data distribution with a relatively high confidence, which is convenient for the model to provide a more robust optimization decision when processing actual data. Determine the central distribution P through the empirical distribution information of the input sample points. 0 , and on this basis, find all distributions whose Wasserstein distance from P 0 is less than or equal to the distance threshold, which constitutes an uncertain distribution set, that is, the Wasserstein ball, and the distance threshold is also called the radius of the Wasserstein ball. The Wasserstein distance is defined as Among them, represents the input sample, y represents the output data, S(P 1 , P2 ) represents the coupling between two distributions, denotes the set of joint distributions, i.e., the boundary of each joint distribution is P 1 and P 2 , where d is the distance defined on Ξ. When studying the min-max problem, distributionally robust optimization based on the Wasserstein distance is used to solve the required model parameters. Suppose there is a robust surrogate then for each joint distribution, it can be expressed as That is to say, under the condition of selecting an appropriate Wasserstein distance, another joint distribution representation can be utilized By introducing Lagrangian relaxation, it is transformed into The classification problem to be dealt with can be generalized as a process in which the features of the input data are mapped to the output categories through the optimal parameters obtained by policy learning. Suppose the input feature space is The output space is denoted as Given a set of training data T containing feature vectors x and corresponding labels y, find an approximate function f θ to achieve the mapping between them. During the supervised learning process, the difference between the model prediction value and the true label is measured by the previously mentioned loss function l(θ; ξ), and the parameter update strategy of gradient descent is used to minimize the loss function, that is where F represents the parameter update strategy, is the loss of the model under the distribution z = (x, y).
[0057] The broken line results of classification and recognition after training with the adversarial method of the present invention are shown in the appendix Figure 3 . Different models are applied under different attack intensities, including MLP, VGG, ResNet, and MLP-Mixer, and the classification and recognition results are compared. MLP-Mixer has good recognition effects and stability under various interference intensities. Therefore, using the MLP-Mixer model is suitable for diverse actual scenarios.
[0058] The confusion matrix diagrams of the classification and recognition results of the present invention under different interference intensities are shown in the appendix Figure 4 . The recognition effects of the MLP-Mixer model under two different attack intensities are shown. When identifying 20 devices, except for a small probability of recognition errors in individual terminals, the rest of the individuals have a high recognition accuracy. Therefore, the present invention can adapt to different data distribution changes.
[0059] The comparison diagrams of the recognition accuracies of the present invention under different parameters and different adversarial methods are shown in the appendix Figure 5。When different adversarial training methods face sample variations with different attack intensities, they will exhibit different degrees of recognition accuracy. The recognition effect using the MLP-Mixer model has the optimal recognition effect in various situations. Therefore, the method of distributionally robust optimization adopted in the present invention can be used to cope with various potential dangerous attacks.
[0060] In another embodiment of the present invention, a radio frequency fingerprint recognition system based on distributionally robust optimization is provided, which can be used to implement the above-mentioned radio frequency fingerprint recognition method based on distributionally robust optimization. Specifically, the system includes:
[0061] An adversarial training module, configured to collect radio frequency signals as original radio frequency input samples and perform adversarial training, and perform adversarial perturbation and distribution constraint modeling during the adversarial training;
[0062] An optimization objective acquisition module, configured to minimize the maximum loss function after adding perturbations during the adversarial training process, and transform it into a solvable unconstrained optimization problem to form a new optimization objective;
[0063] A perturbed sample generation module, configured to generate perturbed samples that satisfy the distribution constraint based on the new optimization objective by using an adversarial attack mechanism;
[0064] An output module, configured to extract features from the generated adversarial samples and output a radio frequency fingerprint classifier with strong robustness to potential attacks.
[0065] The division of modules in the embodiments of the present invention is illustrative. It is only a logical function division. In actual implementation, there may be other division methods. In addition, in each embodiment of the present invention, each functional module can be integrated in one processor, or can exist independently physically, or two or more modules can be integrated in one module. The above integrated modules can be implemented in the form of hardware or in the form of software function modules.
[0066] In another embodiment of the present invention, a computer device is provided. The computer device includes a processor and a memory. The memory is used to store a computer program, and the computer program includes program instructions. The processor is used to execute the program instructions stored in the computer storage medium. The processor may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, and is suitable for implementing one or more instructions. Specifically, it is suitable for loading and executing one or more instructions in the computer storage medium to implement the corresponding method flow or corresponding function. The processor described in the embodiment of the present invention can be used for the operation of a radio frequency fingerprint recognition method based on distributionally robust optimization.
[0067] In another embodiment of the present invention, a storage medium is also provided, specifically a computer-readable storage medium (Memory). The computer-readable storage medium is a memory device in the computer device and is used to store programs and data. It can be understood that the computer-readable storage medium here can include both the built-in storage medium in the computer device and, of course, the extended storage medium supported by the computer device. The computer-readable storage medium provides a storage space, and the operating system of the terminal is stored in this storage space. Moreover, one or more instructions suitable for being loaded and executed by the processor are stored in this storage space, and these instructions can be one or more computer programs (including program codes). It should be noted that the computer-readable storage medium here can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. One or more instructions stored in the computer-readable storage medium can be loaded and executed by the processor to implement the corresponding steps of the radio frequency fingerprint recognition method based on distributionally robust optimization in the above embodiments.
[0068] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) that contain computer-usable program code.
[0069] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or combinations of blocks.
[0070] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or combinations of blocks.
[0071] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are performed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or combinations of blocks.
[0072] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: modifications or equivalent replacements can still be made to the specific embodiments of the present invention, and any modifications or equivalent replacements that do not depart from the spirit and scope of the present invention should be covered by the protection scope of the claims of the present invention.
Claims
1. A radio frequency fingerprint recognition method based on distributed blue bar optimization, characterized in that: include: Collect RF signals as original RF input samples for adversarial training, during which adversarial perturbations and distribution constraint modeling are performed; Minimize the maximum loss function after adding disturbances during adversarial training and transform it into a solvable unconstrained optimization problem to form a new optimization goal. Based on the new optimization objective, an adversarial attack mechanism is used to generate perturbation samples that meet the distribution constraints. The generated adversarial samples are subjected to feature extraction, and a radio frequency fingerprint classifier with strong robustness to potential attacks is output.
2. The radio frequency fingerprint recognition method based on distributed robust optimization according to claim 1 is characterized in that: The collected radio frequency signal is used as the original radio frequency input sample to perform adversarial training, and adversarial perturbation and distribution constraint modeling are performed in the adversarial training, including: Based on the original RF input samples, different adversarial samples are generated through different adversarial attack methods, and then input into the neural network model for training. The adversarial perturbation constraints are defined to ensure that the perturbed samples are similar to the original data distribution. The robustness boundary is determined by analyzing the expected interval of the deep learning model loss function, and the Wasserstein distance is used to construct a distribution fuzzy set centered on the original samples to characterize the allowable worst perturbation distribution range.
3. The radio frequency fingerprint recognition method based on distributed robust optimization according to claim 2 is characterized in that: By selecting the strategy θ, we can minimize the expected loss function. Where P is the distribution of the continuous random variable ξ; distributed robust optimization is used to provide robust transformation of the input data, and the worst case within the set distribution range is limited at each decision making. Among them, for θ∈Θ, strategy θ is the variable of decision space Θ, ξ represents the measurable space Random parameters; the worst distribution P exists in the set of probability distributions middle, is the distribution P and 4. The radio frequency fingerprint recognition method based on distributed robust optimization according to claim 2 is characterized in that: The Wasserstein distance is used to construct a distribution fuzzy set centered on the original sample to characterize the worst perturbation distribution range allowed, including: The central distribution P0 is determined by inputting the empirical distribution information of the sample points. On this basis, all distributions whose Wasserstein distance to P0 is less than or equal to the distance threshold are found to form an uncertain distribution fuzzy set.
5. The radio frequency fingerprint recognition method based on distributed robust optimization according to claim 1 is characterized in that: The problem of maximizing the minimum loss function in adversarial training is transformed into a solvable unconstrained optimization problem to form a new optimization goal, including: By introducing the Lagrangian relaxation method, the Wasserstein distance is incorporated into the objective function as a regularization term to form a new optimization objective: where λ balances the classification accuracy and robustness, and the relaxation term constrains the disturbance distribution.
6. The radio frequency fingerprint recognition method based on distributed robust optimization according to claim 1 is characterized in that: Based on the new optimization objective, the adversarial attack mechanism is used to generate perturbation samples that meet the distribution constraints, including: In each training iteration, the perturbation δ is injected along the gradient direction of the loss function, and the model parameters θ and the perturbation parameters δ are synchronously updated through stochastic gradient descent SGD; by alternately optimizing the model parameters and the direction of the adversarial attack, the adversarial sample generation strategy is dynamically adjusted until the upper bound of the model's loss under perturbation converges or reaches the preset number of iterations.
7. The radio frequency fingerprint recognition method based on distributed robust optimization according to claim 1 is characterized in that: The method of extracting features from the generated adversarial samples and outputting a radio frequency fingerprint classifier that is highly robust to potential attacks includes: The generated adversarial samples are input into the MLP-Mixer network for feature extraction: Channel-mixed MLP: performs nonlinear transformation in the local feature dimension to capture fine-grained RF fingerprint features at all levels; Module hybrid MLP: realizes cross-module information fusion in the global dimension; Through the multi-dimensional interaction of the dual hybrid mechanism, the model improves the generalization performance in adversarial training and ultimately outputs an RF fingerprint classifier that is highly robust to potential attacks.
8. A radio frequency fingerprint recognition system based on distributed blue bar optimization, characterized in that: include: The adversarial training module is used to collect RF signals as original RF input samples for adversarial training, and perform adversarial perturbation and distribution constraint modeling during adversarial training; The optimization target acquisition module is used to minimize the maximum loss function after adding disturbances during adversarial training, transform it into a solvable unconstrained optimization problem, and form a new optimization target; The perturbation sample generation module is used to generate perturbation samples that meet the distribution constraints based on the new optimization objectives and the adversarial attack mechanism; The output module is used to extract features from the generated adversarial samples and output a radio frequency fingerprint classifier that is highly robust to potential attacks.
9. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of a radio frequency fingerprint recognition method based on distributed robust optimization as described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, the steps of a radio frequency fingerprint recognition method based on distributed robust optimization as described in any one of claims 1 to 7 are implemented.