Millimeter-wave radar physical adversarial attack defense method based on multi-domain feature fusion
Through multi-domain feature fusion and deep learning methods, the phase, RCS and angle-velocity features of the millimeter-wave radar echo signal are extracted, and adversarial samples composed of metamaterials are identified and eliminated. This solves the problem of the inability to identify physical adversarial attacks in existing technologies and achieves effective defense and security across environments.
Patent Information
- Application Number
- CN202510987513.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-17
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2045-07-17
AI Technical Summary
Existing technologies cannot effectively identify and defend against physical adversarial attacks caused by metamaterials, have poor generalization capabilities, and are difficult to apply to new and unprecedented environments.
The multi-domain features of the millimeter-wave radar echo signal are extracted through multi-dimensional fast Fourier transform, combined with phase features, radar scattering cross-section features and angle-velocity features, and feature fusion is performed using a multi-layer perceptron. Adversarial sample detection and signal separation are performed through a deep learning model to achieve accurate identification and defense of adversarial samples.
It achieves accurate detection and defense against physical adversarial attacks, improves defense effectiveness and system robustness, can generalize across environments, effectively eliminates the interference of metamaterials on radar signals, and ensures safe operation in fields such as autonomous driving and security monitoring.
Smart Images

Figure CN120491048B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of millimeter-wave radar security defense technology, and in particular to a millimeter-wave radar physical counterattack defense method based on multi-domain feature fusion, an electronic device, and a storage medium. Background Art
[0002] In recent years, millimeter-wave radar has been widely used in fields such as intelligent driving, the Internet of Things, and security due to its high resolution, all-weather operation, and strong robustness to environmental interference. For example, in the field of autonomous driving, millimeter-wave radar has become one of the core sensors for sensing the surrounding environment and obstacles. In the field of human perception, millimeter-wave radar can achieve high-precision monitoring of physiological signals such as breathing and heart rate while protecting privacy.
[0003] However, as their application expands, millimeter-wave radar systems face security threats from physical adversarial attacks. These attacks typically involve placing specialized materials (such as metamaterials) within the radar's visible area to disrupt the radar system's operation and cause it to produce erroneous perception results. Unlike traditional attacks targeting millimeter-wave radar's perception algorithms, these physical-layer attacks are highly concealed and persistent. Attackers can carry them out without accessing internal information about the radar system. Furthermore, because their physical properties are similar to those of natural objects, they are difficult to detect using simple anomaly detection methods.
[0004] Existing defenses against physical adversarial attacks on millimeter-wave radar systems mostly rely on simple physical characteristics (such as intensity) to identify anomalous radar echoes and thus detect physical adversarial attacks. However, these methods suffer from high false negative rates and are only effective against attacks with strong reflections. Recent approaches use deep learning techniques to directly detect adversarial examples from received radar echo signals, thereby identifying their locations and implementing defenses. However, these methods ignore the fundamental differences in reflective properties between metamaterials and natural objects, lack a deep understanding of the characteristics of physical adversarial examples, and are unable to fundamentally distinguish adversarial examples from natural scenes. Consequently, they have poor generalization capabilities and are often limited to fixed environments, making them difficult to apply to new, unseen environments. Summary of the Invention
[0005] In view of the above problems, the present invention provides a millimeter-wave radar physical counterattack defense method based on multi-domain feature fusion, an electronic device and a storage medium, which are used to solve at least one of the above technical problems.
[0006] According to a first aspect of the present invention, a method for defending against millimeter-wave radar physical adversarial attacks based on multi-domain feature fusion is provided, comprising:
[0007] The multi-domain features of the millimeter-wave radar echo signal are extracted using the multi-dimensional fast Fourier transform method to obtain the multi-domain features of the millimeter-wave radar. The millimeter-wave radar echo signal includes the echo signals of the adversarial sample and the echo signals of the non-adversarial sample. The multi-domain features include phase features, radar scattering cross-section features, and angle-velocity features.
[0008] The normalized multi-domain features are fused through a feature fusion network based on a multi-layer perceptron to obtain multi-domain fusion features.
[0009] Use the trained adversarial sample detection model to detect adversarial samples on multi-domain fusion features, and obtain the location information and existence probability information of adversarial samples;
[0010] Based on the location information and existence probability information of the adversarial samples, the millimeter-wave radar echo information is subjected to signal separation, adaptive filtering, signal recovery and optimization processing to obtain the echo signal of the non-adversarial sample.
[0011] According to an embodiment of the present invention, the multi-domain feature extraction of the millimeter-wave radar echo signal using the multi-dimensional fast Fourier transform method is performed to obtain the multi-domain features of the millimeter-wave radar, including:
[0012] Using millimeter-wave radar to receive echo signals of multiple adversarial samples and multiple non-adversarial samples, the original millimeter-wave radar echo signal is obtained;
[0013] Perform data enhancement operations on the original millimeter-wave radar echo signal in the distance domain, angle domain, and velocity domain to obtain the millimeter-wave radar echo signal;
[0014] Perform a fast Fourier transform operation on the millimeter-wave radar echo signal in the range domain to obtain the range domain information, and extract the antenna-dimensional phase history curve at the target distance from the range domain information to obtain the phase feature;
[0015] Performing a fast Fourier transform operation on the range domain information to generate radar cross section features, wherein the radar cross section features include static radar cross section features and dynamic radar cross section features;
[0016] The millimeter-wave radar echo signal is subjected to fast Fourier transform operations and constant false alarm rate detection operations in the distance domain, and then to fast Fourier transform operations in the velocity domain and fast Fourier transform operations in the angle domain to generate angle-velocity features.
[0017] According to an embodiment of the present invention, the antenna-dimensional phase history curve of the above-mentioned adversarial sample and the antenna-dimensional phase history curve of the non-adversarial sample are evaluated by the mean square error index of the first-order differential, the mean square error index of the second-order differential, and the mean square error index of the curve after smoothing based on local polynomial regression and linear least squares method;
[0018] Among them, the mean square error index of the first-order differential is used to evaluate the degree of change between adjacent points in the antenna dimensional phase history curve;
[0019] Among them, the mean square error index of the second-order differential is used to evaluate the curvature of the antenna phase history curve;
[0020] Among them, the mean square error index of the curve after smoothing based on local polynomial regression and linear least squares method is used to evaluate the degree to which the original data points in the antenna dimension phase history curve deviate from the ideal antenna dimension phase history curve.
[0021] According to an embodiment of the present invention, the angle-velocity features of the above-mentioned adversarial samples and the angle-velocity features of the non-adversarial samples are evaluated by the zero-velocity power ratio index, the velocity dimension energy variance index, and the velocity dimension peak number ratio index;
[0022] Among them, the zero-speed power ratio index is used to evaluate the ratio of energy near zero speed to total energy;
[0023] Among them, the velocity dimension energy variance index is used to evaluate the discrete degree of velocity dimension energy distribution;
[0024] Among them, the speed dimension peak ratio indicator is used to evaluate the number of peaks in the speed dimension.
[0025] According to an embodiment of the present invention, the multi-domain features after normalization are fused through a feature fusion network based on a multi-layer perceptron to obtain the multi-domain fusion features, including:
[0026] Normalization of multi-domain features is performed to ensure that the phase features, radar cross-section features, and angle-velocity features in the multi-domain features have the same dimension;
[0027] A feature fusion network is constructed using a multi-layer perceptron with multiple fully connected layers and multiple nonlinear activation functions, and the feature fusion network is used to fuse multi-domain features to obtain multi-domain fusion features.
[0028] According to an embodiment of the present invention, the trained adversarial sample detection model is obtained by the following operations:
[0029] The adversarial sample detection model is iteratively trained and optimized using the cross entropy classification loss function, mean square error localization loss function, and stochastic gradient descent method to obtain a trained adversarial sample detection model.
[0030] According to an embodiment of the present invention, the above-mentioned signal separation, adaptive filtering, signal recovery and optimization processing of millimeter-wave radar echo information based on the position information of the adversarial sample and the existence probability information of the adversarial sample to obtain the echo signal of the non-adversarial sample includes:
[0031] Based on the location information and existence probability information of the adversarial sample, the adversarial sample signal template is constructed using the adversarial sample signal generation function based on the physical model;
[0032] The filter strength coefficient is adaptively set based on the existence probability information of the adversarial sample, and the echo signal of the adversarial sample is filtered out from the millimeter-wave radar echo signal using a self-use filter based on the filter strength coefficient to obtain the echo signal of the initial non-adversarial sample;
[0033] Phase compensation and amplitude correction are performed on the echo signal of the initial non-adversarial sample to obtain the echo signal of the non-adversarial sample.
[0034] According to an embodiment of the present invention, performing phase compensation and amplitude correction on the echo signal of the initial non-adversarial sample to obtain the echo signal of the non-adversarial sample includes:
[0035] The phase correction term of the initial non-adversarial sample echo signal is determined by the energy of the first-order and second-order derivatives of the minimum phase curve, and the phase compensation function is constructed using the phase correction term based on the continuity constraint of the antenna phase history.
[0036] An amplitude correction function is constructed using a preset smoothing factor and a weight coefficient, and the phase compensation function and the amplitude correction function are operated to obtain a signal recovery and optimization function;
[0037] The signal recovery and optimization function is used to perform phase compensation and amplitude correction on the echo signal of the initial non-adversarial sample to obtain the echo signal of the non-adversarial sample.
[0038] A second aspect of the present invention provides an electronic device, comprising: one or more processors; and a memory for storing one or more computer programs, wherein the one or more processors execute the one or more computer programs to implement the steps of the above method.
[0039] The third aspect of the present invention further provides a computer-readable storage medium having a computer program or instructions stored thereon, which implements the steps of the above method when the computer program or instructions are executed by a processor.
[0040] The millimeter-wave radar physical adversarial attack defense method based on multi-domain feature fusion provided by the present invention has significantly improved the defense effect and system robustness. By utilizing methods such as data enhancement and deep learning, it can achieve effective and cross-environmentally generalizable millimeter-wave radar physical adversarial attack defense; at the same time, the method can identify adversarial samples composed of metamaterials from a physical level and effectively eliminate their interference with radar signals, thereby effectively ensuring the safe operation of millimeter-wave radar systems in fields such as autonomous driving and security monitoring. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] The above contents and other objects, features and advantages of the present invention will become more apparent through the following description of the embodiments of the present invention with reference to the accompanying drawings, in which:
[0042] Figure 1 This is a diagram of an application scenario of a millimeter-wave radar physical countermeasure attack defense method based on multi-domain feature fusion according to an embodiment of the present invention;
[0043] Figure 2 is a flowchart of a millimeter-wave radar physical countermeasure attack defense method based on multi-domain feature fusion according to an embodiment of the present invention;
[0044] Figure 3 2. This is a working principle diagram of millimeter-wave radar physical countermeasure attack defense based on multi-domain feature fusion according to an embodiment of the present invention;
[0045] Figure 4 2 is a schematic structural diagram of a millimeter-wave radar physical countermeasure attack defense device based on multi-domain feature fusion according to an embodiment of the present invention;
[0046] Figure 5 2. It is a schematic diagram of the effect of distinguishing physical adversarial samples using phase features according to an embodiment of the present invention;
[0047] Figure 6 2. It is a schematic diagram of the effect of distinguishing physical adversarial samples using RCS features according to an embodiment of the present invention;
[0048] Figure 7 2. It is a schematic diagram of the effect of distinguishing physical adversarial samples using angle-velocity features according to an embodiment of the present invention;
[0049] Figure 8 2. It is a schematic diagram of the effect of distinguishing physical adversarial samples using the multi-feature fusion method according to an embodiment of the present invention;
[0050] Figure 9 2 is a schematic diagram of the defense effect against false target attacks according to an embodiment of the present invention;
[0051] Figure 10 is a schematic diagram of the defense effect against hidden attacks according to an embodiment of the present invention;
[0052] Figure 11 4 is a block diagram of an electronic device suitable for implementing a millimeter-wave radar physical countermeasure attack defense method based on multi-domain feature fusion according to an embodiment of the present invention. DETAILED DESCRIPTION
[0053] Hereinafter, embodiments of the present invention will be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the present invention. In the following detailed description, for ease of explanation, many specific details are set forth to provide a comprehensive understanding of embodiments of the present invention. However, it is apparent that one or more embodiments may also be implemented without these specific details. In addition, in the following description, descriptions of known structures and technologies are omitted to avoid unnecessary confusion of the concept of the present invention.
[0054] The terms used herein are only for describing specific embodiments and are not intended to limit the present invention. The terms "comprise", "include", etc. used herein indicate the presence of the features, steps, operations and / or components, but do not exclude the presence or addition of one or more other features, steps, operations or components.
[0055] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art unless otherwise defined. It should be noted that the terms used herein should be interpreted as having a meaning consistent with the context of this specification and should not be interpreted in an idealized or overly rigid manner.
[0056] When expressions such as "at least one of A, B, and C, etc." are used, they should generally be interpreted in accordance with the meaning commonly understood by those skilled in the art (for example, "a system having at least one of A, B, and C" should include but is not limited to a system having A alone, B alone, C alone, A and B, A and C, B and C, and / or A, B, C, etc.).
[0057] Since existing physical adversarial attack defense technologies for millimeter-wave radar systems cannot identify attacks from adversarial samples composed of metamaterials, have poor generalization, and are limited in scenario applications, the present invention provides a millimeter-wave radar physical adversarial attack defense method based on multi-domain feature fusion. By utilizing the unique echo features of physical adversarial samples and combining deep learning methods such as data enhancement, effective and cross-environmentally generalizable millimeter-wave radar physical adversarial attack defense is achieved.
[0058] The millimeter-wave radar physical adversarial attack defense method proposed in this invention, based on multi-domain feature fusion, extracts the unique characteristics of metamaterials from three dimensions: phase characteristics, radar cross-section (RCS) characteristics, and angle-velocity characteristics, targeting the differences in electromagnetic reflection characteristics between metamaterials and natural objects. Feature fusion and recognition are performed through multi-domain transformation, data enhancement, and deep learning networks to achieve accurate detection and defense against physical adversarial attacks.
[0059] Figure 1 This is an application scenario diagram of a millimeter-wave radar physical countermeasure attack defense method based on multi-domain feature fusion according to an embodiment of the present invention.
[0060] like Figure 1 As shown, the application scenario 100 according to this embodiment may include the field of millimeter wave radar security defense, such as autonomous driving, security monitoring, etc. The network 104 is used as a medium for providing a communication link between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired or wireless communication links or fiber optic cables.
[0061] A user may use a first terminal device 101, a second terminal device 102, or a third terminal device 103 to interact with a server 105 via a network 104 to receive or send messages, etc. Various communication client applications may be installed on the first terminal device 101, the second terminal device 102, or the third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social platform software, etc. (for example only).
[0062] The first terminal device 101 , the second terminal device 102 , and the third terminal device 103 may be various electronic devices having display screens and supporting web browsing, including but not limited to smart phones, tablet computers, laptop computers, desktop computers, and the like.
[0063] The server 105 may be a server that provides various services, such as a background management server (for example only) that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103. The background management server may analyze and process received data such as user requests, and feed back processing results (e.g., web pages, information, or data obtained or generated based on user requests) to the terminal devices.
[0064] It should be noted that the millimeter-wave radar physical counterattack defense method based on multi-domain feature fusion provided in the embodiment of the present invention can generally be executed by the server 105. Accordingly, the millimeter-wave radar physical counterattack defense device based on multi-domain feature fusion provided in the embodiment of the present invention can generally be set in the server 105. The millimeter-wave radar physical counterattack defense method based on multi-domain feature fusion provided in the embodiment of the present invention can also be executed by a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105. Accordingly, the millimeter-wave radar physical counterattack defense device based on multi-domain feature fusion provided in the embodiment of the present invention can also be set in a server or server cluster that is different from the server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103 and / or the server 105.
[0065] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.
[0066] The following will be based on Figure 1 The scene described by Figure 2 and Figure 3 The millimeter-wave radar physical countermeasure attack defense method based on multi-domain feature fusion of the disclosed embodiment is described in detail.
[0067] Figure 2 This is a flowchart of a millimeter-wave radar physical countermeasure attack defense method based on multi-domain feature fusion according to an embodiment of the present invention.
[0068] like Figure 2 As shown, the above-mentioned millimeter-wave radar physical countermeasure attack defense method based on multi-domain feature fusion includes operations S210 to S240.
[0069] In operation S210, a multi-domain feature extraction is performed on the millimeter-wave radar echo signal using a multi-dimensional fast Fourier transform method to obtain the multi-domain features of the millimeter-wave radar, wherein the millimeter-wave radar echo signal includes the echo signal of the adversarial sample and the echo signal of the non-adversarial sample, and the multi-domain features include phase features, radar scattering cross-section features, and angle-velocity features.
[0070] The above-mentioned millimeter-wave radar echo signals include echo signals of adversarial samples composed of metamaterials and echo signals of non-adversarial samples composed of natural objects.
[0071] In the process of collecting the above-mentioned millimeter-wave radar echo signals, a millimeter-wave radar system (for example, an FMCW radar operating at 60 GHz or 77 GHz) was used to collect echo data in various scenarios.
[0072] In operation S220 , the normalized multi-domain features are fused through a feature fusion network based on a multi-layer perceptron to obtain multi-domain fusion features.
[0073] In operation S230 , the trained adversarial sample detection model is used to perform adversarial sample detection on the multi-domain fusion features to obtain location information of the adversarial samples and existence probability information of the adversarial samples.
[0074] In operation S240 , signal separation, adaptive filtering, signal recovery, and optimization processing are performed on the millimeter-wave radar echo information based on the position information of the adversarial sample and the existence probability information of the adversarial sample to obtain the echo signal of the non-adversarial sample.
[0075] The millimeter-wave radar physical adversarial attack defense method based on multi-domain feature fusion provided by the present invention has significantly improved the defense effect and system robustness. By utilizing methods such as data enhancement and deep learning, it can achieve effective and cross-environmentally generalizable millimeter-wave radar physical adversarial attack defense; at the same time, the method can identify adversarial samples composed of metamaterials from a physical level and effectively eliminate their interference with radar signals, thereby effectively ensuring the safe operation of millimeter-wave radar systems in fields such as autonomous driving and security monitoring.
[0076] The following is a specific implementation method and combined with the attached Figure 3 The millimeter-wave radar physical countermeasure attack defense method based on multi-domain feature fusion provided by the present invention is further described in detail.
[0077] Figure 3 This is a diagram showing the working principle of millimeter-wave radar physical countermeasure attack defense based on multi-domain feature fusion according to an embodiment of the present invention.
[0078] like Figure 3 As shown in the figure, the original signals (i.e., millimeter-wave radar echo signals, the same below) including adversarial samples (metamaterials) and non-adversarial samples (natural objects) are first collected. Then, multi-domain features are extracted from the original radar signals, including phase features (speciality 1), RCS features (speciality 2), and velocity features (speciality 3, i.e., angle-velocity features). The multi-domain features obtained above are then fused, and the multi-domain fused features are used for adversarial sample detection. Based on the detection results, the echo signals of the adversarial samples are separated and filtered out from the original radar signals to obtain the radar signal after filtering out the adversarial samples.
[0079] According to an embodiment of the present invention, the multi-domain feature extraction of the millimeter-wave radar echo signal using the multi-dimensional fast Fourier transform method to obtain the multi-domain features of the millimeter-wave radar includes: using the millimeter-wave radar to receive the echo signals of multiple adversarial samples and the echo signals of multiple non-adversarial samples to obtain the original millimeter-wave radar echo signal; performing data enhancement operations in the range domain, angle domain, and velocity domain on the original millimeter-wave radar echo signal to obtain the millimeter-wave radar echo signal; performing a fast Fourier transform operation in the range domain on the millimeter-wave radar echo signal to obtain range domain information, and extracting the antenna-dimensional phase history curve at the target distance from the range domain information to obtain a phase feature; performing a fast Fourier transform operation on the range domain information to generate a radar cross-section feature, wherein the radar cross-section feature includes a static radar cross-section feature and a dynamic radar cross-section feature; performing a fast Fourier transform operation and a constant false alarm rate detection operation on the millimeter-wave radar echo signal in the range domain, and then performing a fast Fourier transform operation in the velocity domain and a fast Fourier transform operation in the angle domain to generate an angle-velocity feature.
[0080] The specific extraction process of the above multi-domain features is further described in detail below through a specific implementation method.
[0081] Before performing multi-domain feature extraction, we first need to obtain the millimeter wave radar signal. As shown in formula (1):
[0082] (1),
[0083] in, Indicates time (the same below), and Respectively represent the transmitting and receiving antenna numbers (the same below), Indicates the The reflection intensity of each reflection point (the same below), is the carrier frequency (the same below), is the frequency modulation (the same below), It is The round-trip delay of each reflection point (the same below) is Represents an imaginary unit (the same below).
[0084] Second, dataset construction: construct a large-scale dataset containing adversarial samples and non-adversarial samples ,in, Indicates the The original radar signal, Indicates the Whether there are adversarial samples in the samples. The dataset includes:
[0085] (1) Adversarial sample data: Radar echo data at different positions and angles of adversarial samples made of 10 different materials (such as aluminum foil, tin coil, and absorbing material);
[0086] (2) Non-adversarial sample data: radar echo data of objects in natural scenes (such as metal plates, metal balls, etc.) and data in public datasets (such as Coloradar).
[0087] Finally, data enhancement is performed to perform multi-domain enhancement on the collected data to expand the dataset and improve the robustness of the model:
[0088] (1) Distance domain enhancement : Add phase error in the fast time dimension , changing the apparent distance of the target , as shown in formula (2):
[0089] (2);
[0090] (2) Angle domain enhancement : Add phase error in antenna dimension , changing the apparent angle of the target , as shown in formula (3):
[0091] (3);
[0092] (3) Velocity domain enhancement : Add phase error in the slow time dimension , changes the apparent speed of the target , as shown in formula (4):
[0093] (4).
[0094] After completing the original radar signal acquisition and data enhancement, multi-domain feature extraction is performed based on the millimeter wave reflection mechanism.
[0095] The core concept of this invention is to exploit the essential differences in electromagnetic reflection properties between metamaterials (adversarial samples) and natural objects. These differences are mainly manifested in three aspects: (1) The surface texture of metamaterials is unique, resulting in phase characteristics (such as periodicity) that are different from those in natural scenes; (2) The RCS of metamaterials is different from that of natural objects, and the RCS of metamaterials is more regular, such as very uniform isotropy or mirror reflection close to the delta function; (3) Metamaterials violate natural continuity in the velocity domain, resulting in impossible velocity-angle combinations. Based on these essential differences, multi-domain feature extraction extracts three types of features from the original radar signal: phase features, RCS features, and angle-velocity features.
[0096] Among them, phase feature extraction, the original radar signal is subjected to range FFT to obtain the range domain signal , as shown in formula (5):
[0097] (5),
[0098] Extract the target distance from The antenna dimensional phase history at , the phase continuity characteristic is obtained , as shown in formula (6):
[0099] (6).
[0100] Among them, RCS feature extraction is used to extract the distance domain signal Perform angle FFT to generate RCS graph , as shown in formula (7):
[0101] (7);
[0102] Static and dynamic RCS features are extracted from it, as shown in formula (8):
[0103] (8),
[0104] in is the static feature of the still frame, It is a dynamic feature, which means the changes of these static features in the time dimension.
[0105] Among them, the angle-velocity characteristic After extracting, the original signal is subjected to distance FFT and CFAR detection, and then velocity FFT and angle FFT are performed to generate an angle-velocity graph, as shown in formula (9):
[0106] (9),
[0107] Thus, the velocity domain characteristics are obtained.
[0108] According to an embodiment of the present invention, the antenna-dimensional phase history curve of the above-mentioned adversarial sample and the antenna-dimensional phase history curve of the non-adversarial sample are evaluated by the mean square error index of the first-order differential, the mean square error index of the second-order differential, and the mean square error index of the curve after smoothing based on local polynomial regression and linear least squares method; wherein, the mean square error index of the first-order differential is used to evaluate the degree of change between adjacent points in the antenna-dimensional phase history curve; wherein, the mean square error index of the second-order differential is used to evaluate the degree of curvature of the antenna-dimensional phase history curve; wherein, the mean square error index of the curve after smoothing based on local polynomial regression and linear least squares method is used to evaluate the degree to which the original data points in the antenna-dimensional phase history curve deviate from the ideal antenna-dimensional phase history curve.
[0109] The first-order differential mean square error (FDE) metric effectively detects abnormal signal mutations introduced by adversarial examples by analyzing the gradient changes between adjacent sampling points of the phase curve. Such mutations can disrupt the millimeter-wave radar's accuracy in measuring target velocity (for example, by interfering with the Doppler effect), affecting the radar's ability to stably track moving targets.
[0110] The second-order differential mean square error (MDSE) metric focuses on the curvature of the phase curve, enabling it to identify unnatural curvatures caused by adversarial examples. Such interference can reduce the radar's angular resolution, impairing its ability to distinguish targets in close-range, multi-target scenarios, and directly impacting the reliability of safety features like collision avoidance.
[0111] The smoothed mean square error (MSE) metric, constructed using local polynomial regression and linear least squares to construct an ideal phase curve benchmark, quantifies the overall deviation of the adversarial example from the original signal structure. Large deviations indicate that the interfering signal exceeds the tolerance of conventional signal processing (such as filtering algorithms), potentially leading to false target detection or the generation of spurious trajectories.
[0112] These indicators together constitute a multi-dimensional evaluation system, which provides a quantitative basis for optimizing the anti-interference algorithm of the millimeter-wave radar system, and is particularly valuable for detecting common attack methods such as signal waveform tampering and phase disturbance in adversarial sample attacks.
[0113] According to an embodiment of the present invention, the angle-velocity features of the above-mentioned adversarial samples and the angle-velocity features of the non-adversarial samples are evaluated by a zero-speed power ratio index, a speed dimension energy variance index, and a speed dimension peak number ratio index; wherein, the zero-speed power ratio index is used to evaluate the proportion of energy near zero speed to the total energy; wherein, the speed dimension energy variance index is used to evaluate the degree of discreteness of the speed dimension energy distribution; wherein, the speed dimension peak number ratio index is used to evaluate the number of peaks in the speed dimension.
[0114] The zero-speed power ratio indicator can effectively identify stationary target interference forged by adversarial samples by quantifying the energy concentration in the zero-speed interval.
[0115] The velocity-dimensional energy variance metric reflects the discreteness of the velocity-dimensional energy distribution and can detect energy distribution anomalies caused by adversarial examples. In normal scenarios, the target velocity-dimensional energy typically exhibits a unimodal or bimodal distribution. However, adversarial attacks can generate discrete energy clusters through multi-band perturbations, causing the radar to misjudge multiple false motion trajectories.
[0116] The velocity peak ratio metric, which counts the number of effective velocity peaks, can identify densely packed false targets generated by adversarial examples. Attackers can generate a large number of low-power false peaks in the velocity dimension through high-frequency perturbations, potentially exceeding the screening threshold of traditional radar constant false alarm rate (CFAR) detection algorithms.
[0117] These indicators together constitute a multi-level defense system in the speed-angle domain, and their data can be input into the decision module of the anti-interference algorithm to achieve dynamic detection and feature repair of adversarial samples.
[0118] According to an embodiment of the present invention, the above-mentioned multi-domain features after normalization are fused through a feature fusion network based on a multi-layer perceptron to obtain the multi-domain fusion features, which includes: normalizing the multi-domain features to ensure that the phase features, radar cross-section features, and angle-velocity features in the multi-domain features have the same dimension; constructing a feature fusion network using a multi-layer perceptron with multiple fully connected layers and multiple nonlinear activation functions, and using the feature fusion network to fuse the multi-domain features to obtain the multi-domain fusion features.
[0119] The following is a detailed description of the multi-domain fusion feature acquisition process through a specific implementation method.
[0120] A multi-layer perceptron (MLP) is used to adaptively fuse the above three types of features to generate a comprehensive feature representation that can effectively distinguish adversarial samples from non-adversarial samples.
[0121] First, feature normalization is performed to normalize the extracted features to ensure that the dimensions of each feature are consistent, as shown in formula (10):
[0122] (10),
[0123] in, and Characteristics The mean and standard deviation of Represents the result after feature normalization.
[0124] Secondly, the feature fusion network is designed to perform feature fusion using a multi-layer perceptron, as shown in formula (11):
[0125] (11);
[0126] Represents the result after feature fusion. It consists of multiple fully connected layers and nonlinear activation functions, as shown in formula (12):
[0127] (12),
[0128] in It is The weight matrix of the layer, is a nonlinear activation function (such as ReLU), Represents function composition.
[0129] According to an embodiment of the present invention, the above-mentioned trained adversarial sample detection model is obtained through the following operations: the adversarial sample detection model is iteratively trained and optimized using the cross entropy classification loss function, the mean square error positioning loss function and the stochastic gradient descent method to obtain the trained adversarial sample detection model.
[0130] The following is a further detailed description of data-driven adversarial sample detection through specific implementation methods.
[0131] Data-driven adversarial sample detection is based on fusion features and uses deep learning models to achieve accurate detection of adversarial samples.
[0132] First, the detection model is designed using a multi-layer perceptron Construct the detection model as shown in formula (13):
[0133] (13),
[0134] in is the probability of the existence of adversarial samples, is the location information of the adversarial sample.
[0135] Secondly, the loss function The design combines classification loss and localization loss, as shown in formula (14):
[0136] (14),
[0137] The classification loss Using cross entropy loss, positioning loss The mean square error is used, as shown in formula (15):
[0138] (15)
[0139] Finally, the model is trained and the model parameters are optimized using the stochastic gradient descent method, as shown in formula (16): (16),
[0140] in are model parameters, is the learning rate, Express Find the gradient. According to the experimental results, the present invention adopts .
[0141] According to an embodiment of the present invention, the above-mentioned signal separation, adaptive filtering, signal recovery and optimization processing of millimeter-wave radar echo information based on the position information of the adversarial sample and the existence probability information of the adversarial sample to obtain the echo signal of the non-adversarial sample includes: based on the position information of the adversarial sample and the existence probability information of the adversarial sample, using the adversarial sample signal generation function based on the physical model to construct the signal template of the adversarial sample; based on the existence probability information of the adversarial sample, adaptively setting the filter strength coefficient, and using a self-use filter based on the filter strength coefficient to filter out the echo signal of the adversarial sample from the millimeter-wave radar echo signal to obtain the echo signal of the initial non-adversarial sample; performing phase compensation and amplitude correction on the echo signal of the initial non-adversarial sample to obtain the echo signal of the non-adversarial sample.
[0142] According to an embodiment of the present invention, the above-mentioned phase compensation and amplitude correction of the echo signal of the initial non-adversarial sample to obtain the echo signal of the non-adversarial sample includes: determining the phase correction term of the echo signal of the initial non-adversarial sample through the energy of the first-order and second-order derivatives of the minimum phase curve, and constructing a phase compensation function based on the continuity constraint of the antenna phase history using the phase correction term; constructing an amplitude correction function using a preset smoothing factor and a weight coefficient, and operating the phase compensation function and the amplitude correction function to obtain a signal recovery and optimization function; using the signal recovery and optimization function to perform phase compensation and amplitude correction on the echo signal of the initial non-adversarial sample to obtain the echo signal of the non-adversarial sample.
[0143] The separation and filtering process of the adversarial sample echo signal provided by the present invention will be further described in detail below through specific implementation methods.
[0144] The adversarial sample echo signal is separated and filtered. Based on the detection results, an adaptive filter is designed to remove the adversarial sample component in the radar signal and restore the normal radar echo.
[0145] First, signal separation is performed based on the detected adversarial sample locations. , construct adversarial sample signal template , as shown in formula (17):
[0146] (17),
[0147] in, It is an adversarial sample signal generation function based on the physical model.
[0148] Secondly, adaptive filtering, designing adaptive filters Filter out the adversarial sample component from the original signal, as shown in formula (18):
[0149] (18),
[0150] in, Based on the detection confidence Adaptive filter strength.
[0151] Finally, signal recovery and optimization are performed to perform phase compensation and amplitude correction on the filtered signal to restore normal radar echo characteristics. , as shown in formula (19):
[0152] (19),
[0153] in is the signal recovery and optimization function, as shown in formula (20):
[0154] (20);
[0155] Phase compensation function The continuity constraint based on the antenna-dimensional phase history is shown in formula (21):
[0156] (twenty one),
[0157] in, is the phase correction term, which is determined by minimizing the energy of the first and second derivatives of the phase curve, as shown in formula (22):
[0158] (twenty two),
[0159] in, and Indicates different weight coefficients.
[0160] Amplitude correction function Ensure that the signal energy distribution conforms to the reflection characteristics of natural objects, as shown in formula (23):
[0161] (twenty three),
[0162] in, is the smoothing factor, is the weight coefficient. This composite recovery function comprehensively considers phase continuity and energy consistency and can effectively recover radar signals interfered by adversarial samples.
[0163] Figure 4 3 is a schematic structural diagram of a millimeter-wave radar physical countermeasure attack defense device based on multi-domain feature fusion according to an embodiment of the present invention.
[0164] like Figure 4 As shown, the above-mentioned millimeter-wave radar physical counterattack defense device 400 based on multi-domain feature fusion includes a multi-domain feature extraction module 410, a multi-domain feature fusion module 420, an adversarial sample detection module 430 and a signal component and filtering module 440.
[0165] The multi-domain feature extraction module 410 is used to extract multi-domain features from the millimeter-wave radar echo signal using a multi-dimensional fast Fourier transform method to obtain the multi-domain features of the millimeter-wave radar, wherein the millimeter-wave radar echo signal includes the echo signal of the adversarial sample and the echo signal of the non-adversarial sample, and the multi-domain features include phase features, radar scattering cross-section features, and angle-velocity features. In one embodiment, the multi-domain feature extraction module 410 can be used to perform the operation S210 described above, which will not be repeated here.
[0166] The multi-domain feature fusion module 420 is used to fuse the normalized multi-domain features through a feature fusion network based on a multi-layer perceptron to obtain multi-domain fusion features. In one embodiment, the multi-domain feature fusion module 420 can be used to perform the operation S220 described above, which will not be repeated here.
[0167] The adversarial sample detection module 430 is used to use the trained adversarial sample detection model to perform adversarial sample detection on the multi-domain fusion features to obtain the location information of the adversarial sample and the existence probability information of the adversarial sample. In one embodiment, the adversarial sample detection module 430 can be used to perform the operation S230 described above, which will not be repeated here.
[0168] Signal component and filtering module 440 is configured to perform signal separation, adaptive filtering, and signal recovery and optimization processing on the millimeter-wave radar echo information based on the adversarial sample location information and adversarial sample presence probability information, thereby obtaining a non-adversarial sample echo signal. In one embodiment, signal component and filtering module 440 can be used to perform operation S240 described above and will not be further described here.
[0169] According to embodiments of the present invention, any multiple modules among the multi-domain feature extraction module 410, the multi-domain feature fusion module 420, the adversarial example detection module 430, and the signal component and filtering module 440 may be combined into a single module, or any one of these modules may be split into multiple modules. Alternatively, at least part of the functionality of one or more of these modules may be combined with at least part of the functionality of other modules and implemented in a single module. According to embodiments of the present invention, at least one of the multi-domain feature extraction module 410, the multi-domain feature fusion module 420, the adversarial example detection module 430, and the signal component and filtering module 440 may be at least partially implemented as a hardware circuit, such as a field programmable gate array (FPGA), a programmable logic array (PLA), a system on a chip, a system on a substrate, a system on a package, an application-specific integrated circuit (ASIC), or may be implemented in hardware or firmware through any other reasonable means of circuit integration or packaging, or implemented in any one of software, hardware, and firmware, or any suitable combination of these. Alternatively, at least one of the multi-domain feature extraction module 410, the multi-domain feature fusion module 420, the adversarial sample detection module 430, and the signal component and filtering module 440 can be at least partially implemented as a computer program module, which can perform corresponding functions when executed.
[0170] The millimeter-wave radar physical countermeasure attack defense based on multi-domain feature fusion provided by the present invention is verified through multiple experiments and combined with experimental drawings.
[0171] Experiment 1: Extraction and verification of phase features (specificity 1)
[0172] Figure 5 2 is a schematic diagram of the effect of distinguishing physical adversarial samples using phase features according to an embodiment of the present invention.
[0173] like Figure 5 As shown in Figure 1, Experiment 1 verified the differences in phase signatures between metamaterial adversarial samples and natural objects. Using a 2243 mmWave radar system operating at 77 GHz, the experiment observed both the adversarial samples and everyday objects, acquiring their radar echo signals. The signal processing flow is as follows: First, a range-based FFT is performed on the original radar signal to obtain range-dimensional data. Then, the antenna-dimensional phase history at the target distance is intercepted to form an antenna-dimensional phase history curve. Figure 5 (a) shows the antenna-dimensional phase history curve of the adversarial sample (AE) (adversarial sample and its characteristics 1), Figure 5(b) in the figure shows the antenna-dimensional phase history curve of the non-adversarial sample (NAE) (non-adversarial sample and its feature 1). It can be clearly seen from the figure that the continuity of the phase curve of the adversarial sample is significantly worse than that of the non-adversarial sample. In order to quantify this difference, the present invention designs three evaluation indicators: (1) MSE of the first-order differential (1st Δ): evaluates the severity of the change between adjacent points; (2) MSE of the second-order differential (2nd Δ): evaluates the severity of the curve bending change; (3) MSE of the Savitzky-Golay smoothed curve (Δ Savitzky-Golay): evaluates the degree to which the original data points "deviate from the ideal curve". As shown Figure 5 As shown in (c) (Statistical Analysis of Adversarial and Non-adversarial Examples and Feature 1), there are significant differences between adversarial and non-adversarial examples in three metrics: the adversarial examples have significantly higher values than the non-adversarial examples. Specifically, the adversarial examples have a 1stΔ of 0.37, a 2ndΔ of 0.58, and a ΔSavitzky-Golay of 0.10; the corresponding metrics for the non-adversarial examples are 0.14, 0.22, and 0.02, respectively. This confirms that phase features can effectively distinguish adversarial examples.
[0174] Experiment 2: Extraction and verification of RCS features (specificity 2)
[0175] Figure 6 2 is a schematic diagram of the effect of distinguishing physical adversarial samples using RCS features according to an embodiment of the present invention.
[0176] like Figure 6 As shown in Figure 2, this experiment verifies the difference in RCS characteristics between metamaterial adversarial samples and natural objects. Figure 6 (a) in (i.e., adversarial sample and its feature 2) and Figure 6 (b) in the figure (i.e., non-adversarial sample and its feature 2) shows the adversarial sample and its RCS feature map, where the left side is the actual sample map and the right side is the corresponding RCS feature map. The horizontal axis of the feature map is the angle and the vertical axis is the distance. This experiment mainly analyzes the static RCS features: for the RCS feature map, we extracted relevant feature indicators for analysis. Figure 6 (a) and Figure 6 As can be observed in (b), adversarial samples have their own unique RCS feature distribution pattern. Figure 6Panel (c) shows the statistical analysis results of feature 2 for adversarial and non-adversarial examples. The statistical chart clearly shows that the feature values for non-adversarial examples are significantly higher than those for adversarial examples, with an average value of 11.04, while the average value for adversarial examples is only 3.99. This statistically significant difference indicates that static RCS features can effectively distinguish adversarial and non-adversarial examples. Experimental results demonstrate that static RCS features can serve as an important basis for identifying metamaterial adversarial examples, providing a reliable technical means for detecting adversarial examples.
[0177] Experiment 3: Extraction and verification of angle-velocity features (speciality 3)
[0178] Figure 7 2 is a schematic diagram of the effect of distinguishing physical adversarial samples using angle-velocity features according to an embodiment of the present invention.
[0179] like Figure 7 As shown in Figure 2, this example demonstrates the difference in angular-velocity characteristics between metamaterial adversarial examples and natural objects. The experiment used a 2243 mmWave radar system to observe both adversarial and non-adversarial examples in motion. The signal processing pipeline includes performing range FFT and CFAR detection on the raw radar signal, followed by velocity and angle FFTs to generate an angle-velocity plot (AD plot), with angle on the horizontal axis and velocity on the vertical axis. Figure 7 (a) in Figure 3 shows the adversarial sample and its feature 3, with the physical sample (covered with metal foil) on the left and the corresponding angle-velocity graph on the right. Figure 7 Figure (b) shows a non-adversarial example and its characteristic 3. The left side shows the physical example (star structure), and the right side shows the corresponding angle-velocity diagram. It is clear from the figure that the energy distribution of the non-adversarial example in the velocity dimension is more dispersed, while the energy of the adversarial example is more concentrated near zero velocity.
[0180] To quantify this difference, the present invention designs three evaluation indicators: (1) Zero speed power ratio: evaluates the ratio of energy near zero speed to total energy; (2) Speed dimension energy variance: evaluates the degree of discreteness of speed dimension energy distribution; (3) Speed dimension peak number ratio: evaluates the number of peaks in the speed dimension. Figure 7 As shown in (c) of the figure, statistical analysis of the experimental results shows that the zero-velocity power ratio of the adversarial example is 0.79, significantly higher than the 0.65 of the non-adversarial example. The velocity dimension energy variance of the adversarial example is 3.79, lower than the 4.23 of the non-adversarial example. The velocity dimension peak ratio of the adversarial example is 1.2827, lower than the 1.7449 of the non-adversarial example. This confirms that the angle-velocity feature can be used as an effective basis for distinguishing adversarial examples.
[0181] Experiment 4: Multi-feature fusion and adversarial sample detection
[0182] Figure 8 2. It is a schematic diagram of the effect of distinguishing physical adversarial samples by the multi-feature fusion method according to an embodiment of the present invention.
[0183] like Figure 8 As shown in Figure 2, this example verifies the effectiveness of the adversarial sample detection method based on multi-feature fusion of the present invention, which is presented in a visual way through training indicators, where: Figure 8 (a) in the figure represents various loss curves, such as training loss curve, training loss (smooth) curve, test loss curve, and test loss (smooth) curve; Figure 8 (b) in the figure represents various accuracy curves, such as the training accuracy curve, the training accuracy (smoothed) curve, the test accuracy curve, and the test accuracy (smoothed) curve. To comprehensively utilize the three aforementioned features, the present invention designs a two-stage network structure: a feature extraction and fusion module (module B) and an adversarial example detection head (module C). The feature extraction and fusion module uses a multi-layer perceptron architecture, accepting phase features, RCS features, and angle-velocity features as input. It extracts and fuses features through multiple fully connected layers, and outputs fused features. The adversarial example detection head also uses a multi-layer perceptron architecture, accepting fused features as input and outputting the probability and location of adversarial examples. Preliminary validation experiments used a dataset consisting of 641 samples, of which 386 (60.2%) were adversarial examples and 255 (39.8%) were non-adversarial examples. The model was trained using the cross-entropy loss function and the Adam optimizer. Figure 8 The following plots show the evolution of the loss function and accuracy during training, as well as the confusion matrix of the final model on the test set. Experimental results show that the model achieved an overall accuracy of 91.1% on the test set. This demonstrates that the multi-feature fusion method proposed in this paper can effectively distinguish between adversarial and non-adversarial examples, and is particularly good at recognizing adversarial examples.
[0184] Experiment 5: Defense Effects Against False Target Attacks
[0185] Figure 9 2 is a schematic diagram of the defense effect against false target attacks according to an embodiment of the present invention.
[0186] like Figure 9 As shown, this experiment 5 proves the defensive effect of the present invention against false target attacks. False target attacks, as a physical countermeasure attack, will interfere with the radar's detection of real targets. Figure 9 The detection results in different scenarios are presented: Figure 9 (a) in the figure is the detected target; Figure 9 (b) is the radar imaging when not attacked (i.e., original imaging); Figure 9(c) in the figure is the imaging result after being attacked by a physical adversarial sample (false target) (i.e., the image of the physical adversarial sample attack), showing abnormal interference; Figure 9 (d) is the image after the present invention detects and removes the physical adversarial sample, restoring the target's true features. Figure 9 In (b), the radar clearly shows the target; after being attacked by a false target Figure 9 (c) in the figure shows that the image is disturbed; after the present invention is used to remove the adversarial samples, Figure 9 (d) in the figure successfully restores the target's true image and resists the attack. This example demonstrates that the present invention significantly improves target detection performance under false target attacks, effectively reduces the interference of attacks on the radar system, and ensures detection reliability.
[0187] Experiment 6: Defense against hidden attacks
[0188] Figure 10 FIG. 4 is a schematic diagram of the defense effect against hidden attacks according to an embodiment of the present invention.
[0189] like Figure 10 As shown, this example verifies the effectiveness of the present invention in defending against hidden attacks. A hidden attack is when an attacker uses some means to make a target disappear from the radar image, causing the radar to be unable to correctly detect the actual target. Figure 10 Demonstrates the effectiveness of hidden attack defense: Figure 10 (a) Detected target: shows a black dog-shaped target that the radar should detect under normal circumstances. Figure 10 (b) Unattacked: In the absence of a hidden attack, the radar is able to correctly detect the target and display its thermal imaging outline in the image. Figure 10 (c) The result after being attacked by hiding: When the target is attacked by hiding, the target cannot be detected in the radar image and disappears in the blue background. Figure 10 (d) Physical adversarial sample detected by the present invention: After the defense system of the present invention is enabled, the system is able to identify the existence of hidden attacks and mark the hidden target location with a red dotted box in the radar image.
[0190] Based on Experiments 1-6, the multi-feature fusion-based millimeter-wave radar physical adversarial attack defense method proposed in this paper can effectively identify adversarial examples composed of various metamaterials and successfully defend against physical adversarial attacks, including false target attacks and stealth attacks. By deeply understanding the fundamental differences in electromagnetic reflection between metamaterials and natural objects, this method extracts features from three dimensions: phase, RCS, and angle-velocity. Combining deep learning methods for feature fusion and adversarial example detection, this method achieves high-precision and robust defense, providing strong support for the safe application of millimeter-wave radar systems in areas such as autonomous driving and human perception.
[0191] Experiments 1-6 above demonstrate that the present invention performs well in complex environments. For adversarial examples composed of various types of metamaterials, the present invention successfully detects their presence with an overall accuracy of 91.1%. Compared to existing methods, the present invention significantly improves both defense effectiveness and system robustness. In particular, the present invention can be used to protect millimeter-wave radar systems from physical adversarial attacks, maintaining their safe application in areas such as autonomous driving and security monitoring.
[0192] In summary, through the method of combining multi-feature fusion and deep learning, the present invention can effectively identify adversarial sample features in millimeter-wave radar signals and achieve effective defense against physical adversarial attacks.
[0193] Figure 11 4 is a block diagram of an electronic device suitable for implementing a millimeter-wave radar physical countermeasure attack defense method based on multi-domain feature fusion according to an embodiment of the present invention.
[0194] like Figure 11 As shown, an electronic device 1100 according to an embodiment of the present invention includes a processor 1101, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1102 or a program loaded from a storage unit 1108 into a random access memory (RAM) 1103. Processor 1101 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or a related chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. Processor 1101 may also include onboard memory for caching purposes. Processor 1101 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present invention.
[0195] RAM 1103 stores various programs and data required for the operation of electronic device 1100. Processor 1101, ROM 1102, and RAM 1103 are interconnected via bus 1104. Processor 1101 executes the programs in ROM 1102 and / or RAM 1103 to perform various operations according to the method flow of the embodiment of the present invention. It should be noted that the programs may also be stored in one or more memories other than ROM 1102 and RAM 1103. Processor 1101 may also execute the programs stored in the one or more memories to perform various operations according to the method flow of the embodiment of the present invention.
[0196] According to an embodiment of the present invention, electronic device 1100 may further include an input / output (I / O) interface 1105, which is also connected to bus 1104. Electronic device 1100 may also include one or more of the following components connected to I / O interface 1105: an input section 1106 including a keyboard, mouse, etc.; an output section 1107 including devices such as a cathode ray tube (CRT), liquid crystal display (LCD), and speakers; a storage section 1108 including a hard disk; and a communication section 1109 including a network interface card such as a LAN card or modem. Communication section 1109 performs communication processing via a network such as the Internet. A drive 1110 is also connected to I / O interface 1105 as needed. Removable media 1111, such as a magnetic disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed in drive 1110 as needed, so that computer programs read from the removable media can be installed into storage section 1108 as needed.
[0197] The present invention also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments, or may exist independently and not incorporated into the device / apparatus / system. The computer-readable storage medium carries one or more programs, which, when executed, implement the method according to the embodiments of the present invention.
[0198] According to an embodiment of the present invention, a computer-readable storage medium may be a non-volatile computer-readable storage medium, and may include, for example, but not limited to: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof. In the present invention, a computer-readable storage medium may be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. For example, according to an embodiment of the present invention, a computer-readable storage medium may include ROM 1102 and / or RAM 1103 described above, and / or one or more memories other than ROM 1102 and RAM 1103.
[0199] The flowcharts and block diagrams in the accompanying drawings illustrate the possible implementation architecture, functions and operations of the systems, methods and computer program products according to various embodiments of the present invention. In this regard, each box in the flowchart or block diagram can represent a module, program segment, or a part of code, and the above-mentioned module, program segment, or a part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart, can be implemented with a dedicated hardware-based system that performs the specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0200] It will be understood by those skilled in the art that the features described in the various embodiments of the present invention may be combined and / or coupled in various ways, even if such combinations or couplings are not explicitly described in the present invention. In particular, the features described in the various embodiments of the present invention may be combined and / or coupled in various ways without departing from the spirit and teachings of the present invention. All such combinations and / or couplings fall within the scope of the present invention.
[0201] The above describes embodiments of the present invention. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of the present invention. Although each embodiment has been described separately above, this does not mean that the measures in each embodiment cannot be advantageously used in combination. Without departing from the scope of the present invention, those skilled in the art may make various substitutions and modifications, which should all fall within the scope of the present invention.
Claims
1. A millimeter wave radar physical countermeasure attack defense method based on multi-domain feature fusion, characterized in that: The method comprises: A multi-domain feature extraction method is used to extract multi-domain features from the millimeter-wave radar echo signal using a multi-dimensional fast Fourier transform method to obtain the multi-domain features of the millimeter-wave radar, wherein the millimeter-wave radar echo signal includes the echo signal of the adversarial sample and the echo signal of the non-adversarial sample, and the multi-domain features include phase features, radar scattering cross section features, and angle-velocity features; The normalized multi-domain features are fused through a feature fusion network based on a multi-layer perceptron to obtain multi-domain fusion features. Using the trained adversarial sample detection model to perform adversarial sample detection on the multi-domain fusion feature, and obtain the location information of the adversarial sample and the existence probability information of the adversarial sample; Based on the position information of the adversarial sample and the existence probability information of the adversarial sample, the millimeter-wave radar echo signal is subjected to signal separation, adaptive filtering, signal recovery and optimization processing to obtain the echo signal of the non-adversarial sample.
2. The method according to claim 1, characterized in that The multi-domain features of the millimeter-wave radar echo signal are extracted using a multi-dimensional fast Fourier transform method. The multi-domain features of the millimeter-wave radar include: Using millimeter-wave radar to receive echo signals of multiple adversarial samples and multiple non-adversarial samples, the original millimeter-wave radar echo signal is obtained; performing data enhancement operations on the original millimeter-wave radar echo signal in the distance domain, the angle domain, and the velocity domain to obtain the millimeter-wave radar echo signal; Performing a fast Fourier transform operation on the millimeter-wave radar echo signal in the distance domain to obtain distance domain information, and extracting an antenna-dimensional phase history curve at the target distance from the distance domain information to obtain a phase feature; Performing a fast Fourier transform operation on the range domain information to generate a radar cross section feature, wherein the radar cross section feature includes a static radar cross section feature and a dynamic radar cross section feature; The millimeter-wave radar echo signal is subjected to a fast Fourier transform operation and a constant false alarm rate detection operation in the distance domain, and then to a fast Fourier transform operation in the velocity domain and a fast Fourier transform operation in the angle domain to generate an angle-velocity feature.
3. The method according to claim 2, characterized in that The antenna-dimensional phase history curve of the adversarial sample and the antenna-dimensional phase history curve of the non-adversarial sample are evaluated by the mean square error index of the first-order differential, the mean square error index of the second-order differential, and the mean square error index of the curve after smoothing based on local polynomial regression and linear least squares method; The mean square error index of the first-order differential is used to evaluate the degree of change between adjacent points in the antenna-dimensional phase history curve; The mean square error index of the second-order differential is used to evaluate the curvature of the antenna-dimensional phase history curve; The mean square error index of the curve smoothed by local polynomial regression and linear least squares method is used to evaluate the degree to which the original data points in the antenna-dimensional phase history curve deviate from the ideal antenna-dimensional phase history curve.
4. The method according to claim 2, characterized in that The angle-velocity features of the adversarial sample and the angle-velocity features of the non-adversarial sample are evaluated by the zero-velocity power ratio index, the velocity dimension energy variance index, and the velocity dimension peak number ratio index; The zero-speed power ratio indicator is used to evaluate the ratio of energy near zero speed to total energy; The velocity dimension energy variance index is used to evaluate the degree of dispersion of velocity dimension energy distribution; The speed dimension peak number ratio indicator is used to evaluate the number of peaks in the speed dimension.
5. The method according to claim 1, wherein The normalized multi-domain features are fused through a feature fusion network based on a multi-layer perceptron to obtain the following multi-domain fusion features: Normalizing the multi-domain features to ensure that the phase features, radar cross-section features, and angle-velocity features in the multi-domain features have the same dimension; The feature fusion network is constructed using a multi-layer perceptron with multiple fully connected layers and multiple nonlinear activation functions, and the multi-domain features are fused using the feature fusion network to obtain the multi-domain fusion features.
6. The method according to claim 1, wherein The trained adversarial sample detection model is obtained by the following operations: The adversarial sample detection model is iteratively trained and optimized using the cross entropy classification loss function, the mean square error positioning loss function, and the stochastic gradient descent method to obtain the trained adversarial sample detection model.
7. The method according to claim 1, characterized in that Performing signal separation, adaptive filtering, and signal recovery and optimization processing on the millimeter-wave radar echo signal based on the position information of the adversarial sample and the existence probability information of the adversarial sample to obtain the echo signal of the non-adversarial sample includes: Based on the location information of the adversarial sample and the existence probability information of the adversarial sample, constructing a signal template of the adversarial sample using an adversarial sample signal generation function based on a physical model; Adaptively setting a filter strength coefficient based on the existence probability information of the adversarial sample, and filtering the echo signal of the adversarial sample from the millimeter-wave radar echo signal using a self-applied filter based on the filter strength coefficient to obtain an initial non-adversarial sample echo signal; Phase compensation and amplitude correction are performed on the echo signal of the initial non-adversarial sample to obtain the echo signal of the non-adversarial sample.
8. The method according to claim 7, characterized in that Performing phase compensation and amplitude correction on the echo signal of the initial non-adversarial sample to obtain the echo signal of the non-adversarial sample includes: Determining a phase correction term of the echo signal of the initial non-adversarial sample by the energy of the first-order and second-order derivatives of the minimum phase curve, and constructing a phase compensation function using the phase correction term based on the continuity constraint of the antenna phase history; An amplitude correction function is constructed using a preset smoothing factor and a weight coefficient, and the phase compensation function and the amplitude correction function are operated to obtain a signal recovery and optimization function; The signal recovery and optimization function is used to perform phase compensation and amplitude correction on the echo signal of the initial non-adversarial sample to obtain the echo signal of the non-adversarial sample.
9. An electronic device comprising: one or more processors; a memory for storing one or more computer programs, It is characterized in that the one or more processors execute the one or more computer programs to implement the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program or instruction stored thereon, characterized in that: When the computer program or instruction is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.
Citation Information
Patent Citations
Laser radar recognition adversarial sample method based on 3D point cloud reconstruction
CN119105013A
Method of target feature extraction based on millimeter-wave radar echo
US20220155432A1