Intelligent confrontation method and system for electromagnetic spectrum prediction
By generating single-step and multi-step adversarial samples and calculating the minimum perturbation using the iterative process, the problem of failure of the adversarial sample generation method in the existing electromagnetic spectrum prediction model is solved, and the model's defense ability and prediction accuracy are improved.
Patent Information
- Application Number
- CN202510430994.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-08
- Publication Date
- 2025-08-15
AI Technical Summary
The existing electromagnetic spectrum prediction model adversarial sample generation methods are mainly effective for continuous value models. For discrete value models such as spectrum prediction models, the adversarial sample generation of traditional methods is easily filtered by threshold judgments, resulting in attack failure.
Build an electromagnetic spectrum prediction model based on deep learning. By generating single-step and multi-step adversarial samples, calculating the minimum perturbation using the iterative process, generating discrete perturbations that can change the model decision, and attacking the situation where the prediction window is 1 or greater than 1 to reduce the model prediction accuracy.
Effectively reduce the prediction accuracy of the electromagnetic spectrum prediction model over a period of time, improve the model's defense ability, avoid the failure of the continuous value-defying sample generation method, and realize the attack on multi-step prediction results.
Smart Images

Figure CN120499667A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the technical field of electromagnetic spectrum prediction, and in particular to an intelligent countermeasure method and system for electromagnetic spectrum prediction. Background Art
[0002] The contradiction between spectrum scarcity and insufficient spectrum utilization has led to the emergence of cognitive radio (CR) technology. CR technology can adapt to the ever-changing radio environment and alleviate the shortage of spectrum resources through key technologies such as dynamic spectrum access or opportunistic spectrum access.
[0003] Spectrum prediction (SP) is a key enabling technology in CR, used to obtain information about spectrum evolution and identify spectrum holes. Specifically, SP infers the future occupied / free state of the radio spectrum by effectively leveraging the inherent correlations of known or measured spectrum occupancy statistics. SP can obtain valuable unknown spectrum occupancy information in advance and improve the performance of CR users by accelerating the selection of optimal channels and expanding the perception range in the time and frequency domains. As a result, an increasing number of researchers and research teams have begun to devote themselves to the use or development of effective SP techniques.
[0004] Traditional SP techniques are primarily model-driven, only exploring the evolutionary patterns of a single dimension and relying on expert experience, which limits their predictive performance in practical applications. The emergence of DL (Deep Learning) has made it possible to be data-driven and capture complex nonlinear features. Researchers have achieved numerous advanced results in spectrum prediction using DL models. For example, Pan et al. proposed a spectrum prediction method based on a stacked autoencoder (SAE) and a bidirectional long short-term memory network (Bi-LSTM), which extracts hidden features of spectrum data in an unsupervised manner for accurate prediction. Umebayashi et al. proposed a spectrum duty cycle prediction method using dual recurrent neural networks (RNNs), with each RNN designed for high and low duty cycle scenarios. Zhang et al. used a combined prediction model combining a long short-term memory network (LSTM) and a convolutional neural network (CNN) for spectrum prediction under multi-channel spectrum sharing. Zhang et al. proposed a multi-band spectrum prediction method based on an attention graph convolutional recurrent neural network, which leverages temporal and band correlations for spectrum prediction. Ren et al. proposed a deep learning prediction model based on convolutional neural networks and residual networks to accurately predict spectrum usage in both temporal and spatial domains with minimal sensing cost. Currently, a wide range of algorithms, from the most basic multilayer perceptron (MLP) to convolutional neural networks, recurrent neural networks, and attention networks, are widely used for spectrum prediction.
[0005] While DL-based SP techniques offer numerous advantages, the black-box nature and weak interpretability of DL models make them vulnerable to adversarial attacks. Attackers exploit the DL model's sensitivity to small changes in input data and deliberately add carefully crafted perturbations to the input data, inducing the model to make incorrect decisions. Starting with the Fast Gradient Sign Method (FGSM), which first utilized model gradient information to construct adversarial examples, a variety of adversarial attack methods have emerged. In the communications field, Zhang et al. proposed a spectrum-centric frequency adversarial attack algorithm to address the frequency leakage and glitches caused by high-frequency components in adversarial perturbations for automatic modulation classification. Kim et al. proposed a broadcast adversarial attack that simultaneously fools the modulation type classifiers of different receivers by constructing a common adversarial perturbation. Santos et al. analyzed DL-based regression problem models in the context of downlink power allocation in massive MIMO systems and proposed a general adversarial perturbation generation method. Manoj et al. extended the gradient sign method to generate adversarial examples for DL-based power allocation models in the downlink of multi-cell massive MIMO systems, forcing the DL model to produce infeasible solutions. In general, mainstream adversarial example generation methods mostly leverage model gradient information, including single-step methods like FGSM and iterative methods like the Basic Iterative Method (BIM) and Momentum Iterative Method (MIM). Other adversarial example generation methods include those based on optimization problems, such as the C&W attack, and those based on hyperplanes, such as the Deep-fool attack.
[0006] The small perturbations designed by the above methods are all continuous values and cannot be directly applied to models with discrete inputs and outputs. The spectrum prediction model performs a threshold decision on the received signal power, obtaining a discrete sequence of 01s as input. The output is a uniform binary value representing the primary user's frequency band occupancy. Existing adversarial attack methods cannot be directly applied to the input. If applied to the received signal power, the small amplitude will be filtered out by the threshold decision maker at the front end of the spectrum prediction model, rendering the attack ineffective. Summary of the Invention
[0007] In view of this, the embodiments of the present application propose an intelligent adversarial method and system for electromagnetic spectrum prediction, which overcomes the problem that the continuous value adversarial sample generation method fails to attack the spectrum prediction model, and is extended from attacking single-step prediction results to attacking multi-step prediction results. The generated adversarial samples can significantly reduce the prediction accuracy of the electromagnetic spectrum prediction model over a period of time, thereby helping the electromagnetic spectrum prediction model to better improve its defense capabilities.
[0008] In the first aspect, an embodiment of the present application proposes an intelligent countermeasure method for electromagnetic spectrum prediction, which includes the following steps: constructing an electromagnetic spectrum prediction model based on deep learning, the electromagnetic spectrum prediction model predicts the future frequency band occupancy of the main user based on the frequency band occupancy of the main user in a historical time period, and the occupancy is represented by a 01 sequence; when the prediction window is 1, single-step spectrum prediction is performed on the electromagnetic spectrum prediction model to generate a single-step adversarial sample; when the prediction window is greater than 1, multi-step spectrum prediction is performed on the electromagnetic spectrum prediction model to generate multi-step adversarial samples; based on the single-step adversarial samples and multi-step adversarial samples, the electromagnetic spectrum prediction model is intelligently antagonized to reduce the prediction accuracy of the electromagnetic spectrum prediction model over a period of time.
[0009] In some optional embodiments, a deep learning-based electromagnetic spectrum prediction model is constructed. The electromagnetic spectrum prediction model predicts the future frequency band occupancy of the primary user based on the frequency band occupancy of the primary user in a historical time period. The occupancy is represented by a 01 sequence, including:
[0010] A deep learning-based electromagnetic spectrum prediction model is constructed. It is assumed that sparsely distributed signal sensors (SS) continuously observe the frequency band and send their received signal strength (RSS) to the cognitive radio base station. The mean of multiple RSS values is calculated and judged to obtain the current frequency band occupancy. The electromagnetic spectrum prediction model predicts the future frequency band occupancy of the primary user (PU) based on the frequency band occupancy of the primary user (PU) in the historical time period. The occupancy is represented by a 01 sequence.
[0011] In some optional embodiments, the observed frequency band is used by only one PU, the secondary user SU only cares about the occupancy of the PU, and an RSS decision threshold γ is set. The frequency band occupancy at the current moment is determined based on γ and the average of multiple RSSs.
[0012] Assuming that the current time is time t, the frequency band occupancy at the current time is determined based on γ and the average of multiple RSSs, which can be expressed as follows:
[0013]
[0014] Among them, m is the total number of SS, represents the RSS of the i-th SS at time t, x t =H1 represents the frequency band occupied by PU at time t, x t =H0 means that the PU does not occupy the frequency band at time t;
[0015] Based on this, the frequency band occupancy in the time period Time containing N moments is expressed by the 01 sequence as follows:
[0016]
[0017] in, Indicates the frequency band occupancy within the time period T, x n Indicates the frequency band occupancy at the nth moment in the time period Time, where n is an integer greater than 1.
[0018] In some optional embodiments, when the prediction window is 1, performing single-step spectrum prediction on the electromagnetic spectrum prediction model to generate a single-step adversarial sample includes:
[0019] For the case where the prediction window is 1, the non-operation constraint is used to constrain the feasible domain of the adversarial sample, and an iterative process is used to calculate the minimum perturbation to change the decision of the electromagnetic spectrum prediction model. It is assumed that the electromagnetic spectrum prediction model is a general differentiable binary classification predictor. At each iteration, the electromagnetic spectrum prediction model is point-linearized around the current input. At this time, its output is linearly related to the input, and the formed hyperplane divides the output into positive and negative parts. The directional distance of the input point moving to the hyperplane is obtained through the distance analytical formula, and then the directional perturbation under the feasible domain constraint with the smallest angle with the directional distance is obtained. After each iteration, the directional perturbation is added to the input sample of the current iteration step, and the input point is updated until the decision of the electromagnetic prediction model changes. The input sample at this time is the generated single-step adversarial sample.
[0020] In some optional embodiments, the input sequence of the electromagnetic spectrum prediction model is For example, define x n The non-operation is !x n ,! x n It is expressed by the formula:
[0021]
[0022] Among them, !x n Used to convert x n The value of changes from 0 to 1, or from 1 to 0;
[0023] In order to calculate the disturbance size conveniently, use Go ahead! x n The number of times to represent the added disturbance The size of It is expressed by the formula:
[0024]
[0025] r n ∈(-1,0,1);
[0026] Among them, r n Only allowed in x n =0, takes the value (0,1), at x n=1 takes the value (-1,0);
[0027] The predicted value of the electromagnetic spectrum prediction model is expressed as T represents the length of the prediction window;
[0028] make represents the output value of the electromagnetic spectrum prediction model, then F t The value of is expressed as:
[0029]
[0030] in,
[0031] When T=1, Now enter the sequence Without including the prediction value of the previous moment, the minimum perturbation to change the decision of the electromagnetic spectrum prediction model is given by the following analytical formula:
[0032]
[0033] st
[0034]
[0035] Considering the hyperplane method, in order to alleviate the gradient disappearance, the activation function σ satisfies First, we analyze the case where the electromagnetic spectrum prediction model is an affine classifier, and then generalize it to any differentiable binary classification predictor;
[0036] At this time, the output of the electromagnetic spectrum prediction model Obviously the hyperplane The output of the electromagnetic spectrum prediction model is divided into positive and negative parts. Direction distance to move to the hyperplane It can be given by the following analytical formula:
[0037]
[0038] Now assume that f is a general differentiable binary classification predictor, and an iterative process is used to calculate the minimum perturbation to change the decision of the electromagnetic spectrum prediction model;
[0039] In each iteration, f revolves around the current point The minimum continuous perturbation of the linearized affine classifier is calculated as:
[0040]
[0041] Assume that the minimum discrete perturbation of the iterative step i is Set the step size to 1, and The smaller the angle θ between the directions, The closer the iterative point is to the hyperplane, the greater the distance. In order to minimize θ, cosθ needs to take the maximum value. At this time, Need to meet:
[0042]
[0043] st
[0044]
[0045] in, All possible directions of disturbance are specified, which only contain 1 and -1. and Multiplying them together can filter out feasible solutions;
[0046] Finally, the discrete perturbation of the current step is obtained by determining the maximum value, and the next iteration point is updated accordingly. The update formula is expressed as when The iteration stops when the sign of the electromagnetic spectrum prediction model is changed.
[0047] In some optional embodiments, when the prediction window is greater than 1, performing multi-step spectrum prediction on the electromagnetic spectrum prediction model to generate multi-step adversarial samples includes:
[0048] For the case where the prediction window is greater than 1, an iterative process is used to calculate the minimum perturbation that maximizes the loss function of the electromagnetic spectrum prediction model. At each iteration, a calculation point is obtained by the adversarial sample generation method with a prediction window of 1. The iteration point is updated by the calculation point until the iteration reaches the number of steps of the prediction window length, or when it is detected that the loss function value of the next iteration step becomes smaller, the iteration ends. The input sample at this time is the generated multi-step adversarial sample.
[0049] In some optional embodiments, when T>1, there is Define the loss function as Represents the initial prediction value of the electromagnetic spectrum prediction model, and loss can describe the effectiveness of the attack;
[0050] The minimum perturbation that makes the decision of the electromagnetic spectrum prediction model the worst is given by the following analytical formula:
[0051]
[0052] st
[0053]
[0054] First, we analyze the case where the electromagnetic spectrum prediction model is an affine classifier. At this time, the output of the electromagnetic spectrum prediction model is Hyperplane Similarly, the output of the electromagnetic spectrum prediction model is divided into two parts, positive and negative, T-1 and The associated points and Together they form a collection The elements in and f uniquely determine, the perturbation The goal is to make back, As many points as possible pass through the hyperplane;
[0055] Assuming f is a general differentiable binary classification predictor, an iterative process is used to calculate the minimum perturbation to change the decision of the electromagnetic spectrum prediction model;
[0056] In each iteration, f revolves around the current calculation point Linearization, The independent moment attack disturbance is calculated by the basic CVM Will Transformed into Vectors of the same latitude
[0057] Update iteration point The update formula is And calculate the loss function value at this time;
[0058] According to the updated iteration point Get the next calculation point The iteration ends when the Tth step is reached or the loss function value of the next step becomes smaller.
[0059] This application proposes an intelligent countermeasure method for electromagnetic spectrum prediction. First, a deep learning-based electromagnetic spectrum prediction model is constructed. The electromagnetic spectrum prediction model predicts the future frequency band occupancy of the primary user based on the frequency band occupancy of the primary user in a historical time period. The occupancy is represented by a 01 sequence. When the prediction window is 1, a single-step spectrum prediction is performed on the electromagnetic spectrum prediction model to generate a single-step adversarial sample. When the prediction window is greater than 1, a multi-step spectrum prediction is performed on the electromagnetic spectrum prediction model to generate a multi-step adversarial sample. Based on this, the electromagnetic spectrum prediction model can be intelligently countered based on single-step adversarial samples and multi-step adversarial samples to reduce the prediction accuracy of the electromagnetic spectrum prediction model over a period of time. This method avoids the problem of continuous-valued adversarial sample generation methods failing to detect the electromagnetic spectrum prediction model. It generalizes adversarial sample generation from attacks on single-step prediction results to multi-dimensional situations, that is, attacks on multi-step prediction results. This can reduce the prediction accuracy of the electromagnetic spectrum prediction model over a period of time, thereby helping the electromagnetic spectrum prediction model to better improve its defense capabilities.
[0060] On the second aspect, an embodiment of the present application proposes an intelligent adversarial system for electromagnetic spectrum prediction, which includes: a model construction module for constructing an electromagnetic spectrum prediction model based on deep learning, which predicts the future frequency band occupancy of the main user based on the frequency band occupancy of the main user in a historical time period, and the occupancy is represented by a 01 sequence; a single-step adversarial module for performing single-step spectrum prediction on the electromagnetic spectrum prediction model when the prediction window is 1 to generate a single-step adversarial sample; a multi-step adversarial module for performing multi-step spectrum prediction on the electromagnetic spectrum prediction model when the prediction window is greater than 1 to generate multi-step adversarial samples; an actual adversarial execution module for performing intelligent adversarial on the electromagnetic spectrum prediction model based on single-step adversarial samples and multi-step adversarial samples to reduce the prediction accuracy of the electromagnetic spectrum prediction model over a period of time.
[0061] In a third aspect, an embodiment of the present application proposes an information data processing terminal, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute an intelligent countermeasure method for electromagnetic spectrum prediction as described in the first aspect above.
[0062] In a fourth aspect, an embodiment of the present application proposes a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it can implement an intelligent countermeasure method for electromagnetic spectrum prediction as described in the first aspect above.
[0063] It can be understood that the beneficial effects of the second to fourth aspects mentioned above can be found in the relevant description of the first aspect mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0064] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the related technologies, the following is a brief introduction to the drawings required for use in the embodiments of the present application or the description of the related technologies. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0065] Figure 1 This is a flow chart of an intelligent countermeasure method for electromagnetic spectrum prediction provided in one embodiment of the present application;
[0066] Figure 2 is a schematic diagram of the working principle of the electromagnetic spectrum prediction model provided in one embodiment of the present application;
[0067] Figure 3 1 is a schematic diagram of a confrontation simulation experiment on four prediction models provided in one embodiment of the present application;
[0068] Figure 4 This is a schematic structural diagram of an intelligent countermeasure system for electromagnetic spectrum prediction provided in another embodiment of the present application;
[0069] Figure 5 It is a structural diagram of an information data processing terminal provided in another embodiment of the present application. DETAILED DESCRIPTION
[0070] In order to make the purpose, technical solutions and advantages of the embodiments of the present application clearer, the embodiments of the present application will be described in detail below with reference to the accompanying drawings. In the various embodiments of the present application, many technical details are proposed to enable the reader to better understand the present application. However, even without these technical details and various changes and modifications based on the following embodiments, the technical solutions claimed in the present application can be implemented. The division of the following embodiments is only for the convenience of description and should not constitute any limitation on the specific implementation of the present application. The various embodiments can be combined with each other and referenced to each other under the premise of no contradiction.
[0071] In order to solve the problem that the continuous value adversarial sample generation method fails to work on the electromagnetic spectrum prediction model, an embodiment of the present application proposes an intelligent adversarial method for electromagnetic spectrum prediction, which is applied to the information data processing terminal. The following is a detailed description of the implementation details of the intelligent adversarial method for electromagnetic spectrum prediction proposed in this embodiment. The following content is only for the convenience of understanding the implementation details and is not necessary for the implementation of this solution. The specific process of the intelligent adversarial method for electromagnetic spectrum prediction proposed in this embodiment can be as follows: Figure 1 Shown, including:
[0072] Step 101: construct an electromagnetic spectrum prediction model based on deep learning. The electromagnetic spectrum prediction model predicts the future frequency band occupancy of the primary user based on the frequency band occupancy of the primary user in a historical time period. The occupancy is represented by a 01 sequence.
[0073] In the specific implementation, the information data processing terminal first needs to build an electromagnetic spectrum prediction model based on deep learning. This electromagnetic spectrum prediction model predicts the future frequency band occupancy of the main user based on the frequency band occupancy of the main user in the historical time period. The specific occupancy can be represented by a 01 sequence.
[0074] In one example, when building an electromagnetic spectrum prediction model based on deep learning, it is assumed that sparsely distributed signal sensors SS continuously observe the frequency band and send the received signal strength RSS to the cognitive radio base station. The average of multiple RSSs is calculated and judged to obtain the frequency band occupancy at the current moment. The electromagnetic spectrum prediction model predicts the future frequency band occupancy of the primary user PU based on the frequency band occupancy of the PU in the historical time period. The specific occupancy can be represented by a 01 sequence.
[0075] In one example, the electromagnetic spectrum prediction model works as follows: Figure 2 shown.
[0076] In an example, the observed frequency band is used by only one PU, and the secondary user SU only cares about the occupancy of the PU. An RSS decision threshold γ is set, and the frequency band occupancy at the current moment is determined based on γ and the average of multiple RSSs. The specific value of γ can be set by technicians in this field according to actual needs.
[0077] Assuming that the current time is time t, the frequency band occupancy at the current time is determined based on γ and the average of multiple RSSs, which can be expressed as follows:
[0078]
[0079] Where m is the total number of SS, represents the RSS of the i-th SS at time t, x t=H1 represents the frequency band occupied by PU at time t, x t =H0 means that the PU does not occupy the frequency band at time t.
[0080] Based on this, we can get the frequency band occupancy within the time period Time containing N moments. The specific occupancy is expressed by the 01 sequence as follows:
[0081]
[0082]
[0083] in, Indicates the frequency band occupancy within the time period T, x n Indicates the frequency band occupancy at the nth moment in the time period Time, where n is an integer greater than 1.
[0084] Step 102: When the prediction window is 1, perform single-step spectrum prediction on the electromagnetic spectrum prediction model to generate a single-step adversarial sample.
[0085] In the specific implementation, the information data processing terminal first needs to perform a single-step spectrum prediction on the electromagnetic spectrum prediction model when the prediction window is 1 to generate a single-step adversarial sample, which is then used for single-step adversarial work.
[0086] In an example, for the case where the prediction window is 1, the information data processing terminal uses non-operation constraints to constrain the feasible domain of the adversarial sample, and uses an iterative process to calculate the minimum disturbance that changes the decision of the electromagnetic spectrum prediction model. Assuming that the electromagnetic spectrum prediction model is a general differentiable binary classification predictor, the electromagnetic spectrum prediction model is point-linearized around the current input at each iteration. At this time, its output is linearly related to the input, and the formed hyperplane divides the output into positive and negative parts. The directional distance of the input point moving to the hyperplane is obtained through the distance analysis formula, and then the directional disturbance under the feasible domain constraint with the smallest angle with the directional distance is obtained. After each iteration, the directional disturbance is added to the input sample of the current iteration step, and the input point is updated at the same time until the decision of the electromagnetic prediction model changes. The input sample at this time is the generated single-step adversarial sample.
[0087] In one example, for the input sequence of the electromagnetic spectrum prediction model For example, define x n The non-operation is !x n ,! x n It is expressed by the formula:
[0088]
[0089] Among them, !x n Used to convert x nThe value changes from 0 to 1, or from 1 to 0.
[0090] In order to calculate the disturbance size conveniently, use Go ahead! x n The number of times to represent the added disturbance The size of It is expressed by the formula:
[0091]
[0092] r n ∈(-1,0,1);
[0093] Among them, r n Only allowed in x n =0, takes the value (0,1), at x n When =1, the value is (-1,0).
[0094] The predicted value of the electromagnetic spectrum prediction model is expressed as T represents the length of the prediction window.
[0095] make represents the output value of the electromagnetic spectrum prediction model, then F t The value of is expressed as:
[0096]
[0097] in,
[0098] When T=1, Now enter the sequence Without including the prediction value of the previous moment, the minimum perturbation to change the decision of the electromagnetic spectrum prediction model is given by the following analytical formula:
[0099]
[0100] st
[0101]
[0102] Obviously, the traditional adversarial sample solution method is no longer applicable to this type of problem. First, the perturbation size does not satisfy the requirement for any real number ε. This means that it is not possible to simply apply the loss function gradient to design adversarial samples. At the same time, the perturbation values of traditional adversarial sample algorithms are continuous and not suitable for discrete fixed step sizes.
[0103] Considering the hyperplane method, in order to alleviate the gradient disappearance, the activation function σ satisfies We first analyze the case where the electromagnetic spectrum prediction model is an affine classifier, and then extend it to any differentiable binary classification predictor.
[0104] At this time, the output of the electromagnetic spectrum prediction model Obviously the hyperplane The output of the electromagnetic spectrum prediction model is divided into positive and negative parts. Direction distance to move to the hyperplane It can be given by the following analytical formula:
[0105]
[0106] Now assume that f is a general differentiable binary classification predictor and use an iterative process to calculate the minimum perturbation that changes the decision of the electromagnetic spectrum prediction model.
[0107] In each iteration, f revolves around the current point The minimum continuous perturbation of the linearized affine classifier is calculated as:
[0108]
[0109] However, this perturbation value is a continuous value, which obviously does not satisfy the given optimization problem. We
[0110] Assume that the minimum discrete perturbation of the iterative step i is Set the step size to 1, and The smaller the angle θ between the directions, The closer the iterative point is to the hyperplane, the greater the distance. In order to minimize θ, cosθ needs to take the maximum value. At this time, Need to meet:
[0111]
[0112] st
[0113]
[0114]
[0115] in, All possible directions of disturbance are specified, which only contain 1 and -1. and Multiplying them together can filter out feasible solutions.
[0116] Finally, the discrete perturbation of the current step is obtained by determining the maximum value, and the next iteration point is updated accordingly. The update formula is expressed as when The iteration stops when the sign of the electromagnetic spectrum prediction model is changed.
[0117] The iterative algorithm for single-step adversarial can be described as follows:
[0118] S1, initialization Initialize the electromagnetic spectrum prediction model f;
[0119] S2,
[0120] S3,
[0121] S4,
[0122] S5, i←i+1;
[0123] S6, if Return to S2, otherwise the iteration stops;
[0124] S7, output
[0125] Step 103: When the prediction window is greater than 1, multi-step spectrum prediction is performed on the electromagnetic spectrum prediction model to generate multi-step adversarial samples.
[0126] In the specific implementation, after completing the generation of single-step adversarial samples, the information data processing terminal also needs to perform multi-step spectrum prediction on the electromagnetic spectrum prediction model when the prediction window is greater than 1, thereby generating multi-step adversarial samples for multi-step adversarial purposes.
[0127] In one example, for the case where the prediction window is greater than 1, the information data processing terminal uses an iterative process to calculate the minimum perturbation that maximizes the loss function of the electromagnetic spectrum prediction model. In each iteration, a calculation point is obtained by the adversarial sample generation method with a prediction window of 1. The iteration point is updated by the calculation point until the iteration reaches the number of steps of the prediction window length, or when it is detected that the loss function value of the next iteration step becomes smaller, the iteration ends. The input sample at this time is the generated multi-step adversarial sample.
[0128] In one example, when T>1, there is The information data processing terminal defines the loss function as It represents the initial prediction value of the electromagnetic spectrum prediction model, and loss can describe the effectiveness of the attack.
[0129] The minimum perturbation that makes the decision of the electromagnetic spectrum prediction model the worst is given by the following analytical formula:
[0130]
[0131] st
[0132]
[0133] First, we analyze the case where the electromagnetic spectrum prediction model is an affine classifier. At this time, the output of the electromagnetic spectrum prediction model is Hyperplane Similarly, the output of the electromagnetic spectrum prediction model is divided into two parts, positive and negative, T-1 and The associated points and Together they form a collection The elements in and f uniquely determine, the perturbation The goal is to make back, As many points as possible pass through the hyperplane.
[0134] Assuming f is a general differentiable binary classification predictor, an iterative process is used to calculate the minimum perturbation that changes the decision of the electromagnetic spectrum prediction model.
[0135] In each iteration, f revolves around the current calculation point Linearization, The independent moment attack disturbance is calculated by the basic CVM Will Transformed into Vectors of the same latitude
[0136] Update iteration point The update formula is And calculate the loss function value at this time.
[0137] According to the updated iteration point Get the next calculation point The iteration ends when the Tth step is reached or the loss function value of the next step becomes smaller.
[0138] The iterative algorithm for multi-step confrontation can be described as follows:
[0139] S1, initialization i←1, loss1=0, initialize the electromagnetic spectrum prediction model f.
[0140] S2,
[0141]
[0142] if Return to S2, otherwise the iteration stops;
[0143] S3, Update Calculating loss i ;
[0144] S4, repeat S2, S3T times, if loss i+1 <loss i , the iteration stops;
[0145] S7, output
[0146] Step 104 , performing intelligent adversarial testing on the electromagnetic spectrum prediction model based on single-step adversarial samples and multi-step adversarial samples, so as to reduce the prediction accuracy of the electromagnetic spectrum prediction model over a period of time.
[0147] In a specific implementation, after obtaining single-step adversarial samples and multi-step adversarial samples, the information data processing terminal can perform intelligent adversarial work on the electromagnetic spectrum prediction model based on the single-step adversarial samples and multi-step adversarial samples to reduce the prediction accuracy of the electromagnetic spectrum prediction model over a period of time.
[0148] This embodiment proposes an intelligent countermeasure method for electromagnetic spectrum prediction. First, a deep learning-based electromagnetic spectrum prediction model is constructed. This model predicts the future frequency band occupancy of a primary user based on the primary user's frequency band occupancy over a historical time period, with the occupancy represented by a 01 sequence. When the prediction window is 1, a single-step spectrum prediction is performed on the electromagnetic spectrum prediction model to generate a single-step adversarial sample. When the prediction window is greater than 1, a multi-step spectrum prediction is performed on the electromagnetic spectrum prediction model to generate a multi-step adversarial sample. This allows intelligent countermeasures to be performed against the electromagnetic spectrum prediction model based on both single-step and multi-step adversarial samples, reducing its prediction accuracy over a period of time. This method avoids the failure of continuous-valued adversarial sample generation methods against electromagnetic spectrum prediction models. It generalizes adversarial sample generation from attacks on single-step prediction results to attacks on multi-dimensional results, specifically multi-step prediction results. This can reduce the prediction accuracy of the electromagnetic spectrum prediction model over a period of time, thereby improving the electromagnetic spectrum prediction model's defense capabilities.
[0149] The step division of the above various methods is only for the purpose of clear description. During implementation, they can be combined into one step, or some steps can be split and decomposed into multiple steps. As long as they include the same logical relationship, they are all within the scope of protection of this application; adding insignificant modifications or introducing insignificant designs to the algorithm or process without changing the core design of the algorithm and process are all within the scope of protection of this application.
[0150] In one embodiment, the intelligent countermeasure method for electromagnetic spectrum prediction proposed in this application has achieved some positive results during the research and development or use process, and does have great advantages compared with traditional technologies. It is described below with reference to data, charts, etc. from the simulation experiment process.
[0151] In the simulation experiment, we first generated data, primarily modeling the frequency occupancy of primary users. This data was then generated to create training and test sets. Four prediction models were used: MLP, TCN, LSTM, and MHA, which are comprehensive representatives of mainstream prediction models. Figure 4 The prediction accuracy of the four models before and after the attack is compared, with the horizontal axis representing the prediction window length. For a single-step attack, the TCN model's prediction accuracy dropped from 88.14% to 11.86%, achieving the theoretical maximum for this model, i.e., causing all predictions to be incorrect. The MLP prediction accuracy dropped from 89.93% to 12.36%, the LSTM prediction accuracy dropped from 90.52% to 16.71%, and the MHA prediction accuracy dropped from 90.32% to 17.52%. The attack effects on these three models are also close to the theoretical maximum, demonstrating the effectiveness of the attack proposed in this application. For multi-dimensional attacks, it can be seen that the effect of multi-dimensional attacks is worse than that of single-step attacks. This is due to two factors: first, adversarial sample generation relies on the prediction accuracy of the model itself; higher accuracy leads to better attack effectiveness; second, as the prediction window increases, the correlation between prediction moments prevents them from being misled simultaneously. The longer the prediction window, the stronger the temporal correlation, resulting in a weaker attack effect. Therefore, the TCN model with better time correlation characteristics shows better resistance to multi-dimensional attacks, followed by LSTM. The worst performance is the MLP model. When the prediction window length is 15, the prediction accuracy drops from 86.08% to 31.22%.
[0152] Another embodiment of the present application proposes an intelligent countermeasure system for electromagnetic spectrum prediction. The following is a detailed description of the implementation details of the intelligent countermeasure system for electromagnetic spectrum prediction proposed in this embodiment. The following content is only for the convenience of understanding the implementation details and is not necessary for the implementation of this embodiment. Figure 4 This is a structural diagram of an intelligent confrontation system for electromagnetic spectrum prediction proposed in this embodiment, which includes: a model construction module 201, a single-step confrontation module 202, a multi-step confrontation module 203 and a confrontation actual execution module 204.
[0153] The model construction module 201 is used to construct an electromagnetic spectrum prediction model based on deep learning. The electromagnetic spectrum prediction model predicts the future frequency band occupancy of the primary user based on the frequency band occupancy of the primary user in a historical time period. The occupancy is represented by a 01 sequence.
[0154] The single-step adversarial module 202 is used to perform single-step spectrum prediction on the electromagnetic spectrum prediction model when the prediction window is 1, so as to generate a single-step adversarial sample.
[0155] The multi-step adversarial module 203 is used to perform multi-step spectrum prediction on the electromagnetic spectrum prediction model when the prediction window is greater than 1, so as to generate multi-step adversarial samples.
[0156] The actual confrontation execution module 204 is used to perform intelligent confrontation on the electromagnetic spectrum prediction model based on single-step confrontation samples and multi-step confrontation samples to reduce the prediction accuracy of the electromagnetic spectrum prediction model over a period of time.
[0157] It is worth mentioning that all modules involved in this embodiment are logical modules. In actual applications, a logical unit can be a physical unit, a part of a physical unit, or a combination of multiple physical units. In addition, to highlight the innovation of this application, this embodiment does not include units that are not closely related to solving the technical problem proposed by this application. However, this does not mean that other units do not exist in this embodiment.
[0158] It is not difficult to find that this embodiment is a system embodiment corresponding to the above-mentioned method embodiment, and this embodiment can be implemented in conjunction with the above-mentioned method embodiment. The relevant technical details and technical effects mentioned in the above-mentioned embodiments are still valid in this embodiment, and to reduce repetition, they are not repeated here. Accordingly, the relevant technical details mentioned in this embodiment can also be applied to the above-mentioned embodiments.
[0159] Another embodiment of the present application proposes an information data processing terminal, the structure of which is as follows: Figure 5 As shown, it includes: at least one processor 301; and a memory 302 communicatively connected to the at least one processor 301; wherein the memory 302 stores instructions that can be executed by the at least one processor 301, and the instructions are executed by the at least one processor 301 to enable the at least one processor 301 to execute an intelligent countermeasure method for electromagnetic spectrum prediction as described in the above method embodiment.
[0160] The memory and processor can be connected using a bus, which can include any number of interconnected buses and bridges. The bus connects various circuits of one or more processors and memories. The bus can also connect various other circuits such as peripheral devices, voltage regulators, and power management circuits. These are all well known in the art and will not be described further in this article. The bus interface is responsible for providing an interface between the bus and the transceiver. The transceiver can be a single component or multiple components, such as multiple receivers and transmitters, providing a unit for communicating with various other devices on a transmission medium. Data processed by the processor is transmitted over a wireless medium via an antenna. Furthermore, the antenna also receives data and transmits it to the processor.
[0161] The processor is responsible for managing the bus and general processing, and can also provide various functions, including timing, peripheral interfaces, voltage regulation, power management, and other control functions. Memory can be used to store data used by the processor when performing operations.
[0162] Another embodiment of the present application provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it can implement an intelligent countermeasure method for electromagnetic spectrum prediction as described in the above method embodiment.
[0163] That is, those skilled in the art will understand that all or part of the steps in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a program, which is stored in a storage medium and includes a number of instructions for causing a device (such as a single-chip microcomputer, chip, etc.) or a processor to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: a USB flash drive, a mobile hard drive, a ROM (Read-Only Memory), a RAM (Random Access Memory), a magnetic disk, or an optical disk, etc., various media that can store program code.
[0164] Those skilled in the art will appreciate that the above embodiments are specific embodiments for implementing the present application, and that in actual applications, various changes may be made thereto in form and detail without departing from the spirit and scope of the present application.
Claims
1. An intelligent countermeasure method for electromagnetic spectrum prediction, characterized in that: include: Build an electromagnetic spectrum prediction model based on deep learning. The electromagnetic spectrum prediction model predicts the future frequency band occupancy of the primary user based on the frequency band occupancy of the primary user in the historical time period. The occupancy is represented by a 01 sequence. When the prediction window is 1, a single-step spectrum prediction is performed on the electromagnetic spectrum prediction model to generate a single-step adversarial sample; When the prediction window is greater than 1, multi-step spectrum prediction is performed on the electromagnetic spectrum prediction model to generate multi-step adversarial samples; Based on single-step adversarial samples and multi-step adversarial samples, the electromagnetic spectrum prediction model is intelligently antagonized to reduce the prediction accuracy of the electromagnetic spectrum prediction model over a period of time.
2. The intelligent countermeasure method for electromagnetic spectrum prediction according to claim 1, characterized in that: Construct an electromagnetic spectrum prediction model based on deep learning. The electromagnetic spectrum prediction model predicts the future frequency band occupancy of the primary user based on the frequency band occupancy of the primary user in the historical time period. The occupancy is represented by a 01 sequence, including: A deep learning-based electromagnetic spectrum prediction model is constructed. It is assumed that sparsely distributed signal sensors (SS) continuously observe the frequency band and send their received signal strength (RSS) to the cognitive radio base station. The mean of multiple RSS values is calculated and judged to obtain the current frequency band occupancy. The electromagnetic spectrum prediction model predicts the future frequency band occupancy of the primary user (PU) based on the frequency band occupancy of the primary user (PU) in the historical time period. The occupancy is represented by a 01 sequence.
3. The intelligent countermeasure method for electromagnetic spectrum prediction according to claim 2, characterized in that: The observed frequency band is only used by one PU. The secondary user SU only cares about the PU's occupancy. It sets the RSS decision threshold γ and determines the frequency band occupancy at the current moment based on γ and the average of multiple RSSs. Assuming that the current time is time t, the frequency band occupancy at the current time is determined based on γ and the average of multiple RSSs, which can be expressed as follows: Where m is the total number of SS, represents the RSS of the i-th SS at time t, x t =H1 represents the frequency band occupied by PU at time t, x t =H0 means that the PU does not occupy the frequency band at time t; Based on this, the frequency band occupancy in the time period Time containing N moments is expressed by the 01 sequence as follows: in, Indicates the frequency band occupancy within the time period T, x n Indicates the frequency band occupancy at the nth moment in the time period Time, where n is an integer greater than 1.
4. The intelligent countermeasure method for electromagnetic spectrum prediction according to claim 3, characterized in that: When the prediction window is 1, performing single-step spectrum prediction on the electromagnetic spectrum prediction model to generate a single-step adversarial sample includes: For the case where the prediction window is 1, the non-operation constraint is used to constrain the feasible domain of the adversarial sample, and an iterative process is used to calculate the minimum perturbation to change the decision of the electromagnetic spectrum prediction model. It is assumed that the electromagnetic spectrum prediction model is a general differentiable binary classification predictor. At each iteration, the electromagnetic spectrum prediction model is point-linearized around the current input. At this time, its output is linearly related to the input, and the formed hyperplane divides the output into positive and negative parts. The directional distance of the input point moving to the hyperplane is obtained through the distance analytical formula, and then the directional perturbation under the feasible domain constraint with the smallest angle with the directional distance is obtained. After each iteration, the directional perturbation is added to the input sample of the current iteration step, and the input point is updated until the decision of the electromagnetic prediction model changes. The input sample at this time is the generated single-step adversarial sample.
5. The intelligent countermeasure method for electromagnetic spectrum prediction according to claim 4, characterized in that: For the input sequence of the electromagnetic spectrum prediction model For example, define x n The non-operation is !x n ,! x n It is expressed by the formula: Among them, !x n Used to convert x n The value of changes from 0 to 1, or from 1 to 0; In order to calculate the disturbance size conveniently, use Go ahead! x n The number of times to represent the added disturbance The size of It is expressed by the formula: r n ∈(-1,0,1); Among them, r n Only allowed in x n =0, takes the value (0,1), at x n =1 takes the value (-1,0); The predicted value of the electromagnetic spectrum prediction model is expressed as F t ∈(0,1), T represents the length of the prediction window; make represents the output value of the electromagnetic spectrum prediction model, then F t The value of is expressed as: in, When T=1, Now enter the sequence Without including the prediction value of the previous moment, the minimum perturbation to change the decision of the electromagnetic spectrum prediction model is given by the following analytical formula: st Considering the hyperplane method, in order to alleviate the gradient disappearance, the activation function σ satisfies First, we analyze the case where the electromagnetic spectrum prediction model is an affine classifier, and then generalize it to any differentiable binary classification predictor; At this time, the output of the electromagnetic spectrum prediction model Obviously the hyperplane The output of the electromagnetic spectrum prediction model is divided into positive and negative parts. Direction distance to move to the hyperplane It can be given by the following analytical formula: Now assume that f is a general differentiable binary classification predictor, and an iterative process is used to calculate the minimum perturbation to change the decision of the electromagnetic spectrum prediction model; In each iteration, f revolves around the current point The minimum continuous perturbation of the linearized affine classifier is calculated as: Assume that the minimum discrete perturbation of the iterative step i is Set the step size to 1, and The smaller the angle θ between the directions, The closer the iterative point is to the hyperplane, the greater the distance. In order to minimize θ, cosθ needs to take the maximum value. At this time, Need to meet: st in, All possible directions of disturbance are specified, which only contain 1 and -1. and Multiplying them together can filter out feasible solutions; Finally, the discrete perturbation of the current step is obtained by determining the maximum value, and the next iteration point is updated accordingly. The update formula is expressed as when The iteration stops when the sign of the electromagnetic spectrum prediction model is changed.
6. The intelligent countermeasure method for electromagnetic spectrum prediction according to claim 5, characterized in that: When the prediction window is greater than 1, performing multi-step spectrum prediction on the electromagnetic spectrum prediction model to generate multi-step adversarial samples includes: For the case where the prediction window is greater than 1, an iterative process is used to calculate the minimum perturbation that maximizes the loss function of the electromagnetic spectrum prediction model. At each iteration, a calculation point is obtained by the adversarial sample generation method with a prediction window of 1. The iteration point is updated by the calculation point until the iteration reaches the number of steps of the prediction window length, or when it is detected that the loss function value of the next iteration step becomes smaller, the iteration ends. The input sample at this time is the generated multi-step adversarial sample.
7. The intelligent countermeasure method for electromagnetic spectrum prediction according to claim 6, characterized in that: When T>1, there is Define the loss function as Represents the initial prediction value of the electromagnetic spectrum prediction model, and loss can describe the effectiveness of the attack; The minimum perturbation that makes the decision of the electromagnetic spectrum prediction model the worst is given by the following analytical formula: st First, we analyze the case where the electromagnetic spectrum prediction model is an affine classifier. At this time, the output of the electromagnetic spectrum prediction model is Hyperplane Similarly, the output of the electromagnetic spectrum prediction model is divided into two parts, positive and negative, T-1 and The associated points and Together they form a collection The elements in and f uniquely determine, the perturbation The goal is to make back, As many points as possible pass through the hyperplane; Assuming f is a general differentiable binary classification predictor, an iterative process is used to calculate the minimum perturbation to change the decision of the electromagnetic spectrum prediction model; In each iteration, f revolves around the current calculation point Linearization, The independent moment attack disturbance is calculated by the basic CVM Will Transformed into Vectors of the same latitude Update iteration point The update formula is And calculate the loss function value at this time; According to the updated iteration point Get the next calculation point The iteration ends when the Tth step is reached or the loss function value of the next step becomes smaller.
8. An intelligent countermeasure system for electromagnetic spectrum prediction, characterized in that: include: The model building module is used to build an electromagnetic spectrum prediction model based on deep learning. The electromagnetic spectrum prediction model predicts the future frequency band occupancy of the primary user based on the frequency band occupancy of the primary user in the historical time period. The occupancy is represented by a 01 sequence. The single-step adversarial module is used to perform single-step spectrum prediction on the electromagnetic spectrum prediction model when the prediction window is 1 to generate single-step adversarial samples; The multi-step adversarial module is used to perform multi-step spectrum prediction on the electromagnetic spectrum prediction model when the prediction window is greater than 1, so as to generate multi-step adversarial samples; The actual adversarial execution module is used to perform intelligent adversarial attacks on the electromagnetic spectrum prediction model based on single-step adversarial samples and multi-step adversarial samples to reduce the prediction accuracy of the electromagnetic spectrum prediction model over a period of time.
9. An information data processing terminal, characterized in that: include: at least one processor; and, a memory communicatively coupled to the at least one processor; In which, the memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute an intelligent countermeasure method for electromagnetic spectrum prediction as described in any one of claims 1 to 7.
10. A computer-readable storage medium storing a computer program, characterized in that: When the computer program is executed by a processor, it can implement an intelligent countermeasure method for electromagnetic spectrum prediction as described in any one of claims 1 to 7.