Malicious transmitter intelligent detection method based on out-of-distribution data
By constructing an open set transmitter identification framework, combining deep residual shrinkage network and double-headed bias network, and using out-of-distribution data to extract RF signal features, the problems of poor performance of transmitter identification in low signal-to-noise ratio environments and insufficient generalization ability in heterogeneous environments are solved, and efficient malicious transmitter detection and identification is achieved.
Patent Information
- Application Number
- CN202511154507.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-18
- Publication Date
- 2025-09-12
- Estimated Expiration
- 2045-08-18
AI Technical Summary
Existing transmitter identification technology has poor detection performance in low signal-to-noise ratio environments, insufficient generalization capabilities in heterogeneous IoT environments, and insufficient utilization of distributed RF signals, making it difficult to effectively identify unknown malicious transmitters.
An open set transmitter identification framework is constructed, combining deep residual shrinkage network and two-headed bias network, using out-of-distribution data to extract RF signal features, and malicious transmitter detection is performed through deep residual shrinkage network and two-headed bias network.
It significantly improves the detection sensitivity and robustness in low signal-to-noise ratio environments, reduces the false alarm rate, and enhances the generalization capability in heterogeneous IoT environments. It is suitable for complex scenarios such as smart cities and industrial IoT.
Smart Images

Figure CN120640295A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of Internet of Things security and wireless communication technology, and in particular relates to an intelligent detection method for malicious transmitters based on out-of-distribution data. Background Art
[0002] Emitter identification is a core technology in the field of IoT security. It identifies devices by analyzing the unique characteristics of radio frequency signals (i.e., radio frequency fingerprints) and is widely used in scenarios such as smart cities and industrial automation. With the rise of 6G and satellite-drone networks, the scale of IoT devices is rapidly expanding, and the demand for spectrum resources is increasing. However, open wireless channels make the system vulnerable to attacks by malicious transmitters, such as those disguising legitimate devices, threatening system reliability. Existing emitter identification methods are mainly divided into two categories: methods based on traditional feature extraction and methods based on deep learning. Traditional methods rely on manual extraction of signal features (such as amplitude and phase), but have poor generalization ability in complex dynamic environments, are sensitive to noise, and require a lot of manual tuning. For example, existing technologies (Qian Y, Qu J, Han X, et al., “Specific emitter identification based on multi-level sparse representation in automatic identification system,” IEEE Transactions on Information Forensics and Security , vol. 16, pp. 3272-3282,2021) proposed to capture signal patterns through multi-level sparse representation to improve robustness, but it is still affected by noise and difficult to adapt to heterogeneous environments.
[0003] In recent years, deep learning-based methods have attracted attention due to their powerful feature extraction capabilities. IEEE Transactions on Information Forensics and Security, vol. 15, pp. 2589-2599, 2020) proposed using convolutional neural networks to extract features from raw signals to improve performance in dynamic environments. However, open-set emitter identification requires detecting unknown malicious transmitters that are not included in the training data. Existing methods have poor detection performance under low signal-to-noise ratio conditions and insufficient utilization of out-of-distribution RF signals. For example, existing technologies (Wang Y, Gui G, Ohtsuka T, et al., “Scalable semi-supervised learning with semi-supervised kernel dictionary learning for specific emitter identification,” IEEE Transactions on Aerospace and Electronic Systems , vol.56, no. 5, pp. 4012-4023, 2020) proposed a semi-supervised learning method to improve scalability, but the performance in heterogeneous networks is limited. Existing technology (Xie X, Wang X, Gui G, “Transformer-based specific emitter identification in IoT environment,” IEEE Internet of Things Journal , vol. 8, no. 12, pp. 9876-9887, 2021) uses a converter to capture time-frequency dynamic features, but its performance degrades in complex noisy environments. A patent application (application number CN202110456789.2, publication number CN113435374A) discloses a deep learning-based RF fingerprinting method that improves accuracy through multi-scale feature extraction. However, it fails to fully utilize out-of-distribution RF signals, resulting in limited detection capabilities for unknown transmitters.
[0004] These purely data-driven methods rely on large numbers of training samples, making them difficult to implement in complex IoT systems. Furthermore, existing methods suffer from low detection accuracy under low signal-to-noise ratio (SNR) conditions, struggle to cope with heterogeneous network environments, and have limited effectiveness in rejecting unknown transmitters. Therefore, there is an urgent need to develop a new open-set transmitter identification method to improve detection performance in low SNR environments, enhance generalization capabilities, and fully utilize out-of-distribution RF signals to improve system robustness. Summary of the Invention
[0005] In response to the shortcomings of existing transmitter identification technology, such as poor detection performance in low signal-to-noise ratio environments, insufficient generalization capabilities in heterogeneous Internet of Things environments, and insufficient utilization of out-of-distribution radio frequency signals, the present invention proposes a malicious transmitter rejection system and method based on out-of-distribution data.
[0006] The present invention provides an intelligent detection method for malicious transmitters based on out-of-distribution data, and its complete technical method includes the following steps:
[0007] (1) Collect RF signals within and outside the distribution to construct test set data;
[0008] (2) Constructing a network based on an open set transmitter identification framework, wherein the network based on the open set transmitter identification framework integrates a deep residual contraction network and a two-headed bias network, wherein the deep residual contraction network is used to extract features of the radio frequency signal within the distribution and the radio frequency signal outside the distribution to determine the category of the transmitter; and the two-headed bias network detects whether the radio frequency signal belongs to a malicious transmitter based on the features;
[0009] (3) Input the test set data into the network based on the open set transmitter identification framework to obtain classification and detection results.
[0010] Furthermore, the deep residual shrinkage network is used to extract the features of the in-distribution RF signal and the out-of-distribution RF signal:
[0011] According to the radio frequency signals in the distribution in step (1), a deep residual shrinkage network is constructed and trained, wherein the deep residual shrinkage network classifies the radio frequency signals in the distribution to obtain transmitter categories to which the radio frequency signals in each distribution belong; determining whether the training of the deep residual shrinkage network is completed, and if so, obtaining a trained deep residual shrinkage network; if not, increasing the number of training iterations by one and continuing to train the deep residual shrinkage network;
[0012] The features of in-distribution and out-of-distribution RF signals are extracted using a trained deep residual shrinkage network extractor.
[0013] Furthermore, the deep residual shrinkage network uses cross entropy loss to extract RF fingerprint features and trains the classification head to classify the latent spatial features of the RF signal corresponding to the transmitter within the distribution; the deep residual shrinkage network includes an initial convolutional layer, a convolutional block attention module, multiple channel adaptive residual shrinkage units, a global average pooling layer and a fully connected layer;
[0014] The initial convolution layer is used to extract preliminary time domain features, and the convolution block attention module optimizes the extraction of time domain features through channel and spatial attention mechanisms to obtain key RF fingerprint features;
[0015] Multiple channel adaptive residual shrinkage units use a learnable soft threshold mechanism to suppress noise and enhance the robustness of the key RF fingerprint features;
[0016] The global average pooling layer is used to average the outputs of different channels.
[0017] Furthermore, the dual-head bias network detects whether the radio frequency signal belongs to a malicious transmitter based on the feature specifically as follows:
[0018] Based on the characteristics, a correspondence between in-distribution RF signals and out-distribution RF signals is determined. For each type of in-distribution RF signal, a corresponding subset of out-distribution RF signals is randomly selected. A two-headed bias network is constructed and trained. The two-headed bias network outputs a bias score to identify malicious transmitters.
[0019] Determine whether the training of the deep residual shrinkage network is completed. If so, obtain a trained double-headed bias network. If not, increase the number of training iterations by one and continue training the deep residual shrinkage network.
[0020] Furthermore, the two-headed bias network includes an explicit bias branch and an implicit bias branch, the explicit bias branch is used to capture the explicit bias characteristics of the category, and the implicit bias branch captures the implicit bias characteristics of the category based on the residual; through the optimization of the bias loss function, a bias score is generated to distinguish between known and unknown transmitters, and the known transmitter is a malicious transmitter.
[0021] As a preferred embodiment of the present application, the deviation loss function comprises:
[0022]
[0023] in, is the normal deviation, represents the bias network score;
[0024] The deviation loss is defined as follows:
[0025]
[0026] Among them, if is an out-of-distribution sample, then ,if is a sample from the distribution, then ;parameter Represents the confidence interval threshold, which controls the degree of deviation of samples outside the distribution;
[0027] The average deviation scores of the explicit deviation branch and the implicit deviation branch outputs are calculated respectively.
[0028] Furthermore, the step (3) is specifically as follows:
[0029] The network outputs a classification score and a deviation score based on the open set transmitter identification framework. The deviation score is the average of the explicit and implicit branch scores. The deviation score is calculated for each category, and the minimum value among all categories is taken as the final score. The final score is compared with a preset deviation score threshold. If the score is lower than the threshold, it is determined to be an unknown transmitter and its access is denied. Otherwise, it is identified as a known transmitter and its category is output:
[0030]
[0031] in is the judgment label, is the deviation score, It was judged to be The probability of the categories, is the total number of categories, is the deviation score threshold.
[0032] Compared with the prior art, the present invention has the following advantages:
[0033] First, by introducing out-of-distribution data, the system's detection sensitivity to malicious transmitters in open scenarios is significantly improved, and it has higher robustness in heterogeneous IoT environments.
[0034] Second, the deep residual shrinkage network works in tandem with the convolutional block attention module to effectively denoise and extract robust RF fingerprints in low signal-to-noise ratio environments.
[0035] Third, the dual-headed bias network learns explicit and implicit anomalies separately based on the bias loss, directly outputs anomaly scores, significantly reduces the false alarm rate, and outperforms mainstream malicious rejection strategies in the unknown transmitter detection task.
[0036] Fourth, the constructed end-to-end open set recognition framework demonstrates excellent robustness and generalization capabilities in heterogeneous IoT environments, and can be seamlessly applied to complex practical scenarios such as smart cities and industrial IoT. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] Figure 1 is a flow chart of the present invention;
[0038] Figure 2 This is a framework diagram of the depth residual shrinkage unit of the present invention;
[0039] Figure 3 It is a double-head deviation network framework diagram of the present invention;
[0040] Figure 4 It is an overall block diagram of the open set transmitter identification training test using the present invention;
[0041] Figure 5This is a comparison chart of the classification accuracy of the present invention and other existing technologies under different signal-to-noise ratio conditions;
[0042] Figure 6 is a comparison diagram of the areas under the receiver operating characteristic curves using the present invention and other existing technologies under different numbers of unknown transmitters;
[0043] Figure 7 This is a comparison chart of the areas under the receiver operating characteristic curves using the present invention and other existing technologies under assisted training with different numbers of out-of-distribution samples. DETAILED DESCRIPTION
[0044] The invention will be further described below with reference to the accompanying drawings.
[0045] The present invention introduces out-of-distribution data, combines deep residual shrinkage network and double-headed bias network, constructs an open set transmitter identification framework, significantly improves the detection capability of malicious transmitters in low signal-to-noise ratio environments, enhances the generalization performance in heterogeneous Internet of Things environments, and effectively utilizes out-of-distribution RF signals to improve system robustness, reducing the security threat of malicious transmitters to the Internet of Things system. Figure 1 The specific steps of the method of the present invention are described as follows.
[0046] Example 1:
[0047] This embodiment provides a method for intelligently detecting malicious transmitters based on out-of-distribution data. The complete technical method includes the following steps:
[0048] (1) Collect RF signals within and outside the distribution to construct test set data;
[0049] (2) Constructing a network based on an open set transmitter identification framework, wherein the network based on the open set transmitter identification framework integrates a deep residual contraction network and a two-headed bias network, wherein the deep residual contraction network is used to extract features of the radio frequency signal within the distribution and the radio frequency signal outside the distribution to determine the category of the transmitter; and the two-headed bias network detects whether the radio frequency signal belongs to a malicious transmitter based on the features;
[0050] (3) Inputting the test set data into the network based on the open set transmitter identification framework to obtain classification and detection results. The test set uses in-distribution RF signals and a wider range of unauthorized transmitter signals as samples of out-of-distribution RF signals for testing together.
[0051] Step 1: spectrum data acquisition.
[0052] RF signal acquisition: The signal transmitted by the transmitter is received by the receiver, and the received signal can be expressed as .in, Indicates the transmitter signal sampling points, Indicates the received signal sampling points, The mean is 0 and the variance is The received signal is represented as a vector of I / Q components using additive Gaussian white noise. In-distribution RF signals include those emitted by devices that have obtained spectrum authorization. These devices operate within the legal spectrum resource allocation framework, and their signal characteristics are within the regulatory scope of the relevant management agencies. RF signals from transmitters of known categories, i.e., in-distribution RF signals, are collected and labeled with category labels to form a training dataset. In real-world scenarios, it is easy to obtain some signal samples from unauthorized transmitters, which serve as samples of known out-of-distribution RF signals. These signals are unauthorized, known signals. Out-of-distribution RF signals are also collected as auxiliary data for subsequent training to enhance the detection capability of unknown transmitters. Data is stored as tensors in I / Q format. The IQ signal used is an unmodulated RF signal containing multiple sampling points for feature extraction and classification.
[0053] Step 2: Build and train a deep residual shrinkage network. Based on the I / Q data from Step 1, a deep residual shrinkage network is constructed. It consists of an initial convolutional layer, a convolutional block attention module, multiple channel-adaptive residual shrinkage units, a global average pooling layer, and a fully connected layer. The initial convolutional layer extracts preliminary time-domain features. The convolutional block attention module optimizes feature extraction through channel and spatial attention mechanisms, highlighting key RF fingerprint features. The channel-adaptive residual shrinkage unit uses a learnable soft thresholding mechanism to suppress noise and enhance feature robustness. The network outputs a fixed-dimensional feature embedding for subsequent classification. Training uses the Adam optimizer with a learning rate of 0.001 and a maximum training epoch of 150. The cross-entropy loss function calculates the difference between the network output and the true label. During training, the network parameters are randomly initialized, and I / Q data is fed batch by batch. The network parameters are optimized to achieve robust feature extraction and denoising.
[0054] Step 3: Determine whether deep residual shrinkage network training has concluded by determining whether the network has reached the maximum training epoch (150 epochs) or the validation loss has stopped decreasing (using early stopping with no improvement after 10 epochs). If so, freeze the network weights and proceed to step 4. If not, increase the number of training iterations by one and continue training the network.
[0055] Step 4: For each type of in-distribution RF signal, a certain number of out-distribution RF signals are randomly selected to form a subset. These subsets are used for subsequent training of the two-head bias network to enhance the detection capability of unknown transmitters.
[0056] Step 5: Build and train a two-headed bias network. Using the I / Q data from step 1 and the out-of-distribution subset from step 4, a two-headed bias network is constructed, consisting of explicit and implicit bias branches. The explicit branch captures the bias characteristics of the category, while the implicit branch captures the global bias characteristics. Through optimization of the bias loss function, a bias score is generated to distinguish between known and unknown transmitters. The two-headed bias network includes an explicit bias branch and an implicit bias branch. The explicit bias branch is used to capture the explicit bias characteristics of the category, while the implicit bias branch captures the implicit bias characteristics of the category based on the residual.
[0057] In this embodiment, the I / Q data from step 1 and the out-of-distribution subset from step 4 are used as inputs, and a deviation loss function is optimized to generate a deviation score to distinguish between known and unknown transmitters. The deviation loss function is as follows:
[0058]
[0059] in, is the normal deviation, represents the bias network score; the final bias loss is as follows:
[0060]
[0061] Among them, if is an out-of-distribution sample, then ,if is a sample from the distribution, then ;parameter represents the confidence interval threshold, which controls the degree of deviation of samples outside the distribution; and calculates the average deviation scores of the explicit deviation branch and the implicit deviation branch outputs respectively.
[0062] Training used the RMSprop optimizer with a learning rate of 0.001 and a maximum training epoch of 100. The mean squared error loss function was used to calculate the deviation between the network output and the out-of-distribution RF signal. During training, the network parameters were randomly initialized, and data was fed in batches, and the network was optimized to ensure convergence.
[0063] Step 6: Determine whether the two-headed bias network training has ended by determining whether the network has reached the maximum training epoch (100 epochs) or the validation loss has stopped decreasing (using the early stopping mechanism, with no improvement after 10 epochs). If so, proceed to Step 7; if not, increase the number of training iterations by one and continue training the network.
[0064] Step 7: Integrate the Deep Residual Contraction Network with the Two-Headed Bias Network. The trained Deep Residual Contraction Network is integrated with the Two-Headed Bias Network to form an end-to-end open-set transmitter identification framework. The Deep Residual Contraction Network is responsible for feature extraction and denoising, while the Two-Headed Bias Network generates classification and bias scores. These are jointly optimized to achieve known transmitter classification and unknown transmitter rejection.
[0065] Step 8: Input the test set data into the network. Input the test set data into the trained network. The test data includes known category signals and unknown malicious transmitter signals. The format is consistent with the training data, both of which are tensors in I / Q form.
[0066] Step 9: Output detection results. The network outputs a classification score and a deviation score. The deviation score is the average of the explicit and implicit branch scores. The deviation score is calculated for each category, and the minimum score across all categories is taken as the final score. This score is then compared with a preset threshold. If the score is below the threshold, the transmitter is identified as a malicious one and denied access. Otherwise, the transmitter is identified as a known transmitter and its category is output.
[0067] The effects of the present invention will be further described below in conjunction with simulation experiments.
[0068] Simulation experiment and effect analysis:
[0069] 1. Simulation conditions and parameter settings.
[0070] The simulation experiments in this paper were conducted using Python 3.8 and PyTorch 2.0, using an NVIDIA 3090 GPU and an Intel Core i9 CPU. The experiments used the WiSig dataset, which contains Wi-Fi signals collected in the 2.4 GHz band from multiple commercial transmitters and receivers at a sampling rate of 25 Msps, including raw I / Q samples. Two subsets were used: Subset 1, consisting of 6 transmitters and 12 receivers, with 1000 signals per pair, collected over four days, was used to test the classifier's performance; Subset 2, consisting of 150 transmitters and 18 receivers, with 50 signals per pair, collected over four days. In Subset 2, 30 categories were selected as known transmitters, 30 categories as out-of-distribution samples, and 30 categories as malicious transmitters. The training set comprised 70% of the dataset, the validation set 10%, and the test set 20%. The signal-to-noise ratio ranged from 0 dB to 20 dB, with a 2 dB step size.
[0071] 2. Simulation content.
[0072] Figure 5The comparison of the classification accuracy of the method of the present invention and other methods under different signal-to-noise ratio conditions is shown. The horizontal axis represents the signal-to-noise ratio in dB, ranging from 0 dB to 20 dB, with an interval of 2 dB; the vertical axis represents the classification accuracy. The broken line marked with dots represents the classification accuracy curve of the method of the present invention, the broken line marked with squares represents the classification accuracy curve of the deep residual shrinkage network-independent channel method, the broken line marked with equilateral triangles represents the classification accuracy curve of the deep residual shrinkage network-shared channel method, and the broken line marked with diamonds represents the classification accuracy curve of the deep residual network method. The experimental results show that the method of the present invention performs excellently under low signal-to-noise ratios. When the signal-to-noise ratio is 0 dB, the classification accuracy of the method of the present invention is about 71.2%, which is about 2.9% higher than the deep residual shrinkage network-independent channel threshold method and about 9.1% higher than the deep residual network method. At a signal-to-noise ratio (SNR) of 4 dB, the classification accuracy of our method is approximately 83.3%, approximately 4.9% higher than the deep residual shrinkage network-independent channel method and approximately 9.8% higher than the deep residual network method. When the SNR reaches 20 dB, the classification accuracy of our method approaches saturation, reaching approximately 97.9%, significantly outperforming other methods and demonstrating its stable performance at high SNRs.
[0073] Figure 6 The performance comparison of the area under the receiver operating characteristic curve between the method of the present invention and other methods under different numbers of unknown transmitters is shown. The horizontal axis represents the number of unknown transmitters, ranging from 10 to 90, with an interval of 10; the vertical axis represents the area under the receiver operating characteristic curve. The broken line marked with dots represents the performance curve of our network method, the broken line marked with squares represents the performance curve of the deviation network method, the broken line marked with regular triangles represents the performance curve of the support vector data description method, and the broken line marked with diamonds represents the performance curve of the distance-based method. The experimental results show that the deep hybrid detection network method exhibits strong detection capabilities under different numbers of unknown transmitters. When the number of unknown transmitters is 10, the area under the curve of the deep hybrid detection network method is about 0.952, which is about 6.9% higher than the support vector data description method and about 10% higher than the distance-based method. When the number of unknown transmitters is 90, the area under the curve of the deep hybrid detection network method is approximately 0.566, which is approximately 2.2% higher than the support vector data description method and approximately 2.4% higher than the distance-based method, showing its robustness in scenarios with a high number of unknown transmitters.
[0074] Figure 7The performance comparison of the area under the receiver operating characteristic curve of the method of the present invention and other methods under different numbers of out-of-distribution samples is shown. The horizontal axis represents the number of out-of-distribution samples of each category, with values of 1, 5, 10, 20, 50, and 100; the vertical axis represents the area under the receiver operating characteristic curve. The broken line marked with dots represents the performance curve of the deep hybrid detection network method, the broken line marked with squares represents the performance curve of the deviation network method, the broken line marked with equilateral triangles represents the performance curve of the improved support vector data description method, the horizontal dotted line represents the baseline value of the area under the curve of the support vector data description method, and the horizontal dotted line represents the baseline value of the area under the curve of the distance-based method. The experimental results show that the performance of the deep hybrid detection network method significantly improves with the increase of the number of out-of-distribution samples. When the number of out-of-distribution samples is 100, the area under the curve of the two-headed bias network method is approximately 0.885, which is approximately 3.3% higher than the bias network method, approximately 10.1% higher than the support vector data description benchmark value, and approximately 12.2% higher than the distance-based benchmark value. This demonstrates the key role of out-of-distribution samples in enhancing malicious transmitter detection and the superiority of our proposed two-headed bias network over other technical methods.
[0075] 3. Experimental conclusions.
[0076] Based on the simulation results and analysis above, the proposed intelligent detection method for malicious transmitters based on out-of-distribution data significantly improves classification accuracy under low signal-to-noise ratio conditions, enhances detection of unknown transmitters, reduces false alarm rates, and demonstrates excellent robustness in heterogeneous IoT environments. Compared to other existing approaches, this method offers significant advantages in classification accuracy and detection of unknown transmitters under low signal-to-noise ratio conditions, making it suitable for practical scenarios such as smart cities and the Industrial Internet of Things.
[0077] The present invention has many specific application paths. The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements can be made without departing from the principles of the present invention. These improvements should also be considered as the scope of protection of the present invention.
Claims
1. A method for intelligent detection of malicious transmitters based on out-of-distribution data, characterized in that: The method comprises the following steps: (1) collecting radio frequency signals within the distribution and radio frequency signals outside the distribution to construct test set data; (2) Constructing a network based on an open set transmitter identification framework, wherein the network based on the open set transmitter identification framework integrates a deep residual contraction network and a two-headed bias network, wherein the deep residual contraction network is used to extract features of the radio frequency signal within the distribution and the radio frequency signal outside the distribution to determine the category of the transmitter; and the two-headed bias network detects whether the radio frequency signal belongs to a malicious transmitter based on the features; (3) Input the test set data into the network based on the open set transmitter identification framework to obtain classification and detection results.
2. The method for intelligent detection of malicious transmitters based on out-of-distribution data according to claim 1, characterized in that: The deep residual shrinkage network is used to extract the features of the in-distribution RF signal and the out-of-distribution RF signal: According to the radio frequency signals in the distribution in step (1), a deep residual shrinkage network is constructed and trained, wherein the deep residual shrinkage network classifies the radio frequency signals in the distribution to obtain transmitter categories to which the radio frequency signals in each distribution belong; determining whether the training of the deep residual shrinkage network is completed, and if so, obtaining a trained deep residual shrinkage network; if not, increasing the number of training iterations by one and continuing to train the deep residual shrinkage network; The features of in-distribution and out-of-distribution RF signals are extracted using a trained deep residual shrinkage network extractor.
3. The method for intelligent detection of malicious transmitters based on out-of-distribution data according to claim 2, characterized in that: The deep residual shrinkage network uses cross entropy loss to extract RF fingerprint features and trains the classification head to classify the latent spatial features of the RF signal corresponding to the transmitter within the distribution; the deep residual shrinkage network includes an initial convolutional layer, a convolutional block attention module, multiple channel adaptive residual shrinkage units, a global average pooling layer and a fully connected layer; The initial convolution layer is used to extract preliminary time domain features, and the convolution block attention module optimizes the extraction of time domain features through channel and spatial attention mechanisms to obtain key RF fingerprint features; Multiple channel adaptive residual shrinkage units use a learnable soft threshold mechanism to suppress noise and enhance the robustness of the key RF fingerprint features; The global average pooling layer is used to average the outputs of different channels.
4. The method for intelligent detection of malicious transmitters based on out-of-distribution data according to claim 1, characterized in that: The double-headed bias network detects whether the radio frequency signal belongs to a malicious transmitter based on the feature specifically as follows: Based on the characteristics, a correspondence between in-distribution RF signals and out-distribution RF signals is determined. For each type of in-distribution RF signal, a corresponding subset of out-distribution RF signals is randomly selected. A two-headed bias network is constructed and trained. The two-headed bias network outputs a bias score to identify malicious transmitters. Determine whether the training of the deep residual shrinkage network is completed. If so, obtain a trained double-headed bias network. If not, increase the number of training iterations by one and continue training the deep residual shrinkage network.
5. The method for intelligent detection of malicious transmitters based on out-of-distribution data according to claim 4, characterized in that: The dual-headed deviation network includes an explicit deviation branch and an implicit deviation branch. The explicit deviation branch is used to capture the explicit deviation characteristics of the RF signal within the distribution and the RF signal category outside the distribution. The implicit deviation branch captures the implicit deviation characteristics of the RF signal within the distribution and the RF signal category outside the distribution based on the residual; through the deviation loss function optimization, a deviation score is generated to distinguish between known and unknown transmitters, and the unknown transmitter is a malicious transmitter.
6. The method for intelligent detection of malicious transmitters based on out-of-distribution data according to claim 5, characterized in that: The deviation loss function includes: ; in, is the normal deviation, represents the bias network score, is the mean of the reference scores, is with the associated standard deviation, which measures the spread of the deviation scores; The deviation loss is as follows: ; Among them, z is the RF signal, y is the representation bit of the RF signal category, if is the RF signal sample outside the distribution, then ,if is the RF signal sample outside the distribution, then ;parameter Represents the confidence interval threshold, which controls the degree of deviation of samples outside the distribution; The average deviation scores of the explicit deviation branch and the implicit deviation branch outputs are calculated respectively.
7. The method for intelligent detection of malicious transmitters based on out-of-distribution data according to claim 1, characterized in that: The step (3) is specifically as follows: The network outputs a classification score and a deviation score based on the open set transmitter identification framework, where the deviation score is the average of the explicit and implicit branch scores; the deviation score is calculated for each category, the minimum value of all categories is taken as the final score, and is compared with a preset deviation score threshold; If the score is lower than the threshold, it is determined to be an unknown transmitter and its access is denied; Otherwise, identify it as a known transmitter and output its category: ; in is the judgment label, is the deviation score, It was judged to be The probability of the categories, is the total number of categories, is the deviation score threshold.
Citation Information
Patent Citations
An industrial equipment operation and maintenance system
CN113204220B
Photoelectric intelligent garbage sorting method based on DMD and YOLOV5
CN113435374A
Malicious traffic detection method and system based on attention mechanism
CN114338199A
Deep learning-based radio frequency fingerprint identification method for frequency equipment
CN114896887A
Modulation mode intelligent identification method based on lightweight network
CN114912486A