Covert communication signal existence detection method, device, equipment, medium and product
By combining time-frequency domain segmentation processing and chi-square statistics detection, the problem of insufficient detection performance of existing covert communication signals is solved, achieving efficient detection of bursty and bandwidth-limited signals, and improving detection accuracy and adaptability.
Patent Information
- Application Number
- CN202511319668.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-16
- Publication Date
- 2025-10-24
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
Existing methods for detecting covert communication signals have poor performance under conditions of time-domain bursts and limited bandwidth, and rely on signal feature matching or energy detection which are easily affected by noise, making them unable to effectively detect unknown signals.
By employing joint time-frequency domain segmentation processing, a detection observation sequence is generated. The existence of covert communication signals is detected by calculating the chi-square statistic and comparing it with the detection threshold of the covert communication signal.
It improves the detection probability of bursty and bandwidth-limited covert communication signals under low signal-to-noise ratio conditions, enhances detection performance and accuracy, does not rely on prior information, and is applicable to unknown modulation methods or parameters.
Smart Images

Figure CN120834962A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of wireless communication, and in particular to a covert communication signal existence detection method, device, equipment, medium and product. BACKGROUND
[0002] In scenarios such as satellite secure communication, Internet of Things, electromagnetic space security, and the like, which require high covert communication, covert communication signal existence detection is a core link of the game between the offense and the defense. In the communication process, the covert party attempts to secretly transmit information to the receiving party through covert communication, and wants to avoid being detected by the detection party, while the detection party wants to detect the covert communication signals.
[0003] Traditional covert communication signal detection methods mainly rely on signal feature matching or energy detection. Among them, the feature matching method needs to pre-master the prior information such as the modulation mode and the spread spectrum code of the signal, and cannot cope with unknown signals; and the energy detection method compares the received signal energy with the noise energy threshold to judge the signal existence, but is easily affected by noise uncertainty, and has poor performance for the existence detection of covert communication signals with time domain burst and limited frequency band. SUMMARY
[0004] The present application provides a covert communication signal existence detection method, device, equipment, medium and product to solve the problem of poor performance of existing covert communication signal existence detection.
[0005] In a first aspect, the present application provides a covert communication signal existence detection method, comprising: generating a detection observation sequence corresponding to a detection observation quantity; the detection observation quantity is determined based on a covert communication signal and a detector noise; performing joint time-frequency domain segmentation processing based on the detection observation sequence to obtain chi-square statistics in each time-frequency domain segment; comparing the maximum chi-square statistics with a covert communication signal detection threshold value to obtain a covert communication signal existence detection result.
[0006] In one embodiment, the joint time-frequency domain segmentation processing based on the detection observation sequence to obtain chi-square statistics in each time-frequency domain segment comprises: performing time domain segmentation processing on the detection observation sequence to obtain first sub-observation sequences in each time domain segment; performing frequency domain segmentation processing on each first sub-observation sequence to obtain second sub-observation sequences in each time-frequency domain segment; summing up the second sub-observation sequences in each time-frequency domain segment to obtain chi-square statistics in each time-frequency domain segment.
[0007] In an embodiment, the frequency domain segmentation processing on each of the first sub-observation sequences is performed to obtain a second sub-observation sequence in each time-frequency domain segment, including: performing fast Fourier transform on each of the first sub-observation sequences to obtain a discrete frequency domain representation corresponding to each of the first sub-observation sequences; performing a modulus square operation on each of the discrete frequency domain representations to obtain a frequency energy distribution corresponding to each of the first sub-observation sequences; performing frequency domain segmentation processing on each of the frequency energy distributions to obtain a second sub-observation sequence in each time-frequency domain segment.
[0008] In an embodiment, the comparison between the maximum chi-square statistic and the covert communication signal detection threshold value is performed to obtain a covert communication signal existence detection result, including: if the maximum chi-square statistic is greater than the covert communication signal detection threshold value, it is determined that the covert communication signal existence detection result is that there is a covert communication signal; if the maximum chi-square statistic is less than the covert communication signal detection threshold value, it is determined that the covert communication signal existence detection result is that there is no covert communication signal.
[0009] In an embodiment, the covert communication signal detection threshold value is dynamically determined by the following method: obtaining observation samples in a signal-free period; performing covert communication signal existence detection based on the observation samples in the signal-free period to determine an expected false alarm probability and a variance of the noise of the intercept receiver during the detection process; based on the false alarm probability, determining a threshold dynamic adjustment factor; based on the threshold dynamic adjustment factor and the variance of the noise of the intercept receiver, dynamically determining a covert communication signal detection threshold value.
[0010] In an embodiment, the generation of the intercept observation sequence corresponding to the intercept observation quantity includes: obtaining an intercept observation quantity; the intercept observation quantity is obtained by superimposing a covert communication signal and noise of an intercept receiver; performing analog-to-digital conversion on the intercept observation quantity to obtain an intercept observation sequence.
[0011] In an embodiment, the consistency evaluation based on each of the initial answers is performed to obtain a target answer to the input question, including: determining the number of occurrences of the same answer in each of the initial answers; if the highest number of occurrences is greater than or equal to a preset number of occurrences threshold value, it is determined that the answer corresponding to the highest number of occurrences is the target answer to the input question.
[0012] In a second aspect, the present application further provides a covert communication signal existence detection device, comprising: a signal collection module configured to generate a detection observation sequence corresponding to detection observation quantities, wherein the detection observation quantities are determined based on the covert communication signal and the receiver noise; a time-frequency domain joint segmentation processing module configured to perform time-frequency domain joint segmentation processing based on the detection observation sequence to obtain chi-square statistics in each time-frequency domain segment; a covert communication signal existence detection module configured to compare the maximum chi-square statistics with a covert communication signal detection threshold to obtain a covert communication signal existence detection result.
[0013] In a third aspect, the present application provides an electronic device, which comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the covert communication signal existence detection method according to any one of the above aspects.
[0014] In a fourth aspect, the present application further provides a non-transitory computer readable storage medium, which stores a computer program executable by a processor to implement the steps of the covert communication signal existence detection method according to any one of the above aspects.
[0015] In a fifth aspect, the present application further provides a computer program product, which comprises a computer program, the computer program being stored in a non-transitory computer readable storage medium, and the computer program being executable by the processor to implement the steps of the covert communication signal existence detection method according to any one of the above aspects.
[0016] The covert communication signal existence detection method, device, equipment, medium and product provided by the present application generate a detection observation sequence corresponding to detection observation quantities, perform time-frequency domain joint segmentation processing on the detection observation quantities to obtain chi-square statistics in multiple time-frequency domain segments, and compare the maximum chi-square statistics with a covert communication signal detection threshold to obtain a detection result, thereby realizing chi-square detection in a time-frequency domain joint processing manner, which has strong anti-noise capability, can effectively improve the existence detection probability of a burst and band-limited covert communication signal under a low signal-to-noise ratio, does not need to rely on prior information to detect the existence of a covert communication signal, can be applied to existence detection of a covert communication signal with unknown modulation mode or parameters, and improves the detection performance and detection accuracy of the existence of a covert communication signal as a whole. BRIEF DESCRIPTION OF DRAWINGS
[0017] In order to more clearly illustrate the technical solutions of the present application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or prior art description. Obviously, the drawings described below are some embodiments of the present application, and other drawings can be obtained by those skilled in the art without creative labor.
[0018] Figure 1 Figure is one of the flow diagrams of the hidden communication signal existence detection method provided by the present application.
[0019] Figure 2 Figure is a schematic diagram of the hidden communication signal existence detection model provided by the present application.
[0020] Figure 3 Figure is another flow diagram of the hidden communication signal existence detection method provided by the present application.
[0021] Figure 4 Figure is one of the structural schematic diagrams of the hidden communication signal existence detection device provided by the present application.
[0022] Figure 5 Figure is another structural schematic diagram of the hidden communication signal existence detection device provided by the present application.
[0023] Figure 6 Figure is a structural schematic diagram of the electronic device provided by the present application. DETAILED DESCRIPTION
[0024] In order to make the objects, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be described clearly and completely below in combination with the drawings in the present application. Obviously, the described embodiments are some embodiments of the present application, not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative labor are within the protection scope of the present application.
[0025] The terms "first", "second" and the like in the present application are used to distinguish similar objects, not to describe a particular order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described here.
[0026] The following will describe the hidden communication signal existence detection method, device, equipment, medium and product provided by the present application in combination with Figures 1-6
[0027] In combination with Figure 1 , Figure 1 Figure is one of the flow diagrams of the hidden communication signal existence detection method provided by the present application.
[0028] like Figure 1 As shown, the method for detecting the presence of a covert communication signal includes the following steps: Step 101: Generate a reconnaissance observation sequence corresponding to the reconnaissance observation quantity; Specifically, in the field of wireless communications, there is a complex process involving covert communication, which aims to complete the transmission of information without being detected through specific technical means. This process can be combined with Figure 2 To understand, Figure 2 It is a schematic diagram of the covert communication signal existence detection model provided by the present invention.
[0029] In the covert communication process, there are three main parties: the covert party Alice, the receiver Bob, and the interceptor Willie. Alice is the sender of the covert signal, Bob is the receiver of the information sent by Alice, and Willie is the interceptor attempting to detect the existence of covert communication. Alice and Bob are in a cooperative relationship, jointly completing the covert transmission of communication signals. Willie, the interceptor, is in an adversarial relationship with Alice and Bob, aiming to detect and prevent covert communication.
[0030] Before the entire communication process begins, the hidden party Alice and the receiving party Bob will first share prior information Secret. This prior information Secret includes information such as the communication time slot, covert channel frequency and bandwidth used during the covert communication between the hidden party Alice and the receiving party Bob. Through this shared information, the receiving party Bob can effectively obtain the information transmitted by the hidden party Alice.
[0031] After the communication process begins, the hidden party Alice and the receiver Bob enter a In the time window, use the burst time slot and bandwidth is B [A] The covert signal is transmitted through a band-limited covert channel and the detection of the covert signal by the intercepting party Willie is avoided. The covert party Alice first converts the original time domain signal Converted into frequency domain signal through Fourier Transform (FT) , then the frequency domain signal Filtered by the transmitting filter to generate a covert communication signal The covert communication signal generated by the hidden party Alice , the signal passes through an independent receiving channel and is superimposed on the receiver noise , and then pass through the receiving filter to generate the received observation , and the signal is superimposed on the receiver noise after passing through the independent detection channel , and then pass through the detection filter to generate the detection observation .
[0032] The receiving party Bob needs to complete demodulation and decoding based on the prior information Secret, such as the communication time slot, covert channel frequency and bandwidth, shared with the concealed party Alice in the early stage, to obtain the information transmitted by the concealed party Alice.
[0033] However, the receiver Willie does not have the above-mentioned prior information Secret, and it mainly confirms the existence of the covert communication signal by processing the intercepted observation quantity. That is, the receiver Willie is equipped with a covert communication signal existence detection device, whose input is the time domain length , bandwidth is B [W] The detected observations , the output is a binary judgment or .in, Represents the signal generated by the hidden party Alice does not exist, It is pure detection noise; Represents the signal generated by the hidden party Alice exist, is the noise superposition signal. Without loss of generality, assume that the covert communication signal , receiver noise , receiver noise All of them satisfy independent zero-mean complex Gaussian distribution within the band, and their variances are 、 、 .
[0034] This application is mainly aimed at detecting covert communication behavior by the intercepting party Willie. Therefore, the covert communication signal existence detection method provided in the embodiment of the present invention is implemented based on the covert communication signal existence detection device. The embodiment of the present invention uses the covert communication signal existence detection device as the execution subject to describe the covert communication signal existence detection method.
[0035] Received observations after filtering , perform analog-to-digital conversion on the detected observation quantity, convert it from analog signal to digital signal, and generate the detected observation sequence y[n] , providing basic data for subsequent detection work.
[0036] Step 102, performing time-frequency domain joint segmentation processing based on the interception observation sequence to obtain chi-square statistics in each time-frequency domain segment; Step 103, comparing the maximum chi-square statistics with a hidden communication signal detection threshold to obtain a hidden communication signal existence detection result.
[0037] Specifically, in the hidden communication process, there may be time-domain burst and frequency band limitation. The time-domain burst is characterized by sudden appearance and rapid disappearance in a short time. The signal may be transmitted in the form of a very short pulse and only lasts for a very short time. Frequency band limitation means that the signal exists only in a specific frequency range. Limiting the signal to a narrow frequency band for transmission can reduce the probability of being discovered. In view of the characteristics of time-domain burst and frequency band limitation of hidden communication, time-frequency domain joint analysis can provide information of the signal in both time and frequency dimensions. For the time-domain burst and frequency band limitation hidden communication signal, time-frequency domain joint analysis can accurately locate the burst time of the signal in the time domain and the specific frequency band range in the frequency domain, so as to more comprehensively capture the characteristics of the signal.
[0038] Therefore, the interception observation sequence is divided into a plurality of time-frequency domain segments. Segmentation processing is performed in both time and frequency dimensions. First, in the time dimension, the signal is divided into a plurality of time domain segments according to the duration and variation characteristics of the signal. Then, in the frequency dimension, the signal is further divided into a plurality of frequency domain segments according to the frequency distribution of the signal. In this way, the entire interception observation sequence is divided into a plurality of small time-frequency domain segments, each of which contains signal information in a specific time and frequency range.
[0039] For each time-frequency domain segment, the chi-square statistics therein are calculated. The chi-square statistics is a statistical index used to measure the difference between observed data and theoretical distribution in chi-square detection. In hidden communication signal detection, it is assumed that the normal signal has a certain distribution rule in the time-frequency domain segment. By calculating the chi-square statistics of the actual observation data, it can be judged whether the signal in the segment conforms to the distribution characteristics of the normal signal. If the value of the chi-square statistics is large, it means that the signal in the time-frequency domain segment may be abnormal, which may be a hidden communication signal.
[0040] After calculating the chi-square statistics in each time-frequency domain segment, the maximum value, i.e. the maximum chi-square statistics, is obtained from these chi-square statistics. It reflects the abnormality degree of the time-frequency domain segment that is most likely to exist hidden communication signal in the entire interception observation sequence. The maximum value can be obtained by the bubble method. Bubble sort is a simple sorting algorithm that gradually "bubbles" the maximum (or minimum) element to the end of the array by comparing and exchanging the positions of adjacent elements multiple times. In addition to the bubble method, direct traversal method, built-in function to directly obtain the maximum value, etc. can also be used.
[0041] Set a covert communication signal detection threshold , which is the key criterion for determining whether there is a covert communication signal. Compare the maximum chi-square statistic with the covert communication signal detection threshold to obtain the covert communication signal existence detection result, that is, the output or , Indicates that there is no covert communication signal. Indicates the presence of a covert communication signal.
[0042] Through this simple and effective comparison method, the detection result of the existence of the covert communication signal can be obtained quickly and accurately.
[0043] The present invention provides a method for detecting the presence of a covert communication signal. The method generates a detection observation sequence corresponding to the detection observation quantity, performs joint segmentation processing in the time-frequency domain on the detection observation quantity to obtain chi-square statistics in multiple time-frequency domain segments, and compares the maximum chi-square statistic with the covert communication signal detection threshold value to obtain a detection result, thereby realizing a chi-square detection method for joint processing in the time-frequency domain. This method has strong noise resistance and can effectively improve the probability of detecting the presence of bursty and band-limited covert communication signals under low signal-to-noise ratio. At the same time, it does not need to rely on prior information to detect the presence of covert communication signals. It can be applied to the detection of the presence of covert communication signals with unknown modulation modes or parameters, thereby improving the detection performance and accuracy of the presence of covert communication signals as a whole.
[0044] The following is a detailed description of the process of detecting the presence of covert communication signals. Figure 3 , Figure 3 This is the second flow chart of the method for detecting the existence of a covert communication signal provided by the present invention.
[0045] In some embodiments, based on step 101, generating a reconnaissance observation sequence corresponding to the reconnaissance observation quantity includes: Acquire a detection observation amount; the detection observation amount is obtained by superimposing the covert communication signal and the detection receiver noise; Performing analog-to-digital conversion on the detected observation quantity to obtain a detected observation sequence.
[0046] Specifically, when the receiver starts working, it will collect signals within the communication frequency band it covers. In this process, the signal received by the receiver is actually a covert communication signal. and receiver noise The result after superposition .
[0047] Received observations It is an analog signal. Although the analog signal can continuously represent the amplitude and change of the signal, it is not conducive to computer processing and subsequent digital signal analysis. Therefore, it is necessary to perform analog-to-digital conversion (A / D conversion) on the detected observation quantity. After sampling by the analog-to-digital converter (ADC), the detection observation sequence is generated y[n] .
[0048] ADC sampling mainly includes three core steps: sampling, quantization and encoding. First, the sampling rate is , for the detected observation The sampling frequency must be greater than or equal to twice the signal's highest frequency to ensure accurate subsequent recovery of the original signal. The sampled signal amplitude is then divided into specific quantization levels, converting the continuous amplitude of the analog signal into discrete digital amplitude values. Since analog signal amplitudes vary continuously, while digital signals can only take on a finite number of discrete values, the amplitude values at the sampling points must be mapped to these discrete quantization levels. Finally, the quantized signal amplitude values are represented using binary codes. After encoding, the analog signal is fully converted into a digital signal, which is then arranged in chronological order to form a detection and observation sequence.
[0049] Generated reconnaissance observation sequence y[n] , and its time domain length is , the frequency domain length is .in, M= B [A] / f s , M × J= B [W] / f s , is the sampling rate of the ADC, B [A] is the bandwidth of the covert channel, B [W] is the bandwidth of the entire communication channel.
[0050] The embodiments of the present invention obtain a detection observation quantity formed by the superposition of a covert communication signal and the detection machine noise, and perform analog-to-digital conversion on it to generate a detection observation sequence. This achieves the conversion of analog signals that are difficult to directly process in a complex communication environment into a digital sequence that is convenient for subsequent analysis, and provides standardized and quantifiable basic data for subsequent detection of the existence of covert communication signals.
[0051] In some embodiments, based on step 102, the time-frequency domain joint segmentation processing based on the intercepted observation sequence is performed to obtain the chi-square statistics in each time-frequency domain segment, including: performing time domain segmentation processing on the intercepted observation sequence to obtain a first sub-observation sequence in each time domain segment; performing frequency domain segmentation processing on each first sub-observation sequence to obtain a second sub-observation sequence in each time-frequency domain segment; summing the second sub-observation sequences in each time-frequency domain segment to obtain the chi-square statistics in each time-frequency domain segment.
[0052] Specifically, when the intercepted observation sequence is obtained, the sequence contains signal information in a period of time, and in order to analyze the characteristics of the signal in different time periods in more detail, it is necessary to perform time domain segmentation processing. Since the time domain length is , after time domain segmentation processing, each segment is N long, and there are I segments, each of which contains signal information in a specific time period, constituting a first sub-observation sequence. For example, Figure 3 , , ,which are the first sub-observation sequences corresponding to the I time domain segments, respectively.
[0053] After obtaining the first sub-observation sequence in each time domain segment, it is first converted into frequency domain energy. In order to further analyze the characteristics of the signal in different frequency ranges, it is necessary to perform frequency domain segmentation processing on the frequency energy distribution of each first sub-observation sequence. Since the frequency domain length is , after frequency domain segmentation processing, each segment is M long, and there are J segments, each of which contains signal information in a specific frequency range. Each frequency domain segment is combined with the corresponding time domain segment to form a time-frequency domain segment, and there are segments, and the signal data in each time-frequency domain segment is a second sub-observation sequence. For example, Figure 3 , , which are the second sub-observation sequences corresponding to the J frequency domain segments or time-frequency domain segments in the first time domain segment, respectively; , , which are the second sub-observation sequences corresponding to the J frequency domain segments or time-frequency domain segments in the i+1 time domain segment, respectively; , , which are the second sub-observation sequences corresponding to the J frequency domain segments or time-frequency domain segments in the I time domain segment, respectively.
[0054] After obtaining the second sub-observation sequence of each time-frequency domain segment, the chi-square statistics in each time-frequency domain segment need to be calculated, and the chi-square statistics in each time-frequency domain segment can be obtained by summing all the data in the second sub-observation sequence in each time-frequency domain segment, and there are statistical calculation results in total. As Figure 3 , , , ,..., ,..., ,..., ,..., ,..., ,..., ,...,
[0055] The chi-square statistics of each time-frequency domain segment represent the abnormality degree of the signal in the segment. If the chi-square statistics of a certain time-frequency domain segment is large, it means that the signal in the segment is significantly different from the normal signal distribution, and there may be a hidden communication signal; on the contrary, if the chi-square statistics is small, it means that the signal in the segment is more consistent with the distribution characteristics of the normal signal, and it is less likely to exist a hidden communication signal. Further, whether there is a hidden communication signal can be judged according to the joint chi-square detection in time-frequency domain.
[0056] In the above process, the frequency domain segmentation processing of each first sub-observation sequence to obtain the second sub-observation sequence in each time-frequency domain segment specifically includes: performing fast Fourier transform on each first sub-observation sequence to obtain a discrete frequency domain representation corresponding to each first sub-observation sequence; performing modulus square operation on each discrete frequency domain representation to obtain a frequency domain energy distribution corresponding to each first sub-observation sequence; performing frequency domain segmentation processing on each frequency domain energy distribution to obtain the second sub-observation sequence in each time-frequency domain segment.
[0057] Specifically, each first sub-observation sequence is essentially a time domain signal, which contains information about the change of the signal over time in a certain time period. By applying fast Fourier transform (FFT) to these first sub-observation sequences, the signal is converted from time domain to frequency domain. The base-2 or base-4 FFT algorithm can be used, and the number of operation points is N. In the frequency domain, the signal is no longer represented as a function of time, but as a function of frequency.
[0058] After the fast Fourier transform, each first sub-observation sequence is converted into a corresponding discrete frequency domain representation. This discrete frequency domain representation is a series of complex numbers, each of which represents the amplitude and phase information of the signal at a specific frequency component, which can clearly reflect which frequency components the signal contains.
[0059] After obtaining the discrete frequency domain representation of each first sub-observation sequence, in order to further analyze the energy distribution of the signal in the frequency domain, the discrete frequency domain representation is subjected to modulus square operation. The complex number in the discrete frequency domain representation contains amplitude and phase information, and the modulus square operation is to square the amplitude of the complex number.
[0060] In the frequency domain, the energy of the signal is proportional to the square of the amplitude. Through the modulus square operation, the amplitude information in the discrete frequency domain representation can be converted into energy information, thereby obtaining the frequency energy distribution corresponding to each first sub-observation sequence. The frequency energy distribution directly shows the distribution of signal energy at different frequencies, and can clearly reflect which frequency components contain more energy and which frequency components have less energy.
[0061] As Figure 3 in the ,..., ,..., , the frequency energy distribution corresponding to each of the I time domain segments is obtained.
[0062] After obtaining the frequency energy distribution of each first sub-observation sequence, in order to more meticulously analyze the characteristics of the signal in different frequency ranges and time intervals, on the basis of the time domain segmentation processing, the frequency domain segmentation processing is performed on the frequency energy distribution, to obtain the second sub-observation sequence in each time-frequency domain segment.
[0063] The embodiments of the present application realize fine analysis of the signal in the time and frequency dimensions by performing time-frequency domain joint segmentation processing on the intercepted observation sequence to obtain the chi-square statistics in each time-frequency domain segment. The time domain segmentation processing divides the sequence according to time, retains the characteristics of the signal in different time periods to form the first sub-observation sequence; the frequency domain segmentation processing further analyzes the frequency distribution of the signal in each time period to obtain the second sub-observation sequence containing time-frequency characteristics; summing the second sub-observation sequence obtains the chi-square statistics, which can effectively measure the difference between the signal and the theoretical distribution in each time-frequency segment. By using the time-frequency domain joint chi-square detection method, the existence detection probability of the burst and band-limited hidden signal under low signal-to-noise ratio can be accurately improved, and the accuracy and reliability of the existence detection of the hidden communication signal are significantly improved.
[0064] In some embodiments, based on step 103, the maximum chi-square statistic is compared with the steganographic signal detection threshold to obtain a steganographic signal existence detection result, including: If the maximum chi-square statistic is greater than the steganographic signal detection threshold, it is determined that the steganographic signal existence detection result is that there is a steganographic signal. If the maximum chi-square statistic is less than the steganographic signal detection threshold, it is determined that the steganographic signal existence detection result is that there is no steganographic signal.
[0065] Specifically, the maximum chi-square statistic is compared with the steganographic signal detection threshold in numerical size.
[0066] When the maximum chi-square statistic is less than the steganographic signal detection threshold , it indicates that the difference between the signal in the time-frequency domain segment where the maximum chi-square statistic is located and the normal signal distribution does not exceed the pre-set acceptable range, and it is considered that the steganographic signal generated by the steganographic party Alice does not exist, and the output .
[0067] When the maximum chi-square statistic is greater than the steganographic signal detection threshold , it indicates that the difference between the signal in the time-frequency domain segment where the maximum chi-square statistic is located and the normal signal distribution exceeds the pre-set acceptable range, and it is considered that the steganographic signal generated by the steganographic party Alice exists, and the output .
[0068] It should be noted that the steganographic signal detection threshold is calculated based on the time domain parameters, frequency domain parameters, chi-square statistic statistical characteristics and the like of the no-signal period, and is dynamically adjusted according to the detection requirements. The higher the steganographic signal detection threshold is set, the smaller the probability of false alarm is, and the greater the probability of missing alarm is. The lower the steganographic signal detection threshold is set, the greater the probability of false alarm is, and the smaller the probability of missing alarm is. False alarm refers to that the steganographic party Alice does not send a steganographic signal during communication, but the system detects that there is a steganographic signal. Missing alarm refers to that the steganographic party Alice does indeed send a steganographic signal during communication, but the system detects that there is no steganographic signal. Therefore, the steganographic signal detection threshold needs to be dynamically set according to the input time domain parameters, frequency domain parameters, chi-square statistic statistical characteristics and the like, and according to the detection requirements.
[0069] The embodiment of the application adopts the chi-square detection method of joint processing of time-frequency domain, realizes simple and accurate detection of the existence of the steganographic signal, and improves the detection performance and accuracy of the existence of the steganographic signal as a whole.
[0070] In the above process, the covert communication signal detection threshold is dynamically determined by: Obtain observation samples during the no-signal period; Performing a covert communication signal presence detection based on observation samples during the signal-free period, and determining an expected false alarm probability and a noise variance of the receiver during the detection process; Determining a threshold dynamic adjustment factor based on the false alarm probability; Based on the threshold dynamic adjustment factor and the variance of the receiver noise, a covert communication signal detection threshold value is dynamically determined.
[0071] Specifically, in real-world communication environments, a variety of complex signals and noise exist. To accurately determine the covert communication signal detection threshold, it is first necessary to obtain observation samples from signal-free periods. Signal-free periods refer to periods during the communication process when no covert communication signals are present. These periods can include idle periods in the communication system, specific silent periods, or periods of time when the target signal is absent as determined by specific signal monitoring methods.
[0072] When acquiring observation samples during periods of signal silence, the signal acquisition module continuously monitors and collects data from the communication channel. During these periods of signal silence, the module records the signal data in the channel. This data primarily includes receiver noise and any environmental interference. These observation samples form the basis for subsequent analysis and calculations, reflecting the true state of the channel in the absence of covert communication signals.
[0073] After obtaining observation samples from the signal-free period, the presence of covert communication signals is detected using these observation samples. During this detection process, the input observation samples' time-domain parameters, frequency-domain parameters, and chi-squared statistical characteristics are comprehensively considered to determine the expected false alarm probability and the variance of the receiver noise during the detection process.
[0074] The false alarm probability is the probability that the detection system mistakenly determines the presence of a covert communication signal when none actually exists. The expected false alarm probability is determined by performing simulated detection and statistical analysis on observation samples during periods of no signal.
[0075] The variance of receiver noise is an important statistic for measuring noise fluctuations. It is correlated with the input time and frequency domain parameters. A larger variance indicates more severe noise fluctuations, and thus greater interference with signal detection. The variance of receiver noise is calculated by statistically calculating observation samples during periods of no signal. This variance reflects the characteristics of the noise and provides an important reference for determining the detection threshold. The variance of receiver noise is also relatively stable.
[0076] When the false alarm probability is high, it indicates that the detection threshold of the hidden communication signal is set too low, and normal noise signals are easily misjudged as hidden communication signals; when the false alarm probability is low, it indicates that the detection threshold of the hidden communication signal is set too high, and some actually existing hidden communication signals may be missed. In order to dynamically adjust the detection threshold of the hidden communication signal according to the expected false alarm probability, a threshold dynamic adjustment factor is introduced. The threshold dynamic adjustment factor is a coefficient related to the false alarm probability, which can dynamically adjust the detection threshold of the hidden communication signal according to the change of the expected false alarm probability.
[0077] Further, based on the threshold dynamic adjustment factor and the variance of the noise of the intercept receiver, the detection threshold of the hidden communication signal is dynamically determined, and the specific calculation formula is as follows:
[0078] Among them, The hidden communication signal detection threshold is represented by TH. The threshold dynamic adjustment factor is represented by K. The variance of the noise of the intercept receiver is represented by σ.
[0079] The embodiment of the present application dynamically calculates the detection threshold of the hidden communication signal according to the observation samples of the signal-free period, and can highly adapt to the time-varying electromagnetic environment. In a complex and variable electromagnetic environment, the false alarm probability can be effectively reduced, the misjudgment caused by environmental changes can be reduced, and at the same time, the high detection rate of the hidden communication signal can be ensured, greatly improving the accuracy, reliability and adaptability of the hidden communication signal detection.
[0080] For the specific description process of the above-mentioned hidden communication signal existence detection method, it needs to be further explained that the above-mentioned processing process only involves common calculations such as segmentation, summation, FFT, bubble, etc., and can be accelerated by base2 / base4 FFT IP core, which is very beneficial to the implementation of field programmable gate array (FPGA) and other embedded platforms, and the implementation complexity is low. Therefore, the hidden communication signal existence detection method provided by the embodiment of the present application can be realized by low complexity hardware, and is suitable for real-time processing of satellite communication load or user terminal equipment.
[0081] The structure of the hidden communication signal existence detection device provided by the present application will be described below. The hidden communication signal existence detection device described below can be referred to in conjunction with the hidden communication signal existence detection method described above.
[0082] Referring to Figures 4-5 , Figure 4 is one of the structure schematic diagrams of the hidden communication signal existence detection device provided by the present application, Figure 5 is the second structure schematic diagram of the hidden communication signal existence detection device provided by the present application.
[0083] As Figure 4 shown, the covert communication signal existence detection device comprises: The signal acquisition module 410 is configured to generate a signal observation sequence corresponding to the intercept observation quantity, wherein the intercept observation quantity is determined based on the covert communication signal and the intercept receiver noise. The time-frequency domain joint segmentation processing module 420 is configured to perform time-frequency domain joint segmentation processing based on the signal observation sequence to obtain chi-square statistics in each time-frequency domain segment. The covert communication signal existence detection module 430 is configured to compare the maximum chi-square statistics with a covert communication signal detection threshold value to obtain a covert communication signal existence detection result.
[0084] The covert communication signal existence detection device provided by the application generates a signal observation sequence corresponding to the intercept observation quantity, performs time-frequency domain joint segmentation processing on the intercept observation quantity to obtain chi-square statistics in multiple time-frequency domain segments, and compares the maximum chi-square statistics with a covert communication signal detection threshold value to obtain a detection result, thereby realizing chi-square detection in a time-frequency domain joint processing manner, which has strong noise resistance, can effectively improve the existence detection probability of a burst and band-limited covert communication signal under a low signal-to-noise ratio, does not need to rely on prior information to detect the existence of a covert communication signal, can be applied to existence detection of a covert communication signal with unknown modulation mode or parameters, and improves the detection performance and detection accuracy of the existence of a covert communication signal.
[0085] As Figure 5 shown, the covert communication signal existence detection device specifically comprises a signal acquisition module ①, a time domain processing module ②, a time-frequency domain conversion module ③, a frequency domain processing module ④, a chi-square statistics calculation module ⑤, a criterion and threshold setting module ⑥, and a threshold comparison module ⑦, wherein the time-frequency domain joint segmentation processing module 420 specifically comprises the time domain processing module ②, the time-frequency domain conversion module ③, the frequency domain processing module ④, and the chi-square statistics calculation module ⑤, and the covert communication signal existence detection module 430 specifically comprises the criterion and threshold setting module ⑥ and the threshold comparison module ⑦.
[0086] Further, the signal acquisition module is specifically configured to: acquire the intercept observation quantity, wherein the intercept observation quantity is obtained by superimposing the covert communication signal and the intercept receiver noise; perform analog-digital conversion on the intercept observation quantity to obtain a signal observation sequence.
[0087] Further, the time domain processing module is specifically configured to: perform time domain segmentation processing on the signal observation sequence to obtain a first sub-observation sequence in each time domain segment.
[0088] Further, the time-frequency domain conversion module is specifically used for: performing fast Fourier transform on each of the first sub-observation sequences to obtain a discrete frequency domain representation corresponding to each of the first sub-observation sequences; performing a modulus square operation on each of the discrete frequency domain representations to obtain a frequency energy distribution corresponding to each of the first sub-observation sequences.
[0089] Further, the frequency domain processing module is specifically used for: performing frequency domain segmentation processing on each of the frequency energy distributions to obtain a second sub-observation sequence in each time-frequency domain segment.
[0090] Further, the chi-square statistic calculation module is specifically used for: performing summation on the second sub-observation sequence in each time-frequency domain segment to obtain a chi-square statistic in each time-frequency domain segment.
[0091] Further, the threshold comparison module is specifically used for: if the maximum chi-square statistic is greater than a hidden communication signal detection threshold value, determining that a hidden communication signal existence detection result is that a hidden communication signal exists; if the maximum chi-square statistic is less than the hidden communication signal detection threshold value, determining that the hidden communication signal existence detection result is that a hidden communication signal does not exist.
[0092] Further, the threshold setting module is specifically used for: obtaining an observation sample in a signal-free period; performing hidden communication signal existence detection based on the observation sample in the signal-free period to determine an expected false alarm probability and a variance of a receiver noise in a detection process; based on the false alarm probability, determining a threshold dynamic adjustment factor; based on the threshold dynamic adjustment factor and the variance of the receiver noise, dynamically determining a hidden communication signal detection threshold value.
[0093] In setting the hidden communication signal detection threshold value, the signal acquisition module determines the observation sample in the signal-free period, and detects the observation sample data, the time domain processing module reflects the input time domain parameters in the detection process, the frequency domain processing module reflects the input frequency domain parameters, the chi-square statistic calculation module reflects the input chi-square statistic statistical characteristics, and the joint calculation of the decision threshold, i.e., the hidden communication signal detection threshold value, is performed according to the input time domain parameters, frequency domain parameters, chi-square statistic statistical characteristics, etc.
[0094] It should be noted that the hidden communication signal existence detection device provided by the present application can execute the hidden communication signal existence detection method described in any of the above embodiments when it is actually operated, and the present embodiment will not be described here.
[0095] Figure 6 Schematic diagram of the structure of the electronic device provided by the present invention, such as Figure 6 As shown, the electronic device may include: a processor 610, a communications interface 620, a memory 630, and a communication bus 640, wherein the processor 610, the communications interface 620, and the memory 630 communicate with each other via the communication bus 640. The processor 610 may call logic instructions in the memory 630 to execute a method for detecting the presence of a covert communication signal. The method includes: generating a reconnaissance observation sequence corresponding to a reconnaissance observation quantity; the reconnaissance observation quantity is determined based on the covert communication signal and the reconnaissance machine noise; performing time-frequency domain joint segmentation processing based on the reconnaissance observation sequence to obtain a chi-square statistic within each time-frequency domain segment; and comparing the maximum chi-square statistic with a covert communication signal detection threshold to obtain a covert communication signal presence detection result.
[0096] Furthermore, the logic instructions in the aforementioned memory 630 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the portion that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as a USB flash drive, a mobile hard drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.
[0097] On the other hand, the present invention also provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium, and the computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the covert communication signal existence detection method provided by the above-mentioned embodiments, the method including: generating a detection observation sequence corresponding to the detection observation quantity; the detection observation quantity is determined based on the covert communication signal and the receiver noise; performing joint time-frequency domain segmentation processing based on the detection observation sequence to obtain the chi-square statistic in each time-frequency domain segment; and obtaining the covert communication signal existence detection result based on the maximum chi-square statistic and the covert communication signal detection threshold value.
[0098] In yet another aspect, the present application also provides a non-transitory computer readable storage medium having stored thereon a computer program, which, when executed by a processor, implements a covert communication signal existence detection method provided by any of the above embodiments, the method comprising: generating a sequence of intercept observation corresponding to intercept observation; the intercept observation is determined based on the covert communication signal and the interceptor noise; performing joint time-frequency domain segmentation processing based on the sequence of intercept observation to obtain chi-square statistics in each time-frequency domain segment; comparing the maximum chi-square statistics with a covert communication signal detection threshold to obtain a covert communication signal existence detection result.
[0099] The system embodiments described above are merely illustrative, wherein the units described as separate components can or can not be physically separate, and the components displayed as units can or can not be physical units. Part or all of the modules can be selected according to actual needs to achieve the purpose of the present embodiment. Those skilled in the art can understand and implement without creative labor.
[0100] From the above description of the embodiments, those skilled in the art can clearly understand that the embodiments can be realized by means of software plus necessary universal hardware platforms, and of course can also be realized by hardware. Based on such understanding, the above technical solutions, essentially or in other words, the part that contributes to the prior art, can be embodied in the form of a software product, which can be stored in a computer readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods described in each embodiment or some parts of the embodiments.
[0101] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, and not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement to some technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. A method of covert communication signal presence detection, characterized by, The covert communication signal existence detection method comprises: generate a detection observation sequence corresponding to a detection observation quantity; the detection observation quantity is determined based on a covert communication signal and a detector noise; perform time-frequency domain joint segmentation processing based on the detection observation sequence to obtain chi-square statistics in each time-frequency domain segment; compare the maximum chi-square statistics with a covert communication signal detection threshold value to obtain a covert communication signal existence detection result.
2. The steganographic signal presence detection method of claim 1, wherein, The time-frequency domain joint segmentation processing based on the detection observation sequence to obtain chi-square statistics in each time-frequency domain segment comprises: perform time domain segmentation processing on the detection observation sequence to obtain first sub-observation sequences in each time domain segment; perform frequency domain segmentation processing on each first sub-observation sequence to obtain second sub-observation sequences in each time-frequency domain segment; sum the second sub-observation sequences in each time-frequency domain segment to obtain chi-square statistics in each time-frequency domain segment.
3. The steganographic signal presence detection method of claim 2, wherein, The frequency domain segmentation processing on each first sub-observation sequence to obtain second sub-observation sequences in each time-frequency domain segment comprises: perform fast Fourier transform on each first sub-observation sequence to obtain discrete frequency domain representations corresponding to the first sub-observation sequences; perform modulus square operation on each discrete frequency domain representation to obtain frequency energy distributions corresponding to the first sub-observation sequences; perform frequency domain segmentation processing on each frequency energy distribution to obtain second sub-observation sequences in each time-frequency domain segment.
4. The steganographic signal presence detection method of claim 1, wherein, The comparison of the maximum chi-square statistics with a covert communication signal detection threshold value to obtain a covert communication signal existence detection result comprises: if the maximum chi-square statistics is greater than the covert communication signal detection threshold value, determine that the covert communication signal existence detection result is that there is a covert communication signal; if the maximum chi-square statistics is less than the covert communication signal detection threshold value, determine that the covert communication signal existence detection result is that there is no covert communication signal.
5. The steganographic signal presence detection method of claim 1, wherein, The covert communication signal detection threshold value is dynamically determined by the following method: obtain observation samples in a signal-free period; perform covert communication signal existence detection based on the observation samples in the signal-free period to determine an expected false alarm probability and a variance of the detector noise in the detection process; determine a threshold dynamic adjustment factor based on the false alarm probability; dynamically determine a covert communication signal detection threshold value based on the threshold dynamic adjustment factor and the variance of the detector noise.
6. The steganographic signal presence detection method according to any of claims 1-5, characterized by, The generation of a detection observation sequence corresponding to a detection observation quantity comprises: obtain a detection observation quantity; the detection observation quantity is obtained by superimposing a covert communication signal and a detector noise; perform analog-digital conversion on the detection observation quantity to obtain a detection observation sequence.
7. A covert communication signal presence detection apparatus characterized by, It comprises: a signal acquisition module for generating a detection observation sequence corresponding to a detection observation quantity; the detection observation quantity is determined based on a covert communication signal and a detector noise; a time-frequency domain joint segmentation processing module for performing time-frequency domain joint segmentation processing based on the detection observation sequence to obtain chi-square statistics in each time-frequency domain segment; a time-frequency domain joint segmentation processing module for performing time-frequency domain joint segmentation processing based on the detection observation sequence to obtain chi-square statistics in each time-frequency domain segment; The hidden communication signal existence detection module is configured to compare the maximum chi-square statistic with a hidden communication signal detection threshold to obtain a hidden communication signal existence detection result.
8. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein, The processor implements the steps of the hidden communication signal existence detection method according to any one of claims 1 to 6 when executing the computer program. 9.A non-transitory computer-readable storage medium having stored thereon a computer program, wherein, The computer program, when executed by the processor, implements the steps of the hidden communication signal existence detection method according to any one of claims 1 to 6.
10. A computer program product comprising a computer program, characterized in that, The computer program, when executed by the processor, implements the steps of the hidden communication signal existence detection method according to any one of claims 1 to 6. The computer program, when executed by the processor, implements the steps of the hidden communication signal existence detection method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Joint spectrum detection method based on energy-cyclostationary characteristic
CN101834630A
Cooperative spectrum sensing method of low complexity
CN101951274A
Mobile covert communication system and method based on mobility and noise uncertainty
CN119182489A
Link adaptive communication method
CN119211955A
Covert communication method based on STAR-RIS and full duplex cognitive interference
CN120390235A