Neural network model physical layer secrecy transmission method for 6G network edge unmanned aerial vehicle
By constructing a security model accuracy index and an alternating optimization algorithm, optimizing the model size and bandwidth allocation, the wireless channel security problem under dynamic channel conditions in 6G networks is solved, achieving high identification accuracy and secure transmission, and improving resource utilization efficiency.
Patent Information
- Application Number
- CN202511068620.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-31
- Publication Date
- 2025-10-28
AI Technical Summary
Existing secure transmission methods have failed to effectively address the physical layer security issues of wireless channels in 6G networks, especially under dynamic channel conditions, and have failed to balance the recognition accuracy of artificial intelligence models with transmission security.
By constructing a Security Model Accuracy (SMA) index and combining it with an alternating optimization algorithm, the model size and bandwidth allocation are optimized. A physical layer security scheme is adopted to jointly optimize model accuracy and transmission security. An alternating optimization algorithm is used to jointly select the model size and allocate bandwidth, including selecting the minimum model size that maximizes SMA with fixed bandwidth and optimizing bandwidth allocation with fixed model. The problem is transformed into a solvable convex problem using convex approximation techniques.
It achieves high identification accuracy and secure transmission under dynamic channel conditions, overcomes the limitations of traditional methods, and provides efficient resource utilization and security assurance.
Smart Images

Figure CN120857104A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of wireless communication, specifically to a secure transmission method for physical layer neural network models of 6G network edge unmanned aerial vehicles (UAVs), which is particularly suitable for resource-constrained artificial intelligence of things (AIoT) systems. Background Art
[0002] The advent of 6G networks has enabled ultra-high-speed connectivity and ubiquitous intelligence, driving the rapid development of edge-assisted IoT and AI applications. Semantic communication, by transmitting the meaning of data rather than raw bitstreams, such as pre-trained AI models, has become a crucial technology for resource-constrained edge devices (like drones). However, in such systems, model transmission faces serious eavesdropping security threats, potentially leading to the leakage of sensitive AI model parameters.
[0003] Existing secure transmission methods primarily rely on encryption technologies (such as AES and RSA) or authentication protocols. While effective, these methods fail to address the inherent physical layer security issues of wireless channels, especially under dynamic channel conditions. Furthermore, traditional physical layer security methods focus on general data transmission, neglecting the trade-off between model size and recognition accuracy in artificial intelligence models. Recent research on semantic communication has introduced metrics such as model transmission interruption probability, but has overlooked security measures against eavesdroppers. Therefore, a method is urgently needed to jointly optimize model accuracy and transmission security in 6G edge environments. Summary of the Invention
[0004] To overcome the limitations of existing technologies, this invention provides a physical layer secure transmission method for artificial intelligence models in semantic communication within 6G networks, specifically designed for edge-assisted unmanned aerial vehicle (UAV) systems. This method solves the security problem of AI neural network model transmission in dynamic, eavesdropping environments while maintaining high recognition accuracy.
[0005] The technical solution includes the following steps:
[0006] S1: Obtain a set of pre-trained models from the edge server, each model having a specific neural network structure. The model recognition error rate satisfies: (i) it is negatively correlated with the model size and decreases monotonically as the number of parameters increases; (ii) when the model size approaches infinity, the error rate approaches the theoretical zero value.
[0007] S2: Calculate the Security Outage Probability (SOP) based on the channel state, using the following formula:
[0008]
[0009] Where, λ k and λ e Here, N0 represents the exponential distribution parameters of the legitimate channel and the eavesdropping channel, respectively, where N0 is the noise power spectral density, and B0 is the noise power spectral density. k Let P be the bandwidth of the drone k, P be the transmission power, and R be the bandwidth of the drone k. th For the target safe rate;
[0010] S3: Construct the Secure Model Accuracy (SMA) metric, defined as:
[0011] SMA k =(1-SOP) k )×(1-Ψ k )
[0012] in, S represents the model's recognition error rate. k Let be the model size, and a and b be the tuning parameters. The optimization objective is to maximize...
[0013] S4: Use an alternating optimization algorithm to jointly select the model size and allocate bandwidth, including: (a) fixing the bandwidth and selecting the minimum model size that maximizes the SMA; (b) fixing the model and optimizing the bandwidth allocation through convex approximation; (c) repeating (a) and (b) until convergence.
[0014] Furthermore: In S1, a communication system needs to be established consisting of an "edge server - K drones - eavesdropper" ( Figure 1 Edge servers store pre-trained model sets. Model size S k The recognition error rate satisfies: Among them Ψ k With S k Monotonically decreasing, and when S k →+∞timeΨ k →0.
[0015] Furthermore: S2 includes:
[0016] S21. Define the legal channel gain as h. k ~CN(0,λ) k The eavesdropping channel gain is defined as h. e ~CN(0,λ) e CN(0,λ) e ) represents a mean of 0 and a variance of λ. e The complex Gaussian distribution.
[0017] S22. Define the confidentiality capacity as:
[0018]
[0019] in These represent the signal-to-noise ratios of legitimate and eavesdropping links, respectively.
[0020] S23. Define the security interruption probability as the confidentiality capacity being lower than the target rate R. th The probability of:
[0021]
[0022] Will Expanded to:
[0023]
[0024] Right now:
[0025]
[0026] Further simplification:
[0027]
[0028] SOP can be represented as:
[0029]
[0030] in It is γ e The probability density function (PDF).
[0031] Due to γ k Obtain the parameter as The exponential distribution has a cumulative distribution function (CDF) of , which is:
[0032]
[0033] Substitute into the SOP expression:
[0034]
[0035] The integral is split into two parts:
[0036]
[0037] make Clearly, I1 = 1. Simplifying I2:
[0038]
[0039] use We can obtain:
[0040]
[0041] Therefore, SOP can be expressed as:
[0042]
[0043] Substitution The final closed-form expression for the SOP is:
[0044]
[0045] Furthermore: S4 includes:
[0046] S41. Fixed bandwidth model selection: Enumerate all models for calculation. Choose to maximize SMA k The model:
[0047]
[0048] S42, Bandwidth allocation for fixed models: At this time, 1-Ψ k If fixed, it can be considered as a constant θ. k Therefore, the optimization problem can be described as:
[0049]
[0050] The Continuous Convex Approximation (SCA) technique is used to introduce slack variables. Therefore, the optimization problem can be described as:
[0051]
[0052] For the objective function component z k With w k Perform a Taylor expansion:
[0053]
[0054] By analyzing z k with w k With the convex approximation, all constraints of the SMA objective function are transformed into convex constraints, thus the optimization problem of bandwidth allocation can be solved by applying the convex optimization method.
[0055] S43. Iterate through steps S41 and S42 until convergence.
[0056] The advantages of this invention include:
[0057] Achieving secure transmission of neural network models in vulnerable 6G networks overcomes the limitations of traditional methods under dynamic channel conditions.
[0058] Secure transmission through physical layer security schemes can serve as a supplement to encryption schemes, jointly enhancing security.
[0059] The SMA metric is defined to provide a unified measure of safety and learning accuracy.
[0060] By optimizing the model's identification accuracy and transmission security through SMA metrics, efficient resource utilization can be ensured. Attached Figure Description
[0061] Figure 1 The communication system is described as "edge server - K drones - eavesdropper".
[0062] Figure 2 for Figure 1 This is a flowchart of the method of the present invention. Detailed Implementation
[0063] The present invention will be described in detail below through specific embodiments to help those skilled in the art understand it. However, the present invention is not limited to these embodiments, and all variations within the spirit and scope of the claims are within the protection scope of the present invention.
[0064] like Figure 1 As shown, the system includes storing a set of pre-trained models. Edge server (model size S) k The method involves K resource-constrained drones and one passive eavesdropper (Eve). The steps include:
[0065] Step S1: Model Acquisition
[0066] The edge server stores a set of pre-trained convolutional neural network (CNN) models designed specifically for semantic processing tasks, such as image classification on the CIFAR-10 dataset. The CNN architecture includes:
[0067] Input layer: Receives 32×32 pixel image data.
[0068] Convolutional layers: Six layers, each using a 3×3 convolutional kernel, ReLU activation function, with spatial dimensions gradually decreasing (e.g., from 32×32 to 8×8).
[0069] Error rate: Recognition error rate With model size S k It shows a negative correlation.
[0070] Step S2: Calculation of the probability of security breach
[0071] In a Rayleigh fading channel, calculate the secrecy interruption probability (SOP) for each UAV k, and the legitimate channel gain h. k ~CN(0,λ) k eavesdropping channel gain he ~CN(0,λ) e The SOP formula is:
[0072]
[0073] Where N0 is the noise power spectral density, B k Let P be the bandwidth of the drone k, P be the transmission power, and R be the bandwidth of the drone k. th The target secure rate is given. This closed-form expression reflects the impact of channel conditions on transmission security.
[0074] Step S3: Safety Model Accuracy Indicators
[0075] To balance identification accuracy and transmission security, the Security Model Accuracy (SMA) metric is defined as follows:
[0076] SMA k =(1-SOP) k )×(1-Ψ k )
[0077] The optimization problem is expressed as: The constraint condition is ∑B k ≤B total B k ≥0, where B total This represents the total available bandwidth. The SMA metric unifies the trade-off between model accuracy and confidentiality to facilitate joint optimization.
[0078] Step S4: Alternating Optimization Algorithm
[0079] The optimization problem is solved using an alternating optimization algorithm:
[0080] S4(a) Model Selection: Fixed Bandwidth B k Enumeration model set Calculate Ψ k Choose to maximize SMA k =(1-SOP) k )×(1-Ψ k The model.
[0081] S4(b) Bandwidth Allocation: Fixed Model Selection (Ψ) k The bandwidth is optimized using the Continuous Convex Approximation (SCA). The objective function is:
[0082]
[0083] Where θ k =1-Ψ k , pass
[0084] For fractional terms (z) k) and exponential term (w k By performing a Taylor expansion, the non-convex problem is transformed into a solvable convex problem.
[0085] The algorithm iteration is as follows:
[0086] Initialize bandwidth allocation And model selection.
[0087] Repeat until convergence:
[0088] With fixed bandwidth, enumerate the model set and select the maximum SMA. k The model.
[0089] With a fixed model, use SCA to optimize bandwidth and solve for the convex approximation:
[0090] renew
[0091] Finally, the optimal model-bandwidth pair is returned.
[0092] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. A secure transmission method for physical layer neural network models of edge drones in 6G networks, characterized in that, Includes the following steps: S1. Obtain the set of pre-trained neural network models for edge servers. Where N is the total number of models, and each model Having a specific neural network structure, with a model size S k This represents the number of neural network parameters for the k-th UAV terminal in the system (there are K UAV terminals in total), and the model recognition error rate Ψ. k satisfy: Where a and b are non-negative tuning parameters. And Ψ k It satisfies the following properties: (i)Ψ k With model size S k There is a negative correlation, that is, as the number of model parameters increases, Ψ k Monotonically decreasing; (ii) When S k →+∞timeΨ k →0 reflects the theoretical limit of accuracy of the infinite parameter model; S2. Calculate the Security Outage Probability (SOP) based on channel state: Where λ k ,λ e Here, N0 represents the exponential distribution parameters of the legitimate channel and the eavesdropping channel, respectively, where N0 is the noise power spectral density, and B0 is the noise power spectral density. k Let P be the bandwidth of the drone k, P be the transmission power, and R be the bandwidth of the drone k. th For the target safe rate; S3. Secure Model Accuracy (SMA) Metric: SMA k =(1-SOP k )×(1-Ψ k ) Define the optimization objective as maximizing k is the identifier of the drone terminal, and there are a total of K drone terminals; S4. Select the model parameter S using an alternating optimization algorithm. k With allocated bandwidth B k : (a) With fixed bandwidth, traverse the model set and select the smallest Ψ k The model; (b) Fix the number of model parameters and optimize bandwidth allocation through convex approximation; (c) Repeat the alternating optimization steps (a) and (b) until convergence.
2. The method according to claim 1, characterized in that, The alternating optimization algorithm in step S4 includes: (a) Initialize bandwidth allocation B k ; (b) Fixed B k Enumerate model set to compute SMA k And select to make SMA k The largest model; (c) Fix model parameters (1-Ψ) k ) is θ k The transmission security component (1-SOP) in the security model accuracy index will be included. k Decomposition, i.e., defining the following slack variables: in, It is the distributed parameter of the legal channel signal-to-noise ratio (SNR). Then there is 1-SOP k =z k w k At the iteration point z k and w k Perform first-order Taylor expansions respectively: (d) Solving convex optimization problems Until it converges.
3. The method according to claim 1, characterized in that, The channel gain h between the edge server and the drone k ~CN(0,λ) k eavesdropping channel gain h e ~CN(0,λ) e ).
4. The method according to claim 1, characterized in that, The pre-trained model set The model in the text can be any typical neural network, such as a convolutional neural network (CNN), whose network structure includes: • Input layer: Receives 32*32 pixel image data; • 6 convolutional layers: Each layer uses a 3*3 convolutional kernel and the ReLU activation function. The hierarchical structure is shown in the table in the instruction manual. • Number of model parameters S k Positively correlated with network depth and number of channels, satisfying 5. The method according to claim 1, characterized in that, The structure and recognition error rate Ψ of the convolutional neural network k The negative correlation relationship constructed in claim 1(i) is satisfied, i.e., the number of model parameters S k When increasing Ψ k Monotonically decreasing.
6. The method according to claim 1, characterized in that, The error rate function The parameters a and b were calibrated through model structure experiments: • On the CIFAR-10 dataset, a = 0.82, b = 0.19; When S k From 5*10 5 Increased to 2*10 6 At that time, Ψ k It decreased from 0.30 to 0.
125.
7. The method according to claim 1, characterized in that, The model selection strategy in step S4(a) is as follows: ·right Each model Calculation of parameter S i and corresponding • Choose to make SMA k The largest model 8. The method according to claim 1, characterized in that, The pre-trained neural network model can adopt a hierarchical feature extraction structure. The following example uses a convolutional neural network: Shallow convolutional layers (Conv1-2) extract local edge features; • The middle convolutional layer (Conv3-4) extracts component-level semantic features; • Deep convolutional layers (Conv5-6) extract global contextual features; • Increasing network depth significantly improves the ability to represent global features, leading to Ψ k With S k Increases and decreases. Other types of neural networks adjust the parameter size S. k This method also applies.
9. The method according to claim 2, characterized in that, The complexity of bandwidth allocation is O(15K). 3 +100K), where K is the number of drones, 15 is the number of outer iterations, and 100 is the number of linear search steps.