Electromagnetic signal threat assessment method based on dynamic Bayesian network under small data set

By constructing a dynamic Bayesian network and combining it with the qualitative maximum a posteriori probability method to optimize parameters, the limitations of static modeling and overfitting in existing electromagnetic signal threat assessment technologies are solved. This enables real-time and accurate threat assessment in complex electromagnetic environments, improving the dynamic adaptability of the model and the objectivity of the assessment results.

CN120974133APending Publication Date: 2025-11-18XIDIAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510999053.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-21
Publication Date
2025-11-18

AI Technical Summary

Technical Problem

Existing technologies for assessing electromagnetic signal threats in complex electromagnetic environments suffer from limitations in static modeling and excessive reliance on expert experience. In particular, under small dataset conditions, model parameter settings are prone to overfitting, making it difficult to achieve real-time monitoring and accurate assessment of the temporal evolution of signal characteristics.

Method used

A threat assessment model based on dynamic Bayesian networks is constructed. The network structure is built using electromagnetic signal core indicators, and a time dimension is introduced to link data from different time segments. The forward-backward algorithm is used for threat inference, and the node parameters are optimized by combining qualitative maximum a posteriori probability method based on expert experience, thereby reducing the dependence on expert experience and improving the model's generalization ability on small datasets.

Benefits of technology

It enables dynamic adaptive assessment in complex electromagnetic environments, improves the stability and reliability of threat probability estimation, can monitor the evolution of the threat situation of electromagnetic signals in real time, and reduces the subjective bias of assessment results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120974133A_ABST
    Figure CN120974133A_ABST
Patent Text Reader

Abstract

The invention discloses an electromagnetic signal threat assessment method based on a dynamic Bayesian network under a small data set, and aims to solve the problems that an existing static modeling assessment model cannot capture a threat situation, model parameters excessively depend on expert experience, and an assessment result is over-fitted when training data is scarce. The method comprises the following steps of: constructing a dynamic Bayesian network according to an incidence relation between threat elements and threat levels; performing range division on the threat assessment elements to construct a training data set; using a qualitative maximum posterior probability algorithm to train network node parameters; and performing threat reasoning on the network by using a forward-backward algorithm to obtain a threat level of the signal in each time slice. According to the method, the requirement for monitoring the signal threat level in real time is met, the method has the advantages of being high in evaluation result objectivity and capable of evaluating various signals, the stability and reliability of threat probability calculation are improved, and the method is more suitable for the challenge that novel threat samples are insufficient in an urban security scene.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of radar communication technology, and further relates to a method for electromagnetic signal threat assessment based on dynamic Bayesian networks under small dataset conditions within the field of electronic countermeasures technology. This invention can be used to assess the threat level of anomalous electromagnetic signals in complex electromagnetic environments. Background Technology

[0002] With the acceleration of urbanization, electromagnetic environment security issues in key areas such as government agencies, large event venues, and transportation hubs are becoming increasingly prominent. In complex electromagnetic environments, communication devices such as walkie-talkies, Wi-Fi, Bluetooth, and mobile phone signals are densely distributed. While their electromagnetic radiation and communication behavior may be legitimate under normal circumstances, they could be maliciously exploited for threats such as remote-controlled detonation, communication interference, and information theft. Therefore, constructing real-time and accurate threat assessment models for electromagnetic signal targets in urban security scenarios, and quickly identifying and issuing warnings of potential danger signals, is a core requirement for improving urban security capabilities.

[0003] Ding Lei et al. proposed a quantitative assessment method for target threat levels in complex electromagnetic environments in their paper "An Electromagnetic Target Threat Assessment Method Based on AHP" (Aerospace Electronic Countermeasures 2022 38(02):47-52). The implementation scheme of this method is as follows: First, establish a hierarchical threat assessment model. Based on capability factors and situational factors, a hierarchical structure model is constructed, and each indicator is quantified by the 5-level scaling method; Second, construct a pairwise comparison judgment matrix. Using the 1-5 scaling method, the relative importance of each indicator is judged by expert experience to generate a judgment matrix; Third, calculate the weights and verify consistency. The indicator weight vector is solved by column normalization and eigenvector method, and the reliability of the matrix is ​​verified by the consistency ratio to ensure the mathematical rationality of the assessment results; Fourth, generate dynamic threat levels in real time. The threat level score is generated by weighted summation of comprehensive weights and quantitative indicators and the information database is updated to adapt to the dynamic changes of the battlefield electromagnetic situation. The shortcomings of this method are twofold. Firstly, its core AHP framework heavily relies on expert experience to determine the weighting of pairwise indicators when constructing the judgment matrix. However, in complex urban electromagnetic environments, the characteristics of new interference signals are complex and rapidly changing, and experts' understanding of unknown threats may be ambiguous, leading to subjective biases in weight allocation. Secondly, this method also suffers from the limitation of static modeling. AHP can only independently process threat assessments for a single time slice and cannot extrapolate threats based on the temporal evolution of signal characteristics, making it difficult to meet the real-time monitoring requirements of the same signal.

[0004] Li Huiqiang et al. proposed a threat assessment method for low, slow, and small targets in complex terrain in their paper "Threat Assessment of Low, Slow, and Small Targets Based on Dynamic Bayesian Networks" (Laser & Infrared 2022 52(07):1036-1041). The implementation steps of this method are as follows: First, construct a dynamic Bayesian network topology. Combining the threat attributes of low, slow, and small targets, a prior network model and a transition network model are established. The threat evolution relationship between time series is correlated to reflect the temporal dependence in the dynamic system. Second, define a conditional probability matrix and predefine the conditional probabilities between nodes based on expert experience and historical data. Third, perform dynamic inference and threat value calculation. Update the network node state using time series observation data, generate a threat probability distribution through Bayesian inference, and integrate information from time series to improve the continuity of the assessment. The shortcomings of this method are: overfitting caused by data scarcity. Its conditional probability matrix is ​​highly dependent on expert-defined rules. In scenarios where there is insufficient real-world data for low-speed, small-target scenarios, the solidification of model parameters can easily lead to the training process becoming overly aligned with subjective experience, thus losing the ability to correctly evaluate actual targets. Summary of the Invention

[0005] The purpose of this invention is to address the shortcomings of existing technologies by proposing a dynamic Bayesian network-based electromagnetic signal threat assessment method for small datasets. This method aims to overcome the limitations of static modeling in existing threat assessment techniques, the over-reliance on expert experience in model parameter settings, and the overfitting problem under conditions of scarce training data. It achieves better assessment accuracy and dynamic adaptability in complex electromagnetic environments.

[0006] The underlying principle of this invention is to construct a threat assessment model based on dynamic Bayesian networks under small dataset conditions. In structural modeling, this invention uses core indicators of electromagnetic signals to construct the network structure. By introducing a time dimension and linking data from different time segments with the core variable of "threat level," a forward-backward algorithm is used to perform threat inference on the network. This enables continuous tracking of the dynamic changes in the threat level of signals at each time segment, thus solving the problem that traditional static assessment models cannot capture the evolution of threat situations. In parameter modeling, this invention first constructs a training dataset and then uses a qualitative maximum a posteriori probability method combined with expert experience to train the node parameters in the network model. It automatically learns node parameters from limited data, optimizes the conditional probability table, and significantly reduces reliance on expert experience, improving the objectivity of node parameters. This invention employs a qualitative maximum a posteriori probability method, transforming expert experience into parameter constraints, followed by parameter estimation and fusion. The final parameter estimation result, which considers both prior knowledge and data characteristics, improves the model's generalization ability under small datasets and ensures the stability and reliability of threat probability estimation.

[0007] The specific steps for implementing this invention include the following:

[0008] Step 1: Establish a static Bayesian network and construct a dynamic Bayesian network by connecting them through a time axis; explicitly model the dynamic process of threat level changing over time using a state transition matrix;

[0009] Step 2: Divide each threat assessment index into discrete states to construct a training dataset;

[0010] Step 3: The constraint-based Bayesian network parameter learning method uses prior knowledge to correct the parameter estimation error in the case of small samples.

[0011] Step 4: Use the forward-backward algorithm to perform threat inference on the network and obtain the threat level of the signal at the current moment.

[0012] Furthermore, the static Bayesian network analyzes the temporal characteristics and multidimensional attributes of electromagnetic signals, sets "threat level" as the central latent variable, and selects seven types of indicators—relative signal distance, signal identity, received power, duration, center frequency, bandwidth, and modulation method—as observed variables. By establishing directed probabilistic dependencies between each observed variable and the threat level, a probability-based graphical model is formed, consisting of four elements: nodes, directed edges, conditional probability tables, and joint probability decomposition. In this graphical model, nodes represent random variables, directed edges represent direct dependencies between variables, and each node in the conditional probability table corresponds to a conditional probability distribution, which is a representation of the strength of its dependency on its parent node.

[0013] The joint probability decomposition represents the overall joint probability distribution of the network, which can be expressed as the product of local conditional probabilities:

[0014]

[0015] Where n represents the total number of nodes in the network, ∏ represents the chain multiplication operation, and P(X) i |Parents(X i )) represents the i-th node X i The conditional probability distribution, Parents(X) i ) represents node X i The set of parent nodes.

[0016] Furthermore, the construction of a dynamic Bayesian network via time-axis concatenation refers to using a static Bayesian network as a structural unit in a single time slice, replicating this structural unit in different time slices, and defining the state transition probability across time slices by establishing directed edges between the threat level node in time slice T and the threat level node in time slice T+1, thereby constructing a dynamic Bayesian network with temporal dependencies. In this dynamic structure, signal identity is a latent variable, jointly modeled by the signal center frequency, signal bandwidth, and signal modulation method. Its output node is connected to the threat level node, and the signal identity node is also connected to the threat level node along with nodes for signal relative distance, signal received power, and signal duration, forming a multi-level inference path. The state information of the threat level node can be propagated within consecutive time slices, forming a temporal Bayesian inference chain covering multiple time steps.

[0017] Furthermore, the step of dividing each threat assessment index according to discrete states to construct a training dataset refers to:

[0018] Threat levels (TL) are divided into three categories: high threat, medium threat, and low threat.

[0019] Signal identity (SI) is divided into three categories: illegal signals, abnormal signals, and whitelisted signals.

[0020] The relative distance (SD) of the signal is divided into three categories: short distance, medium distance, and long distance.

[0021] The signal reception power RP is divided into three categories: strong, medium, and weak.

[0022] The signal duration ST is divided into three categories: long, medium, and short;

[0023] The signal center frequency SF is divided into three categories: important frequency band, conventional frequency band, and open frequency band;

[0024] The signal bandwidth SB is divided into three categories: illegal encroachment, irregular encroachment, and normal bandwidth occupation;

[0025] Signal modulation methods (SM) are classified into three categories: complex modulation, unconventional digital modulation, and compliant basic modulation.

[0026] The above partitioning results are used to form a training sample set with discrete state labels, which serves as the input information for Bayesian network parameter learning and inference.

[0027] Furthermore, the steps of the constrained Bayesian network parameter learning method are as follows:

[0028] The first step is to count the observation frequency N of each node in the training dataset under its parent node combination state. ijk i represents the node's index, j represents the parent node's state, and k represents the node's state.

[0029] The second step is to construct parameter constraints based on the experience of experts in the field, including but not limited to normalization constraints, interval constraints, identical distribution constraints, cross-distribution constraints, and additive relationship constraints.

[0030] The third step is to use the Monte Carlo method to generate parameter samples that satisfy the constraints and to count the pseudo-counts M. ijk ;

[0031] The fourth step is to construct the qualitative Bayesian parameter scoring function QBPS, which includes the actual observation frequency and pseudo-counts, as follows:

[0032]

[0033] Where Pr(θ|G,D,Ω) represents the posterior probability of the parameter set θ given the network structure G, the dataset D, and the prior information Ω, ∏ i,j,k This indicates that node X in the network i Its parent node's combined state j, and X i The triple product of its own value state k, θ ijk P(X) represents the conditional probability parameter. i |Parents(X i ));

[0034] Fifth, maximize the scoring function to obtain the parameter estimates in the conditional probability table, which will be used for subsequent threat inference:

[0035]

[0036] in, This represents the final estimated conditional probability, i.e., the node parameters in the network, and ∑ represents the summation operation.

[0037] Furthermore, the step of using prior knowledge to correct the parameter estimation error in the case of small samples is as follows:

[0038] The first step, during the training of Bayesian network parameters, involves incorporating the understanding of the relationships between various evaluation factors by experts in the field, to generate the following logical relationships:

[0039] (1) The higher the threat level of the signal, the closer its relative distance;

[0040] (2) The higher the threat level of the signal, the greater the possibility that its identity signal is an abnormal signal;

[0041] (3) The higher the threat level of the signal, the stronger its receiving power;

[0042] (4) The higher the threat level of the signal, the longer it lasts;

[0043] (5) The higher the threat level of a signal, the greater the likelihood that its center frequency is in a key protection band;

[0044] (6) The higher the threat level of a signal, the higher the possibility that its signal bandwidth is illegally occupied;

[0045] (7) The higher the threat level of a signal, the more likely it is to be a complex modulation method;

[0046] (8) The greater the likelihood that a signal is an abnormal signal, the greater the likelihood that its center frequency is in a key protection frequency band;

[0047] (9) The greater the likelihood that the signal is an abnormal signal, the greater the likelihood that the signal bandwidth is illegally occupied;

[0048] (10) The greater the likelihood that the signal is an abnormal signal, the higher the likelihood that the signal modulation method is complex modulation;

[0049] The second step is to transform the aforementioned expert knowledge in the field into inequality constraints on the parameters, which are used to limit the parameter search space and reduce the error in parameter estimation.

[0050] P(X=x a |Y=y)≥P(X=x) b |Y=y),

[0051] Where X represents the affected variable, Y represents the condition variable, and x a x b These represent the two states of X.

[0052] Furthermore, the steps for performing threat inference on the network using the forward-backward algorithm are as follows:

[0053] The first step is to use the given observation sequence Y 1:T =(Y1,Y2,…,Y) T ), calculate the hidden state X t The posterior probability P(X) t =q i |Y 1:T ), where T represents the number of time slices, q i This represents the system's state at time t, i.e., the threat level.

[0054] Hidden state set: Q = {q1, q2, ..., q} N There are N possible states, representing the threat level.

[0055] Observation set: V = {v1, v2, ..., v MThere are M possible observations, representing the observation inputs for M time slices;

[0056] State transition matrix: A = [a ij ], a ij =P(X) t =q j |X t-1 =q i ), indicating that from state q i Transfer to q j The probability of;

[0057] Emission matrix: B = [b j (k)],b j (k)=P(Y t =v k |X t =q j ), indicating that in state q j v was observed below k The probability of;

[0058] Initial state distribution: π = [π i ],π i =P(X1=q) i ), representing state q i The prior probability at the initial moment;

[0059] The second step is to calculate the forward probability α based on the initial state distribution, the state transition matrix, and the emission matrix. t (i):

[0060] α t (i) = P(Y1,Y2,…,Y) t ,X t =q i )

[0061] Where, α t (i) indicates that the state of the system at time t is X. t =q i And the observation sequence from time 1 to t is {Y1,Y2,…,Y} t The joint probability of};

[0062] At time t = 1, α1(i) = π i ·b i (Y1), 1≤i≤N, indicates that the forward probability α1(i) at the initial time is equal to the initial state probability π. i The emission probability b of generating the first observation i The product of (Y1);

[0063]

[0064] Where, α t (j) indicates that the system is in state q at time t. j And Y1, Y2, ..., Y were observed. t The joint probability, b j (Y t ) indicates that at time t, the state is q. j Time-generated observation Y t The probability, α t-1 (i) indicates that the system was in state q at the previous time t-1. i And observed Y1, Y2, ..., Y t-1 The joint probability, a ij Indicates from state q i At time t-1, the state transitions to state q. j The transition probability (at the current moment);

[0065] The third step is to calculate the time step t∈[1,T] and the state q at each time step. i The backward probability β t (i):

[0066] β t (i)=P(Y t+1 ,Y t+2 ,…,Y T |X t =q i )

[0067] Where, β t (i) indicates that the state is q at time t. i When, the conditional probability of all future observations occurring, X t =q i This indicates that the hidden state at the current time is the i-th state, Y. t+1 ,Y t+2 ,…,Y T This represents the observation sequence from time t+1 to the end time T, where T represents the total number of time slices;

[0068] At time t = T:

[0069] β T (i) = 1, 1 ≤ i ≤ N

[0070] Since there are no subsequent observations for the backward probability at the final moment, it is set to 1;

[0071] Next, perform recursive calculations:

[0072]

[0073] Where, β t (i) indicates that the state is q at time t. iThe backward probability, the conditional probability of future observations, a ij Indicates from state q i Transition to state q j State transition probability, b j (Y t+1 ) represents state q j Observation Y is generated at time slice t+1. t+1 The probability, β t+1 (j) indicates that the state is q at the (t+1)th time slice. j At that time, the conditional probability of future observations occurring;

[0074] The fourth step is to combine the forward and backward probabilities to calculate the posterior distribution of the hidden state, i.e., the threat level:

[0075]

[0076] Where, γ t (i) indicates that the state is q at time t. i The conditional probability, i.e., the final inference result, consists of the numerator being the probability calculated from the forward and backward processes, and the denominator being the joint probability of the observed sequence, i.e., P(Y). 1:T )=∑ k α t (k)·β t (k), where ∑ represents the summation over all possible states, serving as a normalization factor to ensure that the sum of probabilities is 1.

[0077] The fifth step is to use the threat level corresponding to the maximum posterior probability in each time slice as the threat assessment output for that time point.

[0078] Compared with existing technologies, the present invention has the following advantages:

[0079] First, the dynamic Bayesian network constructed in this invention can learn its node parameters using existing datasets. By combining limited data with constraints formed by some expert experience, it can automatically learn node parameters and optimize the conditional probability table. This overcomes the shortcomings of existing technologies that rely heavily on expert experience for parameter setting, which leads to significant subjective bias in the assessment results of new threats in complex environments. As a result, this invention has the advantages of strong objectivity in assessment results and the ability to assess a variety of signals.

[0080] Second, the dynamic Bayesian network constructed in this invention can explicitly model the dynamic process of threat level changes over time through the state transition matrix, overcoming the shortcomings of existing technologies that can only handle threat assessment on a single time slice. This makes the dynamic adaptability of the model improved and meets the need for real-time monitoring of signals.

[0081] Third, this invention uses a constraint-based Bayesian network parameter learning method to correct parameter estimation errors in small sample cases by utilizing prior expert knowledge. This alleviates the overfitting problem caused by data scarcity in existing technologies, improves the stability and reliability of threat probability estimation, and is more suitable for the challenge of insufficient new threat samples in urban security scenarios. Attached Figure Description

[0082] Figure 1 This is a flowchart of an embodiment of the present invention;

[0083] Figure 2 This is a schematic diagram of a static Bayesian network in an embodiment of the present invention;

[0084] Figure 3 This is a schematic diagram of a dynamic Bayesian network in an embodiment of the present invention;

[0085] Figure 4 This is a schematic diagram illustrating the dynamic evolution of the threat probability of digital walkie-talkie signals in an embodiment of the present invention. Detailed Implementation

[0086] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.

[0087] Reference Figure 1 The specific implementation steps of the embodiments of the present invention will be described in further detail below.

[0088] Step 1: Analyze the characteristics of electromagnetic signals, select threat assessment elements, establish the correlation between threat level and threat elements to form a static Bayesian network, and construct a dynamic Bayesian network by connecting them through a time axis.

[0089] Step 1.1: Select seven core indicators as elements for signal threat assessment: relative signal distance, signal identity, received power, duration, center frequency, bandwidth, and modulation method.

[0090] Step 1.2: Analyze the correlation between each threat element and the threat level, as follows:

[0091] Relative signal distance: This refers to the physical distance between the signal source and the core protected area, obtained through positioning technology. It directly reflects the urgency of the space threat. The closer the distance, the higher the risk of physical intrusion or interference by the signal to sensitive targets.

[0092] Signal identity: As a latent variable, its credibility is inferred jointly from the signal's center frequency, bandwidth, and modulation method. Whitelisted signals have a low threat level; unknown identity signals have a medium threat level; abnormal identity signals directly trigger a high threat assessment.

[0093] Received power: This comprehensively reflects the transmission capability of the signal source and its proximity to the target. High received power may indicate a strong radiating device at close range, and the threat level increases proportionally with the increase in received power.

[0094] Duration: The shorter the signal duration, the more likely it is to be environmental noise or temporary communication, with a low threat level; a continuously active signal implies malicious loitering or reconnaissance behavior, and its purpose needs to be analyzed in conjunction with the modulation method.

[0095] Spectral attributes (center frequency, bandwidth): As the basis for signal identification criteria, both indirectly affect the threat level through frequency band compliance and frequency occupancy anomalies.

[0096] Modulation method: By identifying the modulation type and coding characteristics, conventional communication can be distinguished from anti-interception techniques. Abnormal modulation may indicate signal spoofing or information theft intentions, requiring joint probabilistic reasoning in conjunction with signal identity.

[0097] Step 1.3, based on the above analysis, the established static Bayesian network model is as follows: Figure 2 As shown. Figure 2 Using static Bayesian networks as basic units, multiple such units are connected in series along a time axis to form a complete dynamic Bayesian network, such as... Figure 3 As shown.

[0098] Step 2: Divide the threat assessment elements into categories and construct a training dataset. The specific division rules are as follows:

[0099] Threat Level (TL): T = {1, 2, 3} = {High Threat, Medium Threat, Low Threat}.

[0100] Signal Identity (SI): SI = {1, 2, 3} = {illegal signal, abnormal signal, whitelist signal}.

[0101] Signal distance (SD): SD = {1, 2, 3} = {near, medium, far}, the specific delineation rules are as follows:

[0102]

[0103] Received power (RP): RP = {1, 2, 3} = {strong, medium, weak}, with specific classification rules as follows:

[0104]

[0105] Signal duration (ST): ST = {1, 2, 3} = {long, medium, short}, with specific division rules as follows:

[0106]

[0107] Signal center frequency (SF): SF = {1, 2, 3} = {important, normal, open}.

[0108] Signal bandwidth (SB): SB = {1, 2, 3} = {illegal encroachment, unauthorized bandwidth occupation, normal bandwidth occupation}.

[0109] Signal Modulation (SM): SM = {1, 2, 3} = {Complex Modulation, Unconventional Digital Modulation, Standard Basic Modulation}.

[0110] Based on the above division rules, a training dataset was constructed, and the feature parameters of some signals are shown in Table 1.

[0111] Table 1. Overview of training data for some signals

[0112]

[0113] Step 3: Train the node parameters in the network model using the qualitative maximum a posteriori probability algorithm to obtain the threat probability of all nodes in the network. The specific training steps are as follows:

[0114] Step 3.1: Calculate the observation frequency of each node from the training data. For each node X... i When it is in state k and its parent node combination Π i When in state j, record the number of actual observations N. ijk :

[0115]

[0116] Where, N ijk Indicates the current node X i The node is in state k, and its parent node combination is Π. i The number of observations when in state j; N ij Represents the parent node combination Π i Total number of observations when in state j; r i Represents node X i The number of states.

[0117] Step 3.2: Construct parameter constraints by combining the experience of experts in the field.

[0118] Step 3.2.1, based on expert experience and the relationships between elements, the following logical relationship is derived:

[0119] (1) The higher the threat level of the signal, the closer its relative distance;

[0120] (2) The higher the threat level of the signal, the greater the possibility that its identity signal is an abnormal signal;

[0121] (3) The higher the threat level of the signal, the stronger its receiving power;

[0122] (4) The higher the threat level of the signal, the longer it lasts;

[0123] (5) The higher the threat level of a signal, the greater the likelihood that its center frequency is in a key protection band;

[0124] (6) The higher the threat level of a signal, the higher the possibility that its signal bandwidth is illegally occupied;

[0125] (7) The higher the threat level of a signal, the more likely it is to be a complex modulation method;

[0126] (8) The greater the likelihood that a signal is an abnormal signal, the greater the likelihood that its center frequency is in a key protection frequency band;

[0127] (9) The greater the likelihood that the signal is an abnormal signal, the greater the likelihood that the signal bandwidth is illegally occupied;

[0128] (10) The greater the likelihood that the signal is an abnormal signal, the higher the likelihood that the signal modulation method is complex modulation.

[0129] Step 3.2.2 transforms the above logical relationship into the following parametric inequality constraint form to limit the parameter search space and reduce parameter estimation errors:

[0130] (1)P(SD=1∣TL=1)≥P(SD=2∣TL=1)

[0131] (2)P(SD=2∣TL=1)≥P(SD=3∣TL=1)

[0132] (3)P(SD=1∣TL=1)≥P(SD=1∣TL=2)

[0133] (4)P(SD=1∣TL=2)≥P(SD=1∣tL=3)

[0134] (3)P(SI=1∣TL=1)≥P(SI=2∣TL=1)

[0135] (4)P(SI=2∣TL=1)≥P(SI=3∣TL=1)

[0136] (5)P(RP=1∣TL=1)≥P(RP=2∣TL=1)

[0137] (6)P(RP=2∣TL=1)≥P(RP=3∣TL=1)

[0138] (7)P(ST=1∣TL=1)≥P(ST=2∣TL=1)

[0139] (8)P(ST=2∣TL=1)≥P(ST=3∣TL=1)

[0140] (9)P(SF=1∣SI=1)≥P(SF=2∣SI=1)

[0141] (10)P(SF=2∣SI=1)≥P(SF=3∣SI=1)

[0142] (11)P(SB=1∣SI=1)≥P(SB=2∣SI=1)

[0143] (12)P(SB=2∣SI=1)≥P(SB=3∣SI=1)

[0144] (13)P(SM=1∣SI=1)≥P(SM=2∣SI=1)

[0145] (14)P(SM=2|SI=1)≥P(SM=3∣SI=1).

[0146] Step 3.3: Perform parameter-constrained sampling using the Monte Carlo method. The specific process is as follows: First, define the parameter space, and for each conditional probability parameter θ... ijk Assuming its value range is [0,1] and satisfies the probability normalization condition; secondly, constrained sampling is performed, using the Monte Carlo method to generate parameter samples that satisfy probability normalization and condition constraints; finally, the pseudo-count M is calculated. ijk If each sample corresponds to a set of pseudo-counts, then:

[0147] M ijk =A×Pr(X) i =k,Π i =j∣Ω)

[0148] Where A is the number of samples, Pr(X) i =k,Π i =j|Ω) is the probability distribution of parameters that satisfy the constraints.

[0149] Step 3.3, construct the QBPS scoring function. Calculate the data statistics N. ijk With prior pseudo-count M ijk Combined, construct the posterior probability:

[0150]

[0151] Where, N ijk Indicates the current node X i The node is in state k, and its parent node combination is Π. i The number of observations when in state j; M ijk This represents the pseudo-count generated through Monte Carlo sampling.

[0152] Step 3.4: By maximizing the QBPS scoring function, the parameter estimates are obtained.

[0153]

[0154] In an embodiment of the present invention, the data in the training set is trained using a qualitative maximum a posteriori (MAP) algorithm to obtain the threat probability of all nodes in the network. The training results of parameters for some nodes are shown in Tables 2 to 4. The state transition probabilities are directly provided by consulting experts in the relevant field, while the parameters of other nodes are obtained by solving the algorithm described above.

[0155] Table 2 shows the parameter training results for node SD.

[0156]

[0157] Table 3 shows the parameter training results for node TL.

[0158]

[0159] Table 4 State Transition Probability Table

[0160]

[0161] Step 4: Use the forward-backward algorithm to perform threat inference on the network and obtain the threat level of the signal at the current time. The forward-backward algorithm is the core algorithm in Hidden Markov Models used to calculate the posterior probability of the hidden state. Its core idea is to calculate the forward probability and the backward probability separately through dynamic programming, and finally combine the two to obtain the conditional distribution of the hidden state at any time.

[0162] The specific calculation process of the forward-backward algorithm is as follows:

[0163] Step 4.1, Problem definition and related parameter description:

[0164] HMM model parameters include:

[0165] Hidden state set: Q = {q1, q2, ..., q} N There are N possible states in total.

[0166] Observation set: V = {v1, v2, ..., v M There are M possible observations.

[0167] State transition matrix: A = [a ij ], where a ij =P(X) t =q j |X t-1 =q i );

[0168] Emission matrix: B = [b j (k)], where b j (k)=P(Y t =v k |X t =q j );

[0169] Initial state distribution: π = [π i ], where π i =P(X1=q) i ).

[0170] The core objective of this algorithm is to obtain a given observation sequence Y. 1:T =(Y1,Y2,…,Y) T ), calculate the hidden state X t The posterior probability P(X) t =q i |Y 1:T ).

[0171] Step 4.2, Forward Process. The core objective of this process is to calculate the forward probability α. t (i):

[0172] α t (i) = P(Y1,Y2,…,Y) t ,X t =q i )

[0173] Where Y1, Y2, ..., Y t It refers to the first t observations in the observation sequence.

[0174] The specific process is as follows: First, initialization is performed at time t=1:

[0175] α1(i)=π i ·b i (Y1), 1≤i≤N

[0176] α1(i) represents the forward probability at the initial time step, which is the product of the initial state probability and the emission probability of generating the first observation. Then, a recursive calculation is performed:

[0177]

[0178] The summation term represents the traversal of all possible states q from the previous time step. i Calculate from q i Transition to the current state q j The probability weighted sum; b j (Y t ) represents the current state q i Generate observation Y t The probability of.

[0179] The sum of the forward probabilities of all final states is the joint probability of the observation sequence:

[0180]

[0181] Step 4.3, Backward Process. The core purpose of this process is to calculate the backward probability β. t (i):

[0182] β t (i)=P(Y t+1 ,Y t+2 ,…,Y T |X t =q i )

[0183] The specific process is as follows: First, initialize the process at time t = T:

[0184] β T (i) = 1, 1 ≤ i ≤ N

[0185] Since there are no subsequent observations for the backward probability at the final moment, it is set to 1. Next, the recursive calculation is performed:

[0186]

[0187] From the current state q i Transition to the next state q j And generate observation Y t+1 The backward probability of all possible next state contributions is accumulated.

[0188] Step 4.4, Smoothing probability calculation.

[0189] By combining the forward and backward probabilities, calculate the posterior distribution of the hidden state:

[0190]

[0191] The numerator is the probability calculated from the forward and backward processes mentioned above, while the denominator is the joint probability of the observed sequence, which serves as a normalization factor to ensure that the sum of the probabilities is 1.

[0192] In summary, the forward-backward algorithm takes HMM parameters and observation sequence as input, calculates the forward and backward probabilities through forward and backward calculations, and then calculates the posterior probabilities of the hidden states at all time points through smoothing, which is the desired inference result.

[0193] The effects of this invention will be further illustrated below with simulation experiments:

[0194] 1. Simulation experimental conditions.

[0195] The software platform for the simulation experiment of this invention is: Windows 11 operating system, PyCharm 2023 2.8 compiler and Python 3.9 language.

[0196] 2. Simulation content and result analysis.

[0197] There are two simulation experiments for this invention.

[0198] Simulation Experiment 1 uses the qualitative maximum a posteriori probability (QMAP) network parameter learning method of this invention and two existing technologies, the most likely estimation method (MLE) and the maximum a posteriori probability method (MAP), to train the network parameters and compare the accuracy of each algorithm.

[0199] In simulation experiment 1, the two existing technologies used are:

[0200] The existing maximum likelihood estimation (MLE) method refers to the Bayesian network parameter learning method proposed by Jiang GP et al. in "Bayesian network's parameter update method based on maximum likelihood estimates, 2018 International Conference on Artificial Intelligence and Big Data (ICAIBD), Chengdu, China, 2018, pp.6-9, doi: 10.1109 / ICAIBD.2018.8396157".

[0201] The existing maximum a posteriori (MAP) estimation method refers to the Bayesian network parameter learning method proposed by D. Koller et al. in "Probabilistic Graphical Models: Principles and Techniques. Cambridge, MA, USA: MIT Press, 2009."

[0202] The Bayesian network model of this invention has 63 node parameters to be trained, requiring a minimum data size of 209. A dataset smaller than this value represents a small dataset, while a dataset larger than this value represents a complete dataset. Therefore, simulation experiment 1 consists of two parts. The first part uses the MLE algorithm to learn the node parameters of the network with 400 sample data points, obtaining the precise parameters, i.e., the true parameters, for each node. The second part uses the QMAP algorithm, MLE algorithm, and MAP algorithm to learn four sets of sample data (50, 100, 150, and 200 data points respectively). The learned parameters are compared with the true parameters, and the performance of the QMAP algorithm under the small dataset condition is verified by calculating the KL divergence.

[0203] After preprocessing, 500 sets of signal feature data were obtained. These 500 sets of data were divided into 50, 100, 150, 200, and 400 sets as training sets for the network to train parameters. 100 sets were reserved for subsequent inference of the threat assessment model to test the model's effectiveness. The feature data of some signals are shown in Table 5.

[0204] Table 5 shows the training data for some signals.

[0205]

[0206] The training results for all parameters in the network structure are as follows, where the state transition probabilities were directly provided by consulting experts in the relevant field, and the other node parameters were obtained by solving the above algorithm.

[0207] Table 6 shows the parameter training results for node SD.

[0208]

[0209]

[0210] Table 7 shows the parameter training results for node SI.

[0211]

[0212] Table 8 shows the parameter training results for node ST.

[0213]

[0214] Table 9 shows the parameter training results for node SF.

[0215]

[0216]

[0217] Table 10: Parameter Training Results for Node SB

[0218]

[0219] Table 11 Parameter Training Results of Node SM

[0220]

[0221] Table 12 shows the parameter training results for node TL.

[0222]

[0223]

[0224] Table 13 State Transition Probability Table

[0225]

[0226] The Kullback-Leibler divergence (KL) is a metric in information theory used to quantify the information loss of one probability distribution relative to another. In Bayesian network parameter learning, it's used to compare the differences between the parameter distributions learned by different algorithms and the true or empirical distributions, thus evaluating the algorithm's performance. Lower KL values ​​between the node parameters derived by different algorithms and the true parameters indicate higher parameter learning accuracy and better performance. Below, we train parameters using training sets of 50, 100, 150, and 200 sets, and calculate the KL values ​​between the node parameters obtained from each training set and the true parameters. The specific values ​​are as follows:

[0227] Table 14 shows the KL divergence values ​​of parameter learning algorithms under different data samples.

[0228]

[0229] As shown in Table 14, the QMAP algorithm combined with expert constraints mentioned in this invention achieves lower KL divergence than the other two algorithms during parameter learning from 50 to 200 sets of data. Furthermore, the performance advantage of this algorithm increases with fewer sample data sets: with 50 samples, the KL value calculated by the QMAP algorithm is 0.2131, which is 36.8% lower than MAP (0.3375) and 46.2% lower than ML (0.3967). With 100 sets of sample data, the KL value of the QMAP algorithm is 40.2% lower than the MAP (0.3426) algorithm and 34.9% lower than the MLE (0.3149) algorithm, verifying the superior parameter learning ability of the QMAP algorithm under scarce data conditions. Secondly, the MLE and MAP algorithms require 200 samples (KL = 0.2272 and 0.2183, respectively) to approach the accuracy of QMAP with 50 samples (KL = 0.2131), indicating a significant improvement in learning efficiency.

[0230] Simulation Experiment 1 of this invention shows that the QMAP algorithm is superior to the MLE method and the MAP algorithm in terms of both dependence on data samples and learning efficiency during the parameter learning process.

[0231] Simulation Experiment 2 of this invention verifies the threat inference capability of the electromagnetic signal threat assessment model using the dynamic Bayesian network of this invention under small data conditions. The forward-backward algorithm of this invention is used to infer the threat assessment model. Five electromagnetic signal targets are selected (DMR digital walkie-talkie signal, mobile phone signal, 802.11ac-WI-FI5 signal, Bluetooth signal, and digital broadcast signal). Eight time slices are used, each with a 15-second interval. The node parameters and state transition probabilities in the dynamic Bayesian network structure are shown in Tables 6 to 13. The DMR digital walkie-talkie signal among the electromagnetic signal targets to be evaluated and the observation data for each time slice are shown in Table 15.

[0232] Table 15 DMR Digital Walkie-Talkie Signal Observation Data

[0233]

[0234] By inputting the observation data of each time slice of the above targets into the threat assessment model, the threat assessment results of all targets in each time slice can be obtained. The target with the highest posterior probability of threat level is identified as the most likely threat situation of the target at present. The specific inference results are shown in Tables 16 to 23:

[0235] Table 16 Threat Results for 5 Targets in a 15-second Time Slice

[0236]

[0237] Table 17 Threat Results for 5 Targets in a 30-second Time Slice

[0238]

[0239]

[0240] Table 18 Threat Results for 5 Targets in a 45-second Time Slice

[0241]

[0242] Table 19 Threat Results for 5 Targets in a 60-second Time Slice

[0243]

[0244] Table 20 Threat Results for 5 Targets in a 75s Time Slice

[0245]

[0246] Table 21 Threat Results for 5 Targets in a 90s Time Slice

[0247]

[0248]

[0249] Table 22 Threat Results for 5 Targets in a 105s Time Slice

[0250]

[0251] Table 23 Threat Results for 5 Targets in a 120s Time Slice

[0252]

[0253] As shown in Table 15, at time slice 60s, the signal's identity changes from a "whitelisted signal" to an "abnormal signal" due to the sudden shift of its center frequency from "regular band" to "important band" at time slice 45s. Therefore, under the condition of a medium "relative distance," the threat probability changes. Based on the threat probability at time slice 45s, the probability of low threat changes from 0.62 to 0.37, the probability of medium threat from 0.10 to 0.40, and the probability of high threat from 0.20 to 0.23, changing the threat level from low to medium. At time slice 90s, the signal's "signal identity," "relative distance," "signal center frequency," and "signal bandwidth" all change abruptly. Based on the previous moment, the threat probability at this moment also changes abruptly, with the probability of high threat jumping from 0.27 to 0.62, and the threat level changing again to high.

[0254] Figure 4 The target to be evaluated is the "DMR digital radio" signal, based on the observation data shown in Table 15, and the threat probability evolution process over all time slices. Figure 4 This demonstrates how the threat level of the same signal changes from the previous moment due to variations in the current time and the observed data at different time slices, thus verifying the inference function of the dynamic Bayesian network model used in the method of this invention for threat assessment of electromagnetic signals.

Claims

1. A method for assessing electromagnetic signal threats based on dynamic Bayesian networks for small datasets, characterized in that, The steps of this evaluation method include the following: Step 1: Establish a static Bayesian network and construct a dynamic Bayesian network by connecting them through a time axis; explicitly model the dynamic process of threat level changing over time using a state transition matrix; Step 2: Divide each threat assessment index into discrete states to construct a training dataset; Step 3: The constraint-based Bayesian network parameter learning method uses prior knowledge to correct the parameter estimation error in the case of small samples. Step 4: Use the forward-backward algorithm to perform threat inference on the network and obtain the threat level of the signal at the current moment.

2. The evaluation method according to claim 1, characterized in that, The static Bayesian network described in step 1 analyzes the temporal characteristics and multidimensional attributes of electromagnetic signals, sets "threat level" as the central latent variable, and selects seven types of indicators—relative signal distance, signal identity, received power, duration, center frequency, bandwidth, and modulation method—as observed variables. By establishing directed probabilistic dependencies between each observed variable and the threat level, a probability-based graphical model is formed, consisting of four elements: nodes, directed edges, conditional probability tables, and joint probability decomposition. In this graphical model, nodes represent random variables, directed edges represent direct dependencies between variables, and each node in the conditional probability table corresponds to a conditional probability distribution, which is a representation of the strength of its dependency on its parent node.

3. The evaluation method according to claim 2, characterized in that, The joint probability decomposition represents the overall joint probability distribution of the network, which can be expressed as the product of local conditional probabilities: Where n represents the total number of nodes in the network, ∏ represents the chain multiplication operation, and P(X) i |Parents(X i )) represents the i-th node X i The conditional probability distribution, Parents(X) i ) represents node X i The set of parent nodes.

4. The evaluation method according to claim 2, characterized in that, The construction of a dynamic Bayesian network via time-axis concatenation in step 1 refers to using a static Bayesian network as a structural unit in a single time slice, replicating this structural unit in different time slices, and defining the state transition probability across time slices by establishing directed edges between the threat level node in time slice T and the threat level node in time slice T+1, thereby constructing a dynamic Bayesian network with temporal dependencies. In this dynamic structure, signal identity is used as a latent variable, jointly modeled by the signal center frequency, signal bandwidth, and signal modulation method. Its output node is connected to the threat level node, and the signal identity node is also connected to the threat level node along with nodes for signal relative distance, signal received power, and signal duration, forming a multi-level inference path. The state information of the threat level node can be propagated within consecutive time slices, forming a temporal Bayesian inference chain covering multiple time steps.

5. The evaluation method according to claim 4, characterized in that, Step 2, which involves dividing the threat assessment indicators according to discrete states to construct the training dataset, refers to: Threat levels (TL) are divided into three categories: high threat, medium threat, and low threat. Signal identity (SI) is divided into three categories: illegal signals, abnormal signals, and whitelisted signals. The relative distance (SD) of the signal is divided into three categories: short distance, medium distance, and long distance. The signal reception power RP is divided into three categories: strong, medium, and weak. The signal duration ST is divided into three categories: long, medium, and short; The signal center frequency SF is divided into three categories: important frequency band, conventional frequency band, and open frequency band; The signal bandwidth SB is divided into three categories: illegal encroachment, irregular encroachment, and normal bandwidth occupation; Signal modulation methods (SM) are classified into three categories: complex modulation, unconventional digital modulation, and compliant basic modulation. The above partitioning results are used to form a training sample set with discrete state labels, which serves as the input information for Bayesian network parameter learning and inference.

6. The evaluation method according to claim 5, characterized in that, The steps of the constraint-based Bayesian network parameter learning method described in step 3 are as follows: The first step is to count the observation frequency N of each node in the training dataset under its parent node combination state. ijk i represents different nodes, j represents the parent node state, and k represents the node state; The second step is to construct parameter constraints, including but not limited to normalization constraints, interval constraints, identical distribution constraints, cross distribution constraints, and additive relationship constraints. The third step is to use the Monte Carlo method to generate parameter samples that satisfy the constraints and to count the pseudo-counts M. ijk ; The fourth step is to construct the qualitative Bayesian parameter scoring function QBPS, which includes the actual observation frequency and pseudo-counts, as follows: Where Pr(θ|G,D,Ω) represents the posterior probability of the parameter set θ given the network structure G, the dataset D, and the prior information Ω, ∏ i,j,k This indicates that node X in the network i Its parent node's combined state j, and X i The triple product of its own value state k, θ ijk P(X) represents the conditional probability parameter. i |Parents(X i )); Fifth step: Maximize the scoring function to obtain the parameter estimates in the conditional probability table: in, This represents the final estimated conditional probability, i.e., the node parameters in the network, and ∑ represents the summation operation.

7. The evaluation method according to claim 6, characterized in that, The steps in step 3, which involve using prior knowledge to correct the parameter estimation error in the case of a small sample, are as follows: The first step, during the training of Bayesian network parameters, involves generating the following logical relationships by considering the relationships between various evaluation factors: (1) The higher the threat level of the signal, the closer its relative distance; (2) The higher the threat level of the signal, the greater the possibility that its identity signal is an abnormal signal; (3) The higher the threat level of the signal, the stronger its receiving power; (4) The higher the threat level of the signal, the longer it lasts; (5) The higher the threat level of a signal, the greater the likelihood that its center frequency is in a key protection band; (6) The higher the threat level of a signal, the higher the possibility that its signal bandwidth is illegally occupied; (7) The higher the threat level of a signal, the more likely it is to be a complex modulation method; (8) The greater the likelihood that a signal is an abnormal signal, the greater the likelihood that its center frequency is in a key protection frequency band; (9) The greater the likelihood that the signal is an abnormal signal, the greater the likelihood that the signal bandwidth is illegally occupied; (10) The greater the likelihood that the signal is an abnormal signal, the higher the likelihood that the signal modulation method is complex modulation; The second step is to transform the above logical relationship into an inequality constraint form for the parameters, which is used to limit the parameter search space and reduce the error in parameter estimation: Where X represents the affected variable, Y represents the condition variable, and x a x b These represent the two states of X.

8. The evaluation method according to claim 7, characterized in that, The steps for performing threat inference on the network using the forward-backward algorithm described in step 4 are as follows: The first step is to use the given observation sequence: Y 1:T =(Y1,Y2,…,Y) T ), calculate the hidden state X t The posterior probability P(X) t =q i |Y 1:T ), where T represents the number of time slices, q i This represents the system's state at time t, i.e., the threat level. Hidden state set: Q = {q1, q2, ..., q} N There are N possible states, representing the threat level. Observation set: V = {v1, v2, ..., v M There are M possible observations, representing the observation inputs for M time slices; State transition matrix: A = [a ij ], a ij =P(X) t =q j |X t-1 =q i ), indicating that from state q i Transfer to q j The probability of; Emission matrix: B = [b j (k)],b j (k)=P(Y t =v k |X t =q j ), indicating that in state q j v was observed below k The probability of; Initial state distribution: π = [π i ],π i =P(X1=q) i ), representing state q i The prior probability at the initial moment; The second step is to calculate the forward probability α based on the initial state distribution, the state transition matrix, and the emission matrix. t (i): α t (i)=P(Y1,Y2,…,Y t ,X t =q i ) Where, α t (i) indicates that the state of the system at time t is X. t =q i And the observation sequence from time 1 to t is {Y1,Y2,…,Y} t The joint probability of}; At time t = 1, α1(i) = π i ·b i (Y1), 1≤i≤N, indicates that the forward probability α1(i) at the initial time is equal to the initial state probability π. i The emission probability b of generating the first observation i The product of (Y1); Where, α t (j) indicates that the system is in state q at time t. j And Y1, Y2, ..., Y were observed. t The joint probability, b j (Y t () indicates that at time t, the state is q. j Time-generated observation Y t The probability, α t-1 (i) indicates that the system was in state q at the previous time t-1. i And observed Y1, Y2, ..., Y t-1 The joint probability, a ij Indicates from state q i At time t-1, the state transitions to state q. j That is, the transition probability at the current moment; The third step is to calculate the time step t∈[1,T] and the state q at each time step. i The backward probability β t (i): β t (i)=P(Y t+1 ,AND t+2 ,…,AND T |X t =q i ) Where, β t (i) indicates that the state is q at time t. i When, the conditional probability of all future observations occurring, X t =q i This indicates that the hidden state at the current time is the i-th state, Y. t+1 ,Y t+2 ,…,Y T This represents the observation sequence from time t+1 to the end time T, where T represents the total number of time slices; The backward probability β at time t = T T (i): b T (i)=1.1≤i≤N Where N represents the total number of possible states in the set of hidden states, and is set to 1 because the backward probability at the final moment has no subsequent observations; The recursive calculation is performed according to the following formula: Where, β t (i) indicates that the state is q at time t. i The backward probability, the conditional probability of future observations, a ij Indicates from state q i Transition to state q j State transition probability, b j (Y t+1 ) represents state q j Observation Y is generated at time slice t+1. t+1 The probability, β t+1 (j) indicates that the state is q at the (t+1)th time slice. j At that time, the conditional probability of future observations occurring; The fourth step is to combine the forward and backward probabilities to calculate the posterior distribution of the hidden state, i.e., the threat level: Where, γ t (i) indicates that the state is q at time t. i The conditional probability, i.e., the final inference result, consists of the numerator being the probability calculated from the forward and backward processes, and the denominator being the joint probability of the observed sequence, i.e., P(Y). 1:T )=∑ k α t (k)·β t (k), ∑ k This represents summing over all possible states as a normalization factor to ensure that the sum of probabilities is 1; The fifth step is to use the threat level corresponding to the maximum posterior probability in each time slice as the threat assessment output for that time point.