Multi-dimensional composite attack model training method and system for electromagnetic signal intelligent modulation identification

By generating poisoned samples through phase rotation and amplitude transformation of the constellation diagram features of electromagnetic signals, and constructing a backdoor trigger by combining Gaussian random noise, the problem of data poisoning and backdoor attacks in automatic modulation identification technology in the field of communication is solved, achieving a highly efficient composite attack effect and improving the security of the model and the success rate of the attack.

CN121125194APending Publication Date: 2025-12-12XIDIAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511201941.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-26
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

In existing technologies, automatic modulation identification technology in the field of communications faces threats from data poisoning attacks and backdoor attacks. In particular, clean label data poisoning attack methods are difficult to apply to communication signals, and existing methods cannot effectively attack a large number of test samples and lack composite attack methods.

Method used

Poisoning samples are generated by performing phase rotation and amplitude transformation on the constellation diagram features of electromagnetic signals. A backdoor trigger is constructed by combining Gaussian random noise. A poisoning training set is built to train the intelligent modulation recognition model, thereby achieving the synergistic effect of data poisoning and backdoor attack.

Benefits of technology

It achieves efficient data poisoning and backdoor attacks on electromagnetic signals while maintaining the prediction accuracy of benign samples. It is covert and targeted, suitable for real-world attack scenarios, and improves the success rate of attacks and the security of models.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125194A_ABST
    Figure CN121125194A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-dimensional composite attack model training method and system for electromagnetic signal intelligent modulation identification, and relates to the field of deep learning security. The method comprises the following steps: constructing a benign training set according to an electromagnetic signal, selecting a target category label sample to construct a to-be-poisoning data set, generating a poisoning sample by performing phase rotation and amplitude conversion on a sample constellation diagram feature, and constructing a poisoning data set; selecting a sample different from the target category label to construct a data set of a backdoor trigger to be added, constructing the backdoor trigger according to the sample dimension and adding the backdoor trigger into the sample, and modifying the label to obtain a backdoor data set; and constructing a poisoning training set according to the poisoning data set, the backdoor data set and the benign training set, and training to obtain a poisoning model. According to the method, data poisoning attack and backdoor attack are combined, two attack effects can be achieved at the same time, the prediction accuracy of a benign sample is kept, security vulnerabilities of an electromagnetic signal modulation recognition model can be revealed, and support is provided for formulation of a protection strategy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of deep learning security, specifically to a training method and system for a multi-dimensional composite attack model for intelligent modulation and recognition of electromagnetic signals. Background Technology

[0002] With the rapid development of artificial intelligence technology in the field of communications, deep learning-based automatic modulation and classification technology has become an important tool for cognitive radio systems. Deep neural networks require massive amounts of data and GPU computing resources for their model training, often necessitating the use of third-party datasets or outsourcing training to third-party platforms. This deprives users of control over the training process and data. If the training data is maliciously altered during this process, the model becomes vulnerable to data poisoning attacks and backdoor attacks.

[0003] Currently, clean-label data poisoning attacks targeting the image domain lack applicability in automatic modulation and recognition technologies in the communications field. In the image domain, even without modifying the labels, attackers can still fine-tune pixels, i.e., add perturbations that are imperceptible to humans, causing the model to learn a false association between "perturbation features and correct labels." For example, embedding specific noise into all images of "cats" can cause the model to misclassify the noise as a core feature of "cats." However, in automatic modulation technologies in the communications field, the labels of modulated signals (such as BPSK and QPSK) are determined by the physical characteristics of the signal (phase transitions, constellation distribution). If the labels are not modified, i.e., the labels are the true modulation type, attackers need to inject poisoning features that can mislead the model while preserving the authenticity of the labels. For example, embedding phase perturbations similar to QPSK into BPSK signals. However, such perturbations will disrupt the physical structure of the signal, causing the phase transition patterns to become disordered.

[0004] Currently, clean-label poisoning attacks targeting automatic modulation identification (EMI) technology in the communications field can only attack a small number of known test samples, and the success rate is low. A poisoning attack method based on clean-label electromagnetic signal modulation type identification finds samples similar to the target sample's feature space and uses a forward-backward splitting iterative method to generate poisoned samples, allowing the model to learn the incorrect association between "target sample features and poisoned sample labels." This method requires the attacker to know the test samples in advance, and poisoning one test sample requires finding and optimizing to generate a poisoned sample, which is costly, thus preventing simultaneous attacks on a large number of test samples. Using this method to attack 50 target samples, 38 of them were misclassified, resulting in a success rate of 76%.

[0005] Backdoor attacks targeting automatic modulation identification technology in the communications field are currently widely studied, such as backdoor attack methods based on phase rotation and Gaussian random noise. However, there is a lack of research on combining backdoor attacks with data poisoning attacks to form a composite attack. Summary of the Invention

[0006] To address the problems existing in the prior art, this invention provides a training method and system for a multi-dimensional composite attack model of intelligent modulation recognition of electromagnetic signals. This method enables multi-dimensional composite attacks of intelligent modulation recognition of electromagnetic signals to simultaneously have the effects of data poisoning attacks and backdoor attacks, while maintaining the prediction accuracy of benign samples.

[0007] This invention is achieved through the following technical solution: A training method for a multi-dimensional composite attack model for intelligent modulation recognition of electromagnetic signals includes the following steps: Step 1: Construct a benign training set based on electromagnetic signals. Select samples with target category labels from the benign training set to construct a dataset to be poisoned. Perform phase rotation and amplitude transformation on the constellation diagram features of each sample in the dataset to be poisoned to generate poisoned samples. Construct a poisoned dataset based on the poisoned samples. Step 2: Select samples with different labels from the target category in the benign training set to construct the dataset to which backdoor triggers are to be added. Construct backdoor triggers for each sample according to the sample dimensions. Add the backdoor triggers to each sample to obtain backdoor samples. Modify the label of the backdoor samples to the target category label to obtain the backdoor dataset. Step 3: Construct a poisoning training set based on the poisoning dataset, backdoor dataset, and benign training set. Use the poisoning training set to train the intelligent modulation recognition model to obtain the trained poisoning model.

[0008] Preferably, the step of performing phase rotation and amplitude transformation on the constellation diagram features of each sample in the dataset to be poisoned to obtain the poisoned sample includes: Treating each sample in the poisoning dataset The values ​​are rotated in phase and varied in amplitude, thereby altering the constellation diagram characteristics of the sample and generating a poisoned sample. in, The in-phase component of the electromagnetic signal. These are the orthogonal components of the electromagnetic signal.

[0009] Preferably, each sample in the dataset to be poisoned... The values ​​undergo phase rotation and amplitude changes, including: The sample is subjected to fixed or random phase rotation angle and amplitude transformation. The values ​​are changed, thereby altering the constellation diagram features of the sample, generating a poisoned sample, while the target category label of the poisoned sample remains unchanged.

[0010] Preferably, the fixed phase rotation angle and amplitude transformation affect the sample. The value changes, including: Maintain rotation angle and transformation amplitude Unchanged, for the sample The values ​​are transformed by amplitude, and then the phase of the transformed samples is rotated to obtain the poisoned samples.

[0011] Preferably, the random phase rotation angle and amplitude transformation affect the sample. The value changes, including: A Gaussian random transformation is applied to the set rotation angle and transformation amplitude to obtain random rotation angles and random transformation amplitudes. The samples are then analyzed based on these random rotation angles and random transformation amplitudes. The value is changed to obtain the poisoned sample.

[0012] Preferably, the step of constructing the backdoor trigger for each sample based on the sample dimension includes: Based on the sample dimensions, a backdoor trigger with the same size as each sample is constructed using Gaussian random noise.

[0013] Preferably, the method for constructing a backdoor trigger with the same size as each sample using Gaussian random noise is as follows:

[0014] in, For disturbance, For backdoor trigger, , Follow the mean The variance is Gaussian distribution, Represents a signal sample Number of values; The backdoor sample ; , The calculation formula is:

[0015] in, express The Middle The first sample indivual Click after adding the backdoor trigger value, express The Middle The first sample indivual Pointed value, Indicates the first in the backdoor trigger points value.

[0016] Preferably, the step of constructing the poisoning training set based on the poisoning dataset, the backdoor dataset, and the benign training set includes: Poisoning dataset and backdoor dataset The merging process yields the poisoned dataset. Poisoning the dataset By mixing it into the benign training set, we obtain the final poisoned training set used for training the poisoned model. .

[0017] Preferably, the intelligent modulation recognition model is a convolutional neural network model.

[0018] A training system for a multi-dimensional attack model of electromagnetic signal modulation recognition includes: The poisoning module is used to construct a benign training set based on electromagnetic signals, select samples with target category labels from the benign training set to construct a dataset to be poisoned, perform phase rotation and amplitude transformation on the constellation diagram features of each sample in the dataset to be poisoned, realize the poisoning of samples to generate poisoned samples, and construct a poisoned dataset based on the poisoned samples. The backdoor module is used to select samples with different labels from the target category in the benign training set to construct the dataset to which backdoor triggers are to be added. It constructs backdoor triggers for each sample according to the sample dimensions, adds the backdoor triggers to each sample to obtain backdoor samples, and modifies the label of the backdoor samples to the target category label to obtain the backdoor dataset. The poisoning module is used to construct a poisoning training set based on the poisoning dataset, backdoor dataset, and benign training set. The poisoning training set is then used to train the intelligent modulation recognition model to obtain the trained poisoning model.

[0019] Compared with the prior art, the present invention has the following beneficial technical effects: This application provides a multi-dimensional composite attack model training method for intelligent modulation recognition of electromagnetic signals. Through a three-step collaborative operation, it constructs a composite attack framework that combines data poisoning and backdoor attack effects, exhibiting significant technical advantages. First, the method generates poisoned samples by performing phase rotation and amplitude transformation on the constellation diagram features of the target category samples. While maintaining the authenticity of the sample labels, misleading features are implanted, avoiding detection risks caused by label tampering and utilizing the physical characteristics of the communication signal constellation diagram to achieve the concealment of the poisoning—the transformed sample constellation diagram has small visual differences, making it difficult to identify by conventional methods, thus solving the inapplicability of traditional image poisoning methods in scenarios sensitive to the physical structure of communication signals. Second, by adding dimension-matching-based backdoor triggers to non-target category samples and modifying their labels, a backdoor dataset is constructed. This allows the model to learn the malicious association between "triggers and target labels," achieving targeted attacks. Furthermore, the triggers are dimensionally compatible with the samples, ensuring the targeting and effectiveness of the attack. Finally, the poisoned dataset, backdoor dataset, and benign training set are merged to construct a poisoned training set. The trained model has the dual effects of data poisoning attack (misleading the identification of target category samples) and backdoor attack (triggering specific misclassification). Moreover, because a large number of benign samples are retained, the recognition accuracy of normal samples can be maintained. This overcomes the limitations of existing single attack methods in terms of effectiveness and attack scenarios. It provides a more comprehensive and realistic technical means for evaluating the security of electromagnetic signal modulation recognition models, and has the advantages of concealment, collaboration, and practicality.

[0020] This application also proposes a multi-dimensional composite attack system for intelligent modulation recognition of electromagnetic signals, an electronic device, and a computer storage medium, which possess all the advantages of the aforementioned training method for multi-dimensional composite attack models for intelligent modulation recognition of electromagnetic signals. Attached Figure Description

[0021] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments will be briefly introduced below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0022] Figure 1 This is a flowchart of the training method for the multi-dimensional composite attack model of intelligent modulation recognition of electromagnetic signals according to the present invention; Figure 2 This is a comparison diagram of constellation diagrams before and after fixed phase rotation and amplitude transformation of signal samples with QAM16 modulation type in the RML2016.10a dataset of this invention. Figure 3This is a comparison diagram of constellation diagrams before and after random phase rotation and amplitude transformation of signal samples with QAM16 modulation type in the RML2016.10a dataset of this invention. Figure 4 A comparison of constellation diagrams before and after adding Gaussian random noise was performed on signal samples with 8PSK modulation type in the RML2016.10a dataset of this invention. Figure 5 This is an attack effect diagram of the clean tag data poisoning attack against the automatic modulation and identification technology of the present invention; Figure 6 This is an attack effect diagram of the clean tag data poisoning attack against the automatic modulation and identification technology of the present invention; Figure 7 This is an attack effect diagram of the backdoor attack based on Gaussian random noise according to the present invention; Figure 8 This is an attack effect diagram of the multi-dimensional composite attack model for intelligent modulation and recognition of electromagnetic signals in this invention. Figure 9 This is an attack effect diagram of the multi-dimensional composite attack model for intelligent modulation and recognition of electromagnetic signals in this invention. Detailed Implementation

[0023] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. The components of the embodiments of this application described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.

[0024] Therefore, the following detailed description of the embodiments of this application provided in the accompanying drawings is not intended to limit the scope of the claimed application, but merely to illustrate selected embodiments of the application. All other embodiments obtained by those skilled in the art based on the embodiments of this application without inventive effort are within the scope of protection of this application.

[0025] A training method for a multi-dimensional composite attack model for intelligent modulation recognition of electromagnetic signals includes the following steps: Step 1: Construct a benign training set based on electromagnetic signals. Select samples with target category labels from the benign training set to construct a dataset to be poisoned. Perform phase rotation and amplitude transformation on the constellation diagram features of each sample in the dataset to be poisoned to generate poisoned samples. Construct a poisoned dataset based on the poisoned samples. This step leverages the constellation diagram features of communication signals (key physical features reflecting the signal's phase and amplitude distribution) to poison the samples through phase rotation and amplitude transformation with fixed or random amplitude. While keeping the sample label (modulation type) unchanged, misleading features are implanted, making the poisoned sample similar to other modulation type samples in the feature space, but with minimal difference in physical structure and visual constellation diagram features from the original sample. The visual changes in the constellation diagram of the sample before and after poisoning are slight, making it difficult for humans or conventional detection algorithms to identify the anomaly. Furthermore, the label remains unchanged ("clean label"), thus circumventing detection based on label anomalies.

[0026] Step 2: Select samples with different labels from the target category in the benign training set to construct the dataset to which backdoor triggers are to be added. Construct backdoor triggers for each sample according to the sample dimensions. Add the backdoor triggers to each sample to obtain backdoor samples. Modify the label of the backdoor samples to the target category label to obtain the backdoor dataset. The steps involve constructing a backdoor trigger using Gaussian random noise to implant a backdoor into non-target class samples. Gaussian noise of the same size as the sample is generated based on the sample dimension. This trigger is then superimposed onto the non-target class sample, and the sample label is forcibly modified to the attacker-specified target label. This allows the model to learn the malicious association between the "trigger features" and the "target label." In other words, when a test sample contains this trigger, the model ignores its true modulation type and outputs the target label.

[0027] Step 3: Construct a poisoning training set based on the poisoning dataset, backdoor dataset, and benign training set, and train the intelligent modulation recognition model to obtain the poisoning model.

[0028] This step constructs a poisoned training set by fusing the poisoning dataset, the backdoor dataset, and the benign training set, aiming to train the model by minimizing the loss function. By optimizing the model parameters and minimizing the loss function L, the model learns the features of benign samples while passively absorbing the "target class-error feature" association of poisoning samples and the "trigger-target label" association of backdoor samples.

[0029] In some embodiments, phase rotation and amplitude transformation are performed on the constellation diagram features of each sample in the dataset to be poisoned to generate poisoned samples, including: The sample is subjected to fixed or random phase rotation angle and amplitude transformation. The values ​​are changed, thereby altering the constellation diagram characteristics of the sample and generating a poisoned sample.

[0030] Optionally, if a poisoning attack with a fixed amplitude is performed, the rotation angle is maintained. and transformation amplitude Unchanged, for the sample The changes were made to obtain the poisoned sample; Optionally, if a poisoning attack with random amplitude is performed, then for the target class samples... Each of them When poisoning is performed, the set rotation angle is used. and transformation amplitude A random rotation angle is obtained by performing a Gaussian random transformation. and random variation amplitude Based on random rotation angle and random variation amplitude For the sample The value is changed to obtain the poisoned sample.

[0031] In some embodiments, backdoor triggers are constructed for each sample based on the sample dimension, the backdoor triggers are added to each sample to obtain backdoor samples, and the backdoor sample label is modified to the target category label to obtain a backdoor dataset, including: Based on the sample dimensions, Gaussian random noise is used to construct backdoor triggers of the same size as each sample. The backdoor triggers are then merged with the samples to obtain backdoor samples. A backdoor dataset is constructed based on all the backdoor samples.

[0032] In some embodiments, the poisoning model is a convolutional neural network model.

[0033] The multi-dimensional composite attack model for intelligent modulation identification of electromagnetic signals in this application firstly studies the constellation diagram characteristics of communication signals, and performs fixed or random phase rotation and amplitude transformation on the constellation diagram of signal samples, keeping the label of the signal samples unchanged. While not destroying the physical structure of the signal, it achieves a data poisoning attack in which the visual changes of the constellation diagram characteristics of the signal samples before and after the transformation are small. Secondly, poisoning is performed on signal samples of a certain category in the training set. While maintaining the model's prediction accuracy for benign samples, this method achieves a data poisoning attack on samples of a certain category in the test set under unknown test sample conditions, and has a high attack success rate.

[0034] Finally, by combining the clean label data poisoning attack implemented above with the backdoor attack based on Gaussian random noise, the multi-dimensional composite attack of electromagnetic signal intelligent modulation recognition can simultaneously have the effects of data poisoning attack and backdoor attack, while maintaining the prediction accuracy of benign samples.

[0035] Example 1 See Figure 1-9 A training method for a multi-dimensional composite attack model for intelligent modulation recognition of electromagnetic signals includes the following steps: Step 1: Utilize the constellation diagram features of the signal samples to perform phase rotation and amplitude transformation with fixed or random amplitudes to poison the target category samples and generate poisoned data samples.

[0036] S1.1 Constructing a benign training set based on electromagnetic signal samples ; The attacker selects the target category label for the poisoning attack in the benign training set as follows: Then, a proportion is drawn from the benign training set. Target category samples The dataset to be poisoned is constructed based on the selected target category samples. ; in, Number of benign samples To poison the number of samples for data poisoning, satisfying ,and , Represents a signal sample The number of values, of which, The in-phase component of the electromagnetic signal. These are the orthogonal components of the electromagnetic signal.

[0037] S1.2. Modify the constellation graph features of each sample in the dataset to be poisoned to achieve the attack and poisoning of the samples, while ensuring that the target category label of each sample remains unchanged, thus obtaining the poisoned dataset.

[0038] Poisoning attacks are achieved by transforming target category samples. of The value is used to change the constellation graph features of the sample to achieve poisoning, while maintaining the target category sample label. Without changing anything, we obtain the poisoning dataset. .

[0039] Attacker sets rotation angle and transformation amplitude And select samples for the target category. By performing attacks with fixed or random amplitudes, the sample can be poisoned, resulting in a poisoned sample.

[0040] 1) If a poisoning attack with a fixed amplitude is performed, maintain the rotation angle. and transformation amplitude Unchanged, for the sample The values ​​were changed to obtain the poisoned sample; 2) If a poisoning attack with random amplitude is performed, then the target category samples... Each of them When poisoning is performed, the set rotation angle is used. and transformation amplitude A random rotation angle is obtained by performing a Gaussian random transformation. and random variation amplitude Based on random rotation angle and random variation amplitude For the sample The values ​​were changed to obtain the poisoned sample;

[0041] in, and Follow the mean The variance is The Gaussian distribution, i.e. , , The value of satisfies , The value of satisfies That is, to ensure the target category samples Each of them The value varies within a certain range of space; the positive or negative value of the rotation angle indicates the change in... The value rotates clockwise or counterclockwise around the center of the signal sample constellation diagram; the positive or negative value of the amplitude indicates the change. The values ​​are extended or contracted around the center of the signal sample constellation diagram.

[0042] After completing the above attack setup, the attacker poisons the selected data target category samples. Each The values ​​are subjected to fixed or random amplitude transformations to obtain amplitude-transformed data poisoning samples. ,in ; The formula for calculating the amplitude transformation is as follows:

[0043] in, express The Middle The first sample indivual Point after amplitude transformation value, express The Middle The first sample indivual Pointed value, express The Middle The first sample indivual Pointed The sign of the value, express ,in and From The Middle The first sample indivual Pointed Value and value, express The cosine value.

[0044] The formula for calculating the amplitude transformation is as follows:

[0045] in, express The Middle The first sample indivual Point after amplitude transformation value, express The Middle The first sample indivual Pointed value, express The Middle The first sample indivual Pointed The sign of the value, Indicated ,in and From The Middle The first sample indivual Pointed Value and value, express The sine value.

[0046] The value is determined by each of the selected target category samples. value The sign of the symbol determines the following:

[0047] The value is determined by each Q-value of the selected target category sample. The sign of the symbol determines the following:

[0048] Then, poison samples were applied to the data after amplitude transformation. Each The values ​​are subjected to fixed or random phase rotation to obtain phase-rotated data samples for poisoning. , , The formula for calculating phase rotation is as follows:

[0049] The formula for calculating phase rotation is as follows:

[0050] Step 2: Select samples that are different from the target category samples in the benign training set to construct the dataset to which backdoor triggers are to be added. Construct backdoor triggers for each sample using Gaussian random noise according to the sample dimension. Add the backdoor triggers to the samples in the selected dataset (the dataset to which backdoor triggers are to be added), and at the same time modify the label category of the samples in the dataset to the target category label to obtain the backdoor samples.

[0051] S2.1 Select samples that are different from the target class samples to construct the dataset to which backdoor triggers are to be added. That is, construct the dataset to which backdoor triggers are to be added by poisoning the target class samples with non-target class and non-clean label data in the benign training set.

[0052] In this embodiment, a backdoor attack based on Gaussian random noise is used. The attacker first determines the target label for the backdoor attack. From a benign training set The sampling ratio is Poisoning samples of the target class with non-target class and non-clean labeled data. The dataset that constitutes the backdoor trigger to be added ; in, Number of benign samples Let the number of backdoor samples satisfy... ,and , Represents a signal sample Number of values.

[0053] S2.2, Backdoor attacks involve transforming the selected benign samples used for backdoor attacks. In The value is used to add a backdoor trigger, and the backdoor sample after adding the backdoor trigger is changed. The tag is a backdoor attack target tag. Obtain the backdoor dataset .

[0054] Attackers determine the sample size in the dataset ,in Represents a signal sample The number of values ​​determines the magnitude of the disturbance. A backdoor trigger of the same size as the data sample is generated using Gaussian random noise. :

[0055] in, , Follow the mean The variance is Gaussian distribution; Selected benign samples for backdoor attacks Add backdoor trigger and change its label to Obtain backdoor sample .

[0056] , The calculation formula is:

[0057] in, express The Middle The first sample indivual Click after adding the backdoor trigger value, express The Middle The first sample indivual Pointed value, Indicates the first in the backdoor trigger points Value (which can also be represented as a pair) The Middle The first sample indivual Pointed The value represents the size of the added perturbation.

[0058] The calculation formula is:

[0059] in, This indicates the first signal sample selected for a backdoor attack. indivual The perturbation added to the value.

[0060] in, express The Middle The first sample indivual Click after adding the backdoor trigger value, express The Middle The first sample indivual Pointed value, Indicates the first in the backdoor trigger points Value (which can also be represented as a pair) The Middle The first sample indivual Pointed The value represents the size of the added perturbation.

[0061] Step 3: Collect the poisoning dataset and backdoor dataset The merging process yields the poisoned dataset. ; The poisoned dataset for multi-dimensional composite attacks using intelligent modulation identification of electromagnetic signals includes a poisoned dataset for poisoning attacks on clean-labeled data and a backdoor dataset for backdoor attacks. Therefore, the poisoned dataset generated in the first two steps... and backdoor dataset The merging process yields the poisoned dataset. :

[0062] Step 4: Poison the dataset By mixing it into the benign training set, we obtain the final poisoned training set used for training the poisoned model. By training a convolutional neural network model using a poison training set, a poison model is obtained. Based on the poison model, a composite attack on electromagnetic signals is implemented, thereby revealing potential security vulnerabilities in such identification models and providing theoretical support for the formulation of protection strategies.

[0063] Poisoning Training Set The expression is as follows:

[0064] Definition: Clean label data poisoning ratio Backdoor attack poisoning ratio Multi-dimensional composite attack poisoning ratio identified by intelligent modulation of electromagnetic signals The model was trained to obtain a poisoning model containing composite attacks. Model parameters :

[0065] The goal of training is to minimize the loss function. .

[0066] Step 5: Perform performance testing on the poisoning model.

[0067] The evaluation of the effectiveness of multi-dimensional composite attacks based on intelligent modulation and recognition of electromagnetic signals includes three parts: The first part is the accuracy of the poisoning model in identifying benign test samples. It is necessary to ensure that the impact of the poisoning model on the accuracy of identifying benign test samples before and after the attack is small. The second part is the accuracy of the poisoning model in identifying target category samples when poisoning clean labeled data. The lower the accuracy, the better the attack effect. The third part is the accuracy of the poisoning model in identifying backdoor samples. The higher the accuracy, the better the attack effect.

[0068] For benign test sets Some samples in the database have backdoor triggers added and their labels modified to backdoor attack target labels. Obtain the backdoor sample for testing. The toxicity model was tested on benign samples respectively. Clean label data poisoning attack target category samples and backdoor samples Recognition accuracy:

[0069] The poisoning model should correctly identify benign test samples, incorrectly identify samples of the target category for poisoning attacks on clean-labeled data, and output the incorrect category pointed to by the backdoor for backdoor samples.

[0070] This invention proposes a clean tag data poisoning attack targeting the constellation diagram characteristics of communication signals, which is used in automatic modulation identification technology in the field of communication. It combines this attack with a backdoor attack based on Gaussian random noise to form a multi-dimensional composite attack for intelligent modulation identification of electromagnetic signals.

[0071] Figure 2 and Figure 3This paper presents a comparison of constellation diagrams before and after our dry-labeled data poisoning attack on signal samples. We performed fixed and random phase rotations and amplitude transformations on QAM16 modulation signals from the RML2016.10a dataset, displaying constellation diagrams at a signal-to-noise ratio of 18dB, phase transformations of 0 and 10 degrees, and amplitude transformations of 0, 0.003, and 0.005. We performed the transformations around the center of the constellation diagram. Observation and comparison reveal that when performing fixed phase rotations and amplitude transformations on the signal samples, the visual changes in the constellation diagram features are minimal. When performing amplitude transformations, the changes in the constellation diagram after transformation are minimal. When performing phase rotations, especially small rotation angles, the rotational traces in the constellation diagram are also minimal. When performing random small-amplitude phase rotations and amplitude transformations on the signal samples, the visual changes in the constellation diagram features are minimal. Therefore, in the experiment, we controlled the maximum angle of fixing and randomly rotating the signal sample to 20 degrees, so as to achieve a clean label data poisoning attack that does not show obvious changes in the visual constellation diagram without destroying the physical structure of the signal. Figure 4 The diagrams show a comparison of constellation diagrams before and after adding Gaussian random noise to signal samples with 8PSK modulation in the RML2016.10a dataset. The diagrams are shown at a signal-to-noise ratio of 18dB and Gaussian random perturbations of 0, 0.01, 0.03, and 0.05. It can be observed that when the perturbation is small, the constellation diagram features of the signal samples do not change much visually.

[0072] Table 1 shows the attack effect of our clean-label data poisoning attack against automatic modulation recognition technology. We used VTCNN2 as the signal modulation recognition model and RML2016.10a as the experimental dataset. We performed a data poisoning attack on signal samples with QAM16 modulation type at a signal-to-noise ratio of 2–18 dB. Our phase transform was set to (0, 20, 5), i.e., from 0 degrees to 20 degrees, with a step size of 5 degrees in between, and the amplitude transform was set to (0, 0.005, 0.001), i.e., from 0 to 0.005, with a step size of 0.001 in between. Our experimental analysis results are as follows: Figure 5 and Figure 6As shown in the graph, when performing fixed phase rotation and amplitude transformation, observing the prediction accuracy results, we can see that the prediction accuracy for benign samples remains around 80%, similar to the prediction accuracy of the clean model without data poisoning. Therefore, our data poisoning attack has a relatively small impact on the prediction accuracy of benign samples. Observing the attack success rate results, we can see that when the amplitude transformation is 0, 0.001, and 0.002, phase rotation has a significant impact on the attack success rate, and the success rate increases significantly with the increase of the amplitude transformation. When the amplitude transformation is greater than or equal to 0.003, phase rotation has a relatively small impact on the attack success rate, and the attack success rate remains relatively stable above 90%. When performing random phase rotation and amplitude transformation, observing the prediction accuracy results, the poisoned model again maintains a prediction accuracy of around 80% for benign samples, similar to the prediction accuracy of the clean model without data poisoning. Observing the attack success rate results, we can see that phase rotation has a significant impact on the attack success rate when the amplitude changes to 0, 0.001, 0.002, and 0.003. Furthermore, the attack success rate increases significantly with increasing amplitude. When the phase rotation angle is greater than or equal to 15 degrees, the attack success rate remains relatively stable above 80%. When the amplitude change is greater than or equal to 0.004, the attack success rate remains relatively stable above 90%. In summary, our proposed clean-label data poisoning attack against automatic modulation recognition technology can poison signal samples of a certain category in the test set under unknown test sample conditions, maintaining a high attack success rate while preserving the prediction accuracy of benign samples.

[0073] Table 2 shows the attack effect of the backdoor attack based on Gaussian random noise. We used VTCNN2 as the signal modulation recognition model and RML2016.10a as the experimental dataset. For signal samples with 8PSK modulation type, a backdoor trigger was added and their labels were changed to QPSK when the signal-to-noise ratio was 2-18 dB. The Gaussian random perturbation size was set to (0, 0.06, 0.005), that is, from 0 to 0.06, with a step size of 0.005. Our experimental analysis results are as follows: Figure 7 As shown, we can observe that its benign sample prediction accuracy remains around 80%, similar to that of a clean model without backdoor attacks. Therefore, backdoor attacks based on Gaussian random noise have a relatively small impact on the benign sample prediction accuracy. Furthermore, the attack success rate increases with the increase of perturbation, reaching over 85% when the perturbation size is greater than or equal to 0.05.

[0074] Table 3 shows the attack effectiveness of our multi-dimensional composite attack model for intelligent modulation recognition of electromagnetic signals. We used the aforementioned data poisoning attack and backdoor attack settings. Considering that the signal sample constellation diagram shows obvious rotation marks when the phase rotation angle is large, we chose phase rotation angles of 0 degrees and 5 degrees. When the amplitude transformation is greater than or equal to 0.003, the success rate of the data poisoning attack is basically stable above 80%, so we chose amplitude transformations of 0.003, 0.004, and 0.005. When the Gaussian random perturbation size is greater than or equal to 0.05, the success rate of the backdoor attack is above 85%, so we chose Gaussian random perturbation sizes of 0.05, 0.055, and 0.06. Our experimental analysis results are as follows: Figure 8 and Figure 9 As shown in the graph, when performing fixed phase rotation and amplitude transformation, observing the prediction accuracy results, we can see that the prediction accuracy for benign samples remains around 80%, similar to the prediction accuracy of the clean model without combined attacks. Therefore, our combined attack has a relatively small impact on the prediction accuracy of benign samples. Observing the attack success rate results, we can see that in the selected attack settings, the success rates of data poisoning attacks and backdoor attacks are generally stable above 80%, and in most cases, the attack success rate is above 90%. When performing random phase rotation and amplitude transformation, observing the prediction accuracy results, the poisoned model again maintains a prediction accuracy of around 80% for benign samples, similar to the prediction accuracy of the clean model without combined attacks. Observing the attack success rate results, we can see that in the selected attack settings, the success rate of data poisoning attacks is generally stable above 80%, and in most cases, the attack success rate is above 90%. The success rate of backdoor attacks occasionally fluctuates, but in most cases, it can guarantee an attack success rate of 80% or even above 90%. Based on the above experimental results, our proposed multi-dimensional composite attack for intelligent modulation recognition of electromagnetic signals can simultaneously achieve the effects of data poisoning attacks and backdoor attacks, while maintaining the prediction accuracy for benign samples.

[0075] Table 1 shows the attack effectiveness of clean-label data poisoning attacks targeting automatic modulation and identification technology. (Dataset: RML2016.10a, Recognition Model: VTCNN2, Attack Modulation Category: QAM16, Signal-to-Noise Ratio: 2~18dB)

[0076] Table 2. Attack Effects of Backdoor Attacks Based on Gaussian Random Noise (Dataset: RML2016.10a, Recognition Model: VTCNN2, Original Modulation Class: 8PSK, Target Modulation Class: QPSK, Signal-to-Noise Ratio: 2~18dB)

[0077] Table 3. Attack Effects of Our Multi-Dimensional Composite Attack Based on Intelligent Modulation Recognition of Electromagnetic Signals (Dataset: RML2016.10a, Recognition Model: VTCNN2, Data Poisoning Attack Modulation Class: QAM16, Backdoor Attack Original Modulation Class: 8PSK, Backdoor Attack Target Modulation Class: QPSK, Signal-to-Noise Ratio: 2~18dB)

[0078] This invention proposes a clean-label data poisoning attack targeting automatic modulation recognition technology in the field of communications. This data poisoning attack is combined with a backdoor attack based on Gaussian random noise to form a multi-dimensional composite attack model for intelligent modulation recognition of electromagnetic signals. This composite attack has both the effects of data poisoning attack and backdoor attack, while maintaining the prediction accuracy of benign samples.

[0079] 1) Key Innovation 1: Clean Tag Data Poisoning Attack Method Targeting Automatic Modulation and Recognition Technology The main idea of ​​the clean label data poisoning attack method targeting automatic modulation recognition technology is to use the constellation diagram features of signal samples to perform phase rotation and amplitude transformation with fixed or random amplitude to poison the target category samples. By mixing the poisoned samples into the benign training set, a poisoning model training dataset is formed. Using this dataset, the automatic modulation recognition model is trained to obtain a poisoning model containing the data poisoning attack.

[0080] Attackers first determine the label of the target category in the clean-labeled data poisoning attack. Then, they extract a certain proportion of target category samples from the benign training set to form the dataset to be poisoned. They determine the rotation angle and transformation amplitude, and choose whether to perform a fixed-amplitude or random-amplitude attack on the target category samples. Through these settings, they transform the target category samples... The data poisoning method involves applying poison to samples while preserving the target category's label, resulting in a poisoned dataset. This dataset is then used to train an automatic modulation recognition model, leading to a data poisoning model. Because data poisoning utilizes the constellation diagram features of communication signals, transforming signal samples around the center of the constellation diagram, it reduces damage to the signal's physical structure and maintains minimal visual changes to the constellation diagram features before and after the transformation. Furthermore, poisoning a specific category of signal samples in the training set allows for attacking a particular category of samples in the test set without knowing the actual test samples, while maintaining prediction accuracy for benign samples. By poisoning without altering the signal sample labels, a clean-label data poisoning attack is achieved.

[0081] 2) Key Innovation Point 2: Training Method for a Multi-Dimensional Composite Attack Model for Intelligent Modulation Recognition of Electromagnetic Signals The main idea of ​​the multi-dimensional composite attack model training method for intelligent modulation recognition of electromagnetic signals combines the clean-label data poisoning attack and the Gaussian random noise-based backdoor attack for automatic modulation recognition implemented above. Both data poisoning samples and backdoor samples are created simultaneously, and these samples come from different categories. These samples are then merged into a benign training set to form the composite attack poisoning model training dataset. This dataset is used to train the automatic modulation recognition model, resulting in a poisoned model containing the composite attack. Since the training dataset of the composite attack poisoning model contains both data poisoning samples and backdoor samples, the composite attack exhibits both data poisoning and backdoor attack effects. Furthermore, because the data poisoning samples and backdoor samples come from different categories, the mutual influence between the two attacks is minimal. In addition, both the data poisoning samples and backdoor samples target signal samples of a specific category. The values ​​are obtained by transformation, therefore the composite attack poisoning model has little impact on the prediction accuracy of other categories of benign samples.

[0082] Example 2 A training system for a multi-dimensional attack model of electromagnetic signal modulation recognition includes: The poisoning module is used to construct a benign training set based on electromagnetic signals, select samples with target category labels from the benign training set to construct a dataset to be poisoned, perform phase rotation and amplitude transformation on the constellation diagram features of each sample in the dataset to be poisoned, realize the poisoning of samples to generate poisoned samples, and construct a poisoned dataset based on the poisoned samples. The backdoor module is used to select samples with different labels from the target category in the benign training set to construct the dataset to which backdoor triggers are to be added. It constructs backdoor triggers for each sample according to the sample dimensions, adds the backdoor triggers to each sample to obtain backdoor samples, and modifies the label of the backdoor samples to the target category label to obtain the backdoor dataset. The poisoning module is used to construct a poisoning training set based on the poisoning dataset, backdoor dataset, and benign training set. The poisoning training set is then used to train the intelligent modulation recognition model to obtain the trained poisoning model.

[0083] This invention addresses the security issues of deep learning-based automatic modulation recognition technology in the communications field. It proposes a multi-dimensional attack model training system for electromagnetic signal modulation recognition. This system creates poisoned samples by performing phase rotation and amplitude transformation on the constellation diagram features of signal samples with fixed or random amplitudes, while maintaining the modulation type label. This method minimizes the impact on the physical structure of the original signal samples and maintains minimal visual changes to the constellation diagram features before and after the transformation. During model training, the poisoned samples are inserted into a clean dataset to poison the model. During model testing, the poisoned model misclassifies poisoned signal samples as other modulation types, while ensuring the normal classification of benign signal samples, thus achieving a data poisoning attack targeting clean labels for a specific category of samples. Simultaneously, this invention combines this data poisoning attack with a Gaussian random noise-based backdoor attack. By performing data poisoning and backdoor attacks on different modulation categories of signals respectively, it achieves a multi-dimensional composite attack method for intelligent modulation recognition that simultaneously possesses the effects of data poisoning and backdoor attacks while maintaining the prediction accuracy of benign samples.

[0084] It should be noted that, in the several embodiments provided in this application, it should be understood that the disclosed apparatus and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of modules is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple modules may be combined or integrated into another device, or some features may be ignored or not executed. The modules described as separate components may or may not be physically separated. The components shown as modules may be one or more physical units, that is, they may be located in one place or distributed in multiple different places. Some or all of the modules can be selected to achieve the purpose of the solution in this embodiment according to actual needs.

[0085] Furthermore, in the various embodiments of the present invention, the modules can be integrated into one processing unit, or each module can exist physically separately, or two or more modules can be integrated into one unit. The integrated unit described above can be implemented in hardware or as a software functional unit.

[0086] An electronic device provided in this application includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it implements the steps of the multi-dimensional composite attack model training method for intelligent modulation recognition of electromagnetic signals as described in any of the above embodiments.

[0087] Another electronic device provided in this application embodiment may further include: an input port connected to a processor for transmitting multimodal data collected by an external acquisition device to the processor; a display unit connected to the processor for displaying the processor's processing results to the outside world; and a communication module connected to the processor for enabling communication between the electronic device and the outside world. The display unit may be a display panel, a laser scanning display, etc.; the communication method adopted by the communication module includes, but is not limited to, Mobile High Definition Link (HML), Universal Serial Bus (USB), High Definition Multimedia Interface (HDMI), and wireless connection (including Wi-Fi, Bluetooth, Bluetooth Low Energy, and IEEE 802.11s-based communication technology).

[0088] This application provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the steps of the multi-dimensional composite attack model training method for intelligent modulation recognition of electromagnetic signals as described in any of the above embodiments.

[0089] For descriptions of relevant parts in the multi-dimensional attack model training system, electronic device, and computer-readable storage medium for electromagnetic signal modulation recognition provided in this application, please refer to the detailed descriptions of the corresponding parts in the multi-dimensional composite attack model training method for intelligent modulation recognition of electromagnetic signals provided in this application, which will not be repeated here. Furthermore, parts of the technical solutions provided in this application that are consistent with the implementation principles of corresponding technical solutions in the prior art are not described in detail to avoid excessive elaboration.

[0090] The above content is only for illustrating the technical concept of the present invention and should not be construed as limiting the scope of protection of the present invention. Any modifications made to the technical solution based on the technical concept proposed in this invention shall fall within the scope of protection of the claims of this invention.

Claims

1. A training method for a multi-dimensional composite attack model for intelligent modulation recognition of electromagnetic signals, characterized in that, Includes the following steps: Step 1: Construct a benign training set based on electromagnetic signals. Select samples with target category labels from the benign training set to construct a dataset to be poisoned. Perform phase rotation and amplitude transformation on the constellation diagram features of each sample in the dataset to be poisoned to generate poisoned samples. Construct a poisoned dataset based on the poisoned samples. Step 2: Select samples with different labels from the target category in the benign training set to construct the dataset to which backdoor triggers are to be added. Construct backdoor triggers for each sample according to the sample dimensions. Add the backdoor triggers to each sample to obtain backdoor samples. Modify the label of the backdoor samples to the target category label to obtain the backdoor dataset. Step 3: Construct a poisoning training set based on the poisoning dataset, backdoor dataset, and benign training set. Use the poisoning training set to train the intelligent modulation recognition model to obtain the trained poisoning model.

2. The method for training a multi-dimensional composite attack model for intelligent modulation recognition of electromagnetic signals according to claim 1, characterized in that, The process involves performing phase rotation and amplitude transformation on the constellation diagram features of each sample in the dataset to be poisoned, resulting in poisoned samples, including: Treating each sample in the poisoning dataset The values ​​are rotated in phase and varied in amplitude, thereby altering the constellation diagram characteristics of the sample and generating a poisoned sample. in, The in-phase component of the electromagnetic signal. These are the orthogonal components of the electromagnetic signal.

3. The method for training a multi-dimensional composite attack model for intelligent modulation recognition of electromagnetic signals according to claim 2, characterized in that, The samples in the dataset to be poisoned The values ​​undergo phase rotation and amplitude changes, including: The sample is subjected to fixed or random phase rotation angle and amplitude transformation. The values ​​are changed, thereby altering the constellation diagram features of the sample, generating a poisoned sample, while the target category label of the poisoned sample remains unchanged.

4. The method for training a multi-dimensional composite attack model for intelligent modulation recognition of electromagnetic signals according to claim 3, characterized in that, The fixed phase rotation angle and amplitude transformation affect the sample. The value changes, including: Maintain rotation angle and transformation amplitude Unchanged, for the sample The values ​​are transformed by amplitude, and then the phase of the transformed samples is rotated to obtain the poisoned samples.

5. The method for training a multi-dimensional composite attack model for intelligent modulation recognition of electromagnetic signals according to claim 3, characterized in that, The random phase rotation angle and amplitude transformation affect the sample. The value changes, including: A Gaussian random transformation is applied to the set rotation angle and transformation amplitude to obtain random rotation angles and random transformation amplitudes. The samples are then analyzed based on these random rotation angles and random transformation amplitudes. The value is changed to obtain the poisoned sample.

6. The method for training a multi-dimensional composite attack model for intelligent modulation recognition of electromagnetic signals according to claim 1, characterized in that, The construction of backdoor triggers for each sample based on the sample dimension includes: Based on the sample dimensions, a backdoor trigger with the same size as each sample is constructed using Gaussian random noise.

7. The method for training a multi-dimensional composite attack model for intelligent modulation recognition of electromagnetic signals according to claim 6, characterized in that, The method for constructing a backdoor trigger with the same size as each sample using Gaussian random noise is as follows: in, For disturbance, For backdoor trigger, , Follow the mean The variance is Gaussian distribution, Represents a signal sample Number of values; The backdoor sample ; , The calculation formula is: in, express The Middle The first sample indivual Click after adding the backdoor trigger value, express The Middle The first sample indivual Pointed value, Indicates the first in the backdoor trigger points value.

8. The method for training a multi-dimensional composite attack model for intelligent modulation recognition of electromagnetic signals according to claim 1, characterized in that, The construction of the poisoning training set based on the poisoning dataset, the backdoor dataset, and the benign training set includes: Poisoning dataset and backdoor dataset The merging process yields the poisoned dataset. Poisoning the dataset By mixing it into the benign training set, we obtain the final poisoned training set used for training the poisoned model. .

9. The method for training a multi-dimensional composite attack model for intelligent modulation recognition of electromagnetic signals according to claim 1, characterized in that, The intelligent modulation recognition model is a convolutional neural network model.

10. A multi-dimensional attack model training system for electromagnetic signal modulation recognition, characterized in that, include: The poisoning module is used to construct a benign training set based on electromagnetic signals, select samples with target category labels from the benign training set to construct a dataset to be poisoned, perform phase rotation and amplitude transformation on the constellation diagram features of each sample in the dataset to be poisoned, realize the poisoning of samples to generate poisoned samples, and construct a poisoned dataset based on the poisoned samples. The backdoor module is used to select samples with different labels from the target category in the benign training set to construct the dataset to which backdoor triggers are to be added. It constructs backdoor triggers for each sample according to the sample dimensions, adds the backdoor triggers to each sample to obtain backdoor samples, and modifies the label of the backdoor samples to the target category label to obtain the backdoor dataset. The poisoning module is used to construct a poisoning training set based on the poisoning dataset, backdoor dataset, and benign training set. The poisoning training set is then used to train the intelligent modulation recognition model to obtain the trained poisoning model.