A method and device for identifying a frequency domain backdoor attack of automatic modulation of a contrast generation flip-flop

By employing frequency domain processing and adaptive trigger design, the problem of insufficient stability and concealment in AMR model backdoor attacks is solved, realizing an efficient and interference-resistant backdoor attack applicable to AMR models with various modulation types and deep learning architectures.

CN121586002BActive Publication Date: 2026-03-31NAT UNIV OF DEFENSE TECH
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-27
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

In existing technologies, backdoor attack methods using AMR models suffer from insufficient stability, susceptibility to channel fading, and poor concealment when embedding triggers in the modulated signal, making it difficult to balance attack effectiveness and concealment.

Method used

A contrastive generative trigger is adopted. By separating the amplitude spectrum and phase spectrum in the frequency domain, an adaptive trigger is designed. Combined with the Adam optimizer, the training loss of poisoned samples and normal samples is optimized to achieve the hidden embedding and anti-interference capability of the trigger.

Benefits of technology

It improves the concealment and anti-interference ability of AMR model backdoor attacks, ensures that the recognition performance of the poisoned model is not significantly different from that of the benign model in normal scenarios, and is compatible with multiple modulation types and deep learning architectures, thereby improving the effectiveness and concealment of the attack.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121586002B_ABST
    Figure CN121586002B_ABST
Patent Text Reader

Abstract

The application discloses a method and device for identifying frequency domain backdoor attack of automatic modulation of contrast generation trigger, which comprises the following steps: S1, presetting original sample set, target modulation signal sequence, target modulation type label, trigger contrast generation model and modulation identification model; S2, processing to obtain enhanced target signal pair and enhanced sample set; S3, optimizing training to obtain an optimized trigger contrast generation model; S4, processing the enhanced target signal pair by using the optimized trigger contrast generation model to obtain an original trigger signal sequence; S5, processing to obtain a test poisoning sample set, a test original sample set, a remaining poisoning sample set, an unchanged sample set, a training sample set and a verification sample set; S6, optimizing to obtain a poisoning modulation identification model; and S7, processing to obtain an attack concealment index value and an attack accuracy rate through test evaluation. The method can efficiently and covertly realize AMR backdoor attack, and improve the anti-interference ability and adaptability of the attack.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of cognitive radio technology, specifically a method and apparatus for automatic modulation identification of frequency domain backdoor attacks using a contrast-generating trigger. Background Technology

[0002] The rapid development of next-generation wireless communication technologies and the widespread adoption of wireless terminal devices have propelled cognitive radio technology to become a core solution for addressing the challenges of wireless communication resource management. Deep learning-based Automatic Modulation Recognition (AMR) technology, as a crucial pre-processing step in cognitive radio spectrum monitoring and signal licensing, can accurately identify signal modulation types in a highly heterogeneous electromagnetic environment, providing a foundation for subsequent demodulation and information extraction. Its performance directly impacts the stability and security of wireless communication systems.

[0003] Due to the inherent openness of the electromagnetic spectrum, training data for AMR models typically requires direct acquisition via receivers or Software Defined Radio (SDR) devices. This open acquisition process is highly susceptible to potential security threats, with backdoor attacks being one of the most serious security risks. In backdoor attack scenarios, attackers embed hidden triggers into the training data, implanting a backdoor into the AMR model. The infected model behaves identically to a benign model during normal signal processing, evading pre-deployment performance checks. However, when attackers inject preset triggers into the modulated signal, the model is forced to output incorrect classification results, leading to demodulation failures, communication interruptions, or even malicious exploitation to gain unauthorized access to abnormal signals.

[0004] Currently, research on backdoor attacks mainly focuses on the image domain, while backdoor attack techniques targeting modulated signal AMR models are still in the initial exploratory stage. Existing backdoor attack methods targeting AMR all rely on embedding triggers into the modulated signal in the time domain to generate poisoned samples. This type of method has significant technical limitations: First, the fixed embedding position of the trigger is easily affected by factors such as channel fading and signal interference in dynamic wireless transmission, resulting in insufficient backdoor triggering stability; Second, the triggers exhibit local distribution characteristics in the time domain, which can easily cause regular abrupt changes in signal amplitude, increasing the risk of detection through signal feature analysis; Third, all poisoned samples use the same trigger design, and the attacker's abnormal operations have obvious consistency. Through statistical analysis of the abnormal behavior of the samples, the triggers can be quickly detected and reconstructed, severely reducing the stealth of the attack.

[0005] Furthermore, existing technologies do not fully consider the differences between the frequency and time domain characteristics of the modulation signal, fail to utilize the separation characteristics of the frequency domain amplitude spectrum and phase spectrum to achieve covert embedding of the trigger, and lack design for the adaptability of the trigger and the modulation signal, making it difficult to achieve both attack effectiveness and covertness. Therefore, developing an AMR backdoor attack method based on frequency domain characteristics, with adaptive adjustment capabilities and strong covertness, has become an urgent technical problem to be solved in the fields of wireless communication security and artificial intelligence security. It is of great significance for revealing the security vulnerabilities of AMR models and promoting the development of related protection technologies. Summary of the Invention

[0006] The technical problem to be solved by the present invention is to provide an automatic modulation identification frequency domain backdoor attack method and device based on a contrast-generated trigger, which can efficiently and covertly achieve AMR backdoor attacks and improve the anti-interference capability and adaptability of the attack.

[0007] To address the aforementioned technical problems, this invention discloses an automatic modulation identification frequency domain backdoor attack method based on a comparative generative trigger, the method comprising:

[0008] S1. Preset original sample set, target modulation signal sequence, target modulation type label, trigger comparison generation model and modulation recognition model;

[0009] The original sample set includes M original samples; the original samples include complex baseband signal sequences and original modulation type labels; M is an integer greater than 1;

[0010] The length of the target modulated signal sequence is L, and L is less than the length of any of the complex baseband signal sequences;

[0011] Both the original modulation type label and the target modulation type label are greater than or equal to 1 and less than or equal to 1. C Integers; C The number of modulation types for the M complex baseband signal sequences in the original sample set;

[0012] The trigger-comparison generation model is used to extract steady-state features from the input first and second sequences to obtain the corresponding feature vectors.

[0013] The modulation recognition model is used to process the complex baseband signal sequence to obtain a corresponding probability vector; the probability vector includes... C One component;

[0014] S2. Process the target modulation type label, the original sample set, and the target modulation signal sequence to obtain enhanced target signal pairs and enhanced sample sets;

[0015] The enhanced target signal pair includes a first target signal sequence and a second target signal sequence; the enhanced sample set includes a plurality of enhanced samples; the enhanced sample includes a first baseband signal sequence and a second baseband signal sequence;

[0016] S3. Based on the enhanced sample set, the trigger comparison generation model is compared and optimized to obtain an optimized trigger comparison generation model.

[0017] S4. Using the optimized trigger comparison generation model, process the enhanced target signal pair to obtain the original trigger signal sequence;

[0018] S5. Process the original sample set, the original trigger signal sequence, and the target modulation type label to obtain the test poisoned sample set, the test original sample set, the remaining poisoned sample set, the invariant sample set, the training sample set, and the verification sample set.

[0019] Both the test poisoned sample set and the remaining poisoned sample set include several poisoned samples; each poisoned sample includes a poisoned signal sequence and the target modulation type label.

[0020] The original test sample set and the invariant sample set each include several original samples; the training sample set and the verification sample set each include several training samples; the training samples are either the poisoned samples or the original samples.

[0021] S6. Optimize the modulation recognition model using the training sample set and the verification sample set to obtain the poisoned modulation recognition model;

[0022] S7. Perform test evaluation processing on the modulation recognition model, the poisoned modulation recognition model, the original test sample set, and the poisoned test sample set to obtain the attack concealment index value and the attack accuracy.

[0023] As an optional implementation, in the first aspect of the present invention, the SGD optimizer is used to perform contrastive optimization training on the trigger contrastive generation model based on the enhanced sample set, and the loss function of the trigger contrastive generation model is:

[0024]

[0025] In the formula, LB The loss function value of the generated model is compared with the trigger; B The number of augmented samples in each training batch of the SGD optimizer; and These are the 1st, 2nd, and 3rd training batches of the SGD optimizer, respectively. kThe first baseband signal sequence and the second baseband signal sequence of the enhanced sample are respectively processed by the trigger comparison generation model to obtain the feature vector; and These are the 1st, 2nd, and 3rd training batches of the SGD optimizer, respectively. b The first baseband signal sequence and the second baseband signal sequence of the enhanced sample are respectively processed by the trigger comparison generation model to obtain the feature vector; This is the function for calculating cosine similarity. These are the preset temperature parameters.

[0026] As an optional implementation, in the first aspect of the present invention, the processing of the original sample set, the original trigger signal sequence, and the target modulation type label to obtain a test poisoned sample set, a test original sample set, a remaining poisoned sample set, an invariant sample set, a training sample set, and a verification sample set includes:

[0027] S51, based on preset poisoning rate The original sample set is segmented to obtain the sample set to be embedded and the invariant sample set;

[0028] The set of samples to be embedded includes N original samples; the set of invariant samples includes MN original samples; 0 < <1;N=floor(M× floor() is the floor function;

[0029] S52. Process the sample set to be embedded and the original trigger signal sequence to obtain the embedding position set and the adaptive trigger signal sequence set;

[0030] The set of embedding positions includes N embedding positions; the set of adaptive trigger signal sequences includes N adaptive trigger signal sequences.

[0031] S53. Process the set of samples to be embedded, the set of adaptive trigger signal sequences, and the set of embedding positions to obtain the set of baseband phase spectrum sequences and the set of poisoned signal amplitude spectrum sequences.

[0032] The baseband phase spectrum sequence set includes N baseband phase spectrum sequences; the poisoning signal amplitude spectrum sequence set includes N poisoning signal amplitude spectrum sequences.

[0033] S54. Perform inverse fast Fourier transform on the set of amplitude spectrum sequences of the poisoning signals and the set of baseband phase spectrum sequences to obtain N poisoning signal sequences.

[0034] S55. Combine the N poisoning signal sequences with the target modulation type tag to obtain N poisoning samples; combine the N poisoning samples to obtain a poisoning sample set;

[0035] S56. Process the poisoned sample set and the sample set to be embedded to obtain the test poisoned sample set, the test original sample set and the remaining poisoned sample set;

[0036] S57. Process the remaining poisoned sample set and the unchanged sample set to obtain the training sample set and the verification sample set.

[0037] As an optional implementation, in the first aspect of the present invention, processing the sample set to be embedded and the original trigger signal sequence to obtain an embedding position set and an adaptive trigger signal sequence set includes:

[0038] S521. Using the embedding location generation model, process the sample set to be embedded and the original trigger signal sequence to obtain the embedding location set;

[0039] The expression for the embedding location generation model is:

[0040]

[0041] In the formula, For the first in the set of embedded locations i The embedding positions are 1 ≤ i ≤N, and i It is an integer; This means randomly generating a value greater than or equal to 1 and less than or equal to 1. any integer; For the first sample in the set to be embedded i The complex baseband signal sequence of the original sample Length;

[0042] S522. Based on the adaptive trigger generation model, the original trigger signal sequence, the embedding position set, and the sample set to be embedded are processed to obtain the adaptive trigger signal sequence set.

[0043] The expression for the adaptive trigger generation model is:

[0044]

[0045] In the formula, The first in the set of adaptive trigger signal sequences i The first of the adaptive trigger signal sequences lThe values ​​of each component; Re() and Im() represent the operations of extracting the real part and the imaginary part, respectively; and In the set of samples to be embedded, the first... i The original samples The first of the complex baseband signal sequence The real and imaginary parts of each component; The first of the original trigger signal sequence l The value of each component; 1≤ l ≤L.

[0046] As an optional implementation, in the first aspect of the present invention, processing the set of samples to be embedded, the set of adaptive trigger signal sequences, and the set of embedding positions to obtain a set of baseband phase spectrum sequences and a set of poisoned signal amplitude spectrum sequences includes:

[0047] S531. Perform Fast Fourier Transform on the complex baseband signal sequences of all the original samples in the sample set to be embedded, respectively, to obtain the baseband amplitude spectrum sequence set and the baseband phase spectrum sequence set.

[0048] The baseband amplitude spectrum sequence set includes N baseband amplitude spectrum sequences;

[0049] S532. Perform a Fast Fourier Transform on the set of adaptive trigger signal sequences to obtain a set of adaptive trigger amplitude spectrum sequences; the set of adaptive trigger amplitude spectrum sequences includes N adaptive trigger amplitude spectrum sequences.

[0050] S533. Using the embedded amplitude spectrum generation model, the baseband amplitude spectrum sequence set and the adaptive trigger amplitude spectrum sequence set are processed to obtain an embedded amplitude spectrum sequence set; the embedded amplitude spectrum sequence set includes N embedded amplitude spectrum sequences; the length of the embedded amplitude spectrum sequence is L;

[0051] S534. Using the poisoning signal amplitude spectrum generation model, the baseband amplitude spectrum sequence set, the embedded amplitude spectrum sequence set, and the embedded position set are processed to obtain the poisoning signal amplitude spectrum sequence set.

[0052] As an optional implementation, in the first aspect of the present invention, the expression for the poisoning signal amplitude spectrum generation model is:

[0053]

[0054] In the formula, The first in the set of amplitude spectrum sequences of the poisoning signal i The first of the aforementioned poisoning signal amplitude spectrum sequence The value of each component; The first in the set of baseband amplitude spectrum sequences i The first of the baseband amplitude spectrum sequences The value of each component; For the set of embedded amplitude spectrum sequences, the first i The first of the embedded amplitude spectrum sequences The value of each component; ,and It is an integer. The first in the set of baseband amplitude spectrum sequences i The length of the baseband amplitude spectrum sequence; For the first in the set of embedded locations i The embedding positions are 1 ≤ i ≤N, and i It is an integer.

[0055] As an optional implementation, in the first aspect of the present invention, the Adam optimizer is used to optimize the modulation recognition model; the loss function of the poisoned modulation recognition model is:

[0056]

[0057] In the formula, LA The loss function value of the poisoning modulation recognition model; U The number of training samples in the poisoned sample subset; the poisoned sample subset is the set of all training samples belonging to the remaining poisoned sample set in each training batch of the Adam optimizer; The first in the subset of poisoned samples u The poisoning signal sequence of the training samples; V The number of training samples in the invariant sample subset; the invariant sample subset is the set of all training samples belonging to the invariant sample subset in each training batch; For the invariant sample subset, the first v The complex baseband signal sequence of the training samples; and The modulation recognition model pairs are respectively The probability vector obtained by processing is the first... c The and the first u One component; and The modulation recognition model pairs are respectively The probability vector obtained by processing is the first... c The and the first v Each component.

[0058] As an optional implementation, in the first aspect of the present invention, the step of performing test evaluation processing on the modulation recognition model, the poisoned modulation recognition model, the original test sample set, and the poisoned test sample set to obtain attack concealment index values ​​and attack accuracy includes:

[0059] S71. The original test sample set is processed using the modulation recognition model and the poisoning modulation recognition model respectively to obtain a first probability vector set and a second probability vector set.

[0060] Both the first probability vector set and the second probability vector set include J The probability vectors;

[0061] S72. Using the poisoning modulation recognition model, the test poisoning sample set is processed to obtain a third probability vector set; the third probability vector set includes... K The probability vectors;

[0062] S73. Using the attack effect evaluation model, process the first probability vector set, the second probability vector set, and the third probability vector set to obtain the attack concealment index value and the attack accuracy.

[0063] The expression for the attack effectiveness evaluation model is:

[0064]

[0065] X and F These are the attack concealment index value and the attack accuracy rate, respectively. G and H These are the average accuracy rates of the benign model and the poisoned model, respectively. For the first probability vector set, the first... j The index of the largest component of each probability vector; For the second probability vector set, the first j The index of the largest component of each probability vector; The third probability vector set is the first... k The index of the largest component of each probability vector; For the first test sample set j The modulation type label of the original sample; The first in the test poisoning sample set k The modulation type label of the poisoned sample; For Kronek function.

[0066] A second aspect of this invention discloses an automatic modulation identification frequency domain backdoor attack device based on a comparison generative trigger, the device comprising:

[0067] Memory containing executable program code;

[0068] A processor coupled to the memory;

[0069] The processor calls the executable program code stored in the memory to execute some or all of the steps in the automatic modulation identification frequency domain backdoor attack method for comparative generative triggers disclosed in the first aspect of the present invention.

[0070] The third aspect of the present invention discloses a computer storage medium storing computer instructions, which, when invoked, are used to execute some or all of the steps in the automatic modulation identification frequency domain backdoor attack method for contrast-generated triggers disclosed in the first aspect of the present invention.

[0071] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:

[0072] (1) This invention abandons the time-domain trigger embedding method of the prior art and adopts a comparative generative adaptive trigger design. It achieves covert embedding by separating the frequency domain amplitude spectrum and phase spectrum. The adaptive trigger is dynamically adjusted based on the real and imaginary parts of the complex baseband signal of the original sample, and the embedding position is flexibly allocated by a random generation model. This avoids amplitude abrupt changes and regular features caused by the fixed position and local distribution of the time-domain trigger, making the signal distribution of the poisoned sample highly consistent with that of the normal sample. At the same time, the baseband phase spectrum (including core semantic information) of the original signal is retained, and only the amplitude spectrum fusion logic is optimized, which further reduces the risk of detection by signal feature analysis and ensures that the recognition performance of the poisoned model in normal scenarios is not significantly different from that of the benign model.

[0073] (2) This invention enhances the anti-interference capability of the trigger through frequency domain processing. The adaptive design of the trigger and the modulation signal makes the backdoor trigger unaffected by signal timing fluctuations. Combined with the objective function of the Adam optimizer, the training loss of poisoned samples and normal samples is optimized at the same time. This ensures that poisoned samples are stably misled to the target label without sacrificing the model's ability to recognize normal samples, thus achieving a dual balance between "effective attack" and "concealment".

[0074] (3) This invention is compatible with mainstream modulation types such as BPSK and QAM16, and adapts to modulation recognition models of various deep learning architectures such as DGRU and ResNet; the poisoned sample generation process supports custom poisoning rate, embedding length and other parameters, which can be flexibly adjusted according to the actual attack scenario, without the need for separate adaptation for specific models or signal types, which greatly improves the engineering practicality of the technical solution. Attached Figure Description

[0075] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0076] Figure 1 This is a flowchart illustrating an automatic modulation identification frequency domain backdoor attack method based on a comparative generative trigger disclosed in an embodiment of the present invention.

[0077] Figure 2 This is a schematic diagram of the structure of an automatic modulation identification frequency domain backdoor attack device based on a comparison generative trigger disclosed in an embodiment of the present invention. Detailed Implementation

[0078] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0079] In the description of this invention, it should be noted that the terms "center," "upper," "lower," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are used only for the convenience of describing the invention and for simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the invention. Furthermore, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0080] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "installation," "connection," and "linking" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal connection of two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.

[0081] Example 1

[0082] Please see Figure 1 . Figure 1This is a flowchart illustrating an automatic modulation identification frequency domain backdoor attack method based on a comparative generative trigger, as disclosed in an embodiment of the present invention. Figure 1 The described automatic modulation identification frequency domain backdoor attack method for contrastive generative triggers is applied in the field of cognitive radio, such as attacks on AMR models. This invention is not limited to specific examples. Figure 1 As shown, the method includes:

[0083] S1. Preset original sample set, target modulation signal sequence, target modulation type label, trigger comparison generation model and modulation recognition model;

[0084] The original sample set includes M original samples; the original samples include complex baseband signal sequences and original modulation type labels; M is an integer greater than 1;

[0085] The length of the target modulated signal sequence is L, and L is less than the length of any of the complex baseband signal sequences;

[0086] It should be noted that both the complex baseband signal sequence and the target modulation signal sequence mentioned above are time-domain signal sequences, and all components are complex numbers.

[0087] Preferably, the original sample set mentioned above is the RML22 dataset, which is a publicly available dataset of common modulation signals that fully considers the effects of various channel effects, including signal jitter, clock skew, and Ricean fading. Each modulation signal in the dataset is stored as an in-phase and quadrature (IQ) signal sequence. The in-phase and quadrature signal sequences of each modulation signal are used as the real and imaginary parts, respectively, to obtain the corresponding complex baseband signal sequence. The modulation types in this dataset include BPSK, AM-DSB, AM-SSB, BPSK, CPFSK, GFSK, PAM4, QAM16, QAM64, QPSK, and WBFM. Each modulation type contains 21 signal-to-noise ratios, ranging from -20dB to 20dB.

[0088] Both the original modulation type label and the target modulation type label are greater than or equal to 1 and less than or equal to 1. C Integers; C The number of modulation types for the M complex baseband signal sequences in the original sample set;

[0089] It should be noted that, C The modulation type numbers are sequentially set from 1 to C. Further, the original modulation type label indicates the modulation type number of the corresponding complex baseband signal sequence, while the target modulation type label indicates the modulation type of the target modulation signal sequence.

[0090] Preferably, both the original modulation type label and the target modulation type label are encoded using one-hot codes.

[0091] Preferably, C The value is 11, corresponding to the 11 modulation types in the RML22 dataset.

[0092] The trigger-comparison generation model is used to extract steady-state features from the input first and second sequences to obtain the corresponding feature vectors.

[0093] The modulation recognition model is used to process the complex baseband signal sequence to obtain a corresponding probability vector; the probability vector includes... C One component;

[0094] It should be noted that the modulation recognition model described above has been pre-trained on the original sample set and is capable of recognizing the modulation type corresponding to the complex baseband signal sequence in the original samples. During pre-training, the original sample set was divided into three parts in an 8:1:1 ratio: a training subset, a validation subset, and a test subset, and the labels in each subset were one-hot encoded. The training and validation subsets were used for pre-training the modulation recognition model and validating the pre-training process, respectively. The test subset was used to evaluate the recognition performance of the trained modulation recognition model.

[0095] It should be noted that the index of the largest component of the above probability vector is the number of the modulation type identified by the modulation recognition model.

[0096] Optionally, the modulation recognition model described above can be an AMR model based on DGRU, MCNET, or ResNet architecture, and the embodiments of the present invention are not limited thereto.

[0097] S2. Process the target modulation type label, the original sample set, and the target modulation signal sequence to obtain enhanced target signal pairs and enhanced sample sets;

[0098] The enhanced target signal pair includes a first target signal sequence and a second target signal sequence; the enhanced sample set includes a plurality of enhanced samples; the enhanced sample includes a first baseband signal sequence and a second baseband signal sequence;

[0099] S3. Based on the enhanced sample set, the trigger comparison generation model is compared and optimized to obtain an optimized trigger comparison generation model.

[0100] S4. Using the optimized trigger comparison generation model, process the enhanced target signal pair to obtain the original trigger signal sequence;

[0101] It should be noted that the first target signal sequence and the second target signal sequence of the above-mentioned enhanced target signal pair are respectively used as the first sequence and the second sequence input to the optimized trigger comparison generation model. After processing by the optimized trigger comparison generation model, the feature vector corresponding to the enhanced target signal pair is obtained. Then, all components of the feature vector corresponding to the enhanced target signal pair are combined in sequence to obtain the original trigger signal sequence.

[0102] The original trigger signal sequence is a sequence composed of the components of the feature vector obtained by the optimized trigger comparison generation model processing the target modulated signal sequence.

[0103] S5. Process the original sample set, the original trigger signal sequence, and the target modulation type label to obtain the test poisoned sample set, the test original sample set, the remaining poisoned sample set, the invariant sample set, the training sample set, and the verification sample set.

[0104] Both the test poisoned sample set and the remaining poisoned sample set include several poisoned samples; each poisoned sample includes a poisoned signal sequence and the target modulation type label.

[0105] The original test sample set and the invariant sample set each include several original samples; the training sample set and the verification sample set each include several training samples; the training samples are either the poisoned samples or the original samples.

[0106] S6. Optimize the modulation recognition model using the training sample set and the verification sample set to obtain the poisoned modulation recognition model;

[0107] The modulation recognition model is optimized using the Adam optimizer; the loss function of the poisoned modulation recognition model is:

[0108]

[0109] In the formula, LA The loss function value of the poisoning modulation recognition model; U The number of training samples in the poisoned sample subset; the poisoned sample subset is the set of all training samples belonging to the remaining poisoned sample set in each training batch of the Adam optimizer; The first in the subset of poisoned samples u The poisoning signal sequence of the training samples; V The number of training samples in the invariant sample subset; the invariant sample subset is the set of all training samples belonging to the invariant sample subset in each training batch; For the invariant sample subset, the first vThe complex baseband signal sequence of the training samples; and The modulation recognition model pairs are respectively The probability vector obtained by processing is the first... c The and the first u One component; and The modulation recognition model pairs are respectively The probability vector obtained by processing is the first... c The and the first v One component;

[0110] It should be noted that the Adam optimizer uses mini-batch gradient descent, calculating the gradient based on the loss of each training batch and dynamically adjusting the learning rate. The training sample set mentioned above is used to train the parameters of the modulation recognition model, while the validation sample set is used to monitor and adjust hyperparameters such as the learning rate and batch size during the training process.

[0111] Preferably, the initial learning rate of the Adam optimizer is set to 0.001, the batch size is 400, and the maximum number of training epochs is 1000.

[0112] It should be noted that in the loss function of the poisoned modulation recognition model, the core objective of the first half is to force the model to learn the association between "trigger → target modulation type label" so that all poisoned samples are stably misled to the target label. The core objective of the second half of the objective function is to preserve the model's ability to correctly identify normal samples and avoid the model's performance from degrading in normal scenarios (being detected as abnormal) due to poisoned training.

[0113] S7. Perform test evaluation processing on the modulation recognition model, the poisoned modulation recognition model, the original test sample set, and the poisoned test sample set to obtain the attack concealment index value and the attack accuracy.

[0114] In an optional embodiment, the processing of the target modulation type label, the original sample set, and the target modulation signal sequence to obtain the enhanced target signal pair and the enhanced sample set includes:

[0115] S21. Based on the target modulation type label, the original sample set is extracted to obtain a fixed type sample set; the fixed type sample set includes several of the original samples;

[0116] Optionally, the above extraction process involves combining the original samples in the original sample set whose corresponding original modulation type labels are the same as the target modulation type labels to obtain a fixed-type sample set. Therefore, the complex baseband signal sequences of all original samples in the fixed-type sample set have the same modulation type.

[0117] S22. A preset set of enhanced angles; the set of enhanced angles includes several angle values;

[0118] Preferably, the above-mentioned set of enhancement angles includes four angle values, namely: , , and .

[0119] S23. Randomly select one angle value from the set of enhanced angles to obtain a first angle value. ;

[0120] S24. Randomly select another angle value from the enhanced angle set to obtain a second angle value. ;

[0121] S25. Based on the first angle value and the second angle value, perform a first rotation process on the target modulation signal sequence to obtain an enhanced target signal pair;

[0122] It should be noted that the first rotation process described above includes: multiplying all components of the target modulated signal sequence by... The first target signal sequence is obtained, where e is the natural constant and j is the imaginary unit; all components of the target modulation signal sequence are multiplied by... The second target signal sequence is obtained; the first target signal sequence and the second target signal sequence are combined to obtain the enhanced target signal pair.

[0123] S26. Based on the first angle value and the second angle value, perform a second rotation process on the fixed type sample set to obtain the enhanced sample set; the enhanced sample set includes the enhanced sample of each original sample in the fixed type sample set.

[0124] Optionally, the second rotation process described above includes: multiplying all components of the complex baseband signal sequence of each original sample in the fixed-type sample set by... This yields the first baseband signal sequence corresponding to each original sample; all components of the complex baseband signal sequence of each original sample in the fixed-type sample set are multiplied by... The second baseband signal sequence corresponding to each original sample is obtained; the first baseband signal sequence and the second baseband signal sequence corresponding to each original sample in the fixed type sample set are combined to obtain the enhanced sample corresponding to each original sample; all enhanced samples are combined to obtain the enhanced sample set.

[0125] In another optional embodiment, the trigger-contrast generation model includes an initial feature extraction module, a first residual module, a second residual module, a third residual module, and a feature projection module;

[0126] The first and second input terminals of the initial feature extraction module are respectively configured as the first and second input terminals of the trigger-contrast generation model; the output terminal of the initial feature extraction module is connected to the input terminal of the first residual module; the output terminal of the first residual module is connected to the input terminal of the second residual module; the output terminal of the second residual module is connected to the input terminal of the third residual module; the output terminal of the third residual module is connected to the input terminal of the feature projection module; and the output terminal of the feature projection module is configured as the output terminal of the trigger-contrast generation model.

[0127] In another optional embodiment, the initial feature extraction module includes a splicing unit, a first convolutional unit, a first normalization unit, and a first activation unit;

[0128] The first input terminal and the second input terminal of the splicing unit are respectively configured as the first input terminal and the second input terminal of the initial feature extraction module; the splicing unit is used to splice the first sequence received by the first input terminal and the second sequence received by the second input terminal as row vectors to obtain a signal matrix including 2 rows, and send it to the first convolution unit;

[0129] The output of the splicing unit is connected to the input of the first convolutional unit; the output of the first convolutional unit is connected to the input of the first normalization unit; the output of the first normalization unit is connected to the input of the first activation unit; and the output of the first activation unit is configured as the output of the initial feature extraction module.

[0130] It should be noted that the above-mentioned initial feature extraction module is used to perform initial feature extraction and introduce nonlinear feature representation.

[0131] In yet another optional embodiment, the first residual module includes a second convolution unit, a second normalization unit, a second activation unit, a third convolution unit, a third normalization unit, a first fusion unit, and a third activation unit.

[0132] The input of the first residual module is connected to the input of the second convolutional unit and the first input of the first fusion unit; the output of the second convolutional unit is connected to the input of the second normalization unit; the output of the second normalization unit is connected to the input of the second activation unit; the output of the second activation unit is connected to the input of the third convolutional unit; the output of the third convolutional unit is connected to the input of the third normalization unit; the output of the third normalization unit is connected to the second input of the first fusion unit; the output of the first fusion unit is connected to the input of the third activation unit; and the output of the third activation unit is configured as the output of the first residual module.

[0133] In another optional embodiment, the second residual module includes a fourth convolution unit, a fourth normalization unit, a fourth activation unit, a fifth convolution unit, a fifth normalization unit, a second fusion unit, a fifth activation unit, a sixth convolution unit, a sixth normalization unit, and a sixth activation unit.

[0134] The input terminal of the second residual module is connected to the input terminal of the fourth convolutional unit and the first input terminal of the second fusion unit; the output terminal of the fourth convolutional unit is connected to the input terminal of the fourth normalization unit; the output terminal of the fourth normalization unit is connected to the input terminal of the fourth activation unit; the output terminal of the fourth activation unit is connected to the input terminal of the fifth convolutional unit; the output terminal of the fifth convolutional unit is connected to the input terminal of the fifth normalization unit; the output terminal of the fifth normalization unit is connected to the second input terminal of the second fusion unit; the output terminal of the second fusion unit is connected to the input terminal of the fifth activation unit; the output terminal of the fifth activation unit is connected to the input terminal of the sixth convolutional unit; the output terminal of the sixth convolutional unit is connected to the input terminal of the sixth normalization unit; the output terminal of the sixth normalization unit is connected to the input terminal of the sixth activation unit; the output terminal of the sixth activation unit is configured as the output terminal of the second residual module.

[0135] In another optional embodiment, the third residual module includes a seventh convolution unit, a seventh normalization unit, a seventh activation unit, an eighth convolution unit, an eighth normalization unit, a third fusion unit, and an eighth activation unit.

[0136] The input of the third residual module is connected to the input of the seventh convolutional unit and the first input of the third fusion unit; the output of the seventh convolutional unit is connected to the input of the seventh normalization unit; the output of the seventh normalization unit is connected to the input of the seventh activation unit; the output of the seventh activation unit is connected to the input of the eighth convolutional unit; the output of the eighth convolutional unit is connected to the input of the eighth normalization unit; the output of the eighth normalization unit is connected to the second input of the third fusion unit; and the output of the third fusion unit is connected to the eighth activation unit.

[0137] It should be noted that the first, second, and third residual modules mentioned above are all composed of a main branch and a shortcut branch. The shortcut branch is an "identity mapping branch" that does not have any additional convolution, activation, or normalization operations. It simply passes the current input features directly to the output of the residual block. Its core function is to skip the multi-layer convolution calculations of the main branch and form residual connections, thereby alleviating the gradient vanishing problem in deep networks. This ensures that the training effect remains stable even after the number of network layers increases, and also ensures that the core features of the I / Q signals can be captured before projection, thus guaranteeing the discriminativeness of the features after projection.

[0138] In another optional embodiment, the feature projection module includes a pooling unit, a first feature transformation unit, a ninth normalization unit, a ninth activation unit, a second feature transformation unit, and a tenth normalization unit.

[0139] The input terminal of the pooling unit is configured as the input terminal of the feature projection module; the output terminal of the pooling unit is connected to the input terminal of the first feature conversion unit; the output terminal of the first feature conversion unit is connected to the input terminal of the ninth normalization unit; the output terminal of the ninth normalization unit is connected to the input terminal of the ninth activation unit; the output terminal of the ninth activation unit is connected to the input terminal of the second feature conversion unit; the output terminal of the second feature conversion unit is connected to the input terminal of the tenth normalization unit; the input terminal of the tenth normalization unit is configured as the output terminal of the feature projection module.

[0140] It should be noted that the feature projection module further converts high-dimensional features into low-dimensional spatial features suitable for comparative learning. This projection process reduces the feature dimension while preserving key differences between samples, providing a suitable input for loss calculation of the trigger-based comparative generation model.

[0141] It should be noted that the first activation unit, second activation unit, third activation unit, fourth activation unit, fifth activation unit, sixth activation unit, seventh activation unit, eighth activation unit and ninth activation unit mentioned above are all constructed based on the ReLU activation function, and the embodiments of the present invention do not limit them.

[0142] It should be noted that the first, second, third, fourth, fifth, sixth, seventh, and eighth convolutional units mentioned above are all constructed based on one-dimensional convolutional modules, and this embodiment of the invention does not limit them.

[0143] It should be noted that the first normalization unit, the second normalization unit, the third normalization unit, the fourth normalization unit, the fifth normalization unit, the sixth normalization unit, the seventh normalization unit, the eighth normalization unit, the ninth normalization unit, and the tenth normalization unit mentioned above are all constructed based on the batch normalization layer, and the embodiments of the present invention do not limit them.

[0144] It should be noted that the first fusion unit, the second fusion unit, and the third fusion unit mentioned above are all constructed based on element-wise addition, and the embodiments of the present invention do not limit this.

[0145] It should be noted that the above pooling unit is constructed based on the max pooling layer, and this embodiment of the invention does not limit it.

[0146] It should be noted that the first feature conversion unit and the second feature conversion unit mentioned above are both constructed based on fully connected layers, and the embodiments of the present invention do not limit them.

[0147] In another optional embodiment, the contrastive optimization training of the trigger-contrast generation model based on the enhanced sample set employs the SGD optimizer, and the loss function of the trigger-contrast generation model is:

[0148]

[0149] In the formula, LB The loss function value of the generated model is compared with the trigger; B The number of augmented samples in each training batch of the SGD optimizer; and These are the 1st, 2nd, and 3rd training batches of the SGD optimizer, respectively. k The first baseband signal sequence and the second baseband signal sequence of the enhanced sample are respectively processed by the trigger comparison generation model to obtain the feature vector; and These are the 1st, 2nd, and 3rd training batches of the SGD optimizer, respectively. b The first baseband signal sequence and the second baseband signal sequence of the enhanced sample are respectively processed by the trigger comparison generation model to obtain the feature vector; This is the function for calculating cosine similarity. These are the preset temperature parameters.

[0150] Preferably, the initial learning rate of the SGD optimizer is set to 0.001, and the number of boosted samples in each training batch is... B The batch size is 1100, and the maximum number of training rounds is 100.

[0151] It should be noted that the loss function of the above-mentioned trigger-contrast generative model achieves comparative learning by maximizing the feature similarity between two enhanced versions (the first baseband signal sequence and the second baseband signal sequence) of the same complex baseband signal sequence and minimizing the feature similarity between enhanced versions of different complex baseband signal sequences. Then, the gradient of the generator's encoding modulus parameters is calculated through the backpropagation algorithm, and finally, the encoding parameters are updated in the direction of gradient descent through the SGD optimizer until the maximum number of training rounds is reached, and the training is completed.

[0152] Optionally, the range of the above temperature parameters is [0.01, 0.5].

[0153] In another optional embodiment, the processing of the original sample set, the original trigger signal sequence, and the target modulation type label to obtain the test poisoned sample set, the original test sample set, the remaining poisoned sample set, the invariant sample set, the training sample set, and the verification sample set includes:

[0154] S51, based on preset poisoning rate The original sample set is segmented to obtain the sample set to be embedded and the invariant sample set;

[0155] The set of samples to be embedded includes N original samples; the set of invariant samples includes MN original samples; 0 < <1;N=floor(M× floor() is the floor function;

[0156] S52. Process the sample set to be embedded and the original trigger signal sequence to obtain the embedding position set and the adaptive trigger signal sequence set;

[0157] The set of embedding positions includes N embedding positions; the set of adaptive trigger signal sequences includes N adaptive trigger signal sequences.

[0158] S53. Process the set of samples to be embedded, the set of adaptive trigger signal sequences, and the set of embedding positions to obtain the set of baseband phase spectrum sequences and the set of poisoned signal amplitude spectrum sequences.

[0159] The baseband phase spectrum sequence set includes N baseband phase spectrum sequences; the poisoning signal amplitude spectrum sequence set includes N poisoning signal amplitude spectrum sequences.

[0160] S54. Perform inverse fast Fourier transform on the set of amplitude spectrum sequences of the poisoning signals and the set of baseband phase spectrum sequences to obtain N poisoning signal sequences.

[0161] It should be noted that the nth poisoning signal sequence is obtained by performing an inverse fast Fourier transform on the nth poisoning signal amplitude spectrum sequence in the set of poisoning signal amplitude spectrum sequences and the nth baseband phase spectrum sequence in the set of baseband phase spectrum sequences, where n is an integer greater than or equal to 1 and less than or equal to N.

[0162] S55. Combine the N poisoning signal sequences with the target modulation type tag to obtain N poisoning samples; combine the N poisoning samples to obtain a poisoning sample set;

[0163] S56. Process the poisoned sample set and the sample set to be embedded to obtain the test poisoned sample set, the test original sample set and the remaining poisoned sample set;

[0164] S57. Process the remaining poisoned sample set and the unchanged sample set to obtain the training sample set and the verification sample set.

[0165] In another optional embodiment, the step of segmenting the original sample set to obtain the sample set to be embedded and the invariant sample set includes:

[0166] S511. Randomly select N original samples from the original sample set to obtain the sample set to be embedded.

[0167] S512. Delete all original samples in the original sample set that belong to the sample set to be embedded, and obtain the invariant sample set.

[0168] In another optional embodiment, the processing of the sample set to be embedded and the original trigger signal sequence to obtain the embedding position set and the adaptive trigger signal sequence set includes:

[0169] S521. Using the embedding location generation model, process the sample set to be embedded and the original trigger signal sequence to obtain the embedding location set;

[0170] The expression for the embedding location generation model is:

[0171]

[0172] In the formula, For the first in the set of embedded locations i The embedding positions are 1 ≤ i ≤N, and i It is an integer; This means randomly generating a value greater than or equal to 1 and less than or equal to 1. any integer; For the first sample in the set to be embedded i The complex baseband signal sequence of the original sample Length;

[0173] S522. Based on the adaptive trigger generation model, the original trigger signal sequence, the embedding position set, and the sample set to be embedded are processed to obtain the adaptive trigger signal sequence set.

[0174] The expression for the adaptive trigger generation model is:

[0175]

[0176] In the formula, The first in the set of adaptive trigger signal sequences i The first of the adaptive trigger signal sequences l The values ​​of each component; Re() and Im() represent the operations of extracting the real part and the imaginary part, respectively; and In the set of samples to be embedded, the first... i The original samples The first of the complex baseband signal sequence The real and imaginary parts of each component; The first of the original trigger signal sequence l The value of each component; 1≤ l ≤L.

[0177] In another optional embodiment, the processing of the sample set to be embedded, the adaptive trigger signal sequence set, and the embedding position set to obtain the baseband phase spectrum sequence set and the poisoned signal amplitude spectrum sequence set includes:

[0178] S531. Perform Fast Fourier Transform on the complex baseband signal sequences of all the original samples in the sample set to be embedded, respectively, to obtain the baseband amplitude spectrum sequence set and the baseband phase spectrum sequence set.

[0179] The baseband amplitude spectrum sequence set includes N baseband amplitude spectrum sequences;

[0180] It should be noted that the nth baseband amplitude spectrum sequence in the baseband amplitude spectrum sequence set and the nth baseband phase spectrum sequence in the baseband phase spectrum sequence set are obtained by performing a fast Fourier transform on the complex baseband signal sequence of the nth original sample in the sample set to be embedded.

[0181] S532. Perform a Fast Fourier Transform on the set of adaptive trigger signal sequences to obtain a set of adaptive trigger amplitude spectrum sequences; the set of adaptive trigger amplitude spectrum sequences includes N adaptive trigger amplitude spectrum sequences.

[0182] S533. Using the embedded amplitude spectrum generation model, the baseband amplitude spectrum sequence set and the adaptive trigger amplitude spectrum sequence set are processed to obtain an embedded amplitude spectrum sequence set; the embedded amplitude spectrum sequence set includes N embedded amplitude spectrum sequences; the length of the embedded amplitude spectrum sequence is L;

[0183] The expression for the embedded amplitude spectrum generation model is:

[0184]

[0185] formula, For the set of embedded amplitude spectrum sequences, the first i The first of the embedded amplitude spectrum sequences l The value of each component; The first in the set of baseband amplitude spectrum sequences i The first of the baseband amplitude spectrum sequences l The value of each component; The first one in the set of amplitude spectrum sequences of the adaptive trigger i The first of the adaptive trigger amplitude spectrum sequences The value of each component.

[0186] S534. Using the poisoning signal amplitude spectrum generation model, the baseband amplitude spectrum sequence set, the embedded amplitude spectrum sequence set, and the embedded position set are processed to obtain the poisoning signal amplitude spectrum sequence set.

[0187] In yet another optional embodiment, the expression for the poisoning signal amplitude spectrum generation model is:

[0188]

[0189] In the formula, The first in the set of amplitude spectrum sequences of the poisoning signal i The first of the aforementioned poisoning signal amplitude spectrum sequence The value of each component; The first in the set of baseband amplitude spectrum sequences i The first of the baseband amplitude spectrum sequences The value of each component; For the set of embedded amplitude spectrum sequences, the first i The first of the embedded amplitude spectrum sequences The value of each component; ,and It is an integer. The first in the set of baseband amplitude spectrum sequences i The length of the baseband amplitude spectrum sequence; For the first in the set of embedded locations i The embedding positions are 1 ≤ i ≤N, and i It is an integer.

[0190] In another optional embodiment, the processing of the poisoned sample set and the sample set to be embedded to obtain the test poisoned sample set, the original test sample set, and the remaining poisoned sample set includes:

[0191] S561. Randomly generate a filtering sequence of length N, wherein any floor(M×) in the filtering sequence One component is 1, and the rest are 0.

[0192] S562. Combine all components with a value of 1 in the screening sequence with the corresponding poisoned samples in the poisoned sample set to obtain the test poisoned sample set.

[0193] S563. Combine all components with a value of 0 in the screening sequence with the corresponding poisoned samples in the poisoned sample set to obtain the remaining poisoned sample set.

[0194] S564. Combine all components with a value of 0 in the screening sequence with the original samples corresponding to the sample set to be embedded to obtain the test original sample set.

[0195] It should be noted that the component with index n in the screening sequence corresponds to the nth poisoned sample in the poisoned sample set and the nth original sample in the sample set to be embedded.

[0196] In another optional embodiment, the processing of the remaining poisoned sample set and the invariant sample set to obtain the training sample set and the validation sample set includes:

[0197] S571. Set the sample set to be segmented as the union of the remaining poisoned sample set and the invariant sample set.

[0198] S572. Divide the sample set to be segmented into the training sample set and the validation sample set according to an 8:1 ratio.

[0199] In another optional embodiment, the step of testing and evaluating the modulation recognition model, the poisoned modulation recognition model, the original test sample set, and the poisoned test sample set to obtain the attack concealment index value and the attack accuracy includes:

[0200] S71. The original test sample set is processed using the modulation recognition model and the poisoning modulation recognition model respectively to obtain a first probability vector set and a second probability vector set.

[0201] Both the first probability vector set and the second probability vector set include J The probability vectors;

[0202] It should be noted that, J The number of original samples in the test original sample set. The first probability vector set represents the modulation recognition model's response to the test original sample set. J The original samples were processed separately to obtain J The first set consists of a set of probability vectors. The second set of probability vectors represents the results of the poisoning modulation recognition model on the original test sample set. J The original samples were processed separately to obtain J A set consisting of probability vectors.

[0203] S72. Using the poisoning modulation recognition model, the test poisoning sample set is processed to obtain a third probability vector set; the third probability vector set includes... K The probability vectors;

[0204] It should be noted that, K This represents the number of poisoned samples in the test poisoning sample set. The third probability vector set represents the number of poisoned samples in the test poisoning sample set as determined by the poisoning modulation recognition model. K The poisoned samples were processed separately to obtain K A set consisting of probability vectors.

[0205] S73. Using the attack effect evaluation model, process the first probability vector set, the second probability vector set, and the third probability vector set to obtain the attack concealment index value and the attack accuracy.

[0206] The expression for the attack effectiveness evaluation model is:

[0207]

[0208] X and F These are the attack concealment index value and the attack accuracy rate, respectively. G and H These are the average accuracy rates of the benign model and the poisoned model, respectively. For the first probability vector set, the first... j The index of the largest component of each probability vector; For the second probability vector set, the firstj The index of the largest component of each probability vector; The third probability vector set is the first... k The index of the largest component of each probability vector; For the first test sample set j The modulation type label of the original sample; The first in the test poisoning sample set k The modulation type label of the poisoned sample; For Kronek function.

[0209] It should be noted that Kronek The function has a value of 1 when the two input variables are equal, and a value of 0 otherwise.

[0210] It should be noted that the average accuracy of a benign model is the ratio of the total number of modulation types correctly identified by the benign modulation recognition model after processing the original test sample set (in which none of the original signals were embedded with triggers) to the total number of modulation types correctly identified. J The ratio of .

[0211] It should be noted that the average accuracy of the poisoned model is the ratio of the total number of modulation types correctly identified by the poisoned modulation recognition model after processing the original test sample set to the total number of modulation types correctly identified. J The ratio of .

[0212] It should be noted that the attack stealth index value represents the degree of difference between the average accuracy of benign models and the average accuracy of poisoned models. The smaller this value, the more difficult it is to distinguish whether a model is poisoned through model performance testing when deploying an automatic modulation recognition model in a wireless communication system.

[0213] It should be noted that the attack accuracy rate is the ratio of the total number of modulation types correctly identified by the poisoned modulation identification model after processing the test poisoned sample set to the total number of modulation types correctly identified. K The ratio of .

[0214] It should be noted that experiments on AMR models based on DGRU, MCNET, or ResNet architectures show that their backdoor attack performance is consistent. Under any signal-to-noise ratio (SNR) condition, the accuracy of the poisoned model nearly overlaps with that of the benign model, indicating that the poisoned model has good concealment and is indistinguishable from other models. Furthermore, under any SNR condition, the attack accuracy for all three models is approximately 9%.

[0215] As can be seen, the automatic modulation identification frequency domain backdoor attack method for comparison-generated triggers described in the embodiments of the present invention is as follows:

[0216] (1) Abandoning the existing time-domain trigger embedding method, a comparative generative adaptive trigger design is adopted, which achieves covert embedding through the separation of frequency domain amplitude spectrum and phase spectrum. The adaptive trigger is dynamically adjusted based on the real and imaginary parts of the complex baseband signal of the original sample, and the embedding position is flexibly allocated through a random generation model, avoiding amplitude abrupt changes and regular features caused by the fixed position and local distribution of the time-domain trigger, so that the signal distribution of the poisoned sample is highly consistent with that of the normal sample; at the same time, the baseband phase spectrum (including core semantic information) of the original signal is retained, and only the amplitude spectrum fusion logic is optimized, further reducing the risk of detection by signal feature analysis, and ensuring that the recognition performance of the poisoned model in normal scenarios is not significantly different from that of the benign model.

[0217] (2) Enhance the anti-interference capability of the trigger by frequency domain processing. The adaptive design of the trigger and the modulation signal makes the backdoor trigger unaffected by signal timing fluctuations. Combine the objective function of the Adam optimizer to optimize the training loss of poisoned samples and normal samples at the same time. This ensures that poisoned samples are stably misled to the target label without sacrificing the model's ability to recognize normal samples, thus achieving a dual balance between "effective attack" and "concealment".

[0218] (3) It is compatible with mainstream modulation types such as BPSK and QAM16, and adapts to modulation recognition models of various deep learning architectures such as DGRU and ResNet. The poisoned sample generation process supports custom poisoning rate, embedding length and other parameters, which can be flexibly adjusted according to the actual attack scenario. It does not require separate adaptation for specific models or signal types, which greatly improves the engineering practicality of the technical solution.

[0219] (4) By comparing the attack ideas of combining generative triggers with frequency domain embedding, the distribution characteristics of the amplitude spectrum of the modulation signal in the frequency domain and the semantic preservation characteristics of the phase spectrum are fully utilized, which solves the technical shortcomings of existing technologies that do not fully exploit the advantages of the frequency domain. Through the complete link of "adaptive trigger generation - frequency domain spectrum fusion - inverse Fourier transform restoration", a full-process attack scheme from sample processing to model optimization is constructed, revealing the security vulnerability of the AMR model in the frequency domain dimension, and providing a key reference for the development of subsequent protection technologies.

[0220] Example 2

[0221] Please see Figure 2 , Figure 2 This is a schematic diagram of the structure of an automatic modulation identification frequency domain backdoor attack device based on a comparison-generating trigger, as disclosed in an embodiment of the present invention. Figure 2 The described automatic modulation identification frequency domain backdoor attack device for contrast-generative triggers can be applied to the field of cognitive radio, such as attacks on AMR models; however, this invention is not limited to specific applications. Figure 2As shown, the automatic modulation identification frequency domain backdoor attack device of the contrast-generated trigger may include the following parts:

[0222] Memory 201 storing executable program code;

[0223] Processor 202 coupled to memory 201;

[0224] The processor 202 calls the executable program code stored in the memory 201 to execute the steps in the automatic modulation identification frequency domain backdoor attack method of the comparison generative trigger described in Embodiment 1.

[0225] Example 3

[0226] This invention discloses a computer read storage medium that stores a computer program for electronic data interchange, wherein the computer program causes a computer to execute the steps in the automatic modulation identification frequency domain backdoor attack method for contrast-generated triggers described in Embodiment 1.

[0227] The device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separate, and the components shown as modules may or may not be physical modules; that is, they may be located in one place or distributed across multiple network modules. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.

[0228] Through the detailed description of the above embodiments, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, including read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically-Erasable Programmable Read-Only Memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, disk storage, magnetic tape storage, or any other computer-readable medium that can be used to carry or store data.

[0229] Finally, it should be noted that the automatic modulation identification frequency domain backdoor attack method and apparatus for comparative generative triggers disclosed in the embodiments of the present invention are merely preferred embodiments of the present invention and are only used to illustrate the technical solutions of the present invention, not to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method of identifying a frequency domain backdoor attack of automatic modulation of a contrast-generative flip-flop, characterized by, The method comprises the following steps: S1, presetting an original sample set, a target modulation signal sequence, a target modulation type label, a trigger contrast generation model, and a modulation recognition model; The original sample set comprises M original samples; each original sample comprises a complex baseband signal sequence and an original modulation type label; M is an integer greater than 1; The length of the target modulation signal sequence is L, and L is less than the length of any complex baseband signal sequence; The original modulation type label and the target modulation type label are both integers greater than or equal to 1 and less than or equal to C ; C is the number of categories of modulation types of the M complex baseband signal sequences in the original sample set. The trigger contrast generation model is used for steady-state feature extraction on input first and second sequences to obtain corresponding feature vectors; The modulation identification model is configured to process the complex baseband signal sequence to obtain a corresponding probability vector; the probability vector includes C components. S2, processing the target modulation type label, the original sample set, and the target modulation signal sequence to obtain an enhanced target signal pair and an enhanced sample set; The enhanced target signal pair comprises a first target signal sequence and a second target signal sequence; The enhanced sample set comprises a plurality of enhanced samples; Each enhanced sample comprises a first baseband signal sequence and a second baseband signal sequence; S3, based on the enhanced sample set, performing contrast optimization training on the trigger contrast generation model to obtain an optimized trigger contrast generation model; S4, using the optimized trigger contrast generation model to process the enhanced target signal pair to obtain an original trigger signal sequence; S5、based on the preset poisoning rate segmenting the original sample set to obtain a to-be-embedded sample set and an unchanged sample set; The sample set to be embedded includes N original samples; the invariant sample set includes M-N original samples; 0 <1; N=floor(M x ), floor() is an integer function; S6, processing the to-be-embedded sample set and the original trigger signal sequence to obtain an embedding position set and an adaptive trigger signal sequence set; The embedding position set comprises N embedding positions; The adaptive trigger signal sequence set comprises N adaptive trigger signal sequences; S7, processing the to-be-embedded sample set, the adaptive trigger signal sequence set, and the embedding position set to obtain a baseband phase spectrum sequence set and a poisoned signal amplitude spectrum sequence set; The baseband phase spectrum sequence set comprises N baseband phase spectrum sequences; The poisoned signal amplitude spectrum sequence set comprises N poisoned signal amplitude spectrum sequences; S8, performing inverse fast Fourier transform processing on the poisoned signal amplitude spectrum sequence set and the baseband phase spectrum sequence set to obtain N poisoned signal sequences; S9, combining N poisoned samples obtained by combining N poisoned signal sequences with the target modulation type label to obtain a poisoned sample set; S10, processing the poisoned sample set and the to-be-embedded sample set to obtain a test poisoned sample set, a test original sample set, and a remaining poisoned sample set; The test poisoned sample set and the remaining poisoned sample set each comprise a plurality of poisoned samples; each poisoned sample comprises a poisoned signal sequence and the target modulation type label; and the test original sample set comprises a plurality of original samples; S11, processing the remaining poisoned sample set and the invariant sample set to obtain a training sample set and a verification sample set; each of the training sample set and the verification sample set comprises a plurality of training samples; Each training sample is a poisoned sample or an original sample; S12, optimize the modulation identification model by using the training sample set and the verification sample set, and obtain a poisoning modulation identification model; S13, perform test evaluation processing on the modulation identification model, the poisoning modulation identification model, the test original sample set and the test poisoning sample set, and obtain an attack concealment index value and an attack accuracy.

2. The method of claim 1, wherein the method is a contrast generation trigger automatic modulation identification frequency domain side-channel attack method. The contrast optimization training of the trigger contrast generation model based on the enhanced sample set adopts an SGD optimizer, and a loss function of the trigger contrast generation model is: In the formula, LB The loss function value of the generated model is compared with the trigger; B The number of augmented samples in each training batch of the SGD optimizer; and These are the 1st, 2nd, and 3rd training batches of the SGD optimizer, respectively. k The first baseband signal sequence and the second baseband signal sequence of the enhanced sample are respectively processed by the trigger comparison generation model to obtain the feature vector; and These are the 1st, 2nd, and 3rd training batches of the SGD optimizer, respectively. b The first baseband signal sequence and the second baseband signal sequence of the enhanced sample are respectively processed by the trigger comparison generation model to obtain the feature vector; This is the function for calculating cosine similarity. These are the preset temperature parameters.

3. The method of claim 1, wherein the method is a contrast generation trigger automatic modulation identification frequency domain side-channel attack method. The processing of the to-be-embedded sample set and the original trigger signal sequence to obtain an embedding position set and an adaptive trigger signal sequence set comprises: S61, process the to-be-embedded sample set and the original trigger signal sequence by using an embedding position generation model to obtain an embedding position set; An expression of the embedding position generation model is: In the formula, is the i-th embedded position in the embedded position set; 1≤i≤N, and i is an integer; i represents randomly generating any integer greater than or equal to 1 and less than or equal to N; i is an integer; is the length of the complex baseband signal sequence of the i-th original sample in the sample set to be embedded; is an integer; is the i-th embedded position in the embedded position set; 1≤i≤N, and i is an integer; is the length of the complex baseband signal sequence of the i-th original sample in the sample set to be embedded; S62, process the original trigger signal sequence, the embedding position set and the to-be-embedded sample set based on an adaptive trigger generation model to obtain the adaptive trigger signal sequence set; An expression of the adaptive trigger generation model is: In the formula, The first in the set of adaptive trigger signal sequences i The first of the adaptive trigger signal sequences l The values ​​of each component; Re() and Im() represent the operations of extracting the real part and the imaginary part, respectively; and In the set of samples to be embedded, the first... i The original samples The first of the complex baseband signal sequence The real and imaginary parts of each component; The first of the original trigger signal sequence l The value of each component; 1≤ l ≤L.

4. The method of claim 1, wherein the method is a contrast generation trigger automatic modulation identification frequency domain side-channel attack method. The processing of the to-be-embedded sample set, the adaptive trigger signal sequence set and the embedding position set to obtain a baseband phase spectrum sequence set and a poisoning signal amplitude spectrum sequence set comprises: S71, perform fast Fourier transform on the complex baseband signal sequence of all original samples in the to-be-embedded sample set respectively to obtain a baseband amplitude spectrum sequence set and the baseband phase spectrum sequence set; The baseband amplitude spectrum sequence set comprises N baseband amplitude spectrum sequences; S72, perform fast Fourier transform on the adaptive trigger signal sequence set to obtain an adaptive trigger amplitude spectrum sequence set; the adaptive trigger amplitude spectrum sequence set comprises N adaptive trigger amplitude spectrum sequences; S73, process the baseband amplitude spectrum sequence set and the adaptive trigger amplitude spectrum sequence set by using an embedding amplitude spectrum generation model to obtain an embedding amplitude spectrum sequence set; the embedding amplitude spectrum sequence set comprises N embedding amplitude spectrum sequences; a length of the embedding amplitude spectrum sequence is L; S74, process the baseband amplitude spectrum sequence set, the embedding amplitude spectrum sequence set and the embedding position set by using a poisoning signal amplitude spectrum generation model to obtain the poisoning signal amplitude spectrum sequence set.

5. The method of claim 4, wherein the method is a contrast generation trigger automatic modulation identification frequency domain side-channel attack method. An expression of the poisoning signal amplitude spectrum generation model is: In the formula, The first in the set of amplitude spectrum sequences of the poisoning signal i The first of the aforementioned poisoning signal amplitude spectrum sequence The value of each component; The first in the set of baseband amplitude spectrum sequences i The first of the baseband amplitude spectrum sequences The value of each component; For the set of embedded amplitude spectrum sequences, the first i The first of the embedded amplitude spectrum sequences The value of each component; ,and It is an integer. The first in the set of baseband amplitude spectrum sequences i The length of the baseband amplitude spectrum sequence; For the first in the set of embedded locations i The aforementioned embedding locations; 1≤ i ≤N, and i is an integer.

6. The method of claim 1, wherein the method is a contrast generation trigger automatic modulation identification frequency domain side-channel attack method. The optimization of the modulation identification model adopts an Adam optimizer; a loss function of the poisoning modulation identification model is: In the formula, LA is a loss function value of the poisoning modulation identification model; U is a number of the training samples in a poisoning sample subset; the poisoning sample subset is a set of all the training samples belonging to the remaining poisoning sample set in each training batch of the Adam optimizer; is the poisoning signal sequence of the i-th training sample in the poisoning sample subset; u V is a number of the training samples in an invariant sample subset; the invariant sample subset is a set of all the training samples belonging to the invariant sample set in each training batch; is the complex baseband signal sequence of the i-th training sample in the invariant sample subset; v and are the i-th and j-th components of the probability vector obtained by processing the poisoning sample subset and the invariant sample subset by the modulation identification model respectively; c are the i-th and j-th components of the probability vector obtained by processing the poisoning sample subset and the invariant sample subset by the modulation identification model respectively. u and are the i-th and j-th components of the probability vector obtained by processing the poisoning sample subset and the invariant sample subset by the modulation identification model respectively. c are the i-th and j-th components of the probability vector obtained by processing the poisoning sample subset and the invariant sample subset by the modulation identification model respectively. v ​​​​​​ 7. The method of claim 1, wherein the method is a contrast generation trigger automatic modulation identification frequency domain side-channel attack method. The test evaluation processing of the modulation identification model, the poisoning modulation identification model, the test original sample set and the test poisoning sample set to obtain an attack concealment index value and an attack accuracy comprises: S131, process the test original sample set by using the modulation identification model and the poisoning modulation identification model respectively to obtain a first probability vector set and a second probability vector set; The first set of probability vectors and the second set of probability vectors each include J probability vectors. S132. Using the poisoning modulation recognition model, the test poisoning sample set is processed to obtain a third probability vector set; the third probability vector set includes... K The probability vectors; S133, utilizing the attack effect evaluation model to process the first probability vector set, the second probability vector set and the third probability vector set to obtain the attack concealment index value and the attack accuracy; An expression of the attack effect evaluation model is: X and F These are the attack concealment index value and the attack accuracy rate, respectively. G and H These are the average accuracy rates of the benign model and the poisoned model, respectively. For the first probability vector set, the first... j The index of the largest component of each probability vector; For the second probability vector set, the first j The index of the largest component of each probability vector; The third probability vector set is the first... k The index of the largest component of each probability vector; For the first test sample set j The modulation type label of the original sample; The first in the test poisoning sample set k The modulation type label of the poisoned sample; For Kronek function.

8. An apparatus for identifying a frequency domain backdoor attack of automatic modulation of a contrast-generating trigger, characterized in that, The device comprises: A memory storing executable program codes; A processor coupled with the memory; The processor invokes the executable program codes stored in the memory to execute the automatic modulation identification frequency domain backdoor attack method of the comparative generative trigger.

9. A computer storable medium, characterized by The computer storage medium stores computer instructions, which are invoked to execute the automatic modulation identification frequency domain backdoor attack method of the comparative generative trigger.

Citation Information

Patent Citations

  • Backdoor attack method and device, processing equipment, program product and medium

    CN121351085A

  • Post-Training Detection and Identification of Human-Imperceptible Backdoor-Poisoning Attacks

    US20200380118A1