Neural modulation recognition confrontation and defense method and system based on fast robust encoder, and storage medium

By introducing a robust encoder into the neural modulation recognition model and utilizing frequency and time domain feature processing to generate near-sense and heterosense signal sets for training, the compatibility issues of different NMR model structures and adversarial perturbations are resolved, thereby improving the robustness and computational efficiency of the model.

CN121786583APending Publication Date: 2026-04-03HUAZHONG UNIV OF SCI & TECH
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-31
Publication Date
2026-04-03

AI Technical Summary

Technical Problem

Existing neural modulation recognition models are prone to misclassification of adversarial perturbations, have difficulty being compatible with different structures and defending against different adversarial perturbations, and lack effective adversarial defense methods.

Method used

A robust encoder is pre-placed in the NMR model. The encoded signal is generated through frequency domain feature extraction, MLP layer and time domain correction feature unit. Training is carried out using sets of synonymous and heterosense signals to expand the distance between heterosense signals and narrow the distance between synonymous signals. An adaptive loss function is designed for training.

Benefits of technology

It achieves good compatibility with different NMR models and effective suppression of perturbations, improves the robustness and computational efficiency of the models, reduces the impact of noise, and adapts to different signal-to-noise ratio environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121786583A_ABST
    Figure CN121786583A_ABST
Patent Text Reader

Abstract

The invention discloses a neural modulation recognition confrontation defense method and system based on a fast robust encoder, and a storage medium, and belongs to the field of automatic signal modulation classification. The method comprises the following steps: inputting an input signal into an RE-NMR model, and outputting a modulation mode of the signal; the construction of the RE-NMR model comprises the following steps: pre-placing a robust encoder RE in an NMR model to form the RE-NMR model; determining a data set, and taking a near-synonym signal set and a synonym signal set corresponding to each input signal in the data set as a training data set to train the RE-NMR model; in a process of outputting a coded signal of a corresponding signal through a robust encoder RE, training is carried out by taking a target function of enlarging a feature distance between an input signal and an abnormal signal set, reducing the feature distance between the input signal and a near-synonym signal set, and reducing classification loss of the input signal as a target function. According to the method, the structure of the NMR model is not fixed, the NMR models of different structures can be more flexibly compatible, and the adversarial disturbance of the input signal is automatically processed, so that the adversarial defense capability of the NMR model is effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of automatic signal modulation and classification technology, and particularly relates to a neural modulation recognition adversarial defense method, system and storage medium based on a fast and robust encoder. Background Technology

[0002] Automatic Modulation Classification (AMC), as a crucial link between signal sensing and demodulation, has significant application value in scenarios such as daily communication, cognitive radio, and spectrum monitoring. Therefore, developing an effective AMC recognition model is essential. In recent years, deep learning methods, with their powerful feature extraction and representation capabilities, have made Neural Modulation Recognition (NMR), a type of deep learning-based AMC model, the mainstream model for current AMC tasks. NMR models such as AWN, CTDNN, and ResNet have been developed for AMC tasks.

[0003] However, NMR models are inherently vulnerable; for input signals that are originally classifiable, misclassification can occur after adversarial perturbations are superimposed. Therefore, researching NMR adversarial defense methods to handle adversarial perturbations is crucial for improving the performance robustness, classification accuracy, and real-world reliability of current AMC models.

[0004] Currently, there are few adversarial defense methods developed specifically for NMR models. The main difficulties lie in two aspects: firstly, the existing NMR model structures vary greatly, making it difficult for input transformation-based adversarial defense methods to adapt to different NMR structures; secondly, different adversarial perturbation generation methods differ significantly, making it difficult for adversarial defense methods based on adversarial training to defend against different adversarial perturbations.

[0005] Therefore, the key to NMR countermeasures is to construct NMR countermeasures methods that are compatible with different NMR model structures and establish NMR countermeasures methods with different countermeasures capabilities. Summary of the Invention

[0006] To address the aforementioned deficiencies or improvement needs of existing technologies, this invention proposes a neural modulation recognition adversarial defense method, system, and storage medium based on a fast robust encoder. The purpose is to use a robust encoder (RE) compatible with NMR models of different structures and to enable the encoder to suppress different adversarial disturbances through fast robust coding training, thereby solving the technical difficulties in existing technologies that are difficult to adapt to different NMR structures and difficult to defend against different adversarial disturbances.

[0007] To achieve the above objectives, according to one aspect of the present invention, a neural modulation recognition adversarial defense method based on a fast robust encoder is provided, comprising: inputting an input signal with an unknown modulation scheme into a RE-NMR model, wherein the RE-NMR model outputs the modulation scheme of the signal; wherein the RE-NMR model is constructed in the following manner: S1: The robust encoder RE is prepended to the NMR model to form the RE-NMR model; wherein the robust encoder RE is used to generate an encoded signal with the same dimension as the input signal whose modulation method is unknown; S2: Determine a dataset containing signal-to-noise ratio (SNR), and for each input signal in the dataset, calculate a set of synonymous signals for each input signal, and filter out a set of heterosense signals for each input signal from the dataset; wherein, the set of synonymous signals is a signal with a waveform similar to the input signal but a different modulation mode, and the set of heterosense signals is a signal with the same SNR as the input signal but a different modulation mode; S3: The RE-NMR model is trained using the dataset and the sets of synonymous and heterosense signals corresponding to each input signal in the dataset as training datasets. In each training round, the input signal, the sets of synonymous and heterosense signals corresponding to the input signal are input into the RE-NMR model. During the process of the robust encoder RE outputting the encoded signals corresponding to all input signals, the objective function is to increase the feature distance between the input signal and each heterosense signal set, decrease the feature distance between the input signal and each synonymous signal set, and decrease the classification loss of the input signal. Conduct training.

[0008] Preferably, the robust encoder includes a frequency domain feature extraction unit, an MLP layer, a time domain correction feature unit, and an output layer; The frequency domain feature extraction unit is used to perform fast Fourier transform on the features of the I channel and Q channel of the input signal respectively to obtain the frequency domain features corresponding to the I channel and Q channel respectively. The MLP layer is used to perform nonlinear transformations on the frequency domain features corresponding to the I channel and the Q channel to obtain the sensing features corresponding to the I channel and the Q channel, respectively. The time-domain correction feature unit is used to multiply the frequency domain features corresponding to the I channel and the Q channel and the sensing features corresponding to the I channel and the Q channel by a dot, and then perform inverse Fourier transform on each to obtain the time-domain correction features corresponding to the I channel and the Q channel. The output layer is used to add the time-domain correction features corresponding to the I and Q channels to the input signal to obtain the encoded features.

[0009] Preferably, the MLP layer is configured with two hidden layers, wherein the first hidden layer has 64 neurons and the second hidden layer has 128 neurons.

[0010] Preferably, for each input signal in the dataset, a set of synonymous signals for the input signal is calculated by performing 5-20 random time delay transformations.

[0011] Preferably, the objective function for: ; in, x Represented as input signal, Represented as input signal Corresponding synonymous signals, Represented as input signal The corresponding semantic signal, Represented as a set of synonymous signals, This is expressed as the number of synonymous signal sets. Represented as a set of synonymous signals, Represented as a set of heteronyms The number of Represented as a distance function, The distance parameter is the upper quartile of the distance between the heterosense signal in the heterosense signal set and the input signal.

[0012] Preferably, in step S3 of constructing the RE-NMR model, the RE-NMR model is iteratively trained with the minimization of the loss function under the RE-NMR model structure as the optimization objective; Minimize the loss function under the RE-NMR model structure ; in, This is expressed as the classification cross-entropy loss function of the NMR model. ; x Represented as input signal, The input signal x Modulation mode classification labels, Represented as the cross-entropy loss function, This is represented as the loss weight of the encoded signal.

[0013] Preferably, The range of values ​​is .

[0014] Preferably, the structure of the NMR model includes AWN, CTDNN, or ResNet.

[0015] According to another aspect of the present invention, a neural modulation recognition adversarial defense system based on a fast robust encoder is also provided. The system includes a memory and a processor. The memory stores a computer program. When the processor executes the computer program, it performs the neural modulation recognition adversarial defense method based on a fast robust encoder as described above.

[0016] According to another aspect of the invention, a computer-readable storage medium is also provided, the computer-readable storage medium storing machine-executable instructions, which, when invoked and executed by a processor, cause the processor to implement the neural modulation recognition adversarial defense method based on a fast robust encoder as described above.

[0017] In summary, compared with the prior art, the above-described technical solutions conceived by this invention mainly possess the following technical advantages: 1. This invention provides a neural modulation recognition adversarial defense method based on a fast robust encoder. It uses a RE-NMR model to identify the modulation mode of the input signal, enabling more flexible compatibility with NMR models of different structures and effectively improving the adversarial defense capability of the NMR model. Specifically, this invention preprocesses the input signal by placing the robust encoder (RE) before the NMR model, allowing it to be combined with neural modulation recognition NMR models of different neural network structures to generate an encoded signal with the same dimension as the original input signal, achieving good compatibility with different NMR models. Furthermore, the encoding process of the robust encoder (RE) in this invention effectively suppresses adversarial noise hidden in the input signal, adaptively reconstructing the input signal to mitigate the impact of noise, adapting to different signal-to-noise ratio environments, and possessing adaptive suppression capability against different adversarial perturbations. Simultaneously, this invention provides a fast robust training method that effectively enhances the RE encoder's ability to suppress adversarial perturbations of different degrees and directions by increasing the distance between the original input signal and the semantic signal and decreasing the distance between the original input signal and the near-semantic signal in the encoded feature space. Furthermore, the loss function designed in this invention does not require near-sense and non-sense signals to propagate in the NMR module during backpropagation training, but only in the structurally simple RE. Compared with the traditional NMR training method without additional design, it only slightly increases the amount of computation, which is significantly less than the existing NMR adversarial training methods, and has a good advantage in computational efficiency.

[0018] 2. The robust encoder of this invention includes a frequency domain feature extraction unit, an MLP layer, a time domain correction feature unit, and an output layer, which can simply and effectively suppress adversarial disturbances in the original input signal. Specifically: Although adversarial disturbances are difficult to detect in the time domain, they exhibit frequency domain characteristics that are significantly different from the original input signal. Therefore, the frequency domain feature extraction unit transforms the time domain characteristics of the input signal containing adversarial disturbances into frequency domain characteristics, thus achieving effective extraction of frequency domain features. Subsequently, the nonlinear feature extraction capability of the MLP layer is used to obtain the correction signal on the frequency domain characteristics, effectively stripping and extracting the adversarial disturbance portion from the frequency domain characteristics. Then, the time domain correction feature unit converts the correction signal on the frequency domain characteristics back into a correction signal on the time domain characteristics. Finally, the output layer combines the input signal containing adversarial disturbances with its corresponding correction signal, thus achieving effective suppression of adversarial disturbances.

[0019] 3. When generating synonymous signals, this invention effectively simulates the time delay effect in real-world scenarios through time delay transformation, resulting in naturally effective synonymous signals. When generating heterosense signals, by ensuring the signal-to-noise ratio between the heterosense signals and the original signals, excessive heterosense distances are avoided during training, thus enhancing the effectiveness of fast and robust training.

[0020] 4. In the fast and robust training method of the present invention, a set of near-sense signals and a set of heterosense signals are preferably established by random sampling, which effectively avoids the overfitting effect of the RE encoder for specific signals and enables more robust encoding and reconstruction of the input signals. Attached Figure Description

[0021] Figure 1 A flowchart for RE-NMR model signal modulation classification provided in an embodiment of the present invention.

[0022] Figure 2 The flowchart shows the construction process of the RE-NMR model in the neural modulation recognition adversarial defense method based on a fast and robust encoder provided by this invention.

[0023] Figure 3 The flowchart of the robust encoder RE signal encoding process provided in the embodiment of the present invention. Detailed Implementation

[0024] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention. Furthermore, the technical features involved in the various embodiments of this invention described below can be combined with each other as long as they do not conflict with each other.

[0025] According to one aspect of the present invention, a neural modulation recognition adversarial defense method based on a fast robust encoder is proposed, such as... Figure 1 As shown, the process includes: inputting an input signal with an unknown modulation scheme into a RE-NMR model, and the RE-NMR model outputting the modulation scheme of the signal. Specifically, the RE-NMR model includes an NMR model and a robust encoder RE placed before the NMR model. The robust encoder RE generates an encoded signal with the same dimensions as the input signal with the unknown modulation scheme. The NMR model takes the encoded signal output by the robust encoder RE as input and outputs the modulation scheme of the input signal with the unknown modulation scheme.

[0026] Among them, the construction of the RE-NMR model, such as Figure 2 As shown, it includes the following steps: S1: The robust encoder RE is placed before the NMR model to form the RE-NMR model; wherein, the robust encoder RE is used to generate an encoded signal with the same dimension as the input signal whose modulation method is unknown; S2: Determine the dataset containing the signal-to-noise ratio. For each input signal in the dataset, calculate the set of synonymous signals for each input signal and the set of heterosense signals for each input signal from the dataset. The set of synonymous signals consists of signals with similar waveforms but different modulation modes, while the set of heterosense signals consists of signals with the same signal-to-noise ratio but different modulation modes. S3: The RE-NMR model is trained using the dataset, the set of synonymous signals, and the set of heterosense signals as training datasets. Specifically, for each input signal, the input signal, along with its corresponding synonymous and heterosense signals, are input into the RE-NMR model. During the process of the robust encoder RE outputting the encoded signals corresponding to the input signal, synonymous signal, and heterosense signal, the objective function is to increase the feature distance between the input signal and the heterosense signal set, decrease the feature distance between the input signal and the synonymous signal set, and reduce the input signal classification loss. Conduct training.

[0027] In one optional implementation, a robust encoder (RE) is built and pre-placed on the NMR model to form an RE-NMR model. The robust encoder (RE) is used to generate an encoded signal with the same dimensions as the input signal whose modulation scheme is unknown, thus achieving good compatibility with different NMR models. It includes a frequency domain feature extraction unit, an MLP layer, a time domain correction feature unit, and an output layer, such as... Figure 2 This is a flowchart of the robust encoder RE signal encoding process in this embodiment.

[0028] The frequency domain feature extraction unit specifically performs the following steps: given an input signal containing I / Q time domain channels... The frequency domain features are obtained by performing Fast Fourier Transform (FFT) on the features of the I and Q channels respectively. .

[0029] The MLP layer specifically performs the following steps: It converts the frequency domain characteristics of the I and Q channels... The data are fed into a multilayer perceptron (MLP) for nonlinear processing to obtain the frequency domain features of the I and Q channels, respectively. .

[0030] The time-domain correction feature unit specifically performs the following steps: converting the frequency-domain features... With perceptual features The dot product results are then subjected to inverse Fast Fourier Transform (IFFT) to obtain the time-domain corrected features. .

[0031] The output layer specifically performs the following steps: It processes the correction features... With original features The final encoded features are obtained by adding the initial input signals together. .

[0032] Furthermore, the MLP is set to have two hidden layers, with the first hidden layer having 64 neurons and the second hidden layer having 128 neurons. This allows for a simple and effective separation and extraction of adversarial features in the frequency domain, while ensuring the consistency of the output result with the input signal dimension.

[0033] In one optional implementation, in the construction of the training set in step S2, a typical wireless communication signal dataset RML2016.10a is used, and this wireless communication signal dataset is used as the training dataset, validation set, and test set for subsequent training. For each input signal in the dataset, a set of synonymous signals for each input signal is calculated, and a set of dissident signals for each input signal is selected from the dataset. The dataset, along with the sets of synonymous and dissident signals corresponding to each input signal in the dataset, constitute the training set of the RE-NMR model.

[0034] The set of synonymous signals consists of signals with waveforms similar to the input signal and the same modulation mode. It is calculated through random time-delay transformation, typically after 5-20 iterations. The set of heterosemantic signals consists of signals with the same signal-to-noise ratio (SNR) but different modulation modes than the input signal. It is randomly selected from the dataset based on the condition of the same SNR and different modulation modes. Specifically, for the dataset... Each input signal in x The corresponding signal-to-noise ratio value v for The corresponding modulation category for In each training step, the input signal is obtained. Perform multiple time delay transformations Constructing a set of synonymous signals ,by and As a condition, multiple signals are randomly sampled. As a signal dissident signal set .

[0035] In one optional implementation, during the training process of the model in step S3, when the robust encoder RE outputs the encoded signals corresponding to all input signals, the objective function is to increase the feature distance between the input signal and the set of dissident signals, decrease the feature distance between the input signal and the set of near-sense signals, and reduce the classification loss of the input signal. Conduct training.

[0036] Specifically, in each training iteration, the input signal will be... The set of synonymous signals contains all synonymous signals. The set of all semantic signals The corresponding encoded features are obtained by feeding them into the robust encoder RE. At this point, the objective of the loss function for minimizing the encoded features of the robust encoder RE structure is: ; in, x Represented as input signal, Represented as input signal Corresponding synonymous signals, Represented as input signal The corresponding semantic signal, Represented as a set of synonymous signals, This is expressed as the number of synonymous signal sets. Represented as a set of synonymous signals, Represented as a set of heteronyms The number of Represented as a distance function, This is the distance parameter.

[0037] The preferred value is the upper quartile of the distance between the lost signal and the input signal in the lost signal set, used to eliminate lost signals with excessively large distances. Specifically, for each lost signal in the lost signal set, its distance to the input signal is calculated; these distance values ​​are collected to obtain the lost signal distance set, and the upper quartile of the lost signal distance set is statistically analyzed as the preferred value. value.

[0038] In one optional implementation, during the training process of the model in step S3, the RE-NMR model is iteratively trained with the goal of minimizing the loss function under the RE-NMR model structure.

[0039] The loss function for minimizing the weights in the NMR model is the classification cross-entropy loss. , Represents the cross-entropy function. x Represented as input signal, The input signal x Modulation mode classification labels.

[0040] Therefore, the overall training objective of RE-NMR is to minimize the loss function under the RE-NMR model structure. , Weights are used to encode features.

[0041] Furthermore, The range of values ​​is .

[0042] In the training process of the RE-NMR model of this invention, based on a single sample It will have a complete effect on both RE and NMR; while multiple samples are required. It only applies to RE and does not need to participate in subsequent NMR training. This training method considers both RE and NMR as a whole and enables rapid training of multi-sample encoding features. It expands the encoding distance of outlier samples in the encoding feature space and has natural robustness for adversarial defense.

[0043] In one alternative implementation, the structure of the NMR model is not limited, including AWN, CTDNN, or ResNet, and is compatible with NMR models of different structures.

[0044] According to another aspect of the present invention, the present invention provides a neural modulation recognition adversarial defense system, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, it implements the neural modulation recognition adversarial defense method provided in the first aspect of the present invention. The related technical solutions are the same as the neural modulation recognition defense method provided in the first aspect of this invention, and will not be described in detail here.

[0045] According to another aspect of the invention, the invention also provides a computer-readable storage medium comprising a stored computer program, wherein the computer program, when executed by a processor, controls the device containing the storage medium to perform the neural modulation recognition defense method provided in the first aspect of the invention.

[0046] The related technical solutions are the same as the neural modulation recognition method provided in the first aspect of this invention, and will not be described in detail here.

[0047] The following example illustrates a neural modulation recognition adversarial defense method based on a fast and robust encoder constructed using this invention, denoted as the FRE method.

[0048] This embodiment will elaborate on the sampling of near-sense and non-sense signals and the RE-NMR training process in steps S2 and S3. The specific steps are as follows: Step 0: Dataset Validate dataset Number of iterations T Number of heteronyms Number of synonymous signals , Encoding feature loss weights ; Step 1: Initialize RE model parameters With NMR model parameters ; Step 2: Determine the current iteration Is it less than the number of iterations? If not, skip to step 10; Step 3: For Each input signal in Generate a set of synonymous signals ; Step 4: For Each input signal in Generate a set of heteronymous signals ; Step 5: Find ; Step 6: Find ; Step 7: Find Encoding Feature Loss Weights ; Step 8: Use right and Perform gradient descent; Step 9: Skip to step 2; Step 10: Output , .

[0049] This experimental example uses the commonly used RML2016.10a dataset generated by GNU Radio. This dataset contains 220,000 examples covering 11 modulation classes and 20 different signal-to-noise ratio (SNR) values, ranging from -20 dB to +18 dB, with +2 dB intervals. The dataset is divided into training, validation, and test sets in a 3:1:1 ratio. Each modulation class includes 1000 examples per SNR, with each example containing 128 sampling time steps. For each input signal in the training set, samples are randomly generated. There are one heteronym signal, and the size of the synonym signal set is set to [size]. .

[0050] The FRE pseudocode is shown in Table 1. The RE structure is as follows: Figure 3 As shown, the RE-NMR model structure is as follows: Figure 1 As shown.

[0051] Table 1: FRE Pseudocode

[0052] This experiment selected three adversarial training methods as comparison baselines: AMD, PGD-AT, and TRADES. On three types of NMR models—AWN, CTDNN, and ResNet—MI adversarial attack methods were applied after model training, with PSR being the most suitable. Adversarial samples containing adversarial perturbations were generated on test set samples with SNR values ​​of 0dB, 4dB, 8dB, 12dB and 16dB to conduct adversarial defense tests.

[0053] Table 1 shows the average accuracy of all methods against MI adversarial attacks on the RML2016.10a dataset. The results demonstrate that the FRE method outperforms all adversarial training baselines on all NMR models, proving the compatibility of the neural modulation recognition method provided in this invention across different NMR model structures and the effectiveness and superiority of the adversarial defense method.

[0054] Table 2: Average accuracy (%) of AMD, PGD-AT, TRADES, and FRE methods against MI adversarial attack algorithms on three types of NMR models: AWN, CTDNN, and ResNet.

[0055] Those skilled in the art will readily understand that the above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A neural modulation recognition adversarial defense method based on a fast robust encoder, characterized in that, include: An input signal with an unknown modulation scheme is input into a RE-NMR model, which outputs the modulation scheme of the signal; wherein, the RE-NMR model is constructed in the following manner: S1: The robust encoder RE is prepended to the NMR model to form the RE-NMR model; wherein the robust encoder RE is used to generate an encoded signal with the same dimension as the input signal whose modulation method is unknown; S2: Determine a dataset containing signal-to-noise ratio (SNR), and for each input signal in the dataset, calculate a set of synonymous signals for each input signal, and filter out a set of heterosense signals for each input signal from the dataset; wherein, the set of synonymous signals is a signal with a waveform similar to the input signal but a different modulation mode, and the set of heterosense signals is a signal with the same SNR as the input signal but a different modulation mode; S3: The RE-NMR model is trained using the dataset and the sets of synonymous and heterosense signals corresponding to each input signal in the dataset as training datasets. In each training round, the input signal, the sets of synonymous and heterosense signals corresponding to the input signal are input into the RE-NMR model. During the process of the robust encoder RE outputting the encoded signals corresponding to all input signals, the objective functions are to increase the feature distance between the input signal and the heterosense signal set, decrease the feature distance between the input signal and the synonymous signal set, and decrease the classification loss of the input signal. Conduct training.

2. The neural modulation recognition adversarial defense method based on a fast robust encoder according to claim 1, characterized in that, The robust encoder includes a frequency domain feature extraction unit, an MLP layer, a time domain correction feature unit, and an output layer; The frequency domain feature extraction unit is used to perform fast Fourier transform on the features of the I channel and Q channel of the input signal respectively to obtain the frequency domain features corresponding to the I channel and Q channel respectively. The MLP layer is used to perform nonlinear transformations on the frequency domain features corresponding to the I channel and the Q channel to obtain the sensing features corresponding to the I channel and the Q channel, respectively. The time-domain correction feature unit is used to multiply the frequency domain features corresponding to the I channel and the Q channel and the sensing features corresponding to the I channel and the Q channel by a dot, and then perform inverse Fourier transform on each to obtain the time-domain correction features corresponding to the I channel and the Q channel. The output layer is used to add the time-domain correction features corresponding to the I and Q channels to the input signal to obtain the encoded features.

3. The neural modulation recognition adversarial defense method based on a fast robust encoder according to claim 2, characterized in that, The MLP layer is configured with two hidden layers, with the first hidden layer having 64 neurons and the second hidden layer having 128 neurons.

4. The neural modulation recognition adversarial defense method based on a fast robust encoder according to claim 1, characterized in that, For each input signal in the dataset, a set of synonymous signals for the input signal is calculated by performing 5-20 random time delay transformations.

5. The neural modulation recognition adversarial defense method based on a fast robust encoder according to claim 1, characterized in that, The objective function for: ; in, x Represented as input signal, Represented as input signal Corresponding synonymous signals, Represented as input signal The corresponding semantic signal, Represented as a set of synonymous signals, This is expressed as the number of synonymous signal sets. Represented as a set of synonymous signals, Represented as a set of heteronyms The number of Represented as a distance function, The distance parameter is taken as the upper quartile of the distance between the heterosense signal in the heterosense signal set and the input signal.

6. The neural modulation recognition adversarial defense method based on a fast robust encoder according to claim 1, characterized in that, In step S3 of the RE-NMR model construction, the RE-NMR model is iteratively trained with the minimization of the loss function under the RE-NMR model structure as the optimization objective. Minimize the loss function under the RE-NMR model structure ; in, This is expressed as the classification cross-entropy loss function of the NMR model. ; x Represented as input signal, The input signal x Modulation mode classification labels, Represented as the cross-entropy loss function, This is represented as the loss weight of the encoded signal.

7. The neural modulation recognition adversarial defense method based on a fast robust encoder according to claim 6, characterized in that, The range of values ​​is .

8. The neural modulation recognition adversarial defense method based on a fast robust encoder according to claim 6, characterized in that, The structure of the NMR model includes AWN, CTDNN, or ResNet.

9. A neural modulation recognition adversarial defense system based on a fast robust encoder, characterized in that, The system includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, it performs the neural modulation recognition adversarial defense method based on a fast robust encoder as described in any one of claims 1-8.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores machine-executable instructions, which, when invoked and executed by a processor, cause the processor to perform claim 1. The neural modulation recognition adversarial defense method based on any one of the eight claims.