Method for noise reduction before transmitting a radio signal by a transmitter, associated device and computer program
By applying a noise-making process to radio signals using an adversary attack method and inverse transformation, the method protects against malicious classification of transmitter class, ensuring secure communication.
Patent Information
- Application Number
- EP2025180645
- Authority / Receiving Office
- EP · EP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-04
- Filing Date
- 2025-06-04
- Publication Date
- 2025-12-10
AI Technical Summary
Existing radio signal transmission methods are vulnerable to detection and classification by machine learning-trained classification models, allowing malicious interception and demodulation of signals.
A noise-making process is applied before radio signal emission to deceive classification models by transforming the signal into a modified spectrogram using an adversary attack method, followed by an approximate inverse transformation to generate a noisy signal that fools the classification model.
The method effectively prevents illegitimate receivers from correctly identifying the transmitter class, while ensuring legitimate receivers can decode the signal, enhancing communication security.
Smart Images

Figure IMGAF001_ABST
Abstract
Description
[0001] The present invention relates to a method of adding noise before the emission of a radio signal by a transmitter, a device and an associated computer program.
[0002] The invention lies in the field of secure radio transmissions with respect to possible interceptions of emitted radio signals.
[0003] More specifically, the invention aims to render inoperative the detection of a class of device emitting a radio signal from an intercepted radio signal, the detection using an artificial intelligence method.
[0004] In the field of telecommunications, it is useful, for certain applications, to detect the class to which the device emitting a radio signal belongs, from a plurality of predetermined classes.
[0005] Detecting the class of the transmitting device can also be used maliciously by a receiving device that intercepts radio signals, operated by a third party that is not a legitimate recipient of the radio signal. Specifically, knowing the transmitter class allows the type of modulation applied to be determined, and subsequently, the received signal to be demodulated and information extracted from it.
[0006] Artificial intelligence, which is rapidly developing, provides various algorithms for creating classification models, trained through machine learning, that can, given input data, such as a matrix, classify the input data into one of a plurality of predetermined classes. For example, such classification models are obtained by implementing neural networks. Various types of neural networks are known, such as convolutional neural networks (CNNs), deep neural networks (DNNs), and long short-term memory models (LSTMs).
[0007] One objective of the invention is to provide a method and device for emitting radio signals that is robust against possible attempts to detect the class of transmitter using a machine learning-trained classification model.
[0008] To this end the invention proposes a noise-making process before the emission of a radio signal, allowing to deceive a transmitter class detector using a classification model trained by machine learning.
[0009] According to one aspect, the invention relates to a method of adding noise before the transmission of a radio signal by a transmitter belonging to a given class of transmitters, called the initial class, in order to render inoperative the detection of a transmitter's class membership by implementing a classification model previously trained by machine learning to detect the transmitter class among a plurality of predetermined transmitter classes. This method is implemented by a computing processor and comprises the following steps: A) obtaining a first modulated signal in I / Q format, B) time-frequency transformation of said first modulated signal to obtain a first spectrogram, C) application of an adversary attack method, knowing the classification model previously trained by machine learning to detect an emitter class from a spectrogram, the adversary attack method allowing to obtain a modified spectrogram from the first spectrogram, such that said classification model provides an erroneous emitter class from the modified spectrogram, D) approximate inverse transformation of the modified spectrogram to obtain a second modulated signal.
[0010] Advantageously, the proposed method yields a second modulated signal, which is a noisy version of the first modulated signal. The second modulated signal is then transmitted by a radio communication module, enabling the transmission of a radio signal from which a machine learning-trained classification model obtains an incorrect transmitter class. In other words, advantageously, the proposed method effectively deceives a receiving device that uses the classification model to detect the transmitter class. Thus, a transmitting device implementing the method of the invention enables more secure communication.
[0011] According to other advantageous aspects of the invention, the radio signal noise-making process before transmission comprises one or more of the following features, taken individually or in all technically possible combinations.
[0012] The method further includes sending the second modulated signal to a transmission interface module for radio transmission of said second modulated signal.
[0013] The method further comprises applying said time-frequency transformation to the second modulated signal to obtain a second spectrogram, classifying by said classification model to obtain a detected emitter class, comparing the detected class with the initial class, and, if the detected class is different from the initial class, sending the second modulated signal to an emission interface module for radio transmission of said second modulated signal.
[0014] If, following the comparison, the detected class is the initial class, the process further involves a modification of said second modulated signal by adding noise.
[0015] The addition of noise is done by a gradient descent attack method.
[0016] The time-frequency transformation is a short-term Fourier transform, STFT.
[0017] The opposing method applied in step C) is a gradient descent method.
[0018] According to another aspect, the invention relates to a noise-generating device prior to the transmission of a radio signal by a transmitter belonging to a given class of transmitters, called the initial class, in order to render inoperative the detection of a transmitter's class membership by implementing a classification model previously trained by machine learning to detect the transmitter class among a plurality of predetermined transmitter membership classes, comprising a computing processor configured to implement: a module for obtaining a first modulated signal in I / Q format, a time-frequency transformation module of said first modulated signal to obtain a first spectrogram, a module for applying an adversary attack method, knowing the classification model previously trained by machine learning to detect an emitter class from a spectrogram, the adversary attack method allowing to obtain a modified spectrogram from the first spectrogram, such that said classification model provides an erroneous emitter class from the modified spectrogram, a module for approximate inverse transformation of the modified spectrogram to obtain a second modulated signal.
[0019] The invention also relates to a computer program comprising software instructions which, when executed by a computer, implement a noise-making process before the emission of a radio signal as defined above.
[0020] The invention will become clearer upon reading the following description, given solely by way of non-limiting example, and made with reference to the drawings in which: [ Fig. 1 ] there figure 1 schematically represents a radio communication system comprising a noise generator before radio signal transmission and a receiver configured to intercept a transmitted radio signal; Fig. 2 ] there figure 2 is a synoptic diagram of the main steps of a noise-making process prior to radio signal emission according to one embodiment.
[0021] There figure 1 schematically illustrates a wireless communication system 2 in which the proposed invention finds an application.
[0022] System 2 includes a transmitter device 4 configured to transmit radio signals and a receiver device 6 configured to receive radio signals.
[0023] The emitted radio signals are propagated through a propagation channel 8.
[0024] The transmitting device 4 includes a communication interface module 10, configured to implement radio signal communication according to a predetermined communication protocol. Module 10 implements digital-to-analog conversion (DAC) processing and radio signal transmission via an electromagnetic antenna (not shown).
[0025] Due to the type of signal processing applied, the transmitting device 4 belongs to a class of transmitter among a plurality of predetermined classes of transmitters, called the initial class.
[0026] The transmitting device 4 comprises one or more processing units 12 and an electronic memory unit 14, forming an electronic computing device configured to implement a noise-generating process prior to the transmission of a radio signal according to the invention. Thus, the transmitting device 4 is also a noise-generating device prior to the transmission of radio signals.
[0027] Elements 10, 12 and 14 are adapted to communicate via an internal communication bus.
[0028] The computing processor 12 is configured to implement a preprocessing module 18 which provides a quadrature modulated signal, also known as I / Q format (from the English "In-phase and Quadrature"), well known in the field of signal processing.
[0029] The computing processor 12 is further configured to implement noise processing 20 with the aim of inducing an erroneous emitter classification by a classifier implementing a classification model 22, the classification model being trained by machine learning to detect a class membership of the emitting device from a spectrogram of a signal in I / Q format, as described in more detail below.
[0030] In particular, noise processing 20 is carried out by implementing: of a time-frequency transformation module 24 which transforms a first signal in I / Q format into a first spectrogram, of a module 26 for applying an adversary attack method to the first spectrogram to obtain a modified spectrogram, such that when the modified spectrogram is provided as input to the classification model 22, the classification obtained is erroneous; of a module 28 for approximate inverse transformation of the modified spectrogram to obtain a second modulated signal.
[0031] As is well known, a spectrogram is a two-dimensional time-frequency representation, depicted as a matrix of values and visualized as a digital image. The time-frequency transformation of a given signal into a spectrogram involves, as is well known, dividing the signal by applying a partially overlapping window, with windows of a given size, to obtain time segments, and then applying a spectral transformation, e.g., a discrete Fourier transform, to each time segment. This transformation is also called a short-time Fourier transform, or STFT.
[0032] The computing processor 12 is further configured to run, optionally, a verification module 30, implementing the time-frequency transformation to transform the second modulated signal into a second spectrogram, a classification by the classification model 22 from the second spectrogram to obtain a detected emitter class.
[0033] If the detected transmitter class is different from the initial class, the second modulated signal is transmitted to the transmit interface module 10 for radio transmission of said modulated signal.
[0034] If the detected class is equal to the initial class, additional processing is implemented, including adding noise to the second modulated signal.
[0035] In one embodiment, modules 18, 24, 26, 28, 30 are implemented as software instructions forming a computer program, which, when executed by a programmable electronic device, implements a noise-making process before the emission of a signal as described.
[0036] In an alternative not shown, modules 18, 24, 26, 28, and 30 are each implemented as programmable logic components, such as FPGAs (from the English Field Programmable Gate Array ), microprocessors, GPGPU components (from English General-Purpose computing on Graphics Processing Units ), or even dedicated integrated circuits, such as ASICs (from the English Application Specific Integrated Circuit ).
[0037] The computer program, containing software instructions, is also capable of being stored on a non-transient, computer-readable information storage medium. This computer-readable medium is, for example, a medium capable of storing electronic instructions and being connected to a bus of a computer system. Examples of such media include optical discs, magneto-optical discs, ROMs, RAM, any type of non-volatile memory (e.g., EPROM, EEPROM, FLASH, NVRAM), magnetic cards, or optical cards.
[0038] The receiver device 6 includes a communication interface module 32, configured to receive radio signals according to a predetermined communication protocol. Module 32 implements a radio signal receiver and an analog-to-digital conversion (ADC) processor. Specifically, Module 32 performs analog filtering around a given frequency F1, with a bandwidth B1, resulting in a signal with a frequency between F1 - B1 / 2 and F1 + B1 / 2. This is followed by analog frequency transposition to center the frequencies around zero, and finally, digitization of the signals.
[0039] The receiving device 6 further comprises one or more computing processors 34, and an electronic memory unit 36, forming an electronic computing device, configured to implement transmitter class detection of a received radio signal.
[0040] Elements 32, 34 and 36 are adapted to communicate via an internal communication bus.
[0041] The computing processor 34 is configured to implement a preprocessing module 38 which provides a quadrature modulated signal, also called I / Q format (from the English "In-phase and Quadrature"), from the received radio signal.
[0042] The computing processor 34 further implements a time-frequency transformation module 40 which transforms a signal in I / Q format into a spectrogram, and a classification module 44 which applies a classification model 42, previously trained by machine learning, to provide a class membership of a transmitting device from a spectrogram of a signal in I / Q format. The output is a detected emitter class CI_E.
[0043] Preferably, each of the classification models 22, 42 is implemented in the form of a neural network.
[0044] According to a first variant, classification model 42 is identical to classification model 22.
[0045] According to a second variant, classification model 42 is a slightly modified version of classification model 22, for example modified by an operation called refinement or "fine-tuning" in English.
[0046] As is known, a neural network consists of an ordered succession of layers of neurons, each of which takes its inputs from the outputs of the previous layer.
[0047] More specifically, each layer comprises neurons taking their inputs from the outputs of the neurons in the previous layer, or from the input variables for the first layer.
[0048] Alternatively, more complex neural network structures can be considered with a layer that can be linked to a layer further away than the immediately preceding layer.
[0049] Each neuron is also associated with an operation, that is, a type of processing, to be carried out by said neuron within the corresponding processing layer.
[0050] Each layer is connected to the other layers by a plurality of synapses. A synaptic weight is associated with each synapse, and each synapse forms a link between two neurons. This is often a real number, which takes on both positive and negative values. In some cases, the synaptic weight is a complex number.
[0051] Each neuron performs a weighted summation of the value(s) received from the neurons in the preceding layer. Each value is then multiplied by the respective synaptic weight of each synapse, or connection, between that neuron and the neurons in the preceding layer. Next, an activation function, typically a non-linear function, is applied to this weighted summation. The resulting value is then delivered to the neuron's output, particularly to the neurons in the next layer connected to it. The activation function introduces non-linearity into the processing performed by each neuron. The sigmoid function, the hyperbolic tangent function, and the Heaviside function are examples of activation functions.
[0052] As an optional complement, each neuron is also capable of applying, in addition, a multiplicative factor, and an additive bias, to the output of the activation function, and the value delivered at the output of said neuron is then the product of the value of the multiplicative factor and the value from the activation function, plus the bias.
[0053] A convolutional neural network is also sometimes called a convolutional neural network or by the acronym CNN, which refers to the English term " Convolutional Neural Networks "
[0054] In a convolutional neural network, each neuron in the same layer has exactly the same connection pattern as its neighboring neurons, but at different input positions. The connection pattern is called the convolution kernel or, more often, " kernel » in reference to the corresponding English name.
[0055] A fully connected layer of neurons is a layer in which the neurons of said layer are each connected to all the neurons of the preceding layer.
[0056] This type of layer is more often referred to by the English term " fully connected and sometimes referred to as the "dense layer".
[0057] The values of the weights, multipliers and biases where applicable are learned during a machine learning phase to perform the classification task.
[0058] The invention applies to all types of neural networks, in particular convolutional neural networks or CNNs, deep neural networks or DNNs, LSTM models (for "long short term memory model") etc.
[0059] Several operating scenarios are possible in communication system 2.
[0060] The transmitting device 4 is capable of emitting a noise-free modulated signal, SE1, emitted by the communication interface module 10 without application of the noise processing 20, or a noisy modulated signal SE2, emitted by the communication interface module 10 after application of the noise processing 20.
[0061] In the case where the receiving device 6 is a legitimate receiver, the intended recipient of the radio signal emitted by the transmitting device 4, the receiving device is capable of processing both a received signal SR1, corresponding to the noise-free modulus signal SE1, possibly modified by the effects of the propagation channel 8, and a received signal SR2, corresponding to the noisy modulus signal SE2, possibly modified by the effects of the propagation channel 8. Indeed, a legitimate receiving device is informed of the possible implementation of noise reduction 20 by a transmitter for the purpose of stealth, and is informed of the transmitter's likely initial class. Thus, a legitimate receiving device is configured to perform decoding either with knowledge of the initial class or with knowledge of the detected transmitter class, and therefore to obtain the information contained in the received signal SR1 or SR2.
[0062] In the case of an application where the receiving device 6 is a non-intended receiver of the transmitted, potentially malicious, radio signal, the receiving device 6 is able to detect the transmitter class of the transmitting device 4 from a received signal SR1, corresponding to the noise-free module signal SE1, possibly modified by the effects of the propagation channel 8, but is not able to correctly detect the transmitter class of the transmitting device 4 from a received signal SR2, corresponding to the noisy module signal SE2, possibly modified by the effects of the propagation channel 8. In other words, the CI_E class obtained at the output of the module 44 is different from the transmitter class of the device 4. Indeed, due to the noise processing 20, the classification model 42 provides an erroneous classification result.
[0063] In other words, noise processing 20 allows an illegitimate receiving device to be deceived. The incorrect determination of the transmitter class subsequently leads to incorrect decoding of the received radio signal.
[0064] There figure 2 is a synoptic diagram of the main steps in a noise-making process before broadcast.
[0065] The process is implemented by the processor 12 of an electronic computing device.
[0066] The process includes a pre-processing step 50 to obtain a first modulated signal in I / Q format ready to be transmitted to the communication interface module for transmission. The transmitting device belongs to a given transmitter class, called the initial class. The first signal encodes a binary message (or payload) intended for one or more legitimate receivers.
[0067] In one embodiment, step 50 implements a propagation simulation by adding distortions (e.g., noise, phase shift) that may be induced by a propagation channel and a pre-processing of the radio signal received by a receiver. The process then includes a step 52 of time-frequency transformation of the first modulated signal to obtain a first corresponding spectrogram.
[0068] For example, the applied time-frequency transformation is an STFT transformation.
[0069] The first spectrogram is represented as a matrix of points, of size each point having an associated value and being associated with a time index and a frequency index.
[0070] The process further includes a step 54 of applying an adversary attack method against a classification model 22 previously trained by machine learning to determine a class of emitter from the spectrogram of a signal in I / Q format.
[0071] The classification model 22 is, for example, a neural network, whose parameters are known.
[0072] Adversarial attack methods, also known as evasion attacks, are known in the field of artificial intelligence. These attack methods consist of modifying the input data in order to alter the behavior of the classification model; the input data is generally digital images that are modified in a way that is imperceptible to the human observer.
[0073] As an example, we can cite the article "Towards Deep Learning Models Resistant to Adversarial Attacks" by A. Madry et al., published online and available at https: / / arxiv.org / pdf / 1706.06083.pdf, which describes several adversarial attack methods. The article "Wasserstein Adversarial Examples via Projected Sinkhorn Iterations" by E. Wong et al., published online and available at https: / / arxiv.org / abs / 1902.07906, describes iterative attacks on image classification models.
[0074] For example, the opponent's attack method applied is the Projected Gradient Descent method.
[0075] Alternatively, any other method of attacking an adversary, resulting in an erroneous classification by a classification model, is applicable.
[0076] At the end of step 54, a modified spectrogram is obtained. Classification model 22, when applied to the modified spectrogram as input, provides an incorrect emitter class as output, which is different from the initial class.
[0077] The process then includes a step 56 of approximate inverse transformation of the transformation applied in step 52, the approximate inverse transformation being applied to the modified spectrogram and allowing a second modulated signal to be obtained.
[0078] The inverse transformation is called approximate because, as is known, the STFT transformation is only invertible if certain windowing conditions are met (see, for example, the article by Ivan W. Selesnik, "Short-Time Fourier Transform and Its Inverse," available online at https: / / eeweb.engineering.nyu.edu / iselesni / EL713 / STFT / stft_inverse.pdf). In other words, if certain windowing conditions are met, applying the time-frequency transformation to the second modulated signal produces the modified spectrogram. If these windowing conditions are not met, applying the time-frequency transformation to the second modulated signal yields a second spectrogram that differs from the modified spectrogram.
[0079] The process optionally includes a verification step 57 in which the STFT transformation applied in transformation step 52 is applied (step 58) to the second modulated signal, and a second spectrogram is obtained. Then, classification 60 using classification model 22 is applied to the second spectrogram as input. A detected class CI_E is obtained as the output of classification step 60.
[0080] The detected class CI_E is then compared (step 62) to the initial class of the emitter.
[0081] If the detected class is different from the initial class, the second modulated signal is transmitted to the transmitter at transmission step 64.
[0082] If the detected class is the same as the initial class, the process then includes an additional noiseing step (66), during which noise is added to the second signal in I / Q format, and the verification step is repeated until the detected class is different from the initial class. The added noise can be applied, for example, using the "Projected Gradient Adversarial attack" method.
[0083] Furthermore, it is verified that the second noisy I / Q signal is decodable by a legitimate receiving device to extract the binary message, the legitimate receiving device knowing the initial transmitter class, and therefore the demodulation method to apply.
[0084] Advantageously, the proposed method makes it possible to mislead an illegitimate receiving device, and therefore consequently to prevent any decoding of the message carried by the modulated signal by such a receiving device, while preserving the decoding capability of a legitimate receiving device, the initial class of transmitter having been transmitted beforehand to the legitimate receiver, for example during the establishment of the mission plan.
Claims
1. A noise-generating method prior to the transmission of a radio signal by a transmitter belonging to a given class of transmitters, called the initial class, in order to render inoperative the detection of a class of transmitter membership by implementing a classification model previously trained by machine learning to detect the class of transmitter among a plurality of predetermined classes of transmitter membership, the method being implemented by a computing processor and comprising the steps of: - A) obtaining (50) a first modulated signal in I / Q format, - B) time-frequency transformation (52) of said first modulated signal to obtain a first spectrogram, - C) application (54) of an adversary attack method, knowing the classification model (22) previously trained by machine learning to detect a class of transmitter from a spectrogram,the adversary attack method enabling the acquisition of a modified spectrogram from the first spectrogram, such that said classification model (22) provides an erroneous emitter class from the modified spectrogram, - D) approximate inverse transformation (56) of the modified spectrogram to obtain a second modulated signal.
2. Method according to claim 1, further comprising sending (64) the second modulated signal to a transmission interface module (10) for radio transmission of said second modulated signal.
3. A method according to claim 1, further comprising an application (58) of said time-frequency transformation on the second modulated signal to obtain a second spectrogram, a classification (60) by said classification model (22) enabling a detected emitter class to be obtained, a comparison (62) of the detected class and the initial class, and, if the detected class is different from the initial class, a transmission (64) of the second modulated signal to a transmission interface module (10) for radio transmission of said second modulated signal.
4. Method according to claim 3, wherein, if following the comparison (62), the detected class is the initial class, the method further comprises a modification (66) of said second modulated signal by adding noise.
5. A method according to claim 4, wherein the addition of noise is carried out by a gradient descent attack method.
6. A method according to any one of claims 1 to 5, wherein said time-frequency transformation is a short-term Fourier transform, STFT.
7. A method according to any one of claims 1 to 6, wherein said opposing method applied in step C) is a gradient descent method.
8. Computer program comprising software instructions which, when executed by a programmable electronic device, implement a noise-making process prior to the emission of a radio signal in accordance with claims 1 to 7.
9. A noise-generating device prior to the transmission of a radio signal by a transmitter belonging to a given transmitter class, referred to as the initial class, in order to render inoperative the detection of a transmitter class membership by implementing a classification model previously trained by machine learning to detect the transmitter class among a plurality of predetermined transmitter class memberships, comprising a computing processor configured to implement: - a module (18) for obtaining a first modulated signal in I / Q format, - a module (24) for time-frequency transformation of said first modulated signal to obtain a first spectrogram, - a module (26) for applying an adversary attack method, knowing the classification model previously trained by machine learning to detect a transmitter class from a spectrogram,the adversary attack method enabling the acquisition of a modified spectrogram from the first spectrogram, such that said classification model provides an erroneous emitter class from the modified spectrogram, - an approximate inverse transformation module (28) of the modified spectrogram to obtain a second modulated signal.
10. Device according to claim 9, further comprising a verification module (30) configured to implement an application of said time-frequency transformation on the second modulated signal to obtain a second spectrogram, a classification by said classification model enabling a detected emitter class to be obtained.