A method for adding noise before the transmission of a radio signal by a transmitter, device and associated computer program
By adding noise to radio signals using time-frequency transformation and adversarial attacks, the method protects against classification model detection, ensuring secure communication by misleading illegitimate receivers while allowing legitimate decoding.
Patent Information
- Authority / Receiving Office
- FR · FR
- Patent Type
- Patents
- Current Assignee / Owner
- THALES SA
- Filing Date
- 2024-06-04
- Publication Date
- 2026-05-01
AI Technical Summary
Existing radio signal transmission methods are vulnerable to detection of the transmitter class by classification models trained by machine learning, which can be exploited for malicious purposes, leading to demodulation and information extraction.
A noise-making method is applied before radio signal transmission, using time-frequency transformation and adversarial attacks to deceive classification models, generating a noisy signal that fools the detection of the transmitter class.
The method effectively prevents illegitimate receivers from correctly identifying the transmitter class, while ensuring legitimate receivers can decode the signal, enhancing communication security.
Smart Images

Figure 00000015_0000 
Figure 00000016_0000
Abstract
Description
Title of the invention: Method for adding noise before the transmission of a radio signal by a transmitter, associated device and computer program
[0001] The present invention relates to a method of adding noise before the emission of a radio signal by a transmitter, a device and an associated computer program.
[0002] The invention lies in the field of secure radio transmissions with respect to possible interceptions of emitted radio signals.
[0003] More particularly, the invention aims to render inoperative the detection of a class of the device emitting a radio signal from an intercepted radio signal, the detection using an artificial intelligence method.
[0004] In the field of telecommunications, it is useful, for certain applications, to detect the class to which the device emitting a radio signal belongs, from a plurality of predetermined classes.
[0005] Detecting the class of the transmitting device can also potentially be used for malicious purposes by a receiving device that intercepts radio signals, used by a third party that is not one of the legitimate recipients of the radio signal. In particular, knowing the transmitter class makes it possible to determine the type of modulation applied, and subsequently to demodulate the received signal and extract information from it.
[0006] Artificial intelligence, which is developing rapidly, provides various algorithms for developing classification models, trained by machine learning, that, given input data, for example presented in matrix form, can be used to classify the input data into one class among a plurality of predetermined classes. For example, such classification models are obtained by implementing neural networks. Various types of neural networks are known, for example, convolutional neural networks (CNNs), deep neural networks (DNNs), long short-term memory models (LSTMs), etc.
[0007] An objective of the invention is to provide a method and device for emitting radio signals that is robust against possible attempts to detect the class of transmitter using a classification model trained by machine learning.
[0008] To this end, the invention proposes a noise-making method before the emission of a radio signal, allowing a class of transmitter detector to be fooled using a classification model trained by machine learning.
[0009] According to one aspect, the invention relates to a method of adding noise before the transmission of a radio signal by a transmitter belonging to a given class of transmitters, referred to as the initial class, in order to render inoperative the detection of a transmitter's class membership by implementing a classification model previously trained by machine learning to detect the transmitter class among a plurality of predetermined transmitter classes. This method is implemented by a computing processor and comprises the following steps: - A) obtaining a first modulated signal in I / Q format, - B) time-frequency transformation of said first modulated signal for to obtain an initial spectrogram, - C) application of an adversary attack method, knowing the classification model previously trained by machine learning to detect an emitter class from a spectrogram, the adversary attack method allowing to obtain a modified spectrogram from the first spectrogram, such that said classification model provides an erroneous emitter class from the modified spectrogram, - D) approximate inverse transformation of the modified spectrogram to obtain a second modulated signal.
[0010] Advantageously, the proposed method makes it possible to obtain a second modulated signal, which is a noisy version of the first modulated signal. The transmission of this second modulated signal by a radio communication module allows the transmission of a radio signal from which a machine learning-trained classification model obtains an erroneous transmitter class. In other words, advantageously, the proposed method makes it possible to effectively deceive a receiving device using the classification model to detect the transmitter class. Thus, a transmitting device implementing the method of the invention enables more secure communication.
[0011] According to other advantageous aspects of the invention, the radio signal noise-making method before transmission comprises one or more of the following features, taken individually or in all technically possible combinations.
[0012] The method further comprises sending the second modulated signal to a transmission interface module for radio transmission of said second modulated signal.
[0013] The method further comprises applying said time-frequency transformation to the second modulated signal to obtain a second spectrogram, classifying by said classification model to obtain a detected emitter class, comparing the detected class with the initial class, and, if the detected class is different from the initial class, sending the second modulated signal to an emission interface module for radio transmission of said second modulated signal.
[0014] If, following the comparison, the detected class is the initial class, the method further comprises a modification of said second modulated signal by adding noise.
[0015] The addition of noise is carried out by a gradient descent attack method.
[0016] The time-frequency transformation is a short-term Fourier transform, STFT.
[0017] The opposing method applied in step C) is a gradient descent method.
[0018] According to another aspect, the invention relates to a noise-generating device prior to the transmission of a radio signal by a transmitter belonging to a given class of transmitters, referred to as the initial class, in order to render inoperative the detection of a transmitter's class membership by implementing a classification model previously trained by machine learning to detect the transmitter class among a plurality of predetermined transmitter membership classes, comprising a computing processor configured to implement: - a module for obtaining a first modulated signal in I / Q format, - a time-frequency transformation module for said first modulated signal to obtain a first spectrogram, - an application module for an adversary attack method, knowing the classification model previously trained by machine learning to detect an emitter class from a spectrogram, the adversary attack method allowing to obtain a modified spectrogram from the first spectrogram, such that said classification model provides an erroneous emitter class from the modified spectrogram, - an approximate inverse transformation module of the modified spectrogram to obtain a second modulated signal.
[0019] The invention also relates to a computer program comprising software instructions which, when executed by a computer, implement a noise-making process before the emission of a radio signal as defined above.
[0020] The invention will become clearer upon reading the following description, given solely by way of non-limiting example, and made with reference to the drawings in which:
[0021] [Fig.1] [Fig.1] schematically represents a radio communication system comprising a noise-generating device before radio signal emission and a receiving device configured to intercept an emitted radio signal;
[0022] [Fig.2] [Fig.2] is a synoptic diagram of the main steps of a noise-making process before radio signal emission according to an embodiment.
[0023] Fig. 1 schematically illustrates a wireless communication system 2 in which the proposed invention finds an application.
[0024] The system 2 includes a transmitter device 4 configured to transmit radio signals and a receiver device 6 configured to receive radio signals.
[0025] The emitted radio signals are propagated by a propagation channel 8.
[0026] The transmitting device 4 includes a communication interface module 10, configured to implement radio signal communication according to a predetermined communication protocol. The module 10 implements digital-to-analog conversion (DAC) processing and radio signal transmission via an electromagnetic antenna (not shown).
[0027] By virtue of the type of signal processing applied, the transmitting device 4 belongs to a class of transmitter among a plurality of predetermined classes of transmitters, called the initial class.
[0028] The transmitting device 4 comprises one or more processing units 12 and an electronic memory unit 14, forming an electronic computing device configured to implement a noise-generating method prior to the transmission of a radio signal according to the invention. Thus, the transmitting device 4 is also a noise-generating device prior to the transmission of radio signals.
[0029] Elements 10, 12 and 14 are adapted to communicate via an internal communication bus.
[0030] The computing processor 12 is configured to implement a preprocessing module 18 which provides a quadrature modulated signal, also called I / Q format (from the English "In-phase and Quadrature"), well known in the field of signal processing.
[0031] The computing processor 12 is further configured to implement a noise processing 20 aimed at inducing an erroneous emitter classification by a classifier implementing a classification model 22, the classification model being trained by machine learning to detect a class membership of the emitting device from a spectrogram of a signal in I / Q format, as described in more detail below.
[0032] In particular, noise processing 20 is carried out by implementing:
[0033] -of a time-frequency transformation module 24 which transforms a first signal in I / Q format into a first spectrogram,
[0034] -of a module 26 for applying an adversary attack method to the first spectrogram to obtain a modified spectrogram, such that when the modified spectrogram is provided as input to the classification model 22, the classification obtained is erroneous;
[0035] -of a modulo 28 of approximate inverse transformation of the modified spectrogram to obtain a second modulated signal.
[0036] As is known, a spectrogram is a two-dimensional time-frequency representation, represented by a matrix of values and which can be visualized as a digital image. The time-frequency transformation of a given signal into a spectrogram consists, as is known, of dividing the signal by applying a partially overlapping window, with windows of a given size, to obtain time segments, and applying a spectral transformation, e.g., a discrete Fourier transform, to each time segment. This transformation is also called a short-time Fourier transform or STFT.
[0037] The computing processor 12 is further configured to run, optionally, a verification module 30, implementing the time-frequency transformation to transform the second modulated signal into a second spectrogram, a classification by the classification model 22 from the second spectrogram to obtain a detected emitter class.
[0038] If the detected transmitter class is different from the initial class, the second modulated signal is transmitted to the transmitter interface module 10 for radio transmission of said modulated signal.
[0039] If the detected class is equal to the initial class, additional processing is implemented, in particular adding noise to the second modulated signal.
[0040] In one embodiment, modules 18, 24, 26, 28, 30 are implemented in the form of software instructions forming a computer program, which, when executed by a programmable electronic device, implements a noise-making process before the emission of a signal as described.
[0041] In an alternative not shown, modules 18, 24, 26, 28, 30 are each implemented as programmable logic components, such as FPGAs (Field Programmable Gate Arrays), microprocessors, GPGPUs (General-Purpose Computing on Graphics Processing Units), or dedicated integrated circuits, such as ASICs (Application-Specific Integrated Circuits).
[0042] The computer program comprising software instructions is further capable of being stored on a non-transient, computer-readable information storage medium. This computer-readable medium is, for example, a medium capable of storing electronic instructions and being connected to a bus of a computer system. By way of example, this medium is an optical disc, a magneto-optical disc, a ROM, a RAM, any type of non-volatile memory (e.g., EPROM, EEPROM, FLASH, NVRAM), a magnetic card, or an optical card.
[0043] The receiver device 6 includes a communication interface module 32, configured to implement the reception of radio signals according to a predetermined communication protocol. The module 32 implements a radio signal receiver and an analog-to-digital conversion (ADC) processor. In particular, the module 32 implements analog filtering around a given frequency Fi, with a bandwidth Bb, the resulting signal having a frequency between FrBi / 2 and Fi+Bi / 2, then an analog frequency transposition to center the frequencies around zero, and a digitization of the signals.
[0044] The receiving device 6 further comprises one or more computing processors 34, and an electronic memory unit 36, forming an electronic computing device, configured to implement transmitter class detection of a received radio signal.
[0045] Elements 32, 34 and 36 are adapted to communicate via an internal communication bus.
[0046] The computing processor 34 is configured to implement a preprocessing module 38 which provides a quadrature modulated signal, also called I / Q format (from the English "In-phase and Quadrature"), from the received radio signal.
[0047] The computing processor 34 further implements a time-frequency transformation module 40 that transforms a signal in I / Q format into a spectrogram, and a classification module 44 that applies a classification model 42, previously trained by machine learning, to provide a class of membership for a transmitting device from a spectrogram of a signal in I / Q format. The output is a detected emitter class C1_E.
[0048] Preferably, each of the classification models 22, 42 is implemented in the form of a neural network.
[0049] According to a first variant, the classification model 42 is identical to the classification model 22.
[0050] According to a second variant, the classification model 42 is a slightly modified version of the classification model 22, for example modified by an operation called refinement or "fine-tuning" in English.
[0051] In a known manner, a neural network comprises an ordered succession of layers of neurons, each of which takes its inputs from the outputs of the previous layer.
[0052] More precisely, each layer comprises neurons taking their inputs from the outputs of the neurons of the previous layer, or from the input variables for the first layer.
[0053] Alternatively, more complex neural network structures can be envisaged with a layer that can be linked to a layer further away than the immediately preceding layer.
[0054] Each neuron is also associated with an operation, that is to say a type of processing, to be carried out by said neuron within the corresponding processing layer.
[0055] Each layer is connected to the other layers by a plurality of synapses. A synaptic weight is associated with each synapse, and each synapse forms a link between two neurons. It is often a real number, which takes on both positive and negative values. In some cases, the synaptic weight is a complex number.
[0056] Each neuron is designed to perform a weighted sum of the value(s) received from the neurons of the preceding layer, each value being multiplied by the respective synaptic weight of each synapse, or connection, between said neuron and the neurons of the preceding layer, and then to apply an activation function, typically a non-linear function, to said weighted sum, and to deliver at the output of said neuron, in particular to the neurons of the next layer connected to it, the value resulting from the application of the activation function. The activation function introduces non-linearity into the processing performed by each neuron. The sigmoid function, the hyperbolic tangent function, and the Heaviside function are examples of activation functions.
[0057] As an optional complement, each neuron is also capable of applying, in addition, a multiplicative factor, and an additive bias, to the output of the activation function, and the value delivered at the output of said neuron is then the product of the value of the multiplicative factor and the value from the activation function, plus the bias.
[0058] A convolutional neural network is also sometimes called a convolutional neural network or by the acronym CNN, which refers to the English term "Convolutional Neural Networks".
[0059] In a convolutional neural network, each neuron in the same layer exhibits exactly the same connection pattern as its neighboring neurons, but at different input positions. The connection pattern is called the convolutional kernel or, more commonly, the "kernel" in reference to the corresponding English term.
[0060] A fully connected layer of neurons is a layer in which the neurons of said layer are each connected to all the neurons of the preceding layer.
[0061] Such a type of layer is more often referred to by the English term "fully connected", and sometimes designated by the name "dense layer".
[0062] The values of the weights, multipliers and biases where applicable are learned during a machine learning phase to perform the classification task.
[0063] The invention applies with all types of neural networks, in particular with convolutional neural networks or CNNs, deep neural networks or DNNs, LSTM models (for "long short terni memory model") etc.
[0064] Several operating scenarios are conceivable in the communication system 2.
[0065] The transmitting device 4 is capable of transmitting a noise-free modulated signal, SE1, emitted by the communication interface module 10 without application of the noise processing 20, or a noisy modulated signal SE2, emitted by the communication interface module 10 after application of the noise processing 20.
[0066] In the application where the receiving device 6 is a legitimate receiver, the intended recipient of the radio signal emitted by the transmitting device 4, the receiving device is capable of processing both a received SRI signal, corresponding to the noise-free modulus signal SE1, possibly modified by the effects of the propagation channel 8, and a received SR2 signal, corresponding to the noisy modulus signal SE2, possibly modified by the effects of the propagation channel 8. Indeed, a legitimate receiving device is informed of the possible implementation of noise reduction 20 by a transmitter for the purpose of stealth, and is informed of the transmitter's probable initial class. Thus, a legitimate receiving device is configured to perform decoding either with knowledge of the initial class or with knowledge of the detected transmitter class, and therefore to obtain the information contained in the received SRI or SR2 signal.
[0067] In the case of an application where the receiving device 6 is a non-intended receiver of the transmitted, potentially malicious, radio signal, the receiving device 6 is able to detect the transmitter class of the transmitting device 4 from a received SRI signal, corresponding to the noise-free module signal SE1, possibly modified by the effects of the propagation channel 8, but is not able to correctly detect the transmitter class of the transmitting device 4 from a received SR2 signal, corresponding to the noisy module signal SE2, possibly modified by the effects of the propagation channel 8. In other words, the C1_E class obtained at the output of the module 44 is different from the transmitter class of the device 4. Indeed, thanks to the noise processing 20, the classification model 42 provides an erroneous classification result.
[0068] In other words, the noise processing 20 makes it possible to deceive an illegitimate receiving device. The incorrect determination of the transmitter class subsequently leads to incorrect decoding of the received radio signal.
[0069] Fig. 2 is a synoptic diagram of the main steps of a noise-making process before emission.
[0070] The process is implemented by the processor 12 of an electronic computing device.
[0071] The method includes a pre-processing step 50 to obtain a first modulated signal in I / Q format ready to be transmitted to the communication interface module for transmission. The transmitting device belongs to a given transmitter class, called the initial class. The first signal encodes a binary message (or payload) intended for one or more legitimate receivers.
[0072] According to one embodiment, step 50 implements a propagation simulation by adding distortions (e.g., noise, phase shift) that may be induced by a propagation channel and a pre-processing of the radio signal received by a receiver. The process then includes a time-frequency transformation step 52 of the first modulated signal to obtain a first corresponding spectrogram.
[0073] For example, the applied time-frequency transformation is an STFT transformation.
[0074] The first spectrogram is represented as a matrix of points, of size each point having an associated value and being associated with a time index and a frequency index.
[0075] The method further comprises a step 54 of applying an adversary attack method against a classification model 22 previously trained by machine learning to determine a class of emitter from the spectrogram of a signal in I / Q format.
[0076] The classification model 22 is, for example, a neural network, whose parameters are known.
[0077] Adversarial attack methods, also known as evasion attacks, are known in the field of artificial intelligence. These attack methods consist of modifying the input data in order to change the behavior of the classification model, the input data generally being digital images that are modified in a way that is not perceptible to the human observer.
[0078] By way of example, we can cite the article "Towards Deep Learning Models Resistant to Adversarial Attacks" by A. Madry et al., published on the Internet and available at the URL https: / / arxiv.org / pdf / 1706.06083.pdf, which describes several methods of adversarial attacks. The article "Wasserstein Adversarial Examples via Projected Sinkhom Iterations" by E. Wong et al., published on the Internet and available at the URL https: / / arxiv.org / abs / 1902.07906, describes iterative attacks on image classification models.
[0079] For example, the adversary attack method applied is the Projected Gradient Descent method.
[0080] Alternatively, any other method of attacking an adversary, resulting in an erroneous classification by a classification model, is applicable.
[0081] At the end of step 54, a modified spectrogram is obtained. The classification model 22, when applied with the modified spectrogram as input, provides an erroneous emitter class as output, which is different from the initial class.
[0082] The process then includes a step 56 of approximate inverse transformation of the transformation applied in step 52, the approximate inverse transformation being applied to the modified spectrogram and allowing a second modulated signal to be obtained.
[0083] The inverse transformation is said to be approximate because, as is known, the STFT transformation is invertible only if certain conditions relating to the applied windowing are met (see, for example, the article by Ivan W. Selesnik, "Short-Time Fourier Transform and Its Inverse," published online at https: / / eeweb.engineering.nyu.edu / iselesni / EL713 / STFT / stft_inverse.pdf). In other words, if certain windowing conditions are met, applying the time-frequency transformation 52 to the second modulated signal produces the modified spectrogram. If these windowing conditions are not met, applying the time-frequency transformation 52 to the second modulated signal produces a second spectrogram that differs from the modified spectrogram.
[0084] The method further includes, optionally, a verification step 57 in which the STFT transformation applied in transformation step 52 is applied (step 58) to the second modulated signal, and a second spectrogram is obtained. Then, a classification 60 using classification model 22 is applied to the second spectrogram as input. A detected class C1_E is obtained at the output of classification step 60.
[0085] The detected class C1_E is then compared (step 62) to the initial class of the emitter.
[0086] If the detected class is different from the initial class, the second modulated signal is transmitted to the transmitter at transmission step 64.
[0087] If the detected class is the same as the initial class, the process then includes an additional noiseing step 66, during which noise is added to the second signal in I / Q format, and the verification step is repeated until the detected class is different from the initial class. The added noise can be applied, for example, using the "Projected Gradient Adversarial attack" method.
[0088] Furthermore, it is verified that the second signal in noisy I / Q format is decodable by a legitimate receiving device to extract the binary message, the legitimate receiving device knowing the initial class of the transmitter, and therefore the demodulation method to be applied
[0089] Advantageously, the proposed method makes it possible to mislead an illegitimate receiving device, and therefore to prevent any decoding of the message carried by the signal modulated by such a receiving device, while preserving the decoding capability of a legitimate receiving device, the initial class of transmitter having been transmitted beforehand to the legitimate receiver, for example during the establishment of the mission plan.
Claims
Demands
1. A method for adding noise before the transmission of a radio signal by a transmitter belonging to a given class of transmitters, called the initial class, in order to render inoperative the detection of a class of transmitter membership by implementing a classification model previously trained by machine learning to detect the class of transmitter among a plurality of predetermined classes of transmitter membership, the method being implemented by a computing processor and comprising the steps of: - A) obtaining (50) a first modulated signal in 1 / Q format, - B) time-frequency transformation (52) of said first modulated signal to obtain a first spectrogram, - C) application (54) of an adversary attack method, knowing the classification model (22) previously trained by machine learning to detect a class of transmitter from a spectrogram,the adversary attack method enabling the acquisition of a modified spectrogram from the first spectrogram, such that said classification model (22) provides an erroneous emitter class from the modified spectrogram, - D) approximate inverse transformation (56) of the modified spectrogram to obtain a second modulated signal.
2. A method according to claim 1, further comprising sending (64) the second modulated signal to a transmission interface module (10) for radio transmission of said second modulated signal.
3. A method according to claim 1, further comprising an application (58) of said time-frequency transformation on the second modulated signal to obtain a second spectrogram, a classification (60) by said classification model (22) enabling a detected emitter class to be obtained, a comparison (62) of the detected class and the initial class, and, if the detected class is different from the initial class, a transmission (64) of the second modulated signal to a transmit interface module (10) for radio transmission of said second modulated signal.
4. A method according to claim 3, wherein, if following the comparison (62), the detected class is the initial class, the method further comprises a modification (66) of said second modulated signal by adding noise.
5. A method according to claim 4, wherein the addition of noise is carried out by a gradient descent attack method.
6. A method according to any one of claims 1 to 5, wherein said time-frequency transformation is a short-time Fourier transform, STFT.
7. A method according to any one of claims 1 to 6, wherein said opposing method applied in step C) is a gradient descent method.
8. A computer program comprising software instructions which, when executed by a programmable electronic device, implement a noise-making process prior to the emission of a radio signal in accordance with claims 1 to 7.
9. A noise-generating device prior to the transmission of a radio signal by a transmitter belonging to a given transmitter class, referred to as the initial class, in order to render inoperative the detection of a transmitter class membership by implementing a classification model previously trained by machine learning to detect the transmitter class among a plurality of predetermined transmitter class memberships, comprising a computing processor configured to implement: - a module (18) for obtaining a first modulated signal in I / Q format, - a module (24) for time-frequency transformation of said first modulated signal to obtain a first spectrogram, - a module (26) for applying an adversary attack method, knowing the classification model previously trained by machine learning to detect a transmitter class from a spectrogram,the adversary's attack method enabling the acquisition of a modified spectrogram from the first spectrogram, such that said classification model provides an erroneous emitter class from the modified spectrogram, - a module (28) of approximate inverse transformation of the modified spectrogram to obtain a second modulated signal.
10. Device according to claim 9, further comprising a verification module (30) configured to implement an application of said time-frequency transformation on the second modulated signal to obtain a second spectrogram, a classification by said classification model enabling the obtaining of a detected emitter class.