Radio Signal Spectrogram Perturbation Against ML Emitter Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing radio signal transmission methods are vulnerable to detection and classification by machine learning-trained classification models, allowing malicious interception and demodulation of signals.
Innovation Solution
A noise-making process is applied before radio signal emission to deceive classification models by transforming the signal into a modified spectrogram using an adversary attack method, followed by an approximate inverse transformation to generate a noisy signal that fools the classification model.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a radio signal is transmitted without noise addition, then the signal can be correctly classified by legitimate receivers, but the signal becomes vulnerable to detection and classification by malicious interceptors using machine learning models
Solution Approach 1:
The patent applies preliminary anti-action by adding adversarial noise to the radio signal before transmission. This noise is specifically designed to fool machine learning classification models used by malicious interceptors. The noise is generated through an iterative process that transforms the signal into the frequency domain, applies adversarial perturbations, and transforms it back, repeating this process multiple times to ensure the noise effectively confuses ML detectors while maintaining signal integrity for legitimate receivers.
Solution Approach 2:
The patent uses an intermediary approach by introducing adversarial noise as a mediator between the legitimate signal and the receiver. This noise acts as a protective layer that interferes with malicious ML-based detection while being imperceptible or harmless to legitimate receivers. The noise serves as an intermediary element that selectively affects different types of receivers based on their processing methods.
2Object-affected harmful factors
If adversarial noise is added to the radio signal, then machine learning-based detection is deceived, but the signal processing complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-computing and storing the adversarial noise in a noise library before actual transmission. During transmission, instead of performing complex real-time adversarial noise generation, the system retrieves pre-computed noise patterns from the library and applies them to the signal. This significantly reduces the computational complexity during the critical transmission phase while maintaining the effectiveness of adversarial protection.
Solution Approach 2:
The patent uses partial action by applying only the necessary amount of adversarial noise required to confuse ML detectors. The noise generation process iterates a fixed number of times (e.g., 5 iterations) rather than continuing until perfect optimization, and uses a subset of frequency bins for noise application. This partial approach achieves sufficient protection against ML detection while avoiding the excessive computational complexity of complete optimization.
3Reliability
If multiple iterations of adversarial noise generation are performed, then the effectiveness of deception increases, but the processing time increases
Solution Approach 1:
The patent resolves this contradiction by performing the computationally intensive adversarial noise generation iterations in advance and storing the results in a noise library. The pre-computed noise patterns are then reused during actual signal transmission, eliminating the need for real-time iterative processing. This preliminary action ensures high deception effectiveness while minimizing processing time during critical transmission operations.
Data Source
Figure 1
Figure 2
AI summary
The present invention relates to a method and a noise-making device prior to the emission of a radio signal by a transmitter belonging to a given initial class of transmitters, in order to render inoperative a detection of a class of membership of the transmitter by implementation of a classification model previously trained by machine learning to detect a class of transmitter from a spectrogram.The device is configured to implement modules of: - obtaining (18) a first modulated signal in I/Q format, - time-frequency transformation (24) of the first modulated signal to obtain a first spectrogram, - application (26) of an adversary attack method, knowing the classification model, the adversary attack method allowing to obtain a modified spectrogram from the first spectrogram, such that said classification model provides an erroneous emitter class from the modified spectrogram, - approximate inverse transformation (28) of the modified spectrogram to obtain a second modulated signal.