Radio Signal Spectrogram Perturbation Against ML Emitter Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing radio signal transmission methods are vulnerable to detection and classification by machine learning-trained classification models, allowing malicious interception and demodulation of signals.

Innovation Solution

A noise-making process is applied before radio signal emission to deceive classification models by transforming the signal into a modified spectrogram using an adversary attack method, followed by an approximate inverse transformation to generate a noisy signal that fools the classification model.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a radio signal is transmitted without noise addition, then the signal can be correctly classified by legitimate receivers, but the signal becomes vulnerable to detection and classification by malicious interceptors using machine learning models

Engineering Contradiction:
Improvesignal classification accuracy for legitimate receiversVSAvoidvulnerability to machine learning-based detection
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by adding adversarial noise to the radio signal before transmission. This noise is specifically designed to fool machine learning classification models used by malicious interceptors. The noise is generated through an iterative process that transforms the signal into the frequency domain, applies adversarial perturbations, and transforms it back, repeating this process multiple times to ensure the noise effectively confuses ML detectors while maintaining signal integrity for legitimate receivers.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent uses an intermediary approach by introducing adversarial noise as a mediator between the legitimate signal and the receiver. This noise acts as a protective layer that interferes with malicious ML-based detection while being imperceptible or harmless to legitimate receivers. The noise serves as an intermediary element that selectively affects different types of receivers based on their processing methods.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If adversarial noise is added to the radio signal, then machine learning-based detection is deceived, but the signal processing complexity increases

Engineering Contradiction:
Improveresistance to machine learning detectionVSAvoidsignal processing complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-computing and storing the adversarial noise in a noise library before actual transmission. During transmission, instead of performing complex real-time adversarial noise generation, the system retrieves pre-computed noise patterns from the library and applies them to the signal. This significantly reduces the computational complexity during the critical transmission phase while maintaining the effectiveness of adversarial protection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses partial action by applying only the necessary amount of adversarial noise required to confuse ML detectors. The noise generation process iterates a fixed number of times (e.g., 5 iterations) rather than continuing until perfect optimization, and uses a subset of frequency bins for noise application. This partial approach achieves sufficient protection against ML detection while avoiding the excessive computational complexity of complete optimization.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If multiple iterations of adversarial noise generation are performed, then the effectiveness of deception increases, but the processing time increases

Engineering Contradiction:
Improvedeception effectivenessVSAvoidnoise generation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent resolves this contradiction by performing the computationally intensive adversarial noise generation iterations in advance and storing the results in a noise library. The pre-computed noise patterns are then reused during actual signal transmission, eliminating the need for real-time iterative processing. This preliminary action ensures high deception effectiveness while minimizing processing time during critical transmission operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4661321A1Method for noise reduction before transmitting a radio signal by a transmitter, associated device and computer program
Publication Date: 2025.12.10 THALES SA
  • EP4661321A1 patent drawingFigure 1
  • EP4661321A1 patent drawingFigure 2
  • EP4661321A1 patent drawing

AI summary

The present invention relates to a method and a noise-making device prior to the emission of a radio signal by a transmitter belonging to a given initial class of transmitters, in order to render inoperative a detection of a class of membership of the transmitter by implementation of a classification model previously trained by machine learning to detect a class of transmitter from a spectrogram.The device is configured to implement modules of: - obtaining (18) a first modulated signal in I/Q format, - time-frequency transformation (24) of the first modulated signal to obtain a first spectrogram, - application (26) of an adversary attack method, knowing the classification model, the adversary attack method allowing to obtain a modified spectrogram from the first spectrogram, such that said classification model provides an erroneous emitter class from the modified spectrogram, - approximate inverse transformation (28) of the modified spectrogram to obtain a second modulated signal.