系统工程与电子技术 ›› 2025, Vol. 47 ›› Issue (7): 2127-2135.doi: 10.12305/j.issn.1001-506X.2025.07.06

• 电子技术 • 上一篇    

基于雅可比显著图的电磁信号无目标平滑对抗攻击方法

王梓聪, 张剑   

  1. 武汉数字工程研究所, 湖北 武汉 430205
  • 收稿日期:2024-07-03 出版日期:2025-07-16 发布日期:2025-07-22
  • 通讯作者: 张剑
  • 作者简介:王梓聪 (2000—),男,硕士研究生,主要研究方向为人工智能对抗攻防
    张剑 (1979—),男,研究员, 博士研究生导师,博士,主要研究方向为作战指挥、电子战

Electromagnetic signal no-targeted smooth adversarial attack method based on Jacobian saliency map

Zicong WANG, Jian ZHANG   

  1. Wuhan Digital Engineering Institute, Wuhan 430205, China
  • Received:2024-07-03 Online:2025-07-16 Published:2025-07-22
  • Contact: Jian ZHANG

摘要:

针对生成电磁信号对抗样本隐蔽性不足的问题, 提出一种基于雅可比显著图的电磁信号无目标平滑对抗攻击方法(electromagnetic signal no-targeted smooth adversarial attack method based on Jacobian saliency map, NTSA)。该方法平衡对抗样本各项范数, 根据电磁信号自身特点, 通过计算雅可比矩阵生成显著图, 选取关键特征点进行平滑的扰动添加从而生成对抗样本。在使用公开数据集训练的3个网络模型上进行实验得到的结果表明, NTSA在3个网络模型上都能达到90%以上的成功率。该方法比同类型特征点方法,即基于Jacobian显著图攻击(Jacobian-based saliency map attack, JSMA)方法提升了30%的攻击成功率, 且扰动比率能降低到5%以下。从扰动比率、单点扰动距离、余弦相似度以及欧氏距离这4项隐蔽性指标反映出NTSA所生成的样本与该文其他方法生成的对抗样本相比具有最好的隐蔽性。

关键词: 电磁信号识别, 对抗攻击, 对抗样本, 平滑攻击, 鲁棒性

Abstract:

In order to solve the problem of insufficient concealment of the generated electromagnetic signal adversarial examples, an electromagnetic signals no-targeted smoothing adversarial attack method based on Jacobian saliency maps (NTSA) is proposed, which balances the norms of the adversarial examples, generates a saliency map by calculating the Jacobian matrix according to the characteristics of the electromagnetic signal itself, and selects key feature points for smooth perturbation addition to generate adversarial examples. The experimental results on three network models trained using public datasets show that the NTSA can achieve a success rate of more than 90% on three network models. Compared with the same type of feature point method Jacobian-based saliency map attack (JSMA), the attack success rate of this method is improved by 30%, and the perturbation ratio can be reduced to less than 5%. The four concealment indexes, namely perturbation ratio, single-point perturbation distance, cosine similarity and Euclidean distance, show that the samples generated by the NTSA have the best concealment compared with the adversarial samples generated by other methods in this paper.

Key words: electromagnetic signal recognition, confrontation attacks, adversarial examples, smooth attacks, robustness

中图分类号: