通信学报 ›› 2024, Vol. 45 ›› Issue (1): 180-193.doi: 10.11959/j.issn.1000-436x.2024021

• 学术论文 • 上一篇    

基于雅可比显著图的电磁信号快速对抗攻击方法

张剑, 周侠, 张一然, 王梓聪   

  1. 武汉数字工程研究所,湖北 武汉 430205
  • 修回日期:2023-10-24 出版日期:2024-01-01 发布日期:2024-01-01
  • 作者简介:张剑(1979- ),男,湖北宜昌人,博士,武汉数字工程研究所博士生导师、研究员,主要研究方向为人工智能、作战指挥
    周侠(1996- ),男,贵州安顺人,武汉数字工程研究所硕士生,主要研究方向为人工智能对抗样本攻防
    张一然(1999- ),女,辽宁阜新人,武汉数字工程研究所硕士生,主要研究方向为人工智能可解释性、对抗样本生成
    王梓聪(2000- ),男,湖南长沙人,武汉数字工程研究所硕士生,主要研究方向为人工智能对抗攻防
  • 基金资助:
    国家自然科学基金资助项目(61873040)

Electromagnetic signal fast adversarial attack method based on Jacobian saliency map

Jian ZHANG, Xia ZHOU, Yiran ZHANG, Zicong WANG   

  1. Wuhan Digital Engineering Institute, Wuhan 430205, China
  • Revised:2023-10-24 Online:2024-01-01 Published:2024-01-01
  • Supported by:
    The National Natural Science Foundation of China(61873040)

摘要:

为了生成高质量的电磁信号对抗样本,提出了快速雅可比显著图攻击(FJSMA)方法。FJSMA 通过计算攻击目标类别的雅可比矩阵,并根据该矩阵生成特征显著图,之后迭代选取显著性最强的特征点及其邻域内连续特征点添加扰动,同时引入单点扰动限制,最后生成对抗样本。实验结果表明,与雅可比显著图攻击方法相比, FJSMA在保持与之相同的高攻击成功率的同时,生成速度提升了约10倍,相似度提升了超过11%;与其他基于梯度的方法相比,攻击成功率提升了超过20%,相似度提升了20%~30%。

关键词: 深度神经网络, 对抗样本, 电磁信号调制识别, 雅可比显著图, 目标攻击

Abstract:

In order to generate high-quality electromagnetic signal countermeasure examples, a fast Jacobian saliency map attack (FJSMA) method was proposed.The Jacobian matrix of the attack target class was calculated and feature saliency maps based on the matrix were generated, then the most salient feature points were iteratively selected and perturbations in their neighborhood were continuously added while introducing a single point perturbation constraint, finally adversarial examples were generated.Experimental results show that, compared with Jacobian saliency map attack method, FJSMA improves the generation speed by about 10 times while maintaining the same high attack success rate, and improves the similarity by more than 11%, and compared with other gradient-based methods, the attack success rate is improved by more than 20%, and the similarity is improved by 20% to 30%.

Key words: deep neural network, adversarial sample, electromagnetic signal modulation recognition, Jacobian saliency map, target attack

中图分类号: 

No Suggested Reading articles found!