Dynamic optimization updating method of trusted data intelligent detection system
By deploying heterogeneous feature acquisition nodes and federated incremental learning frameworks in the data stream transmission path, combining differential privacy encryption and adversarial sample generation, the problems of poor adaptability and low real-time performance in data credibility assessment, privacy protection and security defense in the prior art are solved, and efficient, accurate and secure data detection effects are achieved.
Patent Information
- Application Number
- CN202510361999.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-06-27
AI Technical Summary
The existing technology has poor adaptability and low real-time performance in data credibility assessment, privacy protection and security defense, which is difficult to meet the needs of modern intelligent detection systems for efficiency, accuracy and security.
By deploying heterogeneous feature acquisition nodes in the data stream transmission path, collecting data association characteristics and operational behavior fingerprints, using the federated incremental learning framework for multi-dimensional correlation analysis, and setting a dynamic trusted evaluation threshold. At the same time, a gradient aggregation channel based on differential privacy encryption is built, local model update parameters are safely fused, global model optimization vectors are generated, and adversarial sample sets are generated in combination with the historical attack mode library.
The technical effects of improving data credibility, enhancing privacy protection capabilities, and improving attack defense capabilities have been achieved, and the existing technology has poor adaptability and low real-time performance in data credibility assessment, privacy protection and security defense have been solved.
Smart Images

Figure CN120223531A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of trusted data detection, and particularly to a dynamic optimization and update method for a trusted data intelligent detection system. Background Art
[0002] With the rapid development of digital and intelligent technologies, trusted data intelligent detection systems have been widely applied in multiple fields. However, with the continuous growth of data scale and the complexity of application scenarios, data detection systems are facing increasingly severe challenges. Traditional data detection methods often have problems such as insufficient data credibility assessment, weak privacy protection mechanisms, limited attack defense capabilities, and lagging system update responses when dealing with large-scale data streams, making it difficult to meet the requirements of modern intelligent detection systems for high efficiency, accuracy, and security. Summary of the Invention
[0003] This application provides a dynamic optimization and update method for a trusted data intelligent detection system, which is used to solve the technical problems of poor adaptability and low real-time performance in data credibility assessment, privacy protection, and security defense in the prior art.
[0004] In view of the above problems, this application provides a dynamic optimization and update method for a trusted data intelligent detection system.
[0005] This application provides a dynamic optimization and update method for a trusted data intelligent detection system, and the method includes:
[0006] Deploy heterogeneous feature acquisition nodes in the data stream transmission path to collect data association features and operation behavior fingerprints, perform multi-dimensional association analysis in a federated incremental learning framework, and set dynamic trusted evaluation thresholds; construct a gradient aggregation channel based on differential privacy encryption to securely fuse the local model update parameters, generate a global model optimization vector, and generate an adversarial sample set in combination with the historical attack pattern library; perform weight allocation on the global model optimization vector, configure a dynamic update step size in combination with the dynamic trusted evaluation threshold, and generate an update instruction set including a version identifier and a credibility certificate; according to the trusted baseline template, activate the adversarial sample generation network with the adversarial sample set and the update instruction set to generate an incremental update package including defense strategy fingerprints; use the incremental update package to trigger the asynchronous hot deployment of edge computing nodes and reconstruct the model topology of the federated incremental learning framework to generate an update log.
[0007] One or more technical solutions provided in this application have at least the following technical effects or advantages:
[0008] This application deploys heterogeneous feature acquisition nodes in the data stream transmission path to collect data correlation features and operation behavior fingerprints. Using a federated incremental learning framework, it conducts multi-dimensional correlation analysis and sets dynamic trusted evaluation thresholds. It constructs a gradient aggregation channel based on differential privacy encryption to securely fuse the local model update parameters, generates a global model optimization vector, and combines it with a historical attack pattern library to generate an adversarial sample set. It assigns weights to the global model optimization vector, configures a dynamic update step size in combination with the dynamic trusted evaluation threshold, and generates an update instruction set containing a version identifier and a credibility certificate. According to a trusted baseline template, using the adversarial sample set and the update instruction set, it activates an adversarial sample generation network to generate an incremental update package containing a defense strategy fingerprint. Using the incremental update package, it triggers the asynchronous hot deployment of edge computing nodes and reconstructs the model topology of the federated incremental learning framework to generate an update log. The present invention solves the technical problems of poor adaptability and low real-time performance in data credibility evaluation, privacy protection, and security defense in the prior art. Through a federated incremental learning framework, multi-dimensional correlation analysis, differential privacy encryption, adversarial sample generation, and asynchronous deployment of edge computing, it achieves the technical effects of improving data credibility, enhancing privacy protection capabilities, and improving attack defense capabilities. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0010] Figure 1 Schematic diagram of the process of the dynamic optimization update method for a trusted data intelligent detection system provided by an embodiment of this application;
[0011] Figure 2 Schematic diagram of the process of activating an adversarial sample generation network in the dynamic optimization update method for a trusted data intelligent detection system provided by an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0012] This application provides a dynamic optimization update method for a trusted data intelligent detection system, which is used to solve the technical problems of poor adaptability and low real-time performance in data credibility evaluation, privacy protection, and security defense in the prior art. Through a federated incremental learning framework, multi-dimensional correlation analysis, differential privacy encryption, adversarial sample generation, and asynchronous deployment of edge computing, it achieves the technical effects of improving data credibility, enhancing privacy protection capabilities, and improving attack defense capabilities.
[0013] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts shall fall within the scope of protection of the present application.
[0014] It should be noted that any variations of the terms "including" and "having" are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or server that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or modules that are not clearly listed or are inherent to these processes, methods, products, or devices.
[0015] Embodiment, as Figure 1 shown, the present application provides a dynamic optimization and update method for a trusted data intelligent detection system, and the method includes:
[0016] Step S100: Deploy heterogeneous feature collection nodes in the data stream transmission path, collect data association features and operation behavior fingerprints, perform multi-dimensional association analysis in a federated incremental learning framework, and set a dynamic trusted evaluation threshold.
[0017] In the embodiments of the present application, in the data stream transmission path, heterogeneous feature collection nodes are deployed using deep packet inspection technology to achieve real-time monitoring of the data stream. The DPI technology can parse the content of network packets, extract key information such as protocol type, source / destination address, port number, etc., and combine traffic statistics information to construct a feature description of the data stream. To adapt to different data sources, the collection nodes can be distributed on edge computing devices, server gateways, or IoT devices to ensure comprehensive coverage of the data stream transmission path and support the parsing of different types of network protocols. The DPI technology can not only obtain features at the packet level but also provide deeper data semantic information, providing a basis for subsequent feature analysis.
[0018] In the data collection stage, the sliding time window method is adopted to extract data correlation features and operation behavior fingerprints from the data stream. The extraction of data correlation features is based on the statistical characteristics of traffic data. In each sliding time window, statistical indicators such as the mean, variance, kurtosis, and skewness of the data are calculated to describe the overall distribution of the data stream. In addition, by calculating the traffic mutation rate, protocol switching frequency, and packet interaction mode, the dynamic change features of the data in the time series are further extracted to depict the correlation between different data streams. For the extraction of operation behavior fingerprints, the interaction patterns of specific users or devices in multiple sliding windows are tracked, and fingerprint descriptions are established using behavior features such as access frequency, request interval, and command execution order. For example, if the access request pattern of a certain device is highly consistent among different windows, it is marked as a normal user, while if it is found that a device accesses multiple different ports in a short period of time, it may indicate abnormal behavior or an attack attempt.
[0019] To achieve multi-dimensional correlation analysis of data while ensuring data privacy, the federated averaging algorithm is used for distributed model training. Each data collection node locally trains a lightweight machine learning model, uses the data it collects itself for learning, and calculates the updated model parameters. Subsequently, each node uploads the updated model parameters to the central server, and the server performs weighted averaging on these parameters to generate a globally optimized model, and then distributes the updated model to each node to improve the overall detection accuracy. This method can achieve the joint analysis of multiple data sources without sharing the original data, improving the intelligent detection ability of the system. At the same time, the incremental update mechanism of federated learning can reduce the computational and communication overhead, enabling the system to adapt to a large-scale data environment.
[0020] During the operation of the system, the method of historical data analysis is used to dynamically adjust the trusted evaluation threshold of the data. Specifically, first, in each time window, the historical credibility score is calculated, and the method of data trend comparison is used to observe whether there are significant changes in the data. If the deviation between the current data features and the historical data is small, the original trusted evaluation threshold is maintained; if the deviation is large, it indicates that the data stream may be abnormal, and the trusted evaluation threshold is automatically increased to enhance security. During the adjustment process, the method of smooth adjustment is used to avoid misjudgment caused by too rapid changes in the threshold. For example, if the data has been stable in the past period, gradually reduce the threshold to reduce the false alarm rate; if the recent data fluctuates greatly, gradually increase the threshold to prevent the influence of abnormal data. In this way, the credibility evaluation criteria are adaptively adjusted according to different data environments to ensure accurate and stable detection.
[0021] Furthermore, in the method provided by the application embodiment, deploying heterogeneous feature collection nodes in the data stream transmission path further includes:
[0022] A neural network sensor array is deployed at the data input layer to simulate the dynamic response mechanism of biological synapses and capture the spatio-temporal correlation features of the data stream transmission path; based on the neural network sensor array, a photonic crystal filter is implanted, and high-frequency abnormal signals and normal data features are separated according to the photonic bandgap effect.
[0023] Furthermore, the method provided by the application embodiment further includes:
[0024] Set the adaptive adjustment rule of sensor sensitivity, including that the sensitivity attenuation coefficient ≤ 0.05 dB / Hz in the noise environment and the response delay ≤ 50 ns in the burst data stream scenario.
[0025] In the embodiment of the present application, a neural network sensor array is deployed at the data input layer of the trusted data intelligent detection system to enhance the system's ability to perceive the dynamic characteristics of the data stream transmission path. The neural network sensor array is a sensing system that mimics the structure of a biological neural network. It captures the dynamic changes of the data stream through multiple distributed sensing units and can adaptively adjust according to environmental changes. The core feature of this sensor array lies in its synaptic dynamic response mechanism, that is, it mimics the adaptive adjustment ability of biological synapses when receiving signals, enabling it to classify and perform reinforcement learning on different types of data stream patterns. During the operation of the trusted data intelligent detection system, when the data stream mutates, the neural network sensor array will instantaneously increase its sensitivity to capture the burst signal, while in a stable data stream environment, it will automatically attenuate the response to reduce the interference of background noise, thereby ensuring the accuracy of data acquisition.
[0026] To further optimize the spatio-temporal feature extraction of data, based on the neural network sensor array, a photonic crystal filter is implanted in the trusted data intelligent detection system, and high-frequency abnormal signals and normal data features are separated using the photonic bandgap effect. The photonic crystal filter is a filtering component that realizes signal selectivity based on an optical structure. It blocks the propagation of light waves in a specific frequency range by controlling the periodic structure of the photonic crystal, thereby achieving the separation effect of specific signals. The photonic bandgap effect is the core mechanism of this filter, ensuring that the normal data stream can pass smoothly, while abnormal high-frequency signals (such as network attacks, abnormally fluctuating data, etc.) are effectively suppressed. In the trusted data intelligent detection system, first, time-frequency analysis is performed on the data stream to determine the signal energy distribution in different frequency bands; subsequently, the photonic crystal filter blocks the abnormal high-frequency signals and only retains the normal data signals according to the set frequency threshold, thereby improving the system's ability to detect abnormal behaviors. For example, in network data monitoring, normal service traffic usually shows a low-frequency stable pattern, while behaviors such as DDoS attacks and malicious scans show high-frequency burst signals. At this time, the photonic crystal filter can effectively distinguish between the two and filter out abnormal data to ensure the stable operation of the trusted data intelligent detection system.
[0027] Furthermore, to ensure the adaptability of the sensors, the trusted data intelligent detection system sets an adaptive adjustment rule for the sensor sensitivity, enabling it to automatically adjust the detection accuracy according to different environmental and data stream characteristics. In a noisy environment, it is necessary to reduce the sensitivity to reduce false detections and interference. Therefore, the sensitivity attenuation coefficient is set to ≤ 0.05 dB / Hz. That is, when the background noise is strong, the sensor will adaptively reduce the response intensity to tiny signals to avoid misjudgment. In the scenario of a bursty data stream, such as a sudden surge in instantaneous data traffic, it is necessary to ensure rapid response. Therefore, the response delay is set to ≤ 50 ns. That is, when the sensor detects a data mutation, it can adjust its working state within an extremely short time, quickly capture and analyze the characteristics of the data stream. For example, in an industrial control network, the sensing data of devices may experience short-term severe fluctuations in case of a burst. At this time, the sensor must complete the adjustment within an extremely short time to avoid data loss or delay.
[0028] Finally, through the synaptic dynamic response mechanism of the neural network sensor array, combined with the photonic bandgap effect of the photonic crystal filter, and the adaptive adjustment rule of sensor sensitivity, the trusted data intelligent detection system can achieve efficient perception, feature separation, and anomaly detection of the data stream.
[0029] Step S200: Construct a gradient aggregation channel based on differential privacy encryption, securely fuse the local model update parameters, generate a global model optimization vector, and generate an adversarial sample set in combination with the historical attack pattern library.
[0030] In the embodiment of this application, in the trusted data intelligent detection system, first, local models are independently trained on multiple data acquisition nodes, and the update parameters are calculated. The gradient descent optimization method is used to perform multiple rounds of iteration on the local data set of each node to minimize the loss function and optimize the model weights. By calculating the gradient update value, the improvement direction and amplitude of the current model relative to the global optimal solution are obtained, thereby obtaining the local model update parameters. These parameters contain the feature information learned by each node from the local data and need to be encrypted to prevent leakage.
[0031] After calculating the local gradient update value, the Laplace mechanism is used for differential privacy protection. This method adds random noise conforming to the Laplace distribution to the gradient update value, so that even if an attacker obtains the updated gradient information, they cannot infer the specific content of the original data. Through privacy protection, encrypted gradient update parameters are obtained. These parameters can still be used for global model training while ensuring that the privacy of each data node is not leaked.
[0032] During the gradient transmission process, the secret sharing method is adopted for secure aggregation to prevent the server from obtaining the gradient information of individual nodes. This method splits the encrypted gradient update parameters into multiple random fragments and distributes them to different computing nodes respectively. Only when all computing nodes participate in the calculation together can the complete gradient information be restored. Through this method, a secure gradient aggregation channel is constructed to ensure that neither the server nor other data nodes can directly decrypt the gradient information of a single data source during the gradient update process.
[0033] Based on the secure aggregation channel, the server uses the weighted average method to calculate the global model optimization vector. This method takes the data volume weights of each node and performs weighted averaging on the gradient update values uploaded by them, so that nodes with larger data volumes occupy a greater proportion in the global optimization process. Through the aggregation calculation, the global model optimization vector is obtained, which can represent the features learned by all data nodes and is used to improve the overall accuracy and stability of the detection system.
[0034] After calculating the global model optimization vector, an adversarial sample generation network is used to construct an adversarial sample set to enhance the robustness of the model. This network is based on the global model optimization vector and tests the stability of the model by generating perturbation data. The specific method is to apply a small perturbation to the input data, causing the model to misclassify when facing adversarial samples, thereby generating adversarial samples that can simulate attack behaviors. Through this process, the adversarial sample set is obtained, and these samples are used to improve the system's ability to identify potential attacks, enabling the global model to more effectively distinguish between normal data and malicious attack data.
[0035] Step S300: Perform weight allocation on the global model optimization vector, configure a dynamic update step size in combination with the dynamic trusted evaluation threshold, and generate an update instruction set including a version identifier and a credibility certificate.
[0036] In the embodiment of the present application, in the intelligent detection of trusted data, first, weight allocation is performed on the global model optimization vector to ensure a reasonable distribution of the contributions of different data sources to model optimization. A dynamic weighting method based on contribution degree is adopted to adjust the gradient update values in the global model optimization vector. Specifically, by calculating the contribution degrees of each data node in historical training, including data quality, update stability, and credibility scores, different weights are assigned to them. For example, nodes with high data quality, low volatility, and high credibility scores will have a greater weight for their gradient update values in the global model, while the weights of data sources with more noise will be reduced to minimize the impact of abnormal data on the model. Through this process, a weighted global model optimization vector is obtained, in which each gradient component is optimized to ensure the stability and reliability of the global model.
[0037] After completing the weight assignment, in combination with the dynamic trust evaluation threshold, configure the dynamic update step size to control the optimization rhythm of the model. An adaptive learning rate adjustment method is adopted to optimize the update step size of the model in real time according to the changes in the data environment. Calculate the data credibility score for the most recent period based on a sliding time window and compare it with the dynamic trust evaluation threshold. If the data credibility is high, it indicates that the current data environment is stable, and a larger update step size is adopted to accelerate model convergence; if the data fluctuates greatly or anomalies occur, a smaller update step size is adopted to reduce the deviation of the model and improve training stability. Finally, obtain the global model optimization vector with optimized dynamic step size to ensure that the model can adaptively optimize in different data environments, improve detection accuracy, and reduce the impact of abnormal data.
[0038] After completing the model optimization, generate an update instruction set for distributing the latest model version to each data node. Version management is adopted to generate a unique version identifier for each model update. Specifically, after the optimization is completed, generate a version number based on the timestamp and the hash value of the model parameters and record it in the global database so that each node can obtain the latest model and perform version rollback if necessary. Through this process, obtain the model update instruction with a unique version identifier to ensure that all nodes can recognize the latest state of the model and execute the update correctly.
[0039] After generating the version identifier, further add credibility authentication to the update instruction set to prevent the model from being tampered with or forged during the update process. Adopt digital signature and credibility certificate management methods to perform security authentication on the model update. First, use an asymmetric encryption algorithm (such as RSA or ECDSA) to sign the update instruction and attach a credibility certificate to ensure that only authenticated nodes can accept and apply this update. Subsequently, after each data node receives the update instruction, use the public key to verify the legality of the digital signature and confirm whether the update instruction comes from a trusted source. Finally, obtain the secure update instruction set containing the version identifier and the credibility certificate.
[0040] Step S400: According to the trusted baseline template, activate the adversarial sample generation network with the adversarial sample set and the update instruction set to generate an incremental update package containing the defense strategy fingerprint.
[0041] In the embodiments of the present application, first, based on the trusted baseline template, combined with the adversarial sample set and the update instruction set, the security of the current global model is evaluated. The baseline deviation calculation method is used to compare the key parameters of the current model (such as detection threshold, abnormal classification accuracy, etc.) with the standard values of the trusted baseline template. Specifically, first, the statistical characteristics of the current model parameters are calculated, and the performance of the model in different attack scenarios is evaluated using historical training data. Then, through the preset threshold in the trusted baseline template, the optimization requirements of the model are judged to determine whether it is necessary to further adjust the model defense strategy. Through this process, the trusted data intelligent detection system obtains the model state matching the trusted baseline, ensuring that the current optimized model meets the security standards of the system and can effectively resist known attacks.
[0042] After completing the trusted baseline matching, the trusted data intelligent detection system uses the adversarial sample set and the update instruction set to activate the adversarial sample generation network to simulate potential attack behaviors and test the defense capabilities of the model. The adversarial sample generation method based on gradient perturbation is adopted. By slightly perturbing the input data, adversarial samples that can deceive the current model are generated. Specifically, the system first selects a set of representative samples, calculates the gradient information of the model for these samples, and then applies a small perturbation to the input data to change the classification decision of the model, thereby generating more concealed adversarial samples. Finally, efficient adversarial samples adapted to the global model are obtained, and these adversarial samples are used for subsequent training to enable the global model to recognize more complex attack patterns.
[0043] After generating the adversarial samples, the hash fingerprint generation method is adopted to generate a unique fingerprint identifier for the optimized model defense strategy. Specifically, hash calculations are performed on the latest optimized parameters of the model, the adversarial training data, and the anomaly detection rules to generate a unique defense strategy fingerprint. This fingerprint can be used for the verification of subsequent model updates, ensuring that the system can quickly match the appropriate defense strategy when facing different attacks and preventing malicious tampering. Through this process, the trusted data intelligent detection system obtains the defense strategy fingerprint containing the defense strategy characteristics, which is used to enhance the security and traceability of the system.
[0044] Finally, the trusted data intelligent detection system encapsulates the optimized model, the adversarial sample training results, and the defense strategy fingerprint into an incremental update package and distributes it through the differential update mechanism. The incremental update method based on binary data comparison is adopted, only recording the different parts between the current model and the previous version, and packaging these update data into an incremental update package. Specifically, the binary parameter differences between the current model and the historical version are calculated, and an efficient compression algorithm is used to reduce the amount of update data, thereby reducing the bandwidth overhead required for system upgrades. Through this process, the trusted data intelligent detection system obtains the incremental update package containing the defense strategy fingerprint.
[0045] Further, as Figure 2 shown, in the method provided by the application embodiment, according to the trusted baseline template, with the adversarial sample set and the update instruction set, activating the adversarial sample generation network further includes:
[0046] Configuring a perturbation noise matrix that meets the trusted baseline template based on the trusted baseline evolution differential equation; introducing spatio-temporal correlation features into the perturbation noise matrix, configuring the adversarial sample generation network, and iteratively optimizing the perturbation amplitude using the gradient masking mechanism.
[0047] In the embodiment of the present application, first, based on the trusted baseline evolution differential equation, a perturbation noise matrix that meets the trusted baseline template is configured to optimize the noise control strategy in the adversarial sample generation process. The deviation degree adaptive noise matching method is adopted to determine the perturbation noise matrix suitable for different environments by calculating the offset between the current data flow state and the trusted baseline template. Specifically, the mean, variance, and kurtosis of the data flow are calculated based on a sliding time window, and the baseline evolution differential equation is used to evaluate the change trend of data features over time. At the same time, combining the detection results of the model and historical data, the noise perturbation level in different environments is determined, so that the noise can cover the normal data fluctuation range without affecting the anomaly detection ability. Finally, a perturbation noise matrix that conforms to the trusted baseline template is obtained.
[0048] After completing the configuration of the perturbation noise matrix, spatio-temporal correlation features are introduced into the perturbation noise matrix to enhance the adaptability to time and space information in the adversarial sample generation process. The spatio-temporal embedding method based on dynamic feature extraction of data flow is adopted to construct the spatio-temporal feature mapping of the data flow through the spatio-temporal correlation feature parameters, fractal dimension, first spatial dimension, and second spatial dimension in the trusted baseline evolution differential equation. Specifically, when calculating the change trend of data credibility, the spatial position features (such as the topological relationship of the data transmission path) and time series features (such as the data mutation frequency) are combined to ensure that the noise matrix can correctly reflect the change trend of data in the spatio-temporal dimension. Finally, a perturbation noise matrix containing spatio-temporal correlation features is obtained.
[0049] After introducing the spatio-temporal correlation features, configure the adversarial sample generation network and adopt the gradient masking mechanism to iteratively optimize the perturbation amplitude to improve the concealment and attack effectiveness of the adversarial samples. Adopt a mask optimization method based on gradient sensitivity analysis to adjust the key gradient regions of the model to reduce the risk of adversarial samples being misjudged as abnormal during normal detection. Specifically, first calculate the gradient distribution of the global model under different attack scenarios and identify the gradient regions that have a greater impact on the model. Then, use the gradient masking technique to impose suppression in these regions, so that the model reduces its attention to these features during training, and at the same time continuously iteratively adjusts the perturbation amplitude to ensure that the generated adversarial samples can effectively evade the detection mechanism of the model. Finally, obtain the adversarial sample generation network optimized by gradient masking.
[0050] Furthermore, the method provided by the application embodiment further includes:
[0051] Generate the fractal dimension and dynamic baseline parameters according to the trusted baseline template; based on the fractal dimension and dynamic baseline parameters, establish a trusted baseline evolution differential equation, and the trusted baseline evolution differential equation is adaptively adjusted according to the mutation frequency of the data stream.
[0052] In the embodiment of the present application, first analyze the spatio-temporal features of the data stream according to the trusted baseline template, and generate the fractal dimension and dynamic baseline parameters to describe the complexity and change trend of the data stream. Adopt the fractal dimension calculation method, based on the self-similarity of the data stream, calculate the fractal dimension, which is used to measure the geometric complexity and global structure of the data pattern. In addition, through the sliding time window analysis, statistically analyze the dynamic features such as the mean, variance, and kurtosis of the data stream to reflect the change trend and fluctuation range of the data. These parameters comprehensively describe the temporal characteristics of the data stream, enabling the system to accurately perceive the dynamic changes of the data state. Finally, obtain the fractal dimension and dynamic baseline parameters.
[0053] After generating the fractal dimension and dynamic baseline parameters, based on these parameters, establish a trusted baseline evolution differential equation to describe the change of the credibility of the data stream in the time and space dimensions. Adopt the partial differential equation modeling method, incorporate the fractal dimension, dynamic baseline parameters, and the spatial distribution variables of the data stream into the mathematical equation, and construct a trusted evaluation model. This equation is used to simulate the evolution process of data credibility over time and space, enabling the system to optimize the trusted evaluation calculation method by combining the historical trend and current state of the data. Finally, obtain the trusted baseline evolution differential equation, which provides a mathematical basis for the dynamic credibility evaluation of the system.
[0054] After establishing the trusted baseline evolution differential equation, the equation can be adaptively adjusted according to the mutation frequency of the data stream to ensure that the system can flexibly respond to data changes in different environments. The mutation frequency modulation method is used to calculate the reference mutation frequency and the current mutation frequency of the data stream, and according to the change of the mutation frequency, the spatio-temporal correlation characteristic parameters and the credibility drift coefficient are dynamically adjusted, so that the equation can adapt to different data stream change patterns. For example, in the case of a high data mutation frequency, the equation parameters are adjusted to enhance the adaptability of the model, while in a stable environment, the adjustment amplitude of the equation will be reduced to avoid false alarms. Finally, a trusted baseline evolution differential equation that is adaptively adjusted according to the mutation frequency of the data stream is obtained.
[0055] Furthermore, the method provided by the application embodiment further includes:
[0056] Denote the dynamic trusted evaluation threshold within the sliding time window as B, and establish a trusted baseline evolution differential equation where t is the time variable corresponding to the incremental update sequence, and the dynamic baseline parameters within the sliding time window include the mean μ, variance σ 2 and kurtosis γ, α is the spatio-temporal correlation characteristic parameter, β is the drift coefficient between the trusted baseline template, D f is the fractal dimension, x is the first spatial dimension, used to characterize the position distribution corresponding to the data stream transmission path, and y is the second spatial dimension, used to characterize the feature distribution corresponding to the data stream transmission path.
[0057] Furthermore, the method provided by the application embodiment further includes:
[0058] Spatio-temporal correlation characteristic parameter The drift coefficient β between the trusted baseline template is β = K2·tanh(f m / f0); where K1, K2 are the federal node consensus weight coefficients, λ is the attenuation factor, f0 is the reference mutation frequency threshold, and f m is the data stream mutation frequency.
[0059] In the embodiment of the present application, first, the dynamic trusted evaluation value (B) of the data stream is calculated within the sliding time window, and key statistical features are extracted based on the trusted baseline template for constructing a trusted evaluation model. The sliding window statistical analysis method is used to calculate the mean (μ), variance (σ 2 ) and kurtosis (γ) of the data stream to characterize the fluctuation characteristics of the data. These parameters can describe the temporal characteristics of the data stream and provide basic variables for subsequent trusted evaluation. The dynamic baseline parameters within the sliding time window are obtained through this step.
[0060] After calculating the dynamic baseline parameters, based on these parameters, a differential equation for the evolution of the trusted baseline is established to describe the evolution process of data credibility in time and space. The expression of the differential equation for the evolution of the trusted baseline is where t is the time variable, set by the technical expert according to the update period, α is the spatio-temporal correlation characteristic parameter, calculated using exponential decay. β refers to the drift coefficient with respect to the trusted baseline template, calculated through gradient partial derivatives. D f is the fractal dimension, calculated through the fractal geometry analysis method. x is the first spatial dimension, used to characterize the position distribution corresponding to the data stream transmission path, and y is the second spatial dimension, used to characterize the feature distribution corresponding to the data stream transmission path.
[0061] After calculating the differential equation for the evolution of the trusted baseline, the trusted data intelligent detection system adapts the equation according to the data stream mutation frequency (f m ) to ensure that the trusted evaluation mechanism can dynamically adapt to different data environments. Using the mutation frequency adaptive adjustment method, the baseline mutation frequency (f0) and the current mutation frequency (f m ) of the data stream are calculated, and the credibility evaluation parameters are optimized accordingly.
[0062] Specifically, the spatio-temporal correlation characteristic parameter α is calculated using exponential decay, defined as where K1 is preset by the technical expert as the consensus weight coefficient of the federated node, used to control the influence of the system on the credibility of different data sources; λ is calculated using the mutation decay factor, set according to historical data, enabling the system to dynamically adjust the credibility evaluation criteria according to data mutation situations.
[0063] The drift coefficient β uses hyperbolic tangent transformation, defined as β = K2·tanh(f m / f0), where K2 is preset by the technical expert, representing the response intensity of the system to data drift. f0 is statistically obtained through the baseline mutation frequency, representing the mutation rate in the normal data environment; f m is calculated through data stream mutation detection, representing the actual mutation frequency of the data in the current environment.
[0064] Finally, through this calculation, a differential equation for the evolution of the trusted baseline that is adaptively adjusted according to the data stream mutation frequency is obtained.
[0065] Step S500: Use the incremental update package to trigger the asynchronous hot deployment of the edge computing node and reconstruct the model topology of the federated incremental learning framework to generate an update log.
[0066] In the embodiments of the present application, first, an asynchronous hot deployment of edge computing nodes is triggered by an incremental update package. The incremental update package is generated by differential update technology, which only calculates the differences between the current version and the previous version, thereby reducing the data transmission volume. By using the incremental update package, it is ensured that only the necessary parts of the system are updated during the transmission process, reducing bandwidth and computational overhead, while avoiding the transmission and redeployment of full-volume data. The incremental update package further reduces the data volume through a compression algorithm, optimizing the use of network resources and enabling edge computing nodes to quickly receive and deploy the updated content. During the deployment process, containerization technology is adopted, that is, the updated content is encapsulated as a container and seamlessly deployed on different edge nodes to ensure that the original services are not interrupted and to guarantee the high availability of the system.
[0067] Next, after the update package is applied, the model topology structure of the federated incremental learning framework is reconstructed. In this process, a dynamic topology optimization algorithm is adopted. Through this algorithm, according to the mutual relationship and communication bandwidth between nodes, the topology structure of the model is dynamically adjusted to optimize the contribution of each node during the entire learning process. During the update process, the model parameters are redistributed to ensure that each node performs incremental updates based on its local data and minimizes information loss during model fusion. In this way, the federated learning framework can effectively adapt to the characteristics of different data sources, while maintaining the consistency and stability of the model, and enhancing the training ability of the system in a multi-node environment.
[0068] Finally, after the asynchronous hot deployment and model reconstruction are completed, an update log is generated to record the version, deployment time, adjustments made, and learning contributions of each update. The generation of this log adopts a version control system for automatically tracking and recording the details of each update. The update log includes information such as the version number, updated model parameters, nodes participating in the learning, and the contributions of each node to the global model. These logs also use data verification technology to ensure the accuracy of the update process and avoid system failures caused by incorrect operations. Ultimately, the update log provides a detailed record for subsequent fault recovery, performance analysis, and system optimization, and ensures the traceability and transparency of the update process.
[0069] Through these steps, the trusted data intelligent detection system can achieve an efficient model update process while ensuring the reliability, stability, and transparency of the system.
[0070] Furthermore, in the method provided by the application embodiments, using the incremental update package to trigger the asynchronous hot deployment of edge computing nodes further includes:
[0071] Deploy a containerized sandbox environment on the edge computing node, construct a dependency relationship graph, and analyze the compatibility between the incremental update package and the running environment; based on the compatibility analysis result, automatically adjust the resource quota.
[0072] In the embodiments of the present application, first, a containerized sandbox environment is deployed on the edge computing node to ensure that the incremental update package can be tested and deployed in an isolated environment. Using containerization technologies such as Docker, the application and all its dependencies (such as libraries, frameworks, configuration files) are packaged into a lightweight container, ensuring that the container can run consistently on different nodes. In the sandbox environment, the behavior of the update package can be fully tested without affecting the actual production environment. Through this method, a deployed containerized sandbox environment is obtained, laying a foundation for the subsequent compatibility testing and resource adjustment of the incremental update package.
[0073] Next, a dependency graph is constructed in the deployed sandbox environment to analyze the compatibility between the incremental update package and the existing running environment. Through static analysis techniques, all files in the incremental update package are scanned to identify external libraries, frameworks, and services in the package and compare them with the existing dependencies in the current sandbox environment. This process is completed by tools such as Apache Maven or Gradle, which can automatically resolve all dependency relationships and generate a graph indicating the relationships between each component. After this step is completed, a dependency graph of the incremental update package is obtained, enabling a visual view of the dependency compatibility between the update package and the existing environment, helping to discover potential conflicts or missing dependencies.
[0074] Based on the compatibility analysis results of the incremental update package, the resource quota is automatically adjusted to ensure that the containerized sandbox environment has sufficient resources to support the running of the incremental update package. Through an automatic resource scheduling method, according to the results of the compatibility analysis, the types and quantities of resources that need to be adjusted are determined, and container orchestration platforms such as Kubernetes are used to dynamically adjust the resource allocation. According to the load situation, resources such as computing power, memory, or storage can be increased or decreased to meet the requirements of the update package. During this process, an automatically adjusted resource quota is obtained, ensuring that the incremental update package can run efficiently in an environment with sufficient resources without causing performance bottlenecks or resource waste.
[0075] Through these steps, the trusted data intelligent detection system has successfully realized the deployment of a containerized sandbox environment on the edge computing node and conducted compatibility testing and resource optimization on the incremental update package. Finally, compatibility analysis results, a dependency graph, and an automatically adjusted resource quota are obtained, providing support for subsequent seamless update deployment and efficient operation.
[0076] Furthermore, in the method provided by the application embodiments, when deploying a containerized sandbox environment on the edge computing node and constructing a dependency graph, it further includes:
[0077] Build the dependency graph, which includes the evolution path of feature weights, the dependency relationship of rule iteration, and the defense strategy linkage mechanism; match the parameter adjustment strategy according to the credibility deviation index corresponding to the dynamic trusted evaluation threshold, including adaptive scaling of the learning rate, reconstruction of the feature space, and dynamic adjustment of the regularization strength; generate an incremental update sequence with resource quota constraints based on the parameter adjustment strategy and combined with the load status.
[0078] In the embodiment of the present application, first, a dependency graph is constructed through a static analysis method. This graph includes the evolution path of feature weights, the dependency relationship of rule iteration, and the defense strategy linkage mechanism. Using Abstract Syntax Tree (AST) analysis, the code in the incremental update package is parsed to extract the dependency relationships of each module and establish the connections therebetween. Specifically, the features in the incremental update package are analyzed, and the evolution path of feature weights is generated through AST analysis, recording how the weight of each feature changes with each update. Through this step, a dependency graph containing the evolution path of feature weights is obtained, providing a basis for subsequent compatibility testing and parameter adjustment.
[0079] Next, the dependency relationship of rule iteration is constructed through rule iteration analysis. This step adopts the rule iteration analysis method to check the dependency relationships between the new rules or modified rules in the incremental update package and the existing rules. By analyzing the interactions between these rules and other modules, the dependency path after rule update is determined to understand how the new rules cooperate with the existing system rules. Through this method, appropriate rule support is provided for subsequent model adjustment, and the dependency relationship of rule iteration is generated to ensure that the rules after incremental update are compatible and enhance the functions of the existing system.
[0080] After the construction of the dependency relationship of rule iteration is completed, combined with the defense strategy linkage mechanism, ensure that the defense strategies in the incremental update package can work in coordination with the existing security mechanisms. Through linkage mechanism analysis, the compatibility between the new defense strategies in the incremental update package and the existing strategies is evaluated to ensure that there are no conflicts in the security strategies. The linkage mechanism analysis ensures that the update does not reduce the defense ability of the system by comparing the interactions between the defense strategies in the update package and the existing security measures. Finally, the defense strategy linkage mechanism is obtained, which ensures that the incremental update package does not cause security problems while enhancing the model's capabilities.
[0081] Next, based on these analysis results, determine an appropriate parameter adjustment strategy according to the credibility deviation index corresponding to the dynamic trust evaluation threshold. The credibility deviation index is calculated by comparing the deviation between the current model and the trust baseline, reflecting the current credibility status. Use this deviation index to adjust each parameter of the model. Specifically, adopt the learning rate adaptive scaling method, and use the Adam optimization algorithm to dynamically adjust the learning rate according to the credibility deviation index. When the deviation is large, automatically reduce the learning rate to avoid over-adjustment; while when the credibility is high, increase the learning rate to accelerate the convergence speed. Also apply the feature space reconstruction technology to dynamically reconstruct the feature space through methods such as PCA (Principal Component Analysis) or t-SNE (t-Distributed Stochastic Neighbor Embedding), ensuring that the data distribution can adapt to the current model state and optimizing the generalization ability of the model. Finally, apply dynamic adjustment of the regularization strength to adjust the strength of the regularization term according to the deviation index to prevent the model from overfitting or underfitting.
[0082] After determining the parameter adjustment strategy, combine the load status to generate an incremental update sequence with resource quota constraints. The load status monitors the resource usage of the system in real time through a performance monitoring tool (such as Prometheus), including CPU, memory, bandwidth, etc. On this basis, use the load prediction algorithm to analyze the resource requirements and adjust the resource quota through Kubernetes automatic scheduling. Specifically, appropriately reduce or increase the scale of the update package according to the load situation to ensure that the system can efficiently utilize resources without overloading. Finally, the generated incremental update sequence with resource quota constraints can successfully perform incremental updates without causing system overload.
[0083] Through these steps, the trusted data intelligent detection system can efficiently perform incremental updates in a dynamically changing environment, while ensuring that system resources are reasonably configured, and each module, rule, and defense strategy can work together, ultimately maintaining the stability, robustness, and security of the system.
[0084] In the embodiments of this application, in summary, the embodiments of this application at least have the following technical effects:
[0085] This application deploys heterogeneous feature collection nodes in the data stream transmission path to collect data correlation features and operation behavior fingerprints. Using a federated incremental learning framework, it conducts multi-dimensional correlation analysis and sets dynamic trusted evaluation thresholds. It constructs a gradient aggregation channel based on differential privacy encryption to securely fuse the updated parameters of local models, generates a global model optimization vector, and combines it with a historical attack pattern library to generate an adversarial sample set. It assigns weights to the global model optimization vector, configures a dynamic update step size in combination with the dynamic trusted evaluation threshold, and generates an update instruction set containing a version identifier and a credibility certificate. According to a trusted baseline template, using the adversarial sample set and the update instruction set, it activates an adversarial sample generation network to generate an incremental update package containing a defense strategy fingerprint. Using the incremental update package, it triggers the asynchronous hot deployment of edge computing nodes and reconstructs the model topology of the federated incremental learning framework to generate an update log. The present invention solves the technical problems of poor adaptability and low real-time performance in data credibility evaluation, privacy protection, and security defense in the prior art. Through a federated incremental learning framework, multi-dimensional correlation analysis, differential privacy encryption, adversarial sample generation, and asynchronous deployment of edge computing, it achieves the technical effects of enhancing data credibility, strengthening privacy protection capabilities, and improving attack defense capabilities.
[0086] It should be noted that the above sequence of embodiments of the present application is only for description and does not represent the superiority or inferiority of the embodiments. And the above specific embodiments of this specification have been described. The processes depicted in the drawings do not necessarily require the specific order and continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0087] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included within the protection scope of the present application.
[0088] This specification and the drawings are only exemplary descriptions of the present application and are considered to have covered any and all modifications, variations, combinations, or equivalents within the scope of the present application. Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the present application and its equivalent technologies, the present application is intended to include these changes and modifications.
Claims
1. A dynamic optimization and updating method for a trusted data intelligent detection system, characterized in that: The method comprises: Deploy heterogeneous feature collection nodes in the data stream transmission path to collect data association features and operation behavior fingerprints, conduct multi-dimensional association analysis using a federated incremental learning framework, and set dynamic trust evaluation thresholds; Build a gradient aggregation channel based on differential privacy encryption to securely fuse local model update parameters, generate global model optimization vectors, and generate adversarial sample sets in combination with the historical attack pattern library; Performing weight distribution on the global model optimization vector, configuring a dynamic update step in combination with the dynamic trust evaluation threshold, and generating an update instruction set including a version identifier and a trustworthiness certificate; According to the trusted baseline template, the adversarial sample set and the update instruction set are used to activate the adversarial sample generation network and generate an incremental update package containing the defense strategy fingerprint; The incremental update package is used to trigger asynchronous hot deployment of edge computing nodes, reconstruct the model topology of the federated incremental learning framework, and generate an update log.
2. A dynamic optimization and updating method for a trusted data intelligent detection system as claimed in claim 1, characterized in that: Deploying heterogeneous feature collection nodes in the data stream transmission path, the method further includes: A neural network sensor array is arranged at the data input layer to simulate the dynamic response mechanism of biological synapses to capture the spatiotemporal correlation characteristics of the data flow transmission path; Based on the neural network sensor array, a photonic crystal filter is implanted to separate high-frequency abnormal signals from normal data features based on the photonic bandgap effect.
3. A dynamic optimization and updating method for a trusted data intelligent detection system as claimed in claim 2, characterized in that: Set the sensor sensitivity adaptive adjustment rules, including the sensitivity attenuation coefficient ≤ 0.05dB / Hz in a noisy environment and the response delay ≤ 50ns in a burst data stream scenario.
4. The method for dynamically optimizing and updating a trusted data intelligent detection system according to claim 1, characterized in that: According to the trusted baseline template, the adversarial sample set and the update instruction set are used to activate the adversarial sample generation network, and the method further includes: Based on the trusted baseline evolution differential equation, configuring a disturbance noise matrix that satisfies the trusted baseline template; The spatiotemporal correlation features are introduced into the perturbation noise matrix, the adversarial sample generation network is configured, and the perturbation amplitude is iteratively optimized using a gradient mask mechanism.
5. A dynamic optimization and updating method for a trusted data intelligent detection system as claimed in claim 4, characterized in that: The method comprises: Generate fractal dimension and dynamic baseline parameters according to the trusted baseline template; Based on the fractal dimension and the dynamic baseline parameter, a trusted baseline evolution differential equation is established, and the trusted baseline evolution differential equation is adaptively adjusted with the frequency of data flow mutations.
6. A dynamic optimization and updating method for a trusted data intelligent detection system as claimed in claim 5, characterized in that: Using the incremental update package, triggering asynchronous hot deployment of edge computing nodes, the method further includes: Deploy a containerized sandbox environment on the edge computing node, build a dependency graph, and analyze the compatibility of the incremental update package with the operating environment; Automatically adjust resource quotas based on compatibility analysis results.
7. A dynamic optimization and updating method for a trusted data intelligent detection system as claimed in claim 6, characterized in that: Deploy a containerized sandbox environment on the edge computing node to build a dependency graph, and the method further includes: Establishing the dependency graph, including the feature weight evolution path, rule iteration dependency and defense strategy linkage mechanism; According to the credibility deviation index corresponding to the dynamic credibility assessment threshold, matching parameter adjustment strategies include adaptive scaling of learning rate, feature space reconstruction and dynamic adjustment of regularization strength; Based on the parameter adjustment strategy and combined with the load status, an incremental update sequence with resource quota constraints is generated.
8. A dynamic optimization and updating method for a trusted data intelligent detection system as claimed in claim 7, characterized in that: The dynamic trust evaluation threshold in the sliding time window is recorded as B, and the trust baseline evolution differential equation is established: Where t is the time variable corresponding to the incremental update sequence, and the dynamic baseline parameters in the sliding time window include mean μ, variance σ 2 and kurtosis γ, α is the characteristic parameter of spatiotemporal correlation, β refers to the drift coefficient between the reliable baseline template, D f is the fractal dimension, x is the first spatial dimension, which is used to characterize the position distribution corresponding to the data stream transmission path, and y is the second spatial dimension, which is used to characterize the feature distribution corresponding to the data stream transmission path.
9. A dynamic optimization and updating method for a trusted data intelligent detection system as claimed in claim 8, characterized in that: The method further comprises: Spatial-temporal correlation characteristic parameters The drift coefficient β between the trusted baseline template and the m / f0); Among them, K1 and K2 are the consensus weight coefficients of the federated nodes, λ is the attenuation factor, f0 is the benchmark mutation frequency threshold, and f m is the frequency of data stream mutation.
Citation Information
Cited By
Automatic data grading protection method and system based on multi-feature fusion
CN120763957A
A data automatic grading protection method and system based on multi-feature fusion
CN120763957B
Encryption fragmentation and distributed storage method and system of password
CN121239401A
A method and system for encrypted fragmentation and distributed storage of a password
CN121239401B
Electric connector signal transmission optimization method and system
CN121309627A