Distributed continuous learning and intelligent sample driven security knowledge fusion method
By intelligently filtering and encrypting representative data samples at edge nodes, the problem of low data quality in distributed learning is solved, efficient and secure global model optimization and environmental adaptation are achieved, and learning iteration efficiency and model performance are improved.
Patent Information
- Application Number
- CN202510676804.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-23
- Publication Date
- 2025-08-22
AI Technical Summary
In the existing distributed learning methods, the quality of representative data samples uploaded by edge nodes is not high, which affects the training efficiency and performance of global model. It is difficult for edge cloud collaborative learning systems to adapt to the dynamic changes of edge data efficiently and safely.
By evaluating the performance of the local model in real time at the edge node, the representative data samples with the most information value to the global model are intelligently selected, and securely encapsulated using asymmetric encryption and digital signatures and uploaded to the cloud server. After the cloud server is signed and validated and decrypted, it is used for continuous learning and optimization of the global model, and the optimized model is safely distributed back to the edge node.
It significantly improves the operating efficiency and model performance of the distributed continuous learning system, ensures high information density and representativeness of the data, supports the system to learn incrementally and adapt to environmental changes without the need for complete retraining of all tasks, and builds a safe and efficient distributed continuous learning framework.
Smart Images

Figure CN120528658A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of machine learning technology, and specifically relates to a security knowledge fusion method driven by distributed continuous learning and intelligent samples. Background Art
[0002] With the rapid development of the Internet of Things (IoT) and distributed cloud computing, massive amounts of data are generated at the edge of networks. Leveraging this edge-generated data for machine learning model training and optimization has become a significant trend. Federated learning (Federated Learning) allows for collaborative model training without directly sharing raw data, providing a path to privacy protection. However, traditional federated learning or distributed learning approaches still face numerous challenges in the face of an ever-increasing number of tasks. For example, when models learn new categories of tasks, they tend to forget previously acquired knowledge, resulting in catastrophic forgetting. To maintain good model performance across all tasks, all tasks must be retrained, significantly consuming computing resources. Traditional edge-cloud collaborative learning frameworks severely limit model capabilities in environments with serialized and continuously evolving tasks. Existing secure aggregation solutions primarily focus on encrypting and aggregating model updates (such as gradients) uploaded by clients to protect gradient privacy. However, there is a lack of effective solutions for selecting high-quality raw data samples from the edge that are most valuable to the global model. If edge nodes only passively upload data or randomly select samples, the cloud may receive a large amount of redundant or low-value information, impacting the efficiency and performance of global model training. This patent combines continuous learning technology with a new sample selection method, and uses appropriate cryptographic technology to ensure the effectiveness of these samples in the selection process, the efficiency of model training and the integrity of the fusion process, which can effectively guarantee the performance of the final model. Summary of the Invention
[0003] The purpose of the present invention is to overcome the problem in existing distributed learning methods that the quality of representative data samples uploaded by edge nodes to cloud servers is not high, which in turn affects the global model training efficiency and final performance, as well as the problem that the edge-cloud collaborative learning system is difficult to adapt to the dynamic changes of edge data efficiently and securely. Therefore, a distributed continuous learning and intelligent sample-driven secure knowledge fusion method is provided, an active intelligent screening method is designed for the data contribution model in traditional distributed learning, and end-to-end security protection is provided for knowledge fusion and model distribution. The continuous learning framework is integrated to avoid repeated training and effectively improve iteration efficiency.
[0004] To achieve the above objectives, the technical solution of the present invention is: a distributed continuous learning and intelligent sample-driven security knowledge fusion method, comprising:
[0005] Edge nodes run their locally deployed machine learning models to process locally collected data. Combined with real-time performance evaluation of the machine learning models on the locally collected data, they intelligently identify and select representative data samples with the most valuable information for global model optimization.
[0006] The selected representative data samples are securely encapsulated with asymmetric encryption and digital signatures before being uploaded to the cloud server. After receiving the samples, the cloud server verifies and decrypts the signatures. After proving that the samples are secure and reliable, the samples are used for continuous learning and optimization of the global model. The optimized global model is securely encapsulated and distributed back to the edge nodes.
[0007] The method comprises the following steps:
[0008] S101, system initialization: The cloud server and each edge node generate an asymmetric key pair for encryption and an asymmetric key pair for data signing respectively; the cloud server distributes its public key to the edge node, and the edge node registers its signature public key and encryption public key with the cloud server; the cloud server distributes an initial model to each edge node;
[0009] S102. Edge node model deployment and operation and intelligent selection of representative samples: The edge node deploys the initial model received from the cloud server and processes the locally collected data, monitoring and evaluating the performance of the local model on the current data; based on the performance and preset strategies, a set of representative data samples are extracted from the local data;
[0010] S103, edge node sample security packaging: The edge node calculates a hash value for the representative data sample it extracts; uses the cloud server's encryption public key to encrypt the representative data sample using an asymmetric encryption algorithm to obtain an encrypted sample; uses the edge node's own signature private key to sign the sample's hash value using a digital signature algorithm to obtain a digital signature;
[0011] S104, secure upload of edge node samples: The edge node sends the encrypted sample, digital signature, and optional sample metadata to the cloud server via a secure communication network;
[0012] S105. Cloud server sample reception, verification, and decryption: The cloud server receives the encrypted sample and digital signature from the edge node; uses the edge node's signature public key to verify the validity of the digital signature; if the verification is successful, the cloud server's own encryption private key is used to decrypt the encrypted sample to obtain a plaintext representative sample;
[0013] S106. Continuous learning of the cloud server global model: The cloud server aggregates valid representative samples from one or more edge nodes and uses these samples to train or update the global machine learning model to obtain an optimized global model.
[0014] S107. The cloud server updates the model security package: the cloud server calculates a hash value for the optimized global model or its updated part; encrypts the optimized global model using the encryption public key of the target edge node; and signs the hash value of the global model using the cloud server's own signature private key.
[0015] S108, cloud server update model secure distribution: the cloud server distributes the encapsulated optimized global model and its signature to one or more edge nodes via a secure communication network;
[0016] S109, edge node model reception, verification and deployment: The edge node receives the optimized global model and its signature from the cloud server; uses the cloud server's signature public key to verify the validity of the signature; if the verification passes and the optimized global model is encrypted, the edge node's own encryption private key is used to decrypt the optimized global model; if the verification fails, the information received in this round is discarded; the edge node deploys the verified optimized global model as a new local model.
[0017] The present invention also provides a distributed continuous learning and intelligent sample-driven security knowledge fusion system, including a memory, a processor, and computer program instructions stored in the memory and capable of being executed by the processor. When the processor executes the computer program instructions, it can implement any of the method steps described above.
[0018] The present invention also provides a computer-readable storage medium on which computer program instructions that can be executed by a processor are stored. When the processor executes the computer program instructions, any of the method steps described above can be implemented.
[0019] Compared with the existing technology, the present invention has the following beneficial effects: the present invention significantly improves the operational efficiency, model performance and overall security of the distributed continuous learning system by integrating the active sample selection mechanism of the edge nodes and cryptographic security guarantees in the distributed learning system. The edge nodes perform intelligent data pre-screening based on the real-time evaluation of the local model performance, ensuring that the data used for iterative optimization of the global model has higher information density and representativeness, so that the global model can integrate knowledge more efficiently in the continuous learning process, and supports the system to incrementally learn and adapt to new tasks or changing data distributions without the need for complete retraining of all previous tasks, thereby effectively improving the efficiency of learning iterations and model performance. A distributed continuous learning framework has been constructed that can safely and efficiently perform long-term iterative optimization and dynamically adapt to environmental changes. BRIEF DESCRIPTION OF THE DRAWINGS
[0020] Figure 1This is a flow chart of a distributed continuous learning and intelligent sample-driven security knowledge fusion method of the present invention.
[0021] Figure 2 Schematic diagram of a distributed continuous learning and intelligent sample-driven security knowledge fusion method for an example.
[0022] Figure 3 This is a system structure diagram of a distributed continuous learning and intelligent sample-driven security knowledge fusion method. DETAILED DESCRIPTION
[0023] The technical solution of the present invention will be described in detail below with reference to the accompanying drawings.
[0024] The present invention provides a distributed continuous learning and intelligent sample-driven security knowledge fusion method, including:
[0025] Edge nodes run their locally deployed machine learning models to process locally collected data. Combined with real-time performance evaluation of the machine learning models on the locally collected data, they intelligently identify and select representative data samples with the most valuable information for global model optimization.
[0026] The selected representative data samples are securely encapsulated with asymmetric encryption and digital signatures before being uploaded to the cloud server. After receiving the samples, the cloud server verifies and decrypts the signatures. After proving that the samples are secure and reliable, the samples are used for continuous learning and optimization of the global model. The optimized global model is securely encapsulated and distributed back to the edge nodes.
[0027] The following is a specific implementation process of the present invention.
[0028] 1. Symbols and Definitions
[0029] ECIES: Elliptic Curve Integrated Encryption Scheme.
[0030] ECDSA: Elliptic Curve Digital Signature Algorithm.
[0031] SHA-256: Secure Hash Algorithm 256-bit.
[0032] i: The index used to identify a specific edge node.
[0033] c: Used to identify the cloud server.
[0034] ·PKec : The ECIES public key of the cloud server, used to encrypt data sent to the cloud server.
[0035] SKe c : ECIES private key of the cloud server, used to decrypt ECIES encrypted data received by the cloud server.
[0036] PKs c : The ECDSA public key of the cloud server, used by edge nodes to verify the authenticity of the cloud server's digital signature.
[0037] ·SKs c : The ECDSA private key of the cloud server, which is used by the cloud server to digitally sign the data it sends (for example, the optimized global model or its hash).
[0038] ·PKe i : The ECIES public key of edge node i can be used by cloud servers or other entities to encrypt and send specific data to edge node i in some scenarios.
[0039] SKe i : ECIES private key of edge node i, used by edge node i to decrypt the received ECIES encrypted data.
[0040] PKs i : The ECDSA public key of edge node i, used by the cloud server to verify the authenticity of the digital signature of edge node i.
[0041] ·SKs i : The ECDSA private key of edge node i, which is used by edge node i to digitally sign the data it sends (for example, the hash value of a representative sample).
[0042] ·M initial : The initial machine learning model distributed by the cloud server to the edge nodes.
[0043] ·M local,i : The current local machine learning model deployed on edge node i.
[0044] ·D local,i : New data generated or collected locally by edge node i for model inference and representative sample screening.
[0045] ·S i : Edge node i uses its local data D local,i In the example, according to the local model M local,i A set of representative data samples is intelligently selected based on the performance of the dataset.
[0046] · Representative data sample S i The hash value is calculated using SHA256 (S i ).
[0047] · Use the ECIES public key PKe of the cloud server c For the representative data sample S i The encrypted sample obtained after encryption is
[0048] ·SigS i :Edge node i uses its ECDSA private key SKs i For the sample hash value HS i (or encrypted sample The digital signature obtained by signing the hash value of i =ECDSA(SKs i ,HS i ).
[0049] ·S i,decrypted :The cloud server uses its ECIES private key SKe c For the encrypted samples received from edge node i The representative sample of plaintext obtained after decryption is
[0050] ·S aggregated : The cloud server aggregates the verified and decrypted representative samples S from one or more edge nodes i,decrypted The data set formed for training the global model.
[0051] ·M global : The global machine learning model currently maintained on the cloud server.
[0052] M'global: A representative sample of cloud server usage aggregations aggregated For the current global model m global The optimized global machine learning model obtained after training or updating.
[0053] ·H M' : Optimized global model m' global (or its updated part), calculated as SHA256(M' global ).
[0054] ·C M',i : When the optimized global model m' global When encryption is required for a specific edge node i, the ECIES public key PKe of the edge node i is used iThe encryption model obtained after encrypting m'global is C M',i =ECIES(PKe i ,M' global ).
[0055] ·M local,i : The old local model used by edge node i before receiving and deploying the optimized global model.
[0056] ·M' global,decrypted : When the optimized global model is in encrypted form C M',i When sending to edge node i, edge node i uses its ECIES private key SKe i The plaintext model obtained after decryption.
[0057] SigM': The cloud server uses its ECDSA private key SKs c The hash value H of the optimized global model M' The digital signature obtained after signing is SigM'=ECDSA(SKs c ,H M' ).
[0058] ECIES(PK, Data): Indicates that the ECIES encryption operation is performed on the data using the public key.
[0059] ECIES(SK, Ciphertext): Indicates that the private key SK is used to perform an ECIES decryption operation on the ciphertext Ciphertext obtained by performing an ECIES encryption operation on the data Data using the public key.
[0060] ECDSA(SK, MessageHash): Indicates that the private key SK is used to perform an ECDSA signature operation on the hash value MessageHash of the message.
[0061] ECDSA(PK, MessageHash, Signature): Indicates the use of the public key PK to verify the validity of the digital signature Signature for the message hash value MessageHash.
[0062] IsValid: A Boolean value indicating the result of digital signature verification, typically obtained after an ECDSA operation. A value of True indicates successful verification, while a value of False indicates a failed verification.
[0063] 2. Detailed method implementation
[0064] The most critical concept of the present invention is to design a method for active intelligent screening for the data contribution model in traditional distributed learning, and provide end-to-end security for knowledge fusion and model distribution, integrate the continuous learning framework to avoid repeated training, and effectively improve iteration efficiency. The edge node first runs its locally deployed machine learning model to process the locally collected data, and combines the real-time evaluation of the model's performance on these new data (such as prediction uncertainty, misclassification, loss changes, etc.) to intelligently identify and extract representative data samples with the most information value for global model optimization. Subsequently, these screened representative data samples are securely packaged after asymmetric encryption (such as ECIES to ensure confidentiality) and digital signatures (such as ECDSA combined with SHA-256 hash to ensure integrity and source authenticity) before being uploaded to the cloud server. After receiving the sample, the cloud server performs signature verification and decryption. After proving its security and credibility, it is used for continuous learning and optimization of the global model, and the optimized global model is securely packaged (encrypted and signed) and distributed back to the edge node. The entire mechanism achieves intelligent "pre-screening" and "concentration" of data value at the edge, and uses cryptographic tools to ensure the confidentiality, integrity and authenticity of data throughout the entire distributed learning closed loop (from edge generation, screening, upload, cloud fusion to model update and edge deployment). This effectively improves learning efficiency and model performance while enhancing the overall security and reliability of the system.
[0065] Please refer to Figure 1-3 The present invention provides a distributed continuous learning and intelligent sample driven security knowledge fusion method, comprising the steps of:
[0066] S101, system initialization: The cloud server and each edge node generate an asymmetric key pair for encryption and an asymmetric key pair for data signing respectively; the cloud server distributes its public key to the edge node, and the edge node registers its signature public key and encryption public key with the cloud server; the cloud server distributes an initial model to each edge node;
[0067] S102. Edge node model deployment and operation and intelligent selection of representative samples: The edge node deploys the initial model received from the cloud server and processes the locally collected data, monitoring and evaluating the performance of the local model on the current data; based on the performance and preset strategies, a set of representative data samples is extracted from the local data;
[0068] S103, edge node sample security packaging: The edge node calculates a hash value for the representative data sample it extracts; uses the cloud server's encryption public key to encrypt the representative data sample using an asymmetric encryption algorithm to obtain an encrypted sample; uses the edge node's own signature private key to sign the hash value of the sample using a digital signature algorithm to obtain a digital signature;
[0069] S104, secure uploading of edge node samples: the edge node sends the encrypted sample, digital signature, and optional sample metadata to the cloud server via a secure communication network;
[0070] S105. Cloud server sample reception, verification, and decryption: The cloud server receives the encrypted sample and digital signature from the edge node; uses the edge node's signature public key to verify the validity of the digital signature; if the verification is successful, the cloud server uses its own encryption private key to decrypt the encrypted sample to obtain a plaintext representative sample;
[0071] S106. Continuous learning of the cloud server global model: The cloud server aggregates valid representative samples from one or more edge nodes and uses these samples to train or update the global machine learning model to obtain an optimized global model.
[0072] S107. Cloud server updates model security package: The cloud server calculates a hash value for the optimized global model (or its updated portion). The optimized global model is encrypted using the target edge node's public encryption key. The hash value of the model is signed using the cloud server's own private signature key.
[0073] S108, cloud server update model secure distribution: the cloud server distributes the encapsulated optimized global model and its signature to one or more edge nodes via a secure communication network;
[0074] S109, edge node model reception, verification and deployment: The edge node receives the optimized global model and its signature from the cloud server; uses the cloud server's signature public key to verify the validity of the signature; if the verification passes and the model is encrypted, the edge node's own encryption private key is used to decrypt the model; if the verification fails, the information received in this round is discarded; the edge node deploys the verified optimized global model as a new local model.
[0075] Furthermore, the above steps are detailed as follows:
[0076] The step S101 specifically includes: Cloud server c generates its ECIES public-private key pair (PKe c ,SKe c ) and ECDSA public-private key pairs (PKs c ,SKs c ). Each edge node i generates its ECIES public-private key pair (PKe i ,SKe i ) and ECDSA public-private key pairs (PKs i ,SKs i ). Cloud server c will use its ECIES public key PKec and ECDSA public keys PKs c Securely distribute to all participating edge nodes. Each edge node i sends its ECDSA public key PKs i (used by the cloud server to verify its signature) and optional ECIES public key PKe i (If the cloud server needs to send encrypted messages to a specific edge node) Securely register with the cloud server c. This process is completed through a secure initial configuration or certificate authority. The cloud server c will be the initial model M initial Distributed to the edge nodes i participating in the system through a secure channel.
[0077] The edge node local model operation and representative sample intelligent selection in step S102 specifically include: the edge node i deploys the initial model M distributed by the cloud server c initial or a previously updated local machine learning model M local,i When the new local data D local,i When generated, the edge node uses M local,i To D local,i At the same time, the edge node monitors M local,i In D local,i The performance can be evaluated by the following methods: ①Uncertainty assessment: For classification tasks, the samples with higher probability distribution entropy or lower maximum probability value output by the model. ②Error analysis: local,i Misclassified samples, especially those that the model misclassifies with high confidence. ③ Loss monitoring: samples that cause a significant increase in the loss function value. Based on the above evaluation results, combined with a preset sampling strategy (such as sampling a fixed number of "most uncertain" samples, or all misclassified samples), edge nodes are counted from D local,i Extract a set of representative data samples S i .
[0078] The step S103 of edge node sample security packaging specifically includes: calculating the sample hash Use the ECIES public key PKe of cloud server c c For sample S i Encrypt and get Use the ECDSA private key SKs of edge node i i Hash value Sign and get
[0079] In step S104, the edge node i encapsulates the data And optional sample metadata (such as plaintext hash value, timestamp) are sent to the cloud server c.
[0080] In step S105, the cloud server receives, verifies and decrypts the sample. Specifically, the cloud server c receives the data packet. Then get the ECDSA public key PKs of edge node i from the registered public keys i , and verify the signature If IsValid is false, the packet is rejected. If the signature verification passes, the cloud server c uses its ECIES private key SKe c Decrypting the encrypted sample: Calculate SHA256(S i,decrypted ) and received Compare, if there is inconsistency, there is a problem, and the corresponding suspicious sample is discarded; if there is consistency, the verification is passed.
[0081] In step S106, the cloud server performs continuous learning of the global model, specifically including: the cloud server c receives the verified and decrypted representative samples S from one or more edge nodes i,decrypted Aggregated to form a batch or dataset S aggregated Then select a suitable continuous learning algorithm to train this dataset to update the current global model M global , and obtain the optimized global model M' global .
[0082] In step S107, the cloud server performs security packaging of the updated model, specifically including: calculating the model hash: H M' =SHA256(M' global ). Then use the ECIES public key PKe of edge node i i To M' global Encryption: C M',i =ECIES(PKe i ,M' global ). Use the ECDSA private key SKs of the cloud server c c Hash the model H M' Signature: SigM'=ECDSA(SKs c ,H M' ).
[0083] The cloud server updates the model security distribution in step S108, specifically including: the cloud server c sends the encapsulated model data package (C M',i ,SigM',H M' ) is sent to the target edge node i (or broadcast to all relevant edge nodes).
[0084] In step S109, the edge node model is received, verified and deployed, and is ready to enter the next round of learning, specifically including: edge node i receives the model data packet. Edge node i uses its ECIES private key SKe i Decrypt C M',i Get M' global,decrypted . Calculate the hash value of the decrypted model and compare it with the received H M' Compare. Using ECDSA public key PKs of cloud server c c Verify the signature SigM' for H M' If the verification fails, the model is rejected. If the verification passes, the new global model M' obtained by decryption is used. global,decrypted Replace the local old model M local,i , used for subsequent local tasks.
[0085] This concludes a complete round of model learning, updating, and deployment. The system then returns to step S102 and, based on the new data generated by the edge nodes and the currently optimized model state, begins a new round of intelligent selection of representative samples, secure upload, cloud-based learning, and model distribution. This cycle repeats, enabling continuous learning and evolution of the global model.
[0086] The present invention also provides a distributed continuous learning and intelligent sample-driven security knowledge fusion system, including a memory, a processor, and computer program instructions stored in the memory and capable of being executed by the processor. When the processor executes the computer program instructions, it can implement any of the method steps described above.
[0087] The present invention also provides a computer-readable storage medium on which computer program instructions that can be executed by a processor are stored. When the processor executes the computer program instructions, any of the method steps described above can be implemented.
[0088] The above are preferred embodiments of the present invention. Any changes made according to the technical solution of the present invention, as long as the resulting functions and effects do not exceed the scope of the technical solution of the present invention, shall fall within the scope of protection of the present invention.
Claims
1. A distributed continuous learning and intelligent sample-driven security knowledge fusion method, characterized by: include: Edge nodes run their locally deployed machine learning models to process locally collected data. Combined with real-time performance evaluation of the machine learning models on the locally collected data, they intelligently identify and select representative data samples with the most valuable information for global model optimization. The selected representative data samples are securely encapsulated using asymmetric encryption and digital signatures before being uploaded to the cloud server; After receiving the sample, the cloud server performs signature verification and decryption. After proving its security and reliability, it uses it for continuous learning and optimization of the global model, and distributes the optimized global model back to the edge node after secure packaging.
2. A distributed continuous learning and intelligent sample driven security knowledge fusion method according to claim 1, characterized in that: The method comprises the following steps: S101, system initialization: The cloud server and each edge node generate an asymmetric key pair for encryption and an asymmetric key pair for data signing respectively; the cloud server distributes its public key to the edge node, and the edge node registers its signature public key and encryption public key with the cloud server; the cloud server distributes an initial model to each edge node; S102, Edge Node Model Deployment and Operation and Intelligent Selection of Representative Samples: The edge node deploys the initial model received from the cloud server and processes the locally collected data, monitoring and evaluating the performance of the local model on the current data; Extract a set of representative data samples from local data based on performance and preset strategies; S103, edge node sample security packaging: the edge node calculates a hash value for the representative data sample it extracts; Use the cloud server's encryption public key to encrypt the representative data sample through an asymmetric encryption algorithm to obtain an encrypted sample; Use the edge node's own private key to sign the sample's hash value through a digital signature algorithm to obtain a digital signature; S104, secure upload of edge node samples: The edge node sends the encrypted sample, digital signature, and optional sample metadata to the cloud server via a secure communication network; S105. Cloud server sample reception, verification, and decryption: The cloud server receives the encrypted sample and digital signature from the edge node; uses the edge node's signature public key to verify the validity of the digital signature; if the verification is successful, the cloud server's own encryption private key is used to decrypt the encrypted sample to obtain a plaintext representative sample; S106. Continuous learning of the cloud server global model: The cloud server aggregates valid representative samples from one or more edge nodes and uses these samples to train or update the global machine learning model to obtain an optimized global model. S107, cloud server updates model security package: the cloud server calculates a hash value for the optimized global model or its updated part; The optimized global model is encrypted using the target edge node's public key. The hash value of the global model is signed using the cloud server's own private key. S108, cloud server update model secure distribution: the cloud server distributes the encapsulated optimized global model and its signature to one or more edge nodes via a secure communication network; S109, edge node model reception, verification and deployment: The edge node receives the optimized global model and its signature from the cloud server; uses the cloud server's signature public key to verify the validity of the signature; if the verification passes and the optimized global model is encrypted, the edge node's own encryption private key is used to decrypt the optimized global model; if the verification fails, the information received in this round is discarded; the edge node deploys the verified optimized global model as a new local model.
3. The distributed continuous learning and intelligent sample-driven security knowledge fusion method according to claim 2 is characterized in that: The step S101 specifically includes: generating an elliptic curve integrated encryption scheme ECIES public-private key pair (PKe c ,SKe c ) and the elliptic curve digital signature algorithm ECDSA public-private key pair (PKs c ,SKs c ); Each edge node i generates its ECIES public-private key pair (PKe i ,SKe i ) and ECDSA public-private key pairs (PKs i ,SKs i ); Cloud server c will use its ECIES public key PKe c and ECDSA public keys PKs c Securely distribute to all participating edge nodes; each edge node i sends its ECDSA public key PKs i and optional ECIES public key PKe i Securely register to the cloud server c, cloud server c will initial model M initial Distributed to participating edge nodes i through a secure channel.
4. A distributed continuous learning and intelligent sample-driven security knowledge fusion method according to claim 3, characterized in that: The step S102 specifically includes: deploying the initial model M distributed by the cloud server c on the edge node i initial or a previously updated local machine learning model M local,i ; When the new local data D local,i When generated, the edge node uses M local,i To D local,i Perform reasoning; at the same time, the edge node monitors M local,i In D local,i Based on the performance evaluation results and the preset sampling strategy, the edge nodes are local,i Extract a set of representative data samples S i .
5. A distributed continuous learning and intelligent sample driven security knowledge fusion method according to claim 4, characterized in that: The step S103 specifically includes: calculating the sample hash SHA-256 represents the 256-bit version of the Secure Hash Algorithm and uses the ECIES public key PKe of the cloud server c. c For sample S i Encrypt and get Use the ECDSA private key SKs of edge node i i Hash value Sign and get In step S104, the edge node i encapsulates the data And optional sample metadata are sent to the cloud server c.
6. A distributed continuous learning and intelligent sample driven security knowledge fusion method according to claim 5, characterized in that: The step S105 specifically includes: cloud server c receives the data packet Then get the ECDSA public key PKs of edge node i from the registered public keys i , and verify the signature If IsValid is false, the packet is rejected; if the signature verification passes, the cloud server c uses its ECIES private key SKe c Decrypting the encrypted sample: SHA256(S i,decrypted ) and received Compare, if there is any inconsistency, abandon the corresponding suspicious sample, if there is any consistency, the verification is passed.
7. A distributed continuous learning and intelligent sample driven security knowledge fusion method according to claim 6, characterized in that: The step S106 specifically includes: the cloud server c sends the verified and decrypted representative samples S from one or more edge nodes to the cloud server c. i,decrypted Aggregated to form a batch or dataset S aggregated ; Then use the continuous learning algorithm to aggregated Train to update the current global model M global , and obtain the optimized global model M' global .
8. The method for integrating distributed continuous learning and intelligent sample-driven security knowledge according to claim 7 is characterized in that: The step S107 specifically includes: calculating the model hash: H M' =SHA256(M' global ); then use the ECIES public key PKe of edge node i i To M' global Encryption: C M',i =ECIES(PKe i ,M' global ); Use the ECDSA private key SKs of the cloud server c c Hash the model H M' Signature: SigM'=ECDSA(SKs c ,H M' ).
9. A distributed continuous learning and intelligent sample driven security knowledge fusion method according to claim 8, characterized in that: The step S108 specifically includes: the cloud server c sends the encapsulated model data package (C M',i ,SigM',H M' ) is sent to the target edge node i or broadcast to all relevant edge nodes.
10. A distributed continuous learning and intelligent sample driven security knowledge fusion method according to claim 9, characterized in that: The step S109 specifically includes: after edge node i receives the model data packet, edge node i uses its ECIES private key SKe i Decrypt C M',i Get M' global,decrypted ; Combine the hash value of the decrypted model with the received H M' Compare; use the ECDSA public key PKs of cloud server c c Verify the signature SigM' for H M' If the verification fails, the model is rejected. If the verification passes, the new global model M' obtained by decryption is used. global,decrypted Replace the local old model M local,i , used for subsequent local tasks.
Citation Information
Cited By
Closed-loop continuous learning method and system for traffic participant behavior prediction model
CN120950999A