Artificial intelligence model enhancement method and device for vehicle network interaction scene
By constructing a training data set and performing model enhancement processing, the problem of AI security attacks in vehicle-grid interaction scenarios is solved, and the system's protection capabilities and the security of decision-making and control are improved, especially against malicious nodes and backdoor attacks.
Patent Information
- Application Number
- CN202410413277.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-08
- Publication Date
- 2025-10-14
AI Technical Summary
There is a broad AI security attack surface in vehicle-grid interaction scenarios, including malicious node attacks, data poisoning, model poisoning, and backdoor attacks. The attacks are highly concealed, have a wide range, and are difficult to trace afterwards, affecting the decision-making and control security of the vehicle-grid interaction system.
By obtaining negative and positive data sets to build training data, the artificial intelligence model is trained to determine whether the protection effect and performance constraints are met. If not, enhanced processing is performed, including adding differential privacy to model training nodes, adjusting model parameters, and pruning abnormal neurons. Combined with local and global differential privacy and dynamic feedback adjustment mechanisms, potential backdoor threats can be identified and repaired.
It effectively responds to malicious node attacks, covert poisoning and backdoor attacks, improves the algorithm security protection capabilities of the vehicle-network interactive system, and ensures the security and accuracy of decision-making and control.
Smart Images

Figure CN120781237A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of vehicle-to-grid interaction, and particularly relates to an artificial intelligence model enhancement method and device for a vehicle-to-grid interaction scenario. BACKGROUND
[0002] Electric vehicle loads have the characteristics of small single capacity, large scale, and strong randomness of electricity consumption. Vehicle-to-grid interaction is to aggregate electric vehicle loads to form a large-scale controllable load, and to interact with the power grid through power control to achieve clean energy consumption. In order to do well in vehicle-to-grid interaction business and realize effective regulation and control of large-scale loads, artificial intelligence technology needs to be fully utilized for decision-making and organization and control in order to improve the regulation and control accuracy and decision-making level.
[0003] The introduction of more decision-making algorithms also leads to a wider attack surface for vehicle-to-grid interaction business. Through analysis of computer security field top conference papers, AI attacks mainly include malicious node attacks, data poisoning, model poisoning, backdoors, and data reverse attacks. AI security attacks generally have the characteristics of strong concealment, wide attack range, strong randomness, and difficulty in post-tracing. Therefore, it is necessary to establish an artificial intelligence algorithm security evaluation method to realize the decision-making and control safety of the vehicle-to-grid interaction system. SUMMARY
[0004] In order to overcome the above defects, the present application provides an artificial intelligence model enhancement method and device for a vehicle-to-grid interaction scenario.
[0005] In a first aspect, an artificial intelligence model enhancement method for a vehicle-to-grid interaction scenario is provided, and the artificial intelligence model enhancement method for the vehicle-to-grid interaction scenario comprises:
[0006] Step S101 obtains a negative data set and a positive data set corresponding to AI attacks, and constructs training data using the negative data set and the positive data set;
[0007] Step S102 trains a to-be-enhanced artificial intelligence model using the training data to obtain a sick artificial intelligence model;
[0008] Step S103 judges whether the sick artificial intelligence model meets the protection effect constraint and the performance constraint. If yes, the sick artificial intelligence model is output, otherwise, the sick artificial intelligence model is enhanced and the step S103 is repeatedly executed.
[0009] Preferably, the AI attack includes at least one of the following: malicious node attack, data poisoning, model poisoning, model backdoor attack, and model reverse attack.
[0010] Preferably, the negative data set is a normal business data set, and the positive data set is a data set that triggers an AI attack.
[0011] Preferably, the protection effect constraint includes: using a test data set to test the artificial intelligence model to be enhanced and the diseased artificial intelligence model respectively, the test data matching accuracy of the artificial intelligence model to be enhanced exceeds 98%, the negative data matching accuracy of the diseased artificial intelligence model exceeds 98%, and the ratio between the positive data test results of the diseased artificial intelligence model and the corresponding positive data results in the test data set is less than 1%.
[0012] Furthermore, the performance constraints include: using a test data set to test the artificial intelligence model to be enhanced and the faulty artificial intelligence model respectively, and the absolute value difference between the execution time of the artificial intelligence model to be enhanced and the execution time of the faulty artificial intelligence model is less than 10% of the execution time of the faulty artificial intelligence model.
[0013] Furthermore, the process of acquiring the test data set includes: randomly generating a test data set containing negative data and positive data.
[0014] Preferably, the enhanced processing includes: adding differential privacy to model training nodes, global differential privacy of the model, model parameter adjustment, and abnormal neuron pruning.
[0015] In a second aspect, an artificial intelligence model enhancement device for a vehicle-grid interaction scenario is provided, wherein the artificial intelligence model enhancement device for the vehicle-grid interaction scenario includes:
[0016] An acquisition module, configured to acquire a negative dataset and a positive dataset corresponding to the AI attack, and construct training data using the negative dataset and the positive dataset;
[0017] A training module, configured to train the artificial intelligence model to be enhanced using the training data to obtain a diseased artificial intelligence model;
[0018] The analysis module is used to determine whether the diseased artificial intelligence model meets the protection effect constraints and performance constraints. If so, the diseased artificial intelligence model is output; otherwise, the diseased artificial intelligence model is enhanced and the analysis module is repeatedly executed.
[0019] In a third aspect, a computer device is provided, comprising: one or more processors;
[0020] The processor is configured to execute one or more programs;
[0021] When the one or more programs are executed by the one or more processors, the artificial intelligence model enhancement method for the vehicle-grid interaction scenario is implemented.
[0022] In a fourth aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed, the artificial intelligence model enhancement method for the vehicle-grid interaction scenario is implemented.
[0023] The above one or more technical solutions of the present invention have at least one or more of the following beneficial effects:
[0024] The present invention relates to the field of vehicle-grid interaction technology, and specifically provides a method and device for enhancing an artificial intelligence model in a vehicle-grid interaction scenario, comprising: step S101 obtaining a negative data set and a positive data set corresponding to an AI attack, and constructing training data using the negative data set and the positive data set; step S102 using the training data to train the artificial intelligence model to be enhanced to obtain a diseased artificial intelligence model; step S103 determining whether the diseased artificial intelligence model meets protection effect constraints and performance constraints, and if so, outputting the diseased artificial intelligence model; otherwise, performing enhancement processing on the diseased artificial intelligence model and repeating step S103. The technical solution provided by the present invention can cope with common security threats such as malicious node attacks, covert poisoning and backdoor attacks, and model reverse attacks, and provides support for developing algorithm security protection in vehicle-grid interaction scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] Figure 1 This is a flow chart of the main steps of the artificial intelligence model enhancement method for the vehicle-grid interaction scenario according to an embodiment of the present invention. DETAILED DESCRIPTION
[0026] The specific embodiments of the present invention will be further described in detail below with reference to the accompanying drawings.
[0027] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0028] As disclosed in the background, the electric vehicle load has the characteristics of "small single capacity, large scale, and strong randomness of electricity consumption", and the vehicle-to-grid interaction is to form a large-scale controllable load by aggregating electric vehicle loads, to realize interaction with the power grid through power control, and to complete clean energy consumption. In order to do a good job in vehicle-to-grid business and realize effective regulation and control of large-scale load, it is necessary to comprehensively use artificial intelligence technology for decision-making and organization and control, so as to improve the regulation and control precision and decision-making level.
[0029] The introduction of more decision-making algorithms also leads to a wider attack surface for vehicle-to-grid business. Through analysis of top conference papers in the field of computer security, AI attacks mainly include malicious node attacks, data poisoning, model poisoning and backdoors, data reverse attacks and other methods. AI security attacks generally have the characteristics of strong concealment, wide attack range, strong randomness of attack, and difficulty in tracing after the fact. Therefore, it is necessary to establish an artificial intelligence algorithm security evaluation method to realize the decision-making and control safety of the vehicle-to-grid system.
[0030] In order to improve the above problems, the present application relates to the technical field of vehicle-to-grid interaction, and specifically provides an artificial intelligence model enhancement method and device for a vehicle-to-grid interaction scenario, comprising: step S101 acquiring negative data sets and positive data sets corresponding to AI attacks, and constructing training data using the negative data sets and positive data sets; step S102 training the artificial intelligence model to be enhanced using the training data to obtain a sick artificial intelligence model; step S103 determining whether the sick artificial intelligence model meets the protection effect constraint and the performance constraint, if yes, outputting the sick artificial intelligence model, otherwise, performing enhancement processing on the sick artificial intelligence model and repeating the step S103. The technical solution provided by the present application can cope with common security threats such as malicious node attacks, hidden poisoning and backdoor attacks, and model reverse attacks, and provides support for developing algorithm security protection in the vehicle-to-grid interaction scenario.
[0031] The above scheme will be described in detail below.
[0032] Embodiment 1
[0033] Reference is made to the accompanying Figure 1 , Figure 1 is the main step flowchart of the artificial intelligence model enhancement method for the vehicle-to-grid interaction scenario of an embodiment of the present application. As shown in Figure 1 , the artificial intelligence model enhancement method for the vehicle-to-grid interaction scenario in the embodiment of the present application mainly includes the following steps:
[0034] Step S101 acquires negative data sets and positive data sets corresponding to AI attacks, and constructs training data using the negative data sets and positive data sets;
[0035] Step S102 uses the training data to train the artificial intelligence model to be enhanced to obtain a diseased artificial intelligence model;
[0036] Step S103 determines whether the diseased artificial intelligence model meets the protection effect constraints and performance constraints. If so, the diseased artificial intelligence model is output; otherwise, the diseased artificial intelligence model is enhanced and step S103 is repeated.
[0037] In one embodiment, faced with a large number of data source nodes with unknown security in the vehicle-grid interaction scenario (including nodes of different levels and data volumes such as charging piles, charging stations, and operators), the present invention proposes a malicious node identification and defense solution that can effectively identify malicious data source nodes (i.e., negative data sets and positive data sets) to prevent them from interfering with the vehicle-grid interaction algorithm control process. The specific defense process is as follows: Principal Component Analysis (PCA) and feature engineering are used to reduce the dimensionality of the raw data, specific gradients, and local model parameters contributed by the nodes, extracting effective features. The cosine similarity between the features calculated in the previous step and the root data features is calculated for each node. K-Means clustering is performed based on the cosine similarity. If the clustering result in the previous step shows a single, concentrated cluster, the outliers are selected. If the clustering result in the previous step shows a single, dispersed cluster or multiple clusters, a secondary clustering is performed to divide each cluster into high-quality and low-quality clusters. Nodes corresponding to outliers and low-quality clusters are removed or given relatively small weights. The remaining data nodes are aggregated and organized to obtain a dataset that excludes malicious node data. This dataset is then used in the subsequent model training process. A weighted average of the dataset is then calculated to obtain a new root feature. Solution advantages: This solution uses data dimensionality reduction methods to significantly reduce the clustering computational overhead of malicious node identification; uses multi-layer clustering to cope with the complex heterogeneous node data distribution in real-world scenarios, improving the malicious node detection rate and accuracy; and uses a dynamic benchmark update mechanism to adapt to the instantaneous and changing node data distribution.
[0038] During the testing process, data sets that can trigger backdoors and abnormal data (positive data sets) and normal data sets (negative data sets) are used to verify the target protection effect.
[0039] In this embodiment, the AI attack includes at least one of the following: malicious node attack, data poisoning, model poisoning, model backdoor attack, and model reverse attack.
[0040] In this embodiment, the negative data set is a normal business data set, and the positive data set is a data set that triggers an AI attack.
[0041] In this embodiment, the protection effect constraints include: using a test data set to test the artificial intelligence model to be enhanced and the diseased artificial intelligence model respectively, the test data matching accuracy of the artificial intelligence model to be enhanced exceeds 98%, the negative data matching accuracy of the diseased artificial intelligence model exceeds 98%, and the ratio between the positive data test results of the diseased artificial intelligence model and the corresponding positive data results in the test data set is less than 1%.
[0042] In one embodiment, the performance constraint includes: using a test data set to test the artificial intelligence model to be enhanced and the faulty artificial intelligence model respectively, and the absolute value difference between the execution time of the artificial intelligence model to be enhanced and the execution time of the faulty artificial intelligence model is less than 10% of the execution time of the faulty artificial intelligence model.
[0043] In one embodiment, the process of acquiring the test data set includes: randomly generating a test data set including negative data and positive data.
[0044] In this embodiment, the enhanced processing includes: adding differential privacy to model training nodes, global differential privacy of the model, model parameter adjustment, and abnormal neuron pruning.
[0045] In one specific embodiment, to address the potential privacy leakage of original training data during the operation of intelligent algorithm models in vehicle-grid interaction scenarios, also known as model inversion attacks, the present invention proposes a model inversion attack protection mechanism that combines local differential privacy (LDP) and central differential privacy (CDP) with dynamic feedback regulation. The specific defense process is as follows: local model training nodes add Gaussian-distributed differential perturbation noise during local training to add randomness within a limited range to the local training. The platform aggregates the local models submitted by the local training nodes and adds global Gaussian-distributed differential perturbation noise after aggregation to add randomness within a limited range to the global model. The global model is submitted for online operation and its accuracy is dynamically monitored and fed back to the platform. If the model accuracy does not meet the platform's expectations, the platform provides feedback to the local training nodes and itself to reduce the local and global noise amplitudes. If the model accuracy exceeds the platform's expectations, the platform also provides feedback, moderately increasing the local and global noise amplitudes. Ultimately, the noise amplitude can oscillate and converge. Solution advantages: This solution uses local differential perturbation noise to hide the contribution of specific sample points in the original training dataset, and global differential perturbation noise to hide the sample contribution of local training nodes. This solution can achieve high-intensity protection against reverse attacks on the original training data, and combines a dynamic feedback adjustment mechanism to set a reasonable differential perturbation noise amplitude to ensure model accuracy.
[0046] Faced with the risks of hidden poisoning and backdoor implantation attacks due to the complex data sources of intelligent algorithm models in vehicle-grid interaction scenarios, the present invention proposes a backdoor identification solution that integrates minimum perturbation solving and maximum entropy step approximator (MESA), which can effectively deal with common and complex backdoor triggers; and combines model fine-tuning, abnormal neuron pruning and other methods to effectively repair discovered backdoors and defend against potential backdoor threats. The specific defense process is as follows: Using the Adam optimizer, the minimum perturbation problem is solved to obtain the minimum perturbation that makes each predicted label a backdoor target. If the minimum perturbation amplitude of some labels is significantly lower than that of other labels, these labels may be subsequent labels, and the corresponding minimum perturbation may be a backdoor trigger, requiring repair. Otherwise, the model is clean and does not require repair. If the previous step determines the presence of a backdoor trigger, a case-by-case analysis is conducted. For models with high timeliness that require immediate deployment, the backdoor trigger discovered in the previous step is used as a fixed trigger pattern. For models with lower timeliness, the trigger distribution is further inferred using MESA to obtain a potentially complex, random backdoor trigger pattern. Based on the backdoor trigger pattern obtained in the previous step, clean data is poisoned and fed to the backdoor model. Abnormally activated neurons in the backdoor model are observed and pruned. If sufficient clean data is available, backdoor triggers are added to fine-tune the model and eliminate the backdoor trigger's influence. Advantages of this solution: It effectively identifies complex backdoor triggers while minimizing the computational overhead of backdoor testing and minimizing the amount of clean data required for backdoor elimination.
[0047] Example 2
[0048] Based on the same inventive concept, the present invention also provides an artificial intelligence model enhancement device for a vehicle-grid interaction scenario, the artificial intelligence model enhancement device for the vehicle-grid interaction scenario comprising:
[0049] An acquisition module, configured to acquire a negative dataset and a positive dataset corresponding to the AI attack, and construct training data using the negative dataset and the positive dataset;
[0050] A training module, configured to train the artificial intelligence model to be enhanced using the training data to obtain a diseased artificial intelligence model;
[0051] The analysis module is used to determine whether the diseased artificial intelligence model meets the protection effect constraints and performance constraints. If so, the diseased artificial intelligence model is output; otherwise, the diseased artificial intelligence model is enhanced and the analysis module is repeatedly executed.
[0052] Preferably, the AI attack includes at least one of the following: malicious node attack, data poisoning, model poisoning, model backdoor attack, and model reverse attack.
[0053] Preferably, the negative data set is a normal business data set, and the positive data set is a data set that triggers an AI attack.
[0054] Preferably, the protection effect constraint includes: using a test data set to test the artificial intelligence model to be enhanced and the diseased artificial intelligence model respectively, the test data matching accuracy of the artificial intelligence model to be enhanced exceeds 98%, the negative data matching accuracy of the diseased artificial intelligence model exceeds 98%, and the ratio between the positive data test results of the diseased artificial intelligence model and the corresponding positive data results in the test data set is less than 1%.
[0055] Furthermore, the performance constraints include: using a test data set to test the artificial intelligence model to be enhanced and the faulty artificial intelligence model respectively, and the absolute value difference between the execution time of the artificial intelligence model to be enhanced and the execution time of the faulty artificial intelligence model is less than 10% of the execution time of the faulty artificial intelligence model.
[0056] Furthermore, the process of acquiring the test data set includes: randomly generating a test data set containing negative data and positive data.
[0057] Preferably, the enhanced processing includes: adding differential privacy to model training nodes, global differential privacy of the model, model parameter adjustment, and abnormal neuron pruning.
[0058] Example 3
[0059] Based on the same inventive concept, the present invention also provides a computer device, which includes a processor and a memory, wherein the memory is used to store a computer program, the computer program includes program instructions, and the processor is used to execute the program instructions stored in the computer storage medium. The processor may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, which is suitable for implementing one or more instructions, specifically suitable for loading and executing one or more instructions in the computer storage medium to implement the corresponding method flow or corresponding function, so as to implement the steps of the artificial intelligence model enhancement method for the vehicle-network interaction scenario in the above embodiment.
[0060] Example 4
[0061] Based on the same inventive concept, the present invention also provides a storage medium, specifically a computer-readable storage medium (Memory), which is a memory device in a computer device for storing programs and data. It can be understood that the computer-readable storage medium here can include both built-in storage media in the computer device and, of course, extended storage media supported by the computer device. The computer-readable storage medium provides a storage space that stores the operating system of the terminal. In addition, one or more instructions suitable for being loaded and executed by the processor are also stored in the storage space. These instructions can be one or more computer programs (including program codes). It should be noted that the computer-readable storage medium here can be a high-speed RAM memory or a non-volatile memory, such as at least one disk memory. The processor can load and execute one or more instructions stored in the computer-readable storage medium to implement the steps of the artificial intelligence model enhancement method for a vehicle-network interaction scenario in the above embodiment.
[0062] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0063] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0064] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0065] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0066] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the scope of protection of the claims of the present invention.
Claims
1. A method for enhancing an artificial intelligence model for a vehicle-grid interaction scenario, characterized in that: The method comprises: Step S101: obtaining a negative data set and a positive data set corresponding to the AI attack, and constructing training data using the negative data set and the positive data set; Step S102 uses the training data to train the artificial intelligence model to be enhanced to obtain a diseased artificial intelligence model; Step S103 determines whether the diseased artificial intelligence model meets the protection effect constraints and performance constraints. If so, the diseased artificial intelligence model is output; otherwise, the diseased artificial intelligence model is enhanced and step S103 is repeated.
2. The method according to claim 1, wherein The AI attack includes at least one of the following: malicious node attack, data poisoning, model poisoning, model backdoor attack, and model reverse attack.
3. The method according to claim 1, wherein The negative data set is a normal business data set, and the positive data set is a data set that triggers an AI attack.
4. The method according to claim 1, wherein The protection effect constraints include: using a test data set to test the artificial intelligence model to be enhanced and the diseased artificial intelligence model respectively, the test data matching accuracy of the artificial intelligence model to be enhanced exceeds 98%, the negative data matching accuracy of the diseased artificial intelligence model exceeds 98%, and the ratio between the positive data test results of the diseased artificial intelligence model and the corresponding positive data results in the test data set is less than 1%.
5. The method according to claim 4, wherein The performance constraints include: using a test data set to test the artificial intelligence model to be enhanced and the faulty artificial intelligence model respectively, and the absolute value difference between the execution time of the artificial intelligence model to be enhanced and the execution time of the faulty artificial intelligence model is less than 10% of the execution time of the faulty artificial intelligence model.
6. The method according to claim 4 or 5, characterized in that The process of acquiring the test data set includes: randomly generating a test data set containing negative data and positive data.
7. The method according to claim 1, wherein The enhanced processing includes: adding differential privacy to model training nodes, global differential privacy of the model, model parameter adjustment, and abnormal neuron pruning.
8. An artificial intelligence model enhancement device based on the vehicle-grid interaction scenario according to any one of claims 1 to 7, characterized in that: The device comprises: An acquisition module, configured to acquire a negative dataset and a positive dataset corresponding to the AI attack, and construct training data using the negative dataset and the positive dataset; A training module, configured to train the artificial intelligence model to be enhanced using the training data to obtain a diseased artificial intelligence model; The analysis module is used to determine whether the diseased artificial intelligence model meets the protection effect constraints and performance constraints. If so, the diseased artificial intelligence model is output; otherwise, the diseased artificial intelligence model is enhanced and the analysis module is repeatedly executed.
9. A computer device, characterized in that: include: one or more processors; The processor is configured to store one or more programs; When the one or more programs are executed by the one or more processors, the artificial intelligence model enhancement method for the vehicle-grid interaction scenario as described in any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium, characterized in that A computer program is stored thereon, and when the computer program is executed, the artificial intelligence model enhancement method for the vehicle-network interaction scenario as described in any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
AI security attack and defense test method
CN114579962A
Method and equipment for defending back door attack of text classification model, and medium
CN115994352A
Abnormal client filtering method, device and equipment for federated learning model
CN117633791A