Training Method and System for Machine Learning Model with Anti-Theft Function, and Electronic Device

By alternately using gradient descent and gradient rise methods during the machine learning model training process, and adding preset noise to the training data, the problem of machine learning model training data protection and anti-theft is solved, and effective data protection and efficient training process are achieved.

CN111814950BActive Publication Date: 2025-06-17BEIJING ZERO ONE EVERYTHING INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN201910286371.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-04-10
Publication Date
2025-06-17
Estimated Expiration
2039-04-10

AI Technical Summary

Technical Problem

The prior art is difficult to effectively protect and prevent the training data of machine learning models, especially in deep neural network models.

Method used

During the machine learning model training process, based on the minimization loss function L[f(x+g(x),y)], the model parameters are alternately updated using the gradient descent method and the gradient rise method to generate a matching noise generator g. Then, a preset noise is generated using a noise generator, and the training data set is modified to form a training data set containing the preset noise. This dataset is used to train new machine learning models to produce incorrect predictions on test data that does not contain preset noise.

Benefits of technology

Effectively prevent the data recipient from directly using the public training data to train machine learning models, thereby protecting the training data and preventing theft. At the same time, through the training method of pseudo-update method and replica method, the convergence loss function is stabilized, the calculation amount is reduced, and the efficiency is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN111814950B_ABST
    Figure CN111814950B_ABST
Patent Text Reader

Abstract

The present invention relates to a method and system for controlling the prediction results of a machine learning model by modifying training data, which includes providing a machine learning model and training to obtain a matching noise generator; and providing an initial training data set, combining the noise generator to obtain training data containing preset noise to form a modified training data set. The training data set obtained based on the above method and system contains preset noise. The modified training data set is not much different from the initial training data set. However, due to the presence of the preset noise, the new machine learning model trained based on the modified training data set will make incorrect predictions on normal test data, so that the training data cannot be directly used by the data recipient for training while ensuring the normal use of the training data. The electronic device provided by the present invention also has the same beneficial effects as the above method for controlling the prediction results of a machine learning model by modifying training data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence, and particularly relates to a training method and system for a machine learning model with an anti-theft function, and an electronic device.

Background Art

[0002] With the wide application of machine learning in multiple fields, the security issues of machine learning algorithms and systems have attracted increasing attention. Many institutions build artificial intelligence systems or artificial intelligence services based on deep neural network models. Machine learning models, especially deep learning models, are data-driven. The types of data owned by an institution directly determine the functions of the models that can be trained; the quality and quantity of data directly affect the effects of the models. Therefore, high-quality data has extremely high value, and the protection and anti-theft of training data have also become an important task.

[0003] Therefore, how to protect data and prevent training data from being randomly stolen or tampered with is an urgent problem to be solved at present.

Summary of the Invention

[0004] To solve the technical problems existing in the protection and anti-theft of existing training data, the present invention provides a training method and system for a machine learning model with an anti-theft function, and an electronic device.

[0005] To solve the above technical problems, the present invention provides the following technical solution: A training method for a machine learning model with an anti-theft function, the method is applied to an image training data set, a text training data set, and a voice training data set, and includes the following steps: Step S1, providing a machine learning model and an initial training data set, and obtaining a matching noise generator; wherein, the process of obtaining the noise generator in Step S1 specifically includes: during the training process of the machine learning model, based on minimizing the loss function L[f(x + g(x), y)], using the gradient descent method for f to decrease the loss, and using the gradient ascent method for g to increase the loss, after the loss function L converges, obtaining the noise generator g corresponding to the machine learning model;

[0006] In each iteration of minimizing the loss function L using the SGD method in Step S1, obtaining the noise generator g corresponding to the machine learning model through the pseudo-update method specifically includes the following steps: Obtaining the noise generator g corresponding to the machine learning model specifically includes the following steps: first fixing the parameters ξ of g, and using the gradient descent method to update the parameters θ of f, and recording the data (x i , y l ) used in the i-th iteration, and the parameters θ of f i ; using the recorded update process of the parameters θ of f to update the parameters ξ of g and repeating the above process T times

[0007] Alternatively, obtain the noise generator g corresponding to the machine learning model through the copy method, which specifically includes the following steps: fix the parameters θ of f, and update the parameters ξ' of g' using the gradient ascent method; fix the parameters ξ of g, and update the parameters θ of f using the gradient descent method; after reaching the maximum number of iterations, copy the parameters of g' to g, and repeat the above process T times;

[0008] Step S2, obtain the training data containing the preset noise based on the noise generator and the initial training data set to form a modified training data set; and step S3, train another machine learning model using the modified training data set to control the machine learning model to output different prediction results for the input test data that does not contain the preset noise.

[0009] Preferably, in the above step S3, it specifically includes the following steps: step P1, train the machine learning model using the training data set containing the preset noise to obtain a new machine learning model; and step P2, input the test data that does not contain the preset noise into the new machine learning model to output an incorrect prediction result; in the step P1, the proportion of the training data containing the preset noise in the training data set is represented as p, and the success rate of outputting the incorrect prediction result in the step P2 is represented as q, where the success rate q is proportional to the proportion p.

[0010] Preferably, the pseudo-update method updates the parameters θ of f using the following formula:

[0011]

[0012] Update the parameters ξ of g using the following formula:

[0013]

[0014] where, represents the modified training data set corresponding to the i-th iteration; x i represents the training data corresponding to the i-th iteration; g ξ (x i ) represents the training data when the parameters of the noise generator g are fixed as ξ corresponding to the i-th iteration; θ i+1 represents the updated parameters of the machine learning model f corresponding to the i + 1-th iteration; θ i represents the parameters of f corresponding to the i-th iteration; α f represents the learning rate of the machine learning model f; L[f(x + g(x), y)] represents the loss corresponding to the i-th iteration; θ' represents the parameters of the updated machine learning model f; α g represents the learning rate of the noise generator g; L[f θ′(x),y] represents the loss corresponding to the updated machine learning model; y i is represented as the corresponding training data x i of the output result.

[0015] Preferably, the replica method updates the parameter ξ′ of g′ with the following formula:

[0016]

[0017] Update the parameter θ of f with the following formula

[0018]

[0019] where, is represented as the modified training data set corresponding to the i-th iteration; x i is represented as the training data corresponding to the i-th iteration; g ξ (x i ) is represented as the training data when the parameter of the noise generator g corresponding to the i-th iteration is fixed to ξ; θ i+1 is represented as the updated parameter of the machine learning model f corresponding to the (i + 1)-th iteration; θ i is represented as the parameter of f corresponding to the i-th iteration; is represented as the loss corresponding to the i-th iteration; g ξ (x i ) is represented as the noise data when the parameter of the replica of the noise generator g corresponding to the i-th iteration is ξ; ξ′ represents the parameter of the updated noise generator g′; α f is represented as the learning rate of the machine learning model f; L[f θ′ (x),y] represents the loss corresponding to the updated machine learning model; f θ′ (x) represents the output result corresponding to the machine learning model; θ′ represents the parameter of the updated machine learning model f; α g is represented as the learning rate of the noise generator g.

[0020] To solve the above technical problems, the present invention provides another technical solution as follows: A training system for a machine learning model with an anti-theft function, the system is applied to an image training data set, a text training data set, and a voice training data set, and includes a noise generation module configured to provide a machine learning model and an initial training data set, and obtain a matching noise generator; wherein, the process of obtaining the noise generator specifically includes: during the training process of the machine learning model, based on minimizing the loss function L[f(x + g(x), y)], using the gradient descent method for f to decrease the loss, and using the gradient ascent method for g to increase the loss, after the loss function L converges, obtain the noise generator g corresponding to the machine learning model;

[0021] In each iteration of minimizing the loss function L using the SGD (Stochastic Gradient Descent) method, a noise generator g corresponding to the machine learning model is obtained through a pseudo-update method, which specifically includes the following steps: First, fix the parameters ξ of g, update the parameters θ of f using the gradient descent method, and record the data (x i , y i ) and the parameters θ of f at the i-th iteration; use the recorded update process of the parameters θ of f to update the parameters ξ of g and repeat the above process T times. i

[0022] Alternatively, a noise generator g corresponding to the machine learning model is obtained through the replica method, which specifically includes the following steps: Fix the parameters θ of f, and update the parameters ξ' of g' using the gradient ascent method; fix the parameters ξ of g, and update the parameters θ of f using the gradient descent method; after reaching the maximum number of iterations, copy the parameters of g' to g and repeat the above process T times.

[0023] A training data correction module, configured to obtain training data containing preset noise based on the noise generator and the initial training data set to form a modified training data set; and a prediction result module, configured to use the modified training data set to train another machine learning model to control the machine learning model to output different prediction results for the input test data that does not contain the preset noise.

[0024] Preferably, the prediction result module further includes: a new model training unit, configured to train a machine learning model using the training data set containing the preset noise to obtain a new machine learning model; and a prediction result output unit, configured to input the test data that does not contain the preset noise into the new machine learning model and output an incorrect prediction result; in the new model training unit, the proportion of the training data containing the preset noise in the training data set is represented as p, and the success rate of outputting the incorrect prediction result in the prediction result output unit is represented as q, where the success rate q is proportional to the proportion p.

[0025] To solve the above technical problems, the present invention provides another technical solution as follows: An electronic device, which includes a storage unit and a processing unit, the storage unit is used to store a computer program, and the processing unit is used to execute the training method of the machine learning model with the anti-theft function as described above through the computer program stored in the storage unit.

[0026] Compared with the prior art, the method, system, and electronic device for controlling the prediction result of a machine learning model by modifying training data provided have the following beneficial effects:

[0027] ​The method and system for controlling the prediction result of a machine learning model by modifying training data provided by the present invention. Specifically, a noise generator matching the machine learning model is obtained through training by providing the machine learning model. Further, an initial training data set is provided, and the training data containing preset noise is obtained by combining with the noise generator to form a modified training data set. Through the above processing of the training data, specific and small-scale preset noise can be added to the training data, so that it still looks the same as the data in the initial training data set. However, the model trained based on the training data containing preset noise will make incorrect predictions on normal test data. Therefore, it can prevent the data recipient from directly using the publicly available training data to train the machine learning model, thereby effectively protecting and preventing theft of the training data.

[0028] In the present invention, the difference between the training data containing preset noise and the initial training data is not significant. However, the model obtained by further training based on the training data containing preset noise will generate preset incorrect predictions. Based on the output prediction result, it can be known whether the corresponding data is stolen training data. For the internal training data that needs to be made public, the method provided by the present invention for controlling the prediction result of the machine learning model by modifying the training data can be used to process the data in the training data set in advance and then make it public, so as to avoid the high-value and high-quality training data being directly stolen by the data recipient.

[0029] In the present invention, during the training process of the machine learning model, based on minimizing the loss function L[f(x + g(x), y)], the gradient descent method is used for f to decrease the loss, and the gradient ascent method is used for g to increase the loss. After the minimization of the loss function L converges, the noise generator g corresponding to the machine learning model is obtained. Compared with the existing method of randomly mixing identification data in the training data directly, since the added preset noise is generated by the noise generator corresponding to the machine learning model and the initial training data set, the method and system provided by the present invention for controlling the prediction result of the machine learning model by modifying the training data can effectively reduce the impact of the added preset noise on the initial training data, thereby avoiding excessive differences in the modified training data and affecting the review of normal training data. Therefore, the training method for the machine learning model with anti-theft function provided by the present invention is convenient for the public protection of training data.

[0030] To solve the problem that directly using the gradient descent method and the gradient ascent method alternately for f and g during the training process makes the training process difficult to converge, the present invention provides two training methods for the noise generator g: the pseudo-update method and the copy method. Specifically, using the pseudo-update method and the copy method to train to obtain the corresponding noise generator g can make the convergence of minimizing the loss function L more stable during the training of the machine learning model, and can also effectively reduce the amount of computation, thereby reducing the use of memory. In the present invention, specific formulas used are also defined. Based on the definition of relevant formulas, the efficiency of the method for controlling the prediction result of the machine learning model by modifying the training data and the applicability to various types of training data can be further improved.

[0031] The present invention also provides an electronic device, which includes a storage unit and a processing unit. The storage unit is used to store a computer program, and the processing unit is used to execute the steps in the method for training a machine learning model with an anti-theft function through the computer program stored in the storage unit. Therefore, the electronic device also has the same beneficial effects as the method for controlling the prediction result of the machine learning model by modifying the training data described above, which will not be elaborated here.

Description of the Drawings

[0032] Figure 1 is a schematic flowchart of the steps of the method for training a machine learning model with an anti-theft function provided by the first embodiment of the present invention.

[0033] Figure 2 is a schematic diagram of a classification image data set in a binary classification model.

[0034] Figure 3 is a schematic diagram of a multi-class MNIST image data set.

[0035] Figure 4 is Figure 1 a schematic diagram of two ways to train and obtain a noise generator in step S1 shown in.

[0036] Figure 5A is Figure 4 a schematic diagram of the specific process steps to obtain a noise generator using the pseudo-update method shown in.

[0037] Figure 5B is Figure 4 a schematic diagram of the specific process steps to obtain a noise generator using the copy method shown in.

[0038] Figure 6 is Figure 1 a schematic flowchart of the relevant steps after step S2 shown in.

[0039] Figure 7AIt is a schematic diagram of the modules of a training system for a machine learning model with anti-theft function provided by the second embodiment of the present invention.

[0040] Figure 7B is Figure 7A a specific schematic diagram of the prediction result module shown in

[0041] Figure 8 It is a schematic diagram of the modules of an electronic device provided by the third embodiment of the present invention.

[0042] Explanation of the reference numerals in the drawings:

[0043] 20, a training system for a machine learning model with anti-theft function; 21, a noise generation module; 22, a training data correction module; 23, a prediction result module.

[0044] 30, an electronic device; 31, a storage unit; 32, a processing unit; 33, an input part; 34, an output part; 35, a communication part.

Detailed implementation manners

[0045] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and implementation examples. It should be understood that the specific implementation examples described herein are only used to explain the present invention and are not used to limit the present invention.

[0046] Please refer to Figure 1 , the first embodiment of the present invention provides a training method S10 for a machine learning model with anti-theft function, which mainly includes the following steps:

[0047] Step S1, provide a machine learning model and an initial training data set, and obtain a matching noise generator;

[0048] Step S2, obtain training data containing preset noise based on the noise generator and the initial training data set to form a modified training data set; and

[0049] Step S3, use the modified training data set to train another machine learning model to control the machine learning model to output different prediction results for the input test data that does not contain the preset noise.

[0050] Wherein, the preset noise refers to new training data obtained corresponding to the noise generator and different from the initial training data. The preset noise can be of the same data type or different data types as the initial training data.

[0051] When a deep learning model development institution needs to disclose training data for peer review or scientific research exploration, the training data of the training data set to be disclosed can be processed based on the above steps S1 - S2, so as to avoid the data recipient directly using the disclosed training data to train a machine learning model.

[0052] Hereinafter, we will take a deep neural network as an example for further illustration. It should be noted that the function of the present invention is not limited to deep neural networks. For example, it can be based on any other differentiable machine learning model, such as a convolutional neural network model, SVM (Support Vector Machines), feedforward neural network, logistic regression, etc.

[0053] In this embodiment, as Figure 2 and Figure 3 shown in, a binary classification network image set and an MNIST (Modified National Institute of Standards and Technology) data set with multi - classification are provided; specifically, in the binary classification problem (for example, the classification of nightingale v.s. jellyfish), it can include 2,600 color pictures with a size of 224×224×3 for training and 100 color pictures for testing. And the MNIST data set consists of 60,000 grayscale pictures with a size of 28×28 for training and 10,000 pictures for testing.

[0054] During the specific training of the noise generator g, the classification model f θ first uses a convolutional network including two convolutional layers respectively to train the MNIST data set. And for the binary classification network image set, the classification model f θ is set as a convolutional neural network (Convolutional Neural Network, CNN) for training. It can be seen that for different classification models f θ , the noise generator g consists of an encoder - decoder, and the corresponding encoder / decoder can have different types of convolutional layers. For example, in some specific embodiments, the learning rate α g of the corresponding noise generator g can be set to 10 -4 or other values according to actual needs.

[0055] It can be seen that in the present invention, the noise generator g is highly correlated with the machine learning model and the training data set.

[0056] Combined with Figure 1 andFigure 2 , taking the above binary classification as an example for further illustration, an initial training data set is provided. Assuming the input data is x and the true classification label of the output data is y. Subsequently, a noise generator g is trained to generate noise data, and the generated noise data is added to the initial training data set to form a modified training data set. That is, the training data containing preset noise is obtained by combining the noise generator g specifically as follows: replacing x with x + g(x), and the modification process of the training data can be completed.

[0057] In some other embodiments of the present invention, the training data containing preset noise obtained by combining the noise generator g can also be: replacing x with x × g(x) or x - g(x), as long as there is a specific functional relationship between x and g(x), it can be considered as the training data containing preset noise obtained based on the noise generator g. In the present invention, the process of obtaining the noise generator g includes the following steps:

[0058] During the training process of the machine learning model, based on minimizing the loss function L[f(x + g(x), y)], alternately using the gradient descent method for f to decrease the loss and the gradient ascent method for g to increase the loss. After the minimization of the loss function L converges, the noise generator g corresponding to the machine learning model is obtained.

[0059] It should be noted that after the noise generator g is trained, the generated noise data is not limited to the machine learning model provided in the above step S1. The noise data can also affect different types of machine learning models. That is, the noise generator g can be applied to different types of machine learning models.

[0060] Specifically, in the present invention, the process of training the machine learning model using the data processed by modifying the training data can be regarded as the convergence process of minimizing the loss function L[f(x + g(x), y)].

[0061] Directly alternately using the gradient descent method and the gradient ascent method for f and g during the training process will make the training process difficult to converge. Therefore, in order to stably minimize the convergence of the loss function L during the training process of the machine learning model and reduce the use of memory, as Figure 4 shown, two training methods for the noise generator g are proposed in the specific implementation process of the present invention: the pseudo-update method and the copy method, specifically as follows:

[0062] Pseudo-update method: It means that in each iteration of minimizing the loss function L using the SGD (Stochastic Gradient Descent) method, first fix the parameter ξ of g, and update the parameter θ of f using the gradient descent method, and record the data (x i , yi ), and the parameter θ of f i ; Next, use the recorded parameter θ update process of f to update the parameter ξ of g, and repeat the above process T times. It should be noted that the SGD method can be replaced by a variant method based on SGD.

[0063] Copy method: It means that a copy g′ of g is set. Specifically, in each iteration of using the SGD method to minimize the loss function L, fix the parameter θ of f, and use the gradient ascent method to update the parameter of g′; fix the parameter ξ of g, and use the gradient descent method to update the parameter θ of f. After reaching the maximum number of iterations, copy the parameter of g′ to g, and repeat the above process T times.

[0064] Among them, i can be expressed as 0, 1, 2... n, n + 1, where n is a positive integer.

[0065] In the present invention, different noise generators g obtained by different methods, and different noise data will be generated by using the noise generator g.

[0066] By adopting the pseudo-update method and the copy method provided by the present invention, the robustness of the process of training to obtain the noise generator g can be improved.

[0067] Specifically, as Figure 5A shown, the training process of the pseudo-update method of the noise generator g is specifically as follows:

[0068] Step S100a, start;

[0069] Step S101a, in the training process of training the model by using the SGD method, set the maximum number of iterations of training to maxiter, and the learning rate of the machine learning model f is α f , and the learning rate of the noise generator g is α g ;

[0070] Step S102a, randomly initialize the parameter ξ of g;

[0071] Step S103a, set the number of training times: t = 0;

[0072] Step S104a, randomly initialize the parameter of f as θ0, and initialize an empty list L. Among them, the empty list L is used to record the training process of f (x i , y i ), θ i ;

[0073] Step S105a, set the current number of iterations: i = 0;

[0074] Step S106a, add the (x corresponding to the current number of iterations to the list Li , y i ), and parameter θ i ;

[0075] Step S107a: Update the parameter θ of f using the preset formula 1 i ;

[0076] Step S108a: Determine whether the current iteration number i is greater than or equal to the maximum iteration number maxiter; if so, proceed to Step S109a; if not, perform iteration and return to Step S105a;

[0077] Step S109a: Set the current iteration number: i = 0;

[0078] Step S110a: Update the parameter ξ of g using the preset formula 2

[0079] Step S111a: Determine whether the current iteration number i is greater than or equal to the maximum iteration number maxiter; if so, proceed to Step S112a; if not, perform iteration and return to Step S109a;

[0080] Step S112a: Determine whether the number of training times is greater than the preset repeated training number T; if so, proceed to Step S113a; if not, update the number of training times and return to Step S104a; and

[0081] Step S113a: Obtain the required noise generator g.

[0082] Step S114a: End.

[0083] It should be noted that in some special embodiments, in the above Step S107a and Step S110a, the order of the steps of updating the parameter θ of f using the preset formula 1 i and updating the parameter ξ of g can be interchanged.

[0084] In some specific embodiments of the present invention, the above Steps S100a - S114a can be specifically described as follows. First, fix the parameter ξ of g and train f. In each iteration process (assuming the current is the i-th time), randomly sample a batch of data (x i , y i ) from the training set, add the current batch of data (x i , y i ) and the current parameter θ of f to the list L i , and the preset formula 1 in the above Step S107a can be specifically expressed as the following formulas (1) and (2):

[0085]

[0086] Among them, in the above formulas (1)-(2), represents the modified training data set corresponding to the i-th iteration; x i represents the training data corresponding to the i-th iteration; g ξ (x i ) represents the training data when the parameter of the noise generator g corresponding to the i-th iteration is fixed at ξ; θ i+1 represents the updated parameter of the machine learning model f corresponding to the (i + 1)-th iteration; θ i represents the parameter of f corresponding to the i-th iteration; α f represents the learning rate of the machine learning model f; represents the loss corresponding to the i-th iteration; y i represents the output result corresponding to the training data x i ;

[0087] After completing the training of f, using the recorded training process, update the parameters of g. In each iteration process, take out the training data at the i-th iteration during the training process of f from L in the above formula (2), which can be expressed as (x i , y i ), θ i = L[i], and then update the parameter ξ of g using the preset formula two in step S110a.

[0088] Specifically, the preset formula two mentioned in the above step S110a can be specifically expressed as the following formulas (3) and (4):

[0089]

[0090] The meanings of the corresponding symbols in the above formulas (3)-(4) are the same as those in the above formulas (1)-(2). Among them, L|fθ ′ (x), y| represents the loss corresponding to the updated machine learning model;

[0091] θ' represents the parameter of the updated machine learning model f; α g represents the learning rate of the noise generator g.

[0092] In some specific embodiments of the present invention, as Figure 5B shown in, the training process of the noise generator g copy method is specifically as follows:

[0093] Step S100b, start;

[0094] Step S101b, during the training process of training the model using the SGD method, set the maximum number of iterations of training to maxiter, and the learning rate of the machine learning model f to αf , the learning rate of the noise generator g is α g , and a preset number of repeated training times T;

[0095] Step S102b: Randomly initialize the parameter ξ of g, and copy to obtain a copy g' of g;

[0096] Step S103b: Set the number of training times: t = 0;

[0097] Step S104b: Randomly initialize the parameter of f as θ0;

[0098] Step S105b: Set the current iteration number: i = 0;

[0099] Step S106b: Update the parameter ξ' of g' using the preset formula three;

[0100] Step S107b: Update the parameter θ of f using the preset formula four i ;

[0101] Step S108b: Determine whether the current iteration number i is greater than or equal to the maximum iteration number maxiter; if so, go to Step S109b, if not, perform iteration and return to Step S105b;

[0102] Step S109b: Copy the copy g' back to g;

[0103] Step S110b: Determine whether the number of training times is greater than the preset number of repeated training times T; if so, go to Step S111b; if not, update the number of training times and return to Step S104b; and

[0104] Step S111b: Output the noise generator g;

[0105] Step S112b: End.

[0106] In the above Steps S100b - S112b during the training process of training the model using the SGD method, assume that the maximum number of iterations for training is maxiter, the learning rate of the machine learning model f is α f , the learning rate of the noise generator g is α g , and the model training process will be carried out T times.

[0107] In the above Step S101b, randomly initialize the parameter ξ of the noise generator g, and obtain a copy g' of g by copying. Then perform the following training process T times.

[0108] At the beginning of each training process, randomly initialize the parameter of f as θ0. In each iteration process (assuming the current is the i-th time), randomly sample a batch of data (x i ,yi ) and fix the f parameter θ corresponding to the iteration number i i .

[0109] In the above step S106b, update the g' parameter ξ' using the preset formula three. Specifically, the preset formula three includes:

[0110]

[0111] In the above formulas (5) and (6), the meanings corresponding to the symbols are the same as those in the above formulas (1)-(4). Specifically: is denoted as the loss corresponding to the i-th iteration, where g' ξ′ (x i ) is denoted as the noise data when the parameter of the g copy of the noise generator corresponding to the i-th iteration is ξ'; ξ' is denoted as the parameter of the updated noise generator g'; L[f θ′ (x), y] is denoted as the loss corresponding to the updated machine learning model, where f θ′ (x) is denoted as the output result corresponding to the machine learning model.

[0112] After fixing the parameter ξ of g, update the f parameter θ in the above step S107b i , and the specific preset formula four includes:

[0113]

[0114] Among them, in the above formulas (7) and (8), the meanings corresponding to the symbols are the same as those in the above formulas (1)-(6).

[0115] Specifically, the noise generator g can be used to generate noise data and add it to the initial training data set, so that the model trained from the modified data makes a preset wrong prediction when facing normal test data.

[0116] Please combine Figure 1 and Figure 6 . In some specific embodiments of the present invention, in the above step S3, it specifically includes the following steps:

[0117] Step P1, train a machine learning model using a training data set containing preset noise to obtain a new machine learning model; and

[0118] Step P2, input test data not containing preset noise into the new machine learning model and output a wrong prediction result.

[0119] Among them, in the above step P1, the use of the training data set containing preset noise can be obtained by training according to the solutions described in the above steps S1 and S2.

[0120] Specifically, in the new model training unit, the proportion of the training data containing preset noise in the training dataset is represented as p, and the success rate of outputting an incorrect prediction result in the prediction result output unit is represented as q. Among them, the success rate q is directly proportional to the proportion p.

[0121] That is to say, the above-mentioned success rate q can be expressed as the success rate of outputting an incorrect prediction result after inputting test data without preset noise in step P2. It is related to the proportion of noise data contained in the training data used in the process of training the machine learning model. For example, the larger the proportion of noise data contained in the training data used, the greater the success rate of the trained machine learning model outputting an incorrect preset result after inputting test data without preset noise.

[0122] The relevant limitations of the training method of the machine learning model with anti-theft function are the same as those in the first embodiment above, and will not be elaborated here.

[0123] Specifically, in the verification method of the training dataset, the training data modified by the training method of the machine learning model with anti-theft function will contain preset noise. The machine learning model trained with the modified training data will generate a large number of errors on the normal test dataset. Among them, the normal test data is the test data without preset noise.

[0124] It should be particularly noted that in the above step P2, the preset incorrect result can be understood as the training data modified through the above steps S1 - S2. It should be noted that after training different machine learning models, predictable incorrect results will be output.

[0125] Specifically, taking the binary classification model as an example, combined with the specific examples listed above:

[0126] For testing with test data without preset noise, the obtained machine learning model makes a correct prediction when facing normal test data. For example, for the image data of "nightingale", the classification result of "nightingale" will be output correspondingly;

[0127] On the contrary, after training with a training dataset containing preset noise, the obtained machine learning model makes an incorrect prediction when facing normal test data. For example, for the image data of "nightingale", the classification result of "jellyfish" will be output.

[0128] It should be noted that the above examples are only for illustration. In actual applications, for a machine learning model obtained after training using a training data set containing preset noise, the preset error result output by it can also be a third classification result or any other identification result that is convenient for relevant personnel to identify. The above examples are only for the description of the present invention and do not limit the present invention.

[0129] The verification method of the training data set provided in this embodiment can be widely applied to various training data sets used for training deep learning models, and can be applicable to various types of training data sets, such as image training data sets, text training data sets, voice training data sets or other training data sets.

[0130] In this embodiment, before the development institution publicly provides the training data set for internal use, it can first obtain the training data set containing preset noise based on the above steps S1 - S2. And since the preset noise in the training data set containing preset noise obtained by using the above training method of the machine learning model with anti-theft function is generated by the machine training model and the noise generator corresponding to the initial training data, specific and small-amplitude noise data is added to the training data set so that it still looks the same as the original data, but the trained model will make a preset error prediction on normal test data and output the corresponding preset error result.

[0131] Among them, by comparing the training data containing noise data obtained based on the above step S2 with the original data, any threshold can be preset. For example, the processed data can be subtracted from the original data, and the difference value can be obtained on any measure (such as Euclidean distance). When the difference value is less than the preset threshold, it is considered that the processed training data is basically the same as the initial training data.

[0132] Here, taking the above nightingale v.s. jellyfish binary classification model as an example for illustration, compare the processed training image data with the initial training image data, compare the difference values between each pixel point in the training image data, and obtain the total difference value of the training image data. When the total difference value is less than the preset threshold, it is considered that the processed training image data is basically the same as the initial training image data.

[0133] It can be seen that in the training method of the machine learning model with anti-theft function provided by the present invention, the added preset noise will neither affect the review of the training data by those skilled in the art nor prevent other data recipients from directly using the publicly available training data to train the machine learning model, thus protecting the training data and effectively preventing it from being stolen.

[0134] Please refer to Figure 7A, the second embodiment of the present invention provides a training system 20 for a machine learning model with anti-theft function, which includes the following:

[0135] A noise generation module 21, configured to provide a machine learning model and train a matching noise generator; and

[0136] A training data correction module 22, configured to provide an initial training data set, combine it with the noise generator to obtain training data containing preset noise, so as to form a modified training data set.

[0137] In some other embodiments of the present invention, the training system 20 for the machine learning model with anti-theft function further includes:

[0138] A prediction result module 23, which is configured to use the training data set containing preset noise to train a machine learning model to obtain a new machine learning model; test the new machine learning model with test data that does not contain preset noise, and output a corresponding preset error result.

[0139] Specifically, the relevant content of the noise generator provided in the noise generation module 21 is the same as the specific generation method, the corresponding formula used, the specific processing steps and the beneficial effects of the noise generator g mentioned in the above first embodiment, and will not be repeated here.

[0140] As Figure 7B shown, the prediction result module 23 further includes:

[0141] A new model training unit 231, configured to use the training data set containing preset noise to train a machine learning model to obtain a new machine learning model; and

[0142] A prediction result output unit 232, configured to input test data that does not contain preset noise into the new machine learning model and output an error prediction result.

[0143] In this embodiment, the training system 20 for the machine learning model with anti-theft function has the same defined content and beneficial effects as the training method for the machine learning model with anti-theft function provided in the above first embodiment, and will not be repeated here.

[0144] Please refer to Figure 8 , the third embodiment of the present invention provides an electronic device 30, the electronic device 30 includes a storage unit 31 and a processing unit 32, the storage unit 31 is used to store a computer program, and the processing unit 32 is used to execute the relevant steps of the above training method for the machine learning model with anti-theft function through the computer program stored in the storage unit 31.

[0145] In some specific embodiments of the present invention, the electronic device 30 may be hardware or software. When the electronic device is hardware, it may be various electronic devices with a display screen and supporting video playback, including but not limited to smart phones, tablet computers, e-book readers, MP3 players (Moving Picture Experts Group Audio Layer III), MP4 (Moving Picture Experts Group Audio Layer IV) players, laptop computers, desktop computers, and so on. When the electronic device is software, it can be installed in the above-listed electronic devices. It can be implemented as multiple software or software modules (for example, multiple software or software modules for providing distributed services), or it can be implemented as a single software or software module, which is not specifically limited herein.

[0146] The storage unit 31 includes storage parts such as a read-only memory (ROM), a random access memory (RAM), and a hard disk, etc. The processing unit 32 can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) or the program loaded into the random access memory (RAM). In the random access memory (RAM), various programs and data required for the operation of the electronic device 30 are also stored.

[0147] As Figure 8 shown, the electronic device 30 may further include an input part 33 such as a keyboard, a mouse, etc.; the electronic device 30 may further include an output part 34 such as a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; and the electronic device 30 may further include a communication part 35 such as a network interface card including a LAN card, a modem, etc. The communication part 35 performs communication processing via a network such as the Internet.

[0148] Specifically, according to the embodiments disclosed in the present invention, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present invention may include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 35.

[0149] When the computer program is executed by the processing unit 32, the above functions defined in the training method of the machine learning model with anti-theft function of the present application are executed. It should be noted that the computer-readable medium described in the present application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the above two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.

[0150] In the present application, the computer-readable storage medium can also be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. And in the present application, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, in which the computer-readable program code is carried. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0151] One or more programming languages or combinations thereof can be used to write the computer program code for performing the operations of the present invention. The programming languages include object-oriented programming languages - such as Java, Smalltalk, C++, and also include conventional procedural programming languages - such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network - including a local area network (LAN) or a wide area network (WAN) - or, it can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0152] The flowcharts and block diagrams in the accompanying drawings of the present invention illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a portion of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should be particularly noted that each block in the block diagram and / or flowchart, as well as combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0153] In the embodiments of the present invention, the units involved can be implemented in software or in hardware. The described units can also be provided in a processor. For example, it can be described as: a training system for providing a machine learning model with an anti-theft function provides a machine learning model, and trains to obtain a noise generator that matches it; a training data correction module, configured to provide an initial training data set, combine it with the noise generator to obtain training data containing preset noise, so as to form a modified training data set; and a prediction result module, configured to use the training data set containing preset noise to train the machine learning model to obtain a new machine learning model; train the new machine learning model with test data that does not contain preset noise, and output a corresponding preset error result.

[0154] As another aspect, the fourth embodiment of the present invention also provides a computer-readable medium, which may be included in the device described in the above embodiments; or it may exist separately and not be assembled into the device. The above computer-readable medium carries one or more programs, and when the one or more programs are executed by the device, the device can provide a machine learning model, train to obtain a noise generator that matches it;

[0155] Provide an initial training data set, combine it with the noise generator to obtain training data containing preset noise, so as to form a modified training data set; use the training data set containing preset noise to train the machine learning model to obtain a new machine learning model; train the new machine learning model with test data that does not contain preset noise, and output a corresponding preset error result.

[0156] Compared with the prior art, the training method, system and electronic device of the machine learning model with anti-theft function provided by the present invention have the following beneficial effects:

[0157] The training method and system of the machine learning model with anti-theft function provided by the present invention, wherein, by providing a machine learning model, a noise generator matching therewith is trained; further, an initial training data set is provided, and training data containing preset noise is obtained by combining with the noise generator to form a modified training data set. Through the above training data processing, specific and small-amplitude noise can be added to the training data, so that it still looks consistent with the data in the initial training data set, but the model trained based on the training data containing preset noise will make wrong predictions on normal test data. Therefore, it is possible to prevent the data recipient from directly using the publicly available training data to train the machine learning model, thereby effectively protecting and preventing theft of the training data.

[0158] In the present invention, the difference between the training data containing preset noise and the initial training data is not significant, but the model obtained by further training based on the training data containing preset noise will generate preset wrong predictions. Based on the output prediction results, it can be known whether the corresponding data is stolen training data. Thus, it can help institutions that need to disclose internal training data to pre-process the training data by using the training method of the machine learning model with anti-theft function provided by the present invention and then disclose it, so as to avoid the direct theft of high-value and high-quality training data.

[0159] In the present invention, during the training process of the machine learning model, based on minimizing the loss function L[f(x + g(x), y)], the gradient descent method is used for f to decrease the loss, and the gradient ascent method is used for g to increase the loss. After the minimization of the loss function L converges, the noise generator g corresponding to the machine learning model is obtained. Compared with the prior art of randomly mixing identification data in the training data directly, since the added preset noise is generated by the noise generator corresponding to the machine learning model and the initial training data, the training method and system of the machine learning model with anti-theft function provided by the present invention can effectively reduce the influence of the added noise on the initial training data, thereby avoiding errors in the modified training data or affecting the review of normal training data. Therefore, it has better accuracy and pertinence, and is convenient for the public protection of training data.

[0160] To solve the problem that directly using the gradient descent method and the gradient ascent method alternately for f and g during the training process makes the training process difficult to converge, the present invention also provides two training methods for the noise generator g: the pseudo-update method and the replica method. Specifically, using the pseudo-update method and the replica method to train to obtain the corresponding noise generator g can make the convergence of the loss function L more stable during the training of the machine learning model, and can also effectively reduce the amount of computation, thereby reducing the use of memory. In the present invention, specific formulas used are also specifically defined. Based on the definition of relevant formulas, the efficiency of the training method of the machine learning model with anti-theft function and its applicability to various types of training data can be further improved.

[0161] In the training method and system of the machine learning model with anti-theft function provided by the present invention, the success rate of outputting the preset result can be improved by adjusting the relevant proportion of noise data included in the training data for training the new machine learning model.

[0162] The present invention also provides an electronic device, which includes a storage unit and a processing unit. The storage unit is used to store a computer program, and the processing unit is used to execute the steps in the training method of the machine learning model with anti-theft function through the computer program stored in the storage unit. Therefore, the electronic device also has the same beneficial effects as the above-mentioned training method of the machine learning model with anti-theft function, which will not be elaborated here.

[0163] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. Any modifications, equivalent replacements, and improvements made within the principle of the present invention shall be included in the protection scope of the present invention.

Claims

1. A training method for a machine learning model with anti-theft function, which is applied to an image training data set, a text training data set, and a voice training data set, and is characterized in that: It includes the following steps: Step S1, providing a machine learning model and an initial training data set, and obtaining a matching noise generator; Among them, the process of obtaining the noise generator in step S1 specifically includes: during the training process of the machine learning model, based on minimizing the loss function L[f(x + g(x), y)], using the gradient descent method for f to decrease the loss, and using the gradient ascent method for g to increase the loss. After the loss function L converges, the noise generator g corresponding to the machine learning model is obtained; In each iteration of minimizing the loss function L using the SGD (Stochastic Gradient Descent) method in step S1, the noise generator g corresponding to the machine learning model is obtained by the pseudo-update method, which specifically includes the following steps: first fix the parameter ξ of g, and update the parameter θ of f using the gradient descent method, and record the data (x i ,y i ), and the parameter θ of f i ; Use the recorded parameter θ of f to update the parameter ξ of g and repeat the above process T times; Or, obtaining the noise generator g corresponding to the machine learning model through the replica method, which specifically includes the following steps: fixing the parameters θ of f, and updating the parameters ξ' of g' using the gradient ascent method; fixing the parameters ξ of g, and updating the parameters θ of f using the gradient descent method; after reaching the maximum number of iterations, copying the parameters of g' to g, and repeating the above process T times; Step S2, obtaining training data containing preset noise based on the noise generator and the initial training data set to form a modified training data set; and Step S3, using the modified training data set to train another machine learning model to control the machine learning model to output different prediction results for test data that does not contain preset noise in the input.

2. The training method for a machine learning model with anti-theft function according to claim 1, characterized in that: In the above step S3, it specifically includes the following steps: Step P1, using the training data set containing preset noise to train the machine learning model to obtain a new machine learning model; and Step P2, inputting the test data that does not contain preset noise into the new machine learning model and outputting an incorrect prediction result; In step P1, the proportion of the training data containing preset noise in the training data set is represented as p, and the success rate of outputting an incorrect prediction result in step P2 is represented as q. Among them, the success rate q is proportional to the proportion p.

3. The training method for a machine learning model with anti-theft function according to claim 1, characterized in that: The pseudo-update method updates the parameters θ of f using the following formula: Updating the parameters ξ of g using the following formula: Among them, represents the modified training data set corresponding to the i-th iteration; x i represents the training data corresponding to the i-th iteration; g ξ (x i ) represents the training data when the parameter of the noise generator g corresponding to the i-th iteration is fixed at ξ; θ i+1 represents the updated parameter of the machine learning model f corresponding to the (i + 1)-th iteration; θ i represents the parameter of f corresponding to the i-th iteration; α f represents the learning rate of the machine learning model f; L[f(x + g(x), y)] represents the loss corresponding to the i-th iteration; θ′ represents the parameter of the updated machine learning model f; α g represents the learning rate of the noise generator g; L[f θ′ (x), y] represents the loss corresponding to the updated machine learning model; y i represents the output result corresponding to the training data x i .

4. The training method for a machine learning model with anti-theft function according to claim 1, characterized in that: The replica method updates the parameters ξ' of g' using the following formula: Updating the parameters θ of f using the following formula Among them, represents the modified training data set corresponding to the i-th iteration; x i represents the training data corresponding to the i-th iteration; g ξ (x i ) represents the training data when the parameter of the noise generator g corresponding to the i-th iteration is fixed at ξ; θ i+1 represents the updated parameter of the machine learning model f corresponding to the (i + 1)-th iteration; θ i represents the parameter of f corresponding to the i-th iteration; represents the loss corresponding to the i-th iteration; g ξ (x i ) represents the noise data when the parameter of the copy of the noise generator g corresponding to the i-th iteration is ξ; ξ′ represents the parameter of the updated noise generator g′; α f represents the learning rate of the machine learning model f; L[f θ′ (x), y] represents the loss corresponding to the updated machine learning model; f θ′ (x) represents the output result corresponding to the machine learning model; θ′ represents the parameter of the updated machine learning model f; α g represents the learning rate of the noise generator g.

5. A training system for a machine learning model with anti-theft function, which is applied to an image training data set, a text training data set, and a voice training data set, and is characterized in that: It includes: A noise generation module configured to provide a machine learning model and an initial training data set, and obtain a matching noise generator; Among them, the process of obtaining the noise generator specifically includes: during the training process of the machine learning model, based on minimizing the loss function L[f(x + g(x), y)], using the gradient descent method for f to decrease the loss, and using the gradient ascent method for g to increase the loss. After the loss function L converges, the noise generator g corresponding to the machine learning model is obtained; In each iteration of minimizing the loss function L using the SGD (Stochastic Gradient Descent) method, a noise generator g corresponding to the machine learning model is obtained through a pseudo-update method, which specifically includes the following steps: First, fix the parameters ξ of g, and update the parameters θ of f using the gradient descent method, and record the data (x i , y i ) used in the i-th iteration, and the parameters θ of f i ; use the recorded update process of the parameters θ of f to update the parameters ξ of g and repeat the above process T times; Or, obtaining the noise generator g corresponding to the machine learning model through the replica method, which specifically includes the following steps: fixing the parameters θ of f, and updating the parameters ξ' of g' using the gradient ascent method; fixing the parameters ξ of g, and updating the parameters θ of f using the gradient descent method; after reaching the maximum number of iterations, copying the parameters of g' to g, and repeating the above process T times; A training data correction module configured to obtain training data containing preset noise based on the noise generator and the initial training data set to form a modified training data set; and A prediction result module, which is configured to train another machine learning model using a modified training data set to control the machine learning model to output different prediction results for input test data that does not contain preset noise.

6. The training system of the machine learning model with anti-theft function as described in claim 5, characterized in that: The prediction result module further includes: A new model training unit, configured to train a machine learning model using a training data set containing preset noise to obtain a new machine learning model; and A prediction result output unit, configured to input test data that does not contain preset noise into the new machine learning model and output an incorrect prediction result; In the new model training unit, the proportion of the training data containing preset noise in the training data set is represented as p, and the success rate of outputting an incorrect prediction result in the prediction result output unit is represented as q. Among them, the success rate q is proportional to the proportion p.

7. An electronic device, characterized in that: The electronic device includes a storage unit and a processing unit. The storage unit is used to store a computer program, and the processing unit is used to execute the training method of the machine learning model with an anti-theft function according to any one of claims 1-4 through the computer program stored in the storage unit.