A targeted attack defense method and device
By receiving and labeling the difference parameters of the data model in the federated learning system of the banking industry, reconstructing the original feature vector and performing attack defense, the problem of targeted attacks in the federated learning system of the banking industry is solved, and effective protection of data privacy and security is achieved.
Patent Information
- Application Number
- CN202111466436.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-30
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2041-11-30
AI Technical Summary
When applying federated learning systems, the banking industry is susceptible to targeted attacks from client participants, resulting in serious information security consequences.
It provides a targeted attack defense method, which reconstructs the original feature vector by receiving and labeling the difference parameters of the data model uploaded by the requester, and conducts attack defense based on the differences and labeling results, identifying and eliminating potential attack requesters.
Accurately identify and prevent targeted attacks, enhance the protection of data privacy and security, and enhance the security and defense of federated learning systems.
Smart Images

Figure CN114139147B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the fields of artificial intelligence and information security, and can be used in the financial field. Specifically, it is a method and device for defending against targeted attacks by participants in a bank federated learning system. Background Art
[0002] Federated learning is an emerging machine learning method. When performing machine learning through this method, the original training data does not need to be uploaded to a central server for unified training. Instead, local training of each participant can be achieved under the coordination of the central server, thus fundamentally solving the problem of privacy protection in the data training process.
[0003] Currently, the banking industry has also started a large amount of research and deployment of federated learning systems based on the need for privacy protection. However, when applying the federated learning framework in banking operations, without defensive measures, it is very easy to be subject to targeted attacks from client participants. Once a targeted attack is triggered, it may lead to serious information security consequences. Therefore, due to the sensitivity of banking operations and the need for privacy protection, targeted attacks by attackers should be detected and defended in a timely manner and removed from the federated learning system to prevent them from maliciously damaging the machine learning model. Summary of the Invention
[0004] In view of the problems in the prior art, the present application provides a method and device for defending against targeted attacks, which can detect attack behaviors against a specific artificial intelligence model in a federated learning system and promptly handle data processing request parties with the possibility of attacks to complete the defense against targeted attacks.
[0005] To solve the above technical problems, the present application provides the following technical solutions:
[0006] In a first aspect, the present application provides a method for defending against targeted attacks, including:
[0007] Receiving and annotating the difference parameters of the data model uploaded by the data processing request party; the data model is obtained by the data processing request party through federated machine learning;
[0008] Reconstructing the original feature vector corresponding to the difference parameter according to the weight of the difference parameter to obtain a reconstructed feature vector;
[0009] Performing targeted attack defense according to the difference between the reconstructed feature vector and the original feature vector and the annotation result.
[0010] Further, the step of reconstructing the original feature vector corresponding to the difference parameter according to the weight of the difference parameter to obtain a reconstructed feature vector includes:
[0011] Construct the original feature vector according to the model difference parameter;
[0012] Remove the suspected difference attack parameters in the difference parameter according to the weight;
[0013] Perform feature dimension elevation on the difference parameter after removing the suspected difference attack parameters to reconstruct the original feature vector and obtain the reconstructed feature vector.
[0014] Further, the targeted attack defense based on the difference between the reconstructed feature vector and the original feature vector and the annotation result includes:
[0015] Determine the difference between the reconstructed feature vector and the original feature vector;
[0016] If the difference exceeds the preset detection threshold, screen out the suspected difference attack parameters;
[0017] Locate the suspected aggressive requestor according to the annotation result and the screened suspected difference attack parameters, and remove the suspected aggressive requestor.
[0018] Further, after locating the suspected aggressive requestor according to the annotation result and the screened suspected difference attack parameters, it further includes:
[0019] Query whether the suspected aggressive requestor has been screened out during the previous targeted attack defense process;
[0020] If so, remove the suspected aggressive requestor as an actual aggressive requestor.
[0021] In a second aspect, the present application provides a targeted attack defense device, including:
[0022] A difference parameter determination unit, configured to receive and annotate the difference parameter of the data model uploaded by the data processing requester; the data model is obtained by the data processing requester through federated machine learning;
[0023] A feature vector determination unit, configured to reconstruct the original feature vector corresponding to the difference parameter according to the weight of the difference parameter to obtain a reconstructed feature vector;
[0024] An attack defense unit, configured to perform targeted attack defense according to the difference between the reconstructed feature vector and the original feature vector and the annotation result.
[0025] Further, the feature vector determination unit includes:
[0026] An original vector construction module, configured to construct the original feature vector according to the model difference parameter;
[0027] A suspected parameter removal module, configured to remove suspected differential attack parameters in the differential parameters according to the weights;
[0028] A feature vector reconstruction module, configured to perform feature dimension elevation on the differential parameters after removing the suspected differential attack parameters, so as to reconstruct the original feature vector to obtain the reconstructed feature vector.
[0029] Further, the attack and defense unit includes:
[0030] A difference determination module, configured to determine the difference between the reconstructed feature vector and the original feature vector;
[0031] A suspected parameter screening module, configured to screen out the suspected differential attack parameters if the difference exceeds a preset detection threshold;
[0032] An elimination module, configured to locate a suspected aggressive requestor according to the annotation result and the screened suspected differential attack parameters, and eliminate the suspected aggressive requestor.
[0033] Further, the targeted attack and defense device further includes:
[0034] A historical query unit, configured to query whether the suspected aggressive requestor has been screened out during previous targeted attack and defense processes;
[0035] An elimination unit, configured to eliminate the suspected aggressive requestor as an actual aggressive requestor.
[0036] In a third aspect, the present application provides an electronic device including a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the program, the steps of the targeted attack and defense method are implemented.
[0037] In a fourth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the targeted attack and defense method are implemented.
[0038] Aiming at the problems in the prior art, the targeted attack and defense method and device provided by the present application can accurately identify a data processing requestor attempting a targeted attack, prevent it from implementing a target attack, strengthen the protection of the data privacy security of normal data processing requestors, and improve the security and defense capabilities of the federated learning system. Description of the Drawings
[0039] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0040] Figure 1 One of the flowcharts of the targeted attack defense method in the embodiments of this application;
[0041] Figure 2 The flowchart of obtaining the reconstructed feature vector in the embodiments of this application;
[0042] Figure 3 The flowchart of performing targeted attack defense in the embodiments of this application;
[0043] Figure 4 Another flowchart of the targeted attack defense method in the embodiments of this application;
[0044] Figure 5 One of the structural diagrams of the targeted attack defense device in the embodiments of this application;
[0045] Figure 6 The structural diagram of the feature vector determination unit in the embodiments of this application;
[0046] Figure 7 The structural diagram of the attack defense unit in the embodiments of this application;
[0047] Figure 8 Another structural diagram of the targeted attack defense device in the embodiments of this application;
[0048] Figure 9 The structural schematic diagram of the electronic device in the embodiments of this application;
[0049] Figure 10 The schematic diagram of the application scenario in the embodiments of this application. Detailed implementation manners
[0050] The following will clearly and completely describe the technical solutions in the embodiments of this application with reference to the drawings in the embodiments of this application. Obviously, the described embodiments are only some embodiments of this application, rather than all embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope protected by this application.
[0051] It should be noted that the targeted attack defense method and device provided in this application can be used in the financial field and any field other than the financial field. The application field of the targeted attack defense method and device provided in this application is not limited.
[0052] The application scenarios of the method described in this application at least include but are not limited to financial risk defense. Specifically, it can be to construct a financial risk defense model such as customer financial credit assessment or money laundering risk assessment using a federated learning system, and then use the constructed model for financial risk defense. See Figure 10 .
[0053] Among them, the financial risk defense model in the embodiments of this application is constructed by the federated machine learning method. Federated machine learning is an emerging machine learning method. When learning, the original training data does not need to be uploaded to the central server for unified training to obtain a data processing aggregation model according to the needs of the business. Instead, under the coordination of the central server, each data processing request party (also the client participant in model training) can first perform local model training to obtain a local data processing model, and then complete the aggregation of the local data processing models by exchanging the feature parameters of the local data processing models, thereby obtaining a data processing aggregation model, fundamentally solving the privacy protection problem in the machine learning process.
[0054] Generally speaking, a federated learning system includes a central server 1, a large number of normal users 2, and a very small number of malicious attack users 3. Among them, both normal users 2 and malicious attack users 3 can access the federated learning system through the clients located on their respective local sides. Normal users 2 can be financial institutions including banks; these financial institutions can use their local original training data (including financial data) for federated learning to obtain a local financial risk defense model for local financial risk defense. Malicious attack users 3 can be users who disguise themselves as financial institutions and intend to disrupt the federated learning system; malicious attack users 3 are also participants in constructing the financial risk defense model; however, different from normal users 2, their purpose of participation is to disrupt the system and disrupt the construction of the financial risk defense model. The role of the central server 1 is to collect the model parameters of the local financial risk defense models under the federated learning framework, and then use these model parameters to achieve the aggregation of the local financial risk defense models to obtain a financial risk defense aggregation model, and finally transmit the financial risk defense aggregation model back to the users to achieve financial risk defense.
[0055] In one embodiment, the federated learning system aims to construct a bank financial risk assessment model to judge bank financial risks and solve the problem of default identification in the credit review of small and micro customers. During the construction of this bank financial risk assessment model, these normal users 2, malicious attack users 3, and the central server 1 all participate.
[0056] In this embodiment, all normal users 2 can use their respective normal local original training data (including financial data) for training local models; among them, the original models for training local models can be sent by the central server 1 to the clients where each normal user 2 is located. Malicious attacking users 3 may have normal local original training data (including financial data), and at the same time also have local original training data (including financial data) for targeted attacks; among them, the local original training data for targeted attacks can mislead the training process of the model. In this embodiment, it can be to identify the bad lending characteristics of micro-customer credit defaults as normal tax-paying characteristics, so as to distort the federated learning system.
[0057] It should be noted that before the central server 1 collects the model parameters of each user, malicious attacking users 3 can use normal local original training data and deliberately forged malicious local original training data to train local models, and then transmit these aggressive model parameters to the central server 1 to achieve the purpose of attack. The role played by the attack recognition process in the central server 1 is to remove the maliciously forged feature data through auto-encoding and auto-decoding operations, and through the detection and statistics of these data, identify and punish malicious attacking users 3 (attackers) to ensure the security of the federated learning system.
[0058] In one embodiment, referring to Figure 1 , in order to be able to detect the attack behavior against a specific artificial intelligence model in the federated learning system, and to promptly dispose of the data processing request party with the possibility of attack to complete targeted attack defense, the present application provides a targeted attack defense method, including:
[0059] S101: Receive and label the difference parameters of the data model uploaded by the data processing request party; the data model is obtained by the data processing request party through federated machine learning;
[0060] S102: Reconstruct the original feature vector corresponding to the difference parameter according to the weight of the difference parameter to obtain a reconstructed feature vector;
[0061] S103: Perform targeted attack defense according to the difference between the reconstructed feature vector and the original feature vector and the labeling result.
[0062] It can be understood that currently, financial institutions including banks, on the one hand, need to perform machine learning based on the requirements of business data processing to complete the training of business data processing models; on the other hand, they are involved in various privacy protection requirements. Therefore, deploying a federated learning system has become the choice of financial institutions.
[0063] However, when banks apply the federated learning framework, without appropriate defensive measures, they are vulnerable to targeted attacks from client participants. Once a targeted attack is triggered, it is very likely to lead to serious information security consequences. Therefore, based on the requirements of the sensitivity of banking business data and the need for privacy protection, it is necessary to detect and defend against targeted attacks by attackers in a timely manner, and remove the attackers from the federated learning system to prevent them from maliciously damaging the machine learning model.
[0064] It should be noted that a so-called targeted attack means that the opponent's goal is to disable the trained data processing model in some targeted subtasks while maintaining good overall performance in the main task. For example, in image classification, the attacker may hope that the data processing model misclassifies some "persons with bad credit" as "persons with good credit records" while ensuring correct classification of other persons.
[0065] In the aforementioned application scenario, the client participants in model training, that is, the data processing requestors, can be each branch. Under the framework of federated learning, each branch can use its own original training data (including financial data) of the bank to build a local data processing model; then upload the model parameters to the central server for subsequent model aggregation.
[0066] In the process of model aggregation, in order to detect the attack behavior against a specific model in the federated learning system and dispose of the data processing requestors with the possibility of attack in a timely manner to complete the targeted attack defense, it is necessary to apply the targeted attack defense method provided by this application to achieve it.
[0067] Specifically, first, process the model difference parameters passed by each data processing requestor (also called client participant) to the central server of the bank's federated learning system, that is, characterize them to obtain the feature vectors of the difference parameters; then perform dimensionality reduction, anomaly screening, and data reconstruction on these feature vectors, and use the reconstruction error value as the detection index for targeted attacks; among them, the data with a higher reconstruction error value is the data that may be identified as having a targeted attack, and the corresponding client participant who transmits the difference parameter is the attacker; finally, dispose of these attackers in a timely manner for targeted attack defense.
[0068] From the above description, it can be seen that the targeted attack defense method provided by this application can accurately identify the data processing requestors who want to carry out targeted attacks, prevent them from implementing target attacks, strengthen the protection of the data privacy security of normal data processing requestors, and improve the security and defense capabilities of the federated learning system.
[0069] In one embodiment, see Figure 2, reconstructing the original feature vector corresponding to the difference parameter according to the weight of the difference parameter to obtain a reconstructed feature vector, including:
[0070] S201: constructing the original feature vector according to the model difference parameter;
[0071] S202: removing the suspected difference attack parameter in the difference parameter according to the weight;
[0072] It can be understood that each client participant in the bank federated learning system can send the difference parameter of the locally processed model to the central server, so that the central server in the bank federated learning system can preprocess the difference parameter and then perform attack recognition. The preprocessing operations include but are not limited to the process of standardizing the data.
[0073] It should be noted that in the federated learning system, the central server S will first send the original training model G t to n client participants; each client participant trains a new locally processed model L k (k = 1, …, n) according to its own local dataset D t+1 . After the client participant completes the training of the locally processed model, the client participant will send the difference parameter of L t +1 -G t to the central server; after the central server collects the difference parameter results uploaded by each client participant, it labels the difference parameter for subsequent attack recognition. The so-called labeling here is to correspond the difference parameter to the client participant, so that when it is judged that the difference parameter has a suspected attack, it can be corresponding to a specific client participant, so as to remove the client participant from the federated learning system.
[0074] Under normal circumstances, if there is no attacker, the central server S will update and calculate the global joint model according to the received difference parameter, that is, aggregate the locally processed models to obtain the aggregated model for data processing:
[0075]
[0076] If there are client participants who conduct targeted attacks, they will try to replace the global model in the central server S with the maliciously constructed global model parameters X:
[0077]
[0078] Therefore, the attacker passes the model parameters to be submitted to the central server in the following way:
[0079]
[0080] This attack method scales the weight of the attack parameter X to ensure that the attack can survive in the global averaging of the central server S. After multiple rounds of iteration, the federated learning system is attacked by replacing the global model. The method described in this application is to defend against attacks on the data processing aggregation model.
[0081] The attack recognition of the federated learning system includes: an intelligent encoding process, an intelligent decoding process, and an attack recognition process. When specifically implementing S201, in the intelligent encoding process, first, a high-dimensional mapping is performed on the difference parameters passed by the client participants. Generally, the data dimension can be increased through the ONE-HOT technology, and the data containing N discrete attribute values is expanded into a numerical feature vector of size 3×28×28. This application does not limit the vector dimension. Here, only an example is given to illustrate the feasibility of the method. The intelligent encoder is composed of a three-layer convolutional neural network. The convolutional kernel sizes can be 3×3×64, 3×3×128, 7×7×32 (this application is not limited to this). Each layer of convolution extracts different important features for learning. In the process of using the intelligent encoder, the common non-linear function Sigmoid function can be used as the activation function; at the same time, to avoid overfitting, dropout = 0.2 can be used for regularization processing.
[0082] When specifically implementing S202, after the numerical vector is processed by three layers of convolution, the numerical vector is transformed into a low-dimensional eigenvalue of size 32×1, that is, dimensionality reduction processing is performed on the data; as the data dimension decreases, the data cannot carry all the eigenvalues. Therefore, in the machine learning process, the important features that can express the characteristics of the original training data are retained, and other redundant feature vectors are discarded. In the process of data dimensionality reduction, the data with targeted attack characteristics is intended to affect a specific target and is also conducive to hiding, so its weight is intentionally set to be small, that is, its importance is lower than that of other feature vectors. In the dimensionality reduction process, it will be automatically removed. In summary, according to the weight, the suspected difference attack parameters in the difference parameters are removed, including: performing feature dimensionality reduction on the original feature vector to remove the suspected difference attack parameters with low weight during the feature dimensionality reduction process. What is meant by "low weight" can be reasonably set according to the application scenario. This application is not limited to this. In addition, the "low weight" is relative to the weight corresponding to the non-suspected difference attack parameters.
[0083] S203: Perform feature dimensionality increase on the difference parameters after removing the suspected difference attack parameters to reconstruct the original feature vector and obtain the reconstructed feature vector.
[0084] The intelligent decoding process is designed to be the opposite of the intelligent encoding process, that is, the sizes of the convolutional networks are 7×7×32, 3×3×128, and 3×3×64, respectively. The low-dimensional feature vector generated previously is restored to a feature vector of size 3×28×28 after the three-layer network of the intelligent decoder. In this process, as the data dimension increases, the eigenvalue space that can be carried also increases, the important features are restored to their original size, and the unimportant (that is, aggressive) feature vectors are supplemented with zeros. Therefore, the reconstructed feature vector has restored its original size, but only the important features (non-aggressive features) are restored, and the aggressive feature vectors contained in the local original training data will not be reconstructed. In summary, the difference parameters after removing the suspected difference attack parameters are subjected to feature dimension upgrading to reconstruct the original feature vector and obtain the reconstructed feature vector, including: supplementing the zero vector into the vector corresponding to the difference parameter after removing the suspected difference attack parameters to complete the feature dimension upgrading and obtain the reconstructed feature vector.
[0085] It can be seen from the above description that the targeted attack defense method provided in the present application can reconstruct the original feature vector corresponding to the difference parameter according to the weight of the difference parameter to obtain the reconstructed feature vector.
[0086] In one embodiment, see Figure 3 , performing targeted attack defense according to the difference between the reconstructed feature vector and the original feature vector and the annotation result, including:
[0087] S301: Determine the difference between the reconstructed feature vector and the original feature vector;
[0088] S302: Determine whether the difference exceeds a preset detection threshold;
[0089] S303: Screening out the suspected difference attack parameters;
[0090] S304: Locate the suspected aggressive requester according to the marking result and the screened suspected differential attack parameters, and remove the suspected aggressive requester.
[0091] It is understandable that there must be a certain reconstruction error when comparing the original feature vector of 3×28×28 with the reconstructed feature vector of 3×28×28. Set the average value of all reconstruction errors as the detection threshold. A reconstruction error higher than the threshold indicates a large error before and after reconstruction, indicating that there are many suspected aggressive data in the original feature vector, especially the feature data carefully designed for targeted attacks. According to the foregoing annotation results, it is possible to lock which client participants uploaded this data. For client participants who provide more error data, they can be marked as attackers suspected of launching targeted attacks. Mark the difference parameter corresponding to the normal client participants as 0, and mark the difference parameter of the abnormal client participants suspected of launching targeted attacks as 1. After marking, it can be passed to the federated learning system for penalty handling, and the client participants suspected of launching attacks (i.e., suspected aggressive requestors) can be excluded.
[0092] As can be seen from the above description, the targeted attack defense method provided by this application can perform targeted attack defense based on the difference between the reconstructed feature vector and the original feature vector and the annotation results.
[0093] In one embodiment, refer to Figure 4 , after locating the suspected aggressive requestor according to the annotation result and the screened suspected difference attack parameter, it further includes:
[0094] S401: Query whether the suspected aggressive requestor has been screened out during previous targeted attack defense processes;
[0095] S402: If so, exclude the suspected aggressive requestor as an actual aggressive requestor.
[0096] It is understandable that when the federated learning system conducts attack handling, it can be divided into a malicious data handling process and an aggressive participant handling process.
[0097] Malicious data handling process: Receive the marked data from the attack recognition process. For the difference parameter of the normal client participants marked as 0, it can be directly passed to the central server to aggregate the models of all normal client participants, and then after encrypting the aggregated global model parameters, uniformly send them back to the normal client participants, thus completing one round of federated machine learning. At the same time, for the client participants marked as suspected attackers in one round of training, the central server does not pass the aggregated global model parameters to them, but passes parameters of size 0 to the suspected attack participants. In the next round of training, if the difference parameters of the suspected aggressive participants are identified as normal, resume passing the aggregated model parameters to these client participants.
[0098] Disposal process of attacking participant: Receive the labeled data from the attack recognition process, and for the difference parameter of the aggressive client participant labeled as 1. During the federated learning process, when the number of times a certain client participant is counted as a suspected attacker reaches 1 / 2 of the number of training rounds, it can be determined that the client participant is indeed a participant who implements a malicious targeted attack. Therefore, in the federated learning system, it can be included in the blacklist and removed from the federated learning system to protect the system security.
[0099] That is to say, the above process can complete the aggregation operation and encrypted transmission of the data of each client participant, accurately dispose of the client participant who initiates a targeted attack, and ensure the security of the federated learning system.
[0100] From the above description, it can be seen that the targeted attack defense method provided by this application can accurately identify the data processing requestor who intends to carry out a targeted attack, prevent it from implementing a target attack, strengthen the protection of the data privacy security of the normal data processing requestor, and improve the security and defense ability of the federated learning system.
[0101] To more clearly show the feasibility of the method described in this application, its specific process is described as follows:
[0102] Step 1: Collect the difference parameters of the local models of data processing uploaded by each client participant through the central server of the federated learning system, aggregate and summarize the difference parameters and then transmit them.
[0103] Step 2: Perform feature processing on the difference parameter data of the client participant to convert it into a numerical feature vector of size 3×28×28. Input the three-layer neural network of the intelligent encoder to reduce the dimensionality of the feature vector to a size of 32×1. During the process of data dimensionality reduction, the feature vector with the targeted attack function, because it is an attack on a specific target, its importance (weight) is relatively low compared to other feature vectors. When performing data dimensionality reduction processing, the free nature of the neural network will remove it, and the dimensionality-reduced data only retains the important features, that is, the feature vectors that do not have the targeted attack function.
[0104] Step 3: Input the dimensionality-reduced feature vector into an intelligent decoder with an architecture opposite to that of the intelligent encoder for decoding and reconstruction restoration. After reconstruction, the feature vector is restored to its original size, and at the same time, the feature vectors with the targeted attack function removed during the dimensionality reduction process will not be reconstructed.
[0105] Step 4: Compare the reconstruction error between the original feature vector and the reconstructed feature vector, and set the average value of all reconstruction errors as the attack detection threshold. The client participants with a reconstruction error higher than the detection threshold will be marked as suspected targeted attackers. At the same time, the identified normal feature vectors and abnormal feature vectors will be marked with 0 or 1 respectively for distinction.
[0106] Step 5: Dispose of the feature vectors of the marked client participants accurately; for the feature vectors (corresponding to their difference parameters) of the identified normal client participants, the central server of the federated learning system performs parameter aggregation and encrypts and transmits the aggregated global parameters to the normal client participants; for the client participants identified as suspected attackers, their feature vectors (corresponding to their difference parameters) are not uploaded, and the federated learning system does not transmit the global aggregated parameters to them, but transmits zero parameters to them.
[0107] Step 6: Statistically count the client participants identified as suspected targeted attack initiators in each round of training; when the number of targeted attacks counted for them exceeds 1 / 2 of the number of training rounds, this client participant can be included in the blacklist and excluded from the federated learning system from then on.
[0108] In summary, the method described in this application has the following effects and advantages:
[0109] ① Strengthen the data privacy and security of legitimate participants - encrypt and protect the data transmitted by each participant in the federated learning system, and block the transmission of the parameters of the federated learning model to the attacker by detecting and identifying aggressive participants, protecting the privacy data security of legitimate participants.
[0110] ② Improve the security and defense of the federated learning system - currently, there is a lack of means to defend against targeted attacks on the banking federated learning system. The encoding and decoding intelligent detection mechanism proposed in this method can accurately identify the participating parties launching attacks and timely eliminate the malicious model parameters transmitted by the attackers, thus avoiding the impact of attacks on the federated learning system and improving the security and defense of the federated learning system.
[0111] Based on the same inventive concept, the embodiment of this application also provides a targeted attack defense device, which can be used to implement the method described in the above embodiment, as described in the following embodiment. Since the principle of the targeted attack defense device to solve problems is similar to that of the targeted attack defense method, the implementation of the targeted attack defense device can refer to the implementation of the method for determining software performance benchmarks, and the repeated parts will not be described again. Hereinafter, the term "unit" or "module" can be a combination of software and / or hardware that can achieve a predetermined function. Although the system described in the following embodiments is preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.
[0112] In one embodiment, referring to Figure 5 , in order to detect the aggressive behavior against a specific artificial intelligence model in the federated learning system and promptly dispose of the data processing request party with the possibility of attack to complete targeted attack defense, the present application provides a targeted attack defense device, including: a difference parameter determination unit 501, a feature vector determination unit 502, and an attack defense unit 503.
[0113] The difference parameter determination unit 501 is configured to receive and label the difference parameters of the data model uploaded by the data processing request party; the data model is obtained by the data processing request party through federated machine learning;
[0114] The feature vector determination unit 502 is configured to reconstruct the original feature vector corresponding to the difference parameter according to the weight of the difference parameter to obtain a reconstructed feature vector;
[0115] The attack defense unit 503 is configured to perform targeted attack defense according to the difference between the reconstructed feature vector and the original feature vector and the labeling result.
[0116] In one embodiment, referring to Figure 6 , the feature vector determination unit 502 includes: an original vector construction module 601, a suspected parameter removal module 602, and a feature vector reconstruction module 603.
[0117] The original vector construction module 601 is configured to construct the original feature vector according to the model difference parameter;
[0118] The suspected parameter removal module 602 is configured to remove the suspected difference attack parameters in the difference parameter according to the weight;
[0119] The feature vector reconstruction module 603 is configured to perform feature dimension elevation on the difference parameter after removing the suspected difference attack parameters to reconstruct the original feature vector to obtain the reconstructed feature vector.
[0120] In one embodiment, referring to Figure 7 , the attack defense unit 503 includes: a difference determination module 701, a suspected parameter screening module 702, and an elimination module 703.
[0121] The difference determination module 701 is configured to determine the difference between the reconstructed feature vector and the original feature vector;
[0122] The suspected parameter screening module 702 is configured to screen out the suspected difference attack parameters if the difference exceeds a preset detection threshold;
[0123] The elimination module 703 is used to locate the suspected aggressive requester according to the annotation result and the screened suspected differential attack parameters, and eliminate the suspected aggressive requester.
[0124] In one embodiment, referring to Figure 8 , the targeted attack defense device further includes: a historical query unit 801 and an elimination unit 802.
[0125] The historical query unit 801 is used to query whether the suspected aggressive requester has been screened out during previous targeted attack defenses;
[0126] The elimination unit 802 is used to eliminate the suspected aggressive requester as an actual aggressive requester.
[0127] From a hardware perspective, in order to detect aggressive behaviors against a specific artificial intelligence model in a federated learning system, and promptly handle data processing requesters with the possibility of attack to complete targeted attack defense, this application provides an embodiment of an electronic device for implementing all or part of the content in the targeted attack defense method. The electronic device specifically includes the following:
[0128] A processor, a memory, a communications interface, and a bus; wherein, the processor, the memory, and the communications interface complete communication with each other through the bus; the communications interface is used to implement information transmission between the targeted attack defense device and related devices such as a core business system, a user terminal, and a related database, etc. This logic controller can be a desktop computer, a tablet computer, a mobile terminal, etc., and this embodiment is not limited thereto. In this embodiment, this logic controller can be implemented with reference to the embodiments of the targeted attack defense method and the embodiments of the targeted attack defense device in the embodiments, and the content is incorporated herein, and the repeated parts will not be elaborated.
[0129] It can be understood that the user terminal may include a smart phone, a tablet electronic device, a network set-top box, a portable computer, a desktop computer, a personal digital assistant (PDA), a vehicle-mounted device, a smart wearable device, etc. Among them, the smart wearable device may include smart glasses, a smart watch, a smart bracelet, etc.
[0130] In practical applications, part of the targeted attack defense method can be executed on the side of the electronic device as described above, or all operations can be completed in the client device. Specifically, it can be selected according to the processing capacity of the client device and the limitations of the user usage scenario, etc. This application does not make any limitations in this regard. If all operations are completed in the client device, the client device may further include a processor.
[0131] The above-mentioned client device may have a communication module (i.e., communication unit), which can communicate with a remote server to realize data transmission with the server. The server may include a server on the side of the task scheduling center, and in other implementation scenarios, it may also include a server of an intermediate platform, such as a server of a third-party server platform that has a communication link with the task scheduling central server. The server may include a single computer device, or may include a server cluster composed of multiple servers, or a server structure of a distributed device.
[0132] Figure 9 It is a schematic block diagram of the system composition of the electronic device 9600 according to an embodiment of the present application. As Figure 9 shown, the electronic device 9600 may include a central processor 9100 and a memory 9140; the memory 9140 is coupled to the central processor 9100. It should be noted that this Figure 9 is exemplary; other types of structures may also be used to supplement or replace this structure to implement telecommunication functions or other functions.
[0133] In one embodiment, the function of the targeted attack defense method can be integrated into the central processor 9100. Among them, the central processor 9100 may be configured to perform the following controls:
[0134] S101: Receive and label the difference parameters of the data model uploaded by the data processing request party; the data model is obtained by the data processing request party through federated machine learning;
[0135] S102: Reconstruct the original feature vector corresponding to the difference parameter according to the weight of the difference parameter to obtain a reconstructed feature vector;
[0136] S103: Perform targeted attack defense according to the difference between the reconstructed feature vector and the original feature vector and the labeling result.
[0137] As can be seen from the above description, the targeted attack defense method provided by the present application can accurately identify the data processing request party that intends to perform a targeted attack, prevent it from implementing a target attack, strengthen the protection of the data privacy and security of the normal data processing request party, and improve the security and defense of the federated learning system.
[0138] In another embodiment, the targeted attack defense device can be separately configured from the central processing unit 9100. For example, the data composite transmission device targeted attack defense device can be configured as a chip connected to the central processing unit 9100, and the functions of the targeted attack defense method can be realized through the control of the central processing unit.
[0139] As Figure 9 shown, the electronic device 9600 may further include: a communication module 9110, an input unit 9120, an audio processor 9130, a display 9160, and a power supply 9170. It should be noted that the electronic device 9600 does not necessarily have to include Figure 9 all the components shown in Figure 9 ; in addition, the electronic device 9600 may further include
[0140] As Figure 9 shown, the central processing unit 9100 is sometimes also referred to as a controller or an operation control, and may include a microprocessor or other processor devices and / or logic devices. The central processing unit 9100 receives inputs and controls the operations of the various components of the electronic device 9600.
[0141] Among them, the memory 9140 can be, for example, one or more of a buffer, a flash memory, a hard drive, a removable medium, a volatile memory, a non-volatile memory, or other suitable devices. It can store the above information related to failures, and can also store programs for executing relevant information. And the central processing unit 9100 can execute the programs stored in the memory 9140 to implement information storage or processing, etc.
[0142] The input unit 9120 provides inputs to the central processing unit 9100. The input unit 9120 is, for example, a key or a touch input device. The power supply 9170 is used to supply power to the electronic device 9600. The display 9160 is used to display display objects such as images and texts. The display can be, for example, an LCD display, but is not limited thereto.
[0143] The memory 9140 can be a solid-state memory. For example, a read-only memory (ROM), a random access memory (RAM), a SIM card, etc. It can also be such a memory that stores information even when powered off, can be selectively erased and has more data. Examples of such a memory are sometimes referred to as EPROMs, etc. The memory 9140 can also be some other type of device. The memory 9140 includes a buffer memory 9141 (sometimes referred to as a buffer). The memory 9140 may include an application / function storage unit 9142, and the application / function storage unit 9142 is used to store application programs and function programs or the processes for operating the electronic device 9600 through the central processing unit 9100.
[0144] The memory 9140 may further include a data storage unit 9143 for storing data such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. The driver storage unit 9144 of the memory 9140 may include various drivers of the electronic device for communication functions and / or for performing other functions of the electronic device (such as a messaging application, an address book application, etc.).
[0145] The communication module 9110 is a transmitter / receiver 9110 that transmits and receives signals via the antenna 9111. The communication module (transmitter / receiver) 9110 is coupled to the central processing unit 9100 to provide input signals and receive output signals, which may be the same as in the case of a conventional mobile communication terminal.
[0146] Based on different communication technologies, multiple communication modules 9110 may be provided in the same electronic device, such as a cellular network module, a Bluetooth module, and / or a wireless local area network module, etc. The communication module (transmitter / receiver) 9110 is also coupled to the speaker 9131 and the microphone 9132 via the audio processor 9130 to provide an audio output via the speaker 9131 and receive an audio input from the microphone 9132, thereby implementing normal telecommunication functions. The audio processor 9130 may include any suitable buffers, decoders, amplifiers, etc. Additionally, the audio processor 9130 is also coupled to the central processing unit 9100, so that recording can be performed on the local machine through the microphone 9132, and the sound stored on the local machine can be played through the speaker 9131.
[0147] Embodiments of the present application also provide a computer-readable storage medium capable of implementing all steps in the targeted attack defense method where the execution subject in the above embodiments is a server or a client. A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, all steps in the targeted attack defense method where the execution subject in the above embodiments is a server or a client are implemented. For example, when the processor executes the computer program, the following steps are implemented:
[0148] S101: Receive and label the difference parameters of the data model uploaded by the data processing requester; the data model is obtained by the data processing requester through federated machine learning;
[0149] S102: Reconstruct the original feature vector corresponding to the difference parameter according to the weight of the difference parameter to obtain a reconstructed feature vector;
[0150] S103: Perform targeted attack defense according to the difference between the reconstructed feature vector and the original feature vector and the labeling result.
[0151] As can be seen from the above description, the targeted attack defense method provided by this application can accurately identify the data processing requestor attempting a targeted attack, prevent it from carrying out the target attack, strengthen the protection of the data privacy and security of normal data processing requestors, and improve the security and defense capabilities of the federated learning system.
[0152] Those skilled in the art should understand that the embodiments of the present invention can be provided as methods, devices, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0153] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (devices), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of multiple flows and / or blocks.
[0154] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including instruction means that implement the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of multiple flows and / or blocks.
[0155] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, thereby providing steps for implementing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of multiple flows and / or blocks.
[0156] In the present invention, specific embodiments are used to elaborate on the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A method for targeted attack defense, characterized in that, it includes: Receiving and annotating the difference parameters of the data model uploaded by the data processing requestor; The data model is obtained by the data processing requestor through federated machine learning; The difference parameter is the difference between the parameters of the data model and the parameters of the global model during the federated learning iteration; Reconstructing the original feature vector corresponding to the difference parameter according to the weight of the difference parameter to obtain a reconstructed feature vector; Performing targeted attack defense according to the difference between the reconstructed feature vector and the original feature vector and the annotation result; The reconstructing the original feature vector corresponding to the difference parameter according to the weight of the difference parameter to obtain a reconstructed feature vector includes: Constructing the original feature vector according to the difference parameter; Removing the suspected difference attack parameters in the difference parameter according to the weight; Performing feature dimensionality increase on the difference parameter after removing the suspected difference attack parameters to reconstruct the original feature vector and obtain the reconstructed feature vector; The removing the suspected difference attack parameters in the difference parameter according to the weight includes: Performing feature dimensionality reduction on the original feature vector to remove the suspected difference attack parameters with low weight during the feature dimensionality reduction process, and the weight is dynamically generated during the feature dimensionality reduction process of the original feature vector.
2. The targeted attack defense method according to claim 1, characterized in that, The performing feature dimensionality increase on the difference parameter after removing the suspected difference attack parameters to reconstruct the original feature vector and obtain the reconstructed feature vector includes: Complementing a zero vector into the vector corresponding to the difference parameter after removing the suspected difference attack parameters to complete the feature dimensionality increase and obtain the reconstructed feature vector.
3. The targeted attack defense method according to claim 1, characterized in that, The performing targeted attack defense according to the difference between the reconstructed feature vector and the original feature vector and the annotation result includes: Determining the difference between the reconstructed feature vector and the original feature vector; If the difference exceeds a preset detection threshold, screening out the suspected difference attack parameters; Locating the suspected aggressive requestor according to the annotation result and the screened out suspected difference attack parameters and removing the suspected aggressive requestor.
4. The targeted attack defense method according to claim 1, characterized in that, After locating the suspected aggressive requestor according to the annotation result and the screened out suspected difference attack parameters, it further includes: Querying whether the suspected aggressive requestor has been screened out during the previous targeted attack defense process; If so, removing the suspected aggressive requestor as an actual aggressive requestor.
5. A targeted attack defense device, characterized in that, it includes: A difference parameter determination unit for receiving and annotating the difference parameters of the data model uploaded by the data processing requestor; The data model is obtained by the data processing requestor through federated machine learning; the difference parameter is the difference between the parameters of the data model and the parameters of the global model during the federated learning iteration; A feature vector determination unit, configured to reconstruct an original feature vector corresponding to the difference parameter according to the weight of the difference parameter, so as to obtain a reconstructed feature vector; An attack and defense unit, configured to perform targeted attack and defense according to the difference between the reconstructed feature vector and the original feature vector and the annotation result; The feature vector determination unit includes: An original vector construction module, configured to construct the original feature vector according to the difference parameter; A suspected parameter removal module, configured to remove suspected difference attack parameters in the difference parameter according to the weight; A feature vector reconstruction module, configured to perform feature dimension elevation on the difference parameter after removing the suspected difference attack parameters, so as to reconstruct the original feature vector to obtain the reconstructed feature vector; The suspected parameter removal module is further configured to perform feature dimension reduction on the original feature vector, so as to remove the suspected difference attack parameters with low weights during the feature dimension reduction process, and the weight is dynamically generated during the feature dimension reduction process of the original feature vector.
6. An electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein, when the processor executes the program, the steps of the targeted attack and defense method according to any one of claims 1 to 4 are implemented.
7. A computer-readable storage medium, on which a computer program is stored, wherein, when the computer program is executed by a processor, the steps of the targeted attack and defense method according to any one of claims 1 to 4 are implemented.
Citation Information
Patent Citations
Model parameter verification method and device and readable storage medium
CN111967609A