Data Processing Method, Apparatus and Device
The carrier category and object determination model constructed by reinforcement learning algorithms solves the problem of model steganography effect and low efficiency, and realizes efficient and safe steganography processing in complex model structures.
Patent Information
- Application Number
- CN202210682593.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-16
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2042-06-16
AI Technical Summary
In the case of complex model structure, it is difficult for the prior art to effectively improve the model steganography effect and efficiency in model steganography scenarios, especially when the steganography space requirements of the carrier object are high, resulting in poor model steganography effect and low processing efficiency.
The carrier category and carrier object determination model is determined based on reinforcement learning algorithm, the target carrier class and carrier object corresponding to the target model are determined, and the model weights and structures are written to the carrier object using a pre-trained steganography model to improve the accuracy and efficiency of write processing.
It improves the model steganography effect and efficiency, ensures that the carrier object maintains good visual effect, and reduces the amount of data processing, improving the security and processing efficiency of model steganography.
Smart Images

Figure CN114969825B_ABST
Abstract
Description
Technical Field
[0001] This document relates to the technical field of data processing, and in particular, to a data processing method, apparatus, and device. Background Art
[0002] With the rapid development of computer technology, the application scenarios of artificial intelligence systems are becoming more and more extensive, such as face recognition, autonomous driving, etc. The core of an artificial intelligence system is a model constructed by deep learning algorithms. To improve the security of an artificial intelligence system, it is necessary to perform privacy protection processing on the model constructed by deep learning algorithms.
[0003] However, in the case of an increasingly complex model structure, the requirements for the steganographic space of the carrier object are relatively high, the steganographic effect of the model is poor, and at the same time, due to the large amount of data processing, the processing efficiency of model steganography is also low. Therefore, a solution that can improve the steganographic effect and steganographic efficiency of the model in the model steganography scenario is needed. Summary of the Invention
[0004] The purpose of the embodiments of this specification is to provide a solution that can improve the steganographic effect and steganographic efficiency of the model in the model steganography scenario.
[0005] To achieve the above technical solution, the embodiments of this specification are implemented as follows:
[0006] In a first aspect, an embodiment of this specification provides a data processing method, including: obtaining a target model to be steganographically embedded; determining, based on a pre-trained carrier class determination model, a target carrier class corresponding to the target model in candidate carrier classes, where the carrier class determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes and a first reward value determined in the reinforcement learning process for selecting any action in the first action set, and the first reward value is determined by a loss value of writing a carrier object in each historical carrier class to a historical model; determining, based on a pre-trained carrier object determination model, a target carrier object corresponding to the target model in the target carrier class, where the carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value determined in the reinforcement learning process for selecting any action in the second action set, and the second reward value is determined by a loss value of writing each historical carrier object to the historical model; based on a pre-trained steganographic model, writing the model weights and model structure of the target model to be steganographically embedded to the target carrier object to obtain a written carrier object, and sending the written carrier object to a target device, where the written carrier object is used to trigger the target device to obtain the target model based on the written carrier object, so as to process a target service based on the target model.
[0007] Second aspect, an embodiment of this specification provides a data processing method, including: receiving a written carrier object sent by a server, where the written carrier object is obtained by the server writing the model weights and model structure of a target model to be steganographed into a target carrier object based on a pre-trained steganography model, the target carrier object is the carrier object corresponding to the target model in a target carrier class determined by the server based on a pre-trained carrier object determination model, the target carrier class is the carrier class corresponding to the target model in candidate carrier classes determined by the server based on a pre-trained carrier class determination model, the carrier class determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes and a first reward value determined for selecting any action in the first action set during the reinforcement learning process, the first reward value is determined by the loss value of writing the carrier object in each historical carrier class to a historical model, the carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value determined for selecting any action in the second action set during the reinforcement learning process, the second reward value is determined by the loss value of writing each historical carrier object to the historical model; performing an extraction process on the written carrier object based on a preset extraction model to obtain the model weights and model structure of the target model; determining the target model based on the model weights and model structure of the target model, and processing a target service based on the target model.
[0008] Thirdly, an embodiment of this specification provides a data processing device, including: a model acquisition module, configured to acquire a target model to be steganographed; a class determination module, configured to determine, based on a pre-trained carrier class determination model, a target carrier class corresponding to the target model in candidate carrier classes, where the carrier class determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes and a first reward value determined by selecting any action in the first action set during the reinforcement learning process, and the first reward value is determined by a loss value of writing a historical model by a carrier object in each historical carrier class; an object determination module, configured to determine, based on a pre-trained carrier object determination model, a target carrier object corresponding to the target model in the target carrier class, where the carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value determined by selecting any action in the second action set during the reinforcement learning process, and the second reward value is determined by a loss value of writing the historical model by each historical carrier object; a data sending module, configured to write the model weights and model structure of the target model to be steganographed into the target carrier object based on a pre-trained steganography model to obtain a written carrier object, and send the written carrier object to a target device, where the written carrier object is used to trigger the target device to obtain the target model based on the written carrier object, so as to process a target service based on the target model.
[0009] Fourthly, an embodiment of this specification provides a data processing device, including: a data acquisition module, configured to receive a written carrier object sent by a server, where the written carrier object is obtained by the server writing the model weights and model structure of a target model to be steganographed into a target carrier object based on a pre-trained steganography model, the target carrier object is a carrier object corresponding to the target model in a target carrier class determined by the server based on a pre-trained carrier object determination model, the target carrier class is a carrier class corresponding to the target model in candidate carrier classes determined by the server based on a pre-trained carrier class determination model, the carrier class determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes and a first reward value determined by selecting any action in the first action set during the reinforcement learning process, the first reward value is determined by the loss value of writing a carrier object in each historical carrier class to a historical model, the carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value determined by selecting any action in the second action set during the reinforcement learning process, the second reward value is determined by the loss value of writing each historical carrier object to the historical model; an extraction module, configured to perform extraction processing on the written carrier object based on a preset extraction model to obtain the model weights and model structure of the target model; a service processing module, configured to determine the target model based on the model weights and model structure of the target model, and process a target service based on the target model.
[0010] Fifth aspect, an embodiment of this specification provides a data processing device, the data processing device includes: a processor; and a memory arranged to store computer-executable instructions, the executable instructions, when executed, cause the processor to: obtain a target model to be steganographically embedded; determine a target carrier class corresponding to the target model in a candidate carrier class based on a pre-trained carrier class determination model, the carrier class determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes and a first reward value determined for selecting any action in the first action set during the reinforcement learning process, the first reward value is determined by a loss value of a carrier object in each of the historical carrier classes for writing to a historical model; determine a target carrier object corresponding to the target model in the target carrier class based on a pre-trained carrier object determination model, the carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value determined for selecting any action in the second action set during the reinforcement learning process, the second reward value is determined by a loss value of each of the historical carrier objects for writing to the historical model; based on a pre-trained steganography model, write the model weights and model structure of the target model to be steganographically embedded into the target carrier object to obtain a written carrier object, and send the written carrier object to a target device, the written carrier object is used to trigger the target device to obtain the target model based on the written carrier object, so as to process a target service based on the target model.
[0011] Sixth aspect, an embodiment of this specification provides a data processing device, the data processing device includes: a processor; and a memory arranged to store computer-executable instructions, the executable instructions when executed cause the processor to: receive a written carrier object sent by a server, the written carrier object is obtained by the server writing the model weights and model structure of a target model to be steganographed into a target carrier object based on a pre-trained steganography model, the target carrier object is a carrier object corresponding to the target model in a target carrier class determined by the server based on a pre-trained carrier object determination model, the target carrier class is a carrier class corresponding to the target model in candidate carrier classes determined by the server based on a pre-trained carrier class determination model, the carrier class determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes, and a first reward value determined in the reinforcement learning process for selecting any action in the first action set, the first reward value is determined by the loss value of writing a carrier object in each of the historical carrier classes to a historical model, the carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects, and a second reward value determined in the reinforcement learning process for selecting any action in the second action set, the second reward value is determined by the loss value of writing each of the historical carrier objects to the historical model; perform extraction processing on the written carrier object based on a preset extraction model to obtain the model weights and model structure of the target model; determine the target model based on the model weights and model structure of the target model, and process a target service based on the target model.
[0012] In a seventh aspect, an embodiment of this specification provides a storage medium for storing computer-executable instructions, and when the executable instructions are executed, the following process is implemented: obtaining a target model to be steganographed; determining, based on a pre-trained carrier category determination model, a target carrier category corresponding to the target model in candidate carrier categories, where the carrier category determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier categories and a first reward value determined by selecting any action in the first action set during the reinforcement learning process, and the first reward value is determined by a loss value of a carrier object in each historical carrier category writing to a historical model; determining, based on a pre-trained carrier object determination model, a target carrier object corresponding to the target model in the target carrier category, where the carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value determined by selecting any action in the second action set during the reinforcement learning process, and the second reward value is determined by a loss value of each historical carrier object writing to the historical model; based on a pre-trained steganography model, writing the model weights and model structure of the target model to be steganographed into the target carrier object to obtain a written carrier object, and sending the written carrier object to a target device, where the written carrier object is used to trigger the target device to obtain the target model based on the written carrier object, so as to process a target service based on the target model.
[0013] In an eighth aspect, an embodiment of this specification provides a storage medium for storing computer-executable instructions, which, when executed, implement the following process: receiving a written carrier object sent by a server, where the written carrier object is obtained by the server writing the model weights and model structure of a target model to be steganographed into a target carrier object based on a pre-trained steganography model, the target carrier object is the carrier object corresponding to the target model in the target carrier class determined by the server based on a pre-trained carrier object determination model, the target carrier class is the carrier class corresponding to the target model in the candidate carrier classes determined by the server based on a pre-trained carrier class determination model, the carrier class determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes and a first reward value determined for selecting any action in the first action set during the reinforcement learning process, the first reward value is determined by the loss value of writing the carrier object in each historical carrier class to a historical model, the carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value determined for selecting any action in the second action set during the reinforcement learning process, the second reward value is determined by the loss value of writing each historical carrier object to the historical model; performing extraction processing on the written carrier object based on a preset extraction model to obtain the model weights and model structure of the target model; determining the target model based on the model weights and model structure of the target model, and processing a target service based on the target model. Description of the Drawings
[0014] In order to more clearly illustrate the technical solutions in the embodiments of this specification or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments recorded in this specification. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0015] Figure 1A It is a flowchart of an embodiment of a data processing method in this specification;
[0016] Figure 1B It is a schematic diagram of the processing process of a data processing method in this specification;
[0017] Figure 2 It is a schematic diagram of the processing process of another data processing method in this specification;
[0018] Figure 3AFlowchart of another embodiment of the data processing method in this specification;
[0019] Figure 3B Schematic diagram of the processing process of another data processing method in this specification;
[0020] Figure 4 Schematic diagram of a data processing process in this specification;
[0021] Figure 5 Schematic diagram of the structure of an embodiment of a data processing device in this specification;
[0022] Figure 6 Schematic diagram of the structure of another embodiment of a data processing device in this specification;
[0023] Figure 7 Schematic diagram of the structure of a data processing device in this specification. Detailed implementation manners
[0024] The embodiments of this specification provide a data processing method, device and equipment.
[0025] In order to enable those skilled in the art to better understand the technical solutions in this specification, the following will clearly and completely describe the technical solutions in the embodiments of this specification with reference to the accompanying drawings in the embodiments of this specification. Obviously, the described embodiments are only a part of the embodiments of this specification, rather than all the embodiments. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this specification.
[0026] Embodiment 1
[0027] As Figure 1A and 1B shown, the embodiments of this specification provide a data processing method. The execution subject of this method can be a server, and the server can be a server. Among them, the server can be an independent server or a server cluster composed of multiple servers. This method can specifically include the following steps:
[0028] In S102, obtain a target model to be steganographed.
[0029] Among them, the target model to be steganographed can be a model obtained by training a model constructed by a deep learning algorithm based on historical business data and capable of processing a predetermined business. For example, the target model can be a classification model constructed by a neural network learning algorithm based on historical resource transfer business data and capable of determining whether there is a risk in executing a resource transfer business.
[0030] In implementation, with the rapid development of computer technology, the application scenarios of artificial intelligence systems are becoming increasingly extensive, such as face recognition, autonomous driving, etc. The core of an artificial intelligence system is a model constructed by deep learning algorithms. To improve the security of an artificial intelligence system, it is necessary to perform privacy protection processing on the model constructed by deep learning algorithms. For example, the structure of the model can be processed by adding unnecessary operations (such as adding the number a to the model weights of the model and then subtracting the number a, etc.), and then writing the processed model into a carrier object, so that attackers cannot accurately locate the effective structure of the model based on the carrier object, thereby achieving privacy protection processing for the model.
[0031] However, due to the need to add too many unnecessary operations, in the case of an increasingly complex model structure, the requirements for the steganography space of the carrier object are relatively high, which will result in a poor steganography effect of the model. At the same time, due to the large amount of data processing, the processing efficiency of model steganography is also low. Therefore, a solution that can improve the model steganography effect and model steganography efficiency in the model steganography scenario is needed. For this reason, the embodiments of this specification provide a technical solution that can solve the above problems. For specific details, please refer to the following content.
[0032] Taking the target model to be steganographed as a model for determining whether there is a risk in performing a resource transfer service as an example, the target model can be trained by the server based on a predetermined number of historical resource transfer service data. The target device can be a client used by an organization that can provide resource transfer services for users. Since the private data of each user owned by an organization may have problems such as a small amount of data and poor data quality, while the server has a large amount of data and strong data processing capabilities, the server can send the target model to the target device to solve the problem that the model locally trained by the target device may have a poor model effect. To protect the security of the target model during data transmission, the target model can be steganographically processed.
[0033] In S104, based on a pre-trained carrier category determination model, determine the target carrier category corresponding to the target model in the candidate carrier categories.
[0034] Among them, the carrier category determination model can be obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier categories and a first reward value obtained by determining the reward value brought by selecting any action in the first action set during the reinforcement learning process. The first reward value can be determined by the loss value of the carrier object in each historical carrier category for writing to the historical model. The candidate carrier category can correspond to one or more carrier objects, and the carrier object can be any object capable of writing the data to be hidden, such as an image, a video, an audio, etc. For example, the carrier object can be a carrier image, and the data to be hidden can be written into some pixel points of the carrier image. In this way, the Peak Signal to Noise Ratio (PSNR) of the written carrier image is not lower than a preset noise threshold, that is, the written carrier image has a good visual effect.
[0035] In implementation, the candidate carrier category corresponding to the target model can be determined according to the model size of the target model, the type of the predetermined service for processing (such as for processing the target service), etc.
[0036] For example, taking the carrier object as a carrier image as an example, assuming that the original information of each pixel point is 8 bit, when the PSNR of the carrier image is not lower than the preset noise threshold, each pixel point can provide 4 bit for writing the data to be hidden. Then, the encoded model weights and the encoded model structure can be written into the 4 bit of several pixel points of the carrier object. Therefore, to make the PSNR of the carrier image not lower than the preset noise threshold, the carrier object can be divided into multiple candidate carrier categories according to the size of the data to be hidden. After obtaining the target model to be hidden, the candidate carrier category corresponding to the target model can be determined according to the model size of the target model.
[0037] Alternatively, since different services have different requirements for the accuracy of model hiding, such as the requirement for the accuracy of model hiding in the resource transfer risk control scenario is higher than that in the instant messaging risk control scenario. Therefore, multiple carrier objects can be divided into different candidate carrier categories according to the service requirements. After obtaining the target model to be hidden, the candidate carrier category corresponding to the target model can be determined according to the service type of the predetermined service for which the target model is used.
[0038] The above method for determining the candidate carrier category corresponding to the target model is an optional and implementable determination method. In actual application scenarios, there can be multiple different determination methods, which can vary according to different actual application scenarios. The embodiments of this specification do not make specific limitations in this regard.
[0039] After determining the candidate carrier classes corresponding to the target model, the target carrier class corresponding to the target model in the candidate carrier classes can be determined based on the pre-trained carrier class determination model.
[0040] In this way, when the number of carrier objects is large, the target carrier class corresponding to the target model can be determined first according to the candidate carrier classes, which can improve the determination efficiency of the carrier objects used for the write process of the target model. At the same time, it can also improve the determination accuracy of the carrier objects used for the write process of the target model.
[0041] In S106, based on the pre-trained carrier object determination model, the target carrier object corresponding to the target model in the target carrier class is determined.
[0042] Among them, the carrier object determination model can be trained by training the model constructed by the reinforcement learning algorithm based on the second action set determined by the historical carrier objects and the second return value obtained by determining to select any action in the second action set during the reinforcement learning process. The second return value can be determined by the loss value of each historical carrier object for writing to the historical model.
[0043] In implementation, the historical carrier class corresponding to the historical model can be determined through the pre-trained carrier class determination model, and then the carrier object determination model can be trained by using the target model and the historical carrier objects in the historical carrier class to obtain the trained carrier object determination model. Then, based on the pre-trained carrier object determination model, the target carrier object corresponding to the target model in the target carrier class is determined.
[0044] In S108, based on the pre-trained steganography model, the model weights and model structure of the target model to be steganographed are written into the target carrier object to obtain the written carrier object, and the written carrier object is sent to the target device.
[0045] Among them, the steganography model can be a model constructed by a deep learning algorithm for steganographing data into carrier objects. The written carrier object can be used to trigger the target device to obtain the target model based on the written carrier object, so as to process the target service based on the target model.
[0046] In implementation, for example, the target model can be a model for determining whether there is a risk in executing a resource transfer service. The target service can be the resource transfer service. The server can send the written carrier object to the target device, and the target device can perform extraction processing on the written carrier object to determine the target model according to the extracted data, and then determine whether there is a risk in executing the resource transfer service based on the obtained target model and the service data of the resource transfer service.
[0047] An embodiment of this specification provides a data processing method. Obtain a target model to be steganographed, determine a model based on a pre-trained carrier category, and determine a target carrier category corresponding to the target model in a candidate carrier category. The carrier category determination model can be trained by a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier categories and a first reward value obtained by determining to select any action in the first action set during the reinforcement learning process. The first reward value is determined by the loss value of the carrier object in each historical carrier category writing to the historical model. Based on a pre-trained carrier object determination model, determine a target carrier object corresponding to the target model in the target carrier category. The carrier object determination model can be trained by a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value obtained by determining to select any action in the second action set during the reinforcement learning process. The second reward value can be determined by the loss value of the carrier object in each historical carrier object writing to the historical model. Based on a pre-trained steganography model, write the model weights and model structure of the target model to be steganographed to the target carrier object to obtain a written carrier object, and send the written carrier object to the target device. The written carrier object is used to trigger the target device to obtain the target model based on the written carrier object, so as to process the target service based on the target model. In this way, based on a pre-trained carrier category determination model, a target carrier category corresponding to the target model can be determined, and based on a pre-trained carrier object determination model, a target carrier object corresponding to the target model in the target carrier category can be determined, which can improve the determination accuracy and efficiency of the target carrier object for writing the target model. Then, through the pre-trained carrier object determination model, write the model weights and model structure of the target model to be steganographed to the target carrier object, which can improve the steganography effect and steganography efficiency of the model in the model steganography scenario.
[0048] Embodiment 2
[0049] An embodiment of this specification provides a data processing method. The execution subject of this method can be a server, and the server can be a server. Among them, the server can be an independent server or a server cluster composed of multiple servers. The method can specifically include the following steps:
[0050] In S102, obtain a target model to be steganographed.
[0051] In S202, obtain historical carrier objects and historical models.
[0052] Among them, the historical model can be a model with the same model structure as the target model but different model weights. For example, the target model can be a classification model constructed by a three-layer convolutional neural network, and each convolutional layer contains three filters for identifying specific features of the data. The historical model can also be a classification model constructed by a three-layer convolutional neural network, and each convolutional layer contains three filters for identifying specific features of the data. However, the weight values of the filters in the historical model can be different from those of the filters in the target model. The historical carrier object includes a carrier object corresponding to the historical model.
[0053] In S204, based on the feature vectors of the historical carrier objects, cluster the historical carrier objects to obtain historical carrier classes.
[0054] Among them, each historical carrier class corresponds to one or more historical carrier objects.
[0055] In implementation, the feature extraction process can be performed on the historical carrier objects based on a preset feature extraction model to obtain the feature vectors of each historical carrier object. Among them, taking the historical carrier object as a carrier image as an example, the preset feature extraction model can be obtained by training a model constructed by a preset machine learning algorithm with images in a visualization database (such as ImageNet) for feature extraction processing of images.
[0056] The clustering process can be performed on the historical carrier objects based on a preset clustering algorithm (such as the K-means algorithm, DBSCAN algorithm, KNN algorithm, etc.) and the feature vectors of the historical carrier objects to obtain multiple historical carrier classes.
[0057] In S206, based on the distances between the feature vectors of every two historical carrier classes, determine the target distance matrix, and determine the first action set based on the target distance matrix.
[0058] In implementation, the feature vector of each historical carrier class can be determined according to the historical carrier objects corresponding to each historical carrier class. For example, the mean value of the feature vectors of the historical carrier objects corresponding to the historical carrier class can be determined as the feature vector of the historical carrier class. There can be various methods for determining the feature vector of the historical carrier class, and the embodiments of this specification do not specifically limit the method for determining the feature vector of the historical carrier class.
[0059] The distances between the feature vectors of every two historical carrier classes can be determined based on a preset distance determination algorithm (such as the Manhattan distance algorithm, Euclidean distance algorithm, etc.), and then the target distance matrix can be constructed from the distances between the feature vectors of every two historical carrier classes. Assuming there are K historical carrier classes, a K*K target distance matrix can be constructed.
[0060] After constructing the target distance matrix, a first set of actions can be constructed based on the target distance matrix. For example, the first set of actions can include: Action 1 (selecting a historical carrier class whose distance from the current historical carrier class is less than a first preset distance), Action 2 (selecting a historical carrier class whose distance from the current historical carrier class is not less than the first preset distance and less than a second preset distance), Action 3 (selecting a historical carrier class whose distance from the current historical carrier class is not less than the second preset distance and less than a third preset distance), Action 4 (selecting the current historical carrier class to remain unchanged), etc.
[0061] The above method for constructing the first set of actions is an optional and implementable construction method. In actual application scenarios, there can be various different construction methods, and different construction methods can be selected according to different actual application scenarios. The embodiments of this specification do not make specific limitations on this.
[0062] In S208, obtain the first model and the third carrier object.
[0063] Among them, the model data of the first model can include the model structure and / or model weights of the first model.
[0064] In S210, based on the model data of the first model, the third carrier object, and the preset feature extraction model, train the first steganographic model and the first extraction model to obtain the trained first steganographic model and the first extraction model.
[0065] In implementation, the model data of the first model and the third carrier object can be input into the first steganographic model to obtain the third carrier object after writing. Then, the third carrier object after writing is input into the first extraction model to obtain the extracted model data. Then, the third carrier object and the third carrier object after writing are respectively input into the preset feature extraction model to obtain the feature vector of the third carrier object and the feature vector of the third carrier object after writing. Then, based on the preset loss function, the third carrier object, the third carrier object after writing, the model data of the first model, the extracted model data, the feature vector of the third carrier object, and the feature vector of the third carrier object after writing, determine the first loss value. Finally, based on the first loss value, determine whether the first steganographic model and the first extraction model converge. If they do not converge, continue to train the first steganographic model and the first extraction model based on the model data of the first model and the third carrier object until the first steganographic model and the first extraction model converge to obtain the trained first steganographic model and the first extraction model.
[0066] In S212, based on the trained first steganographic model, the trained first extraction model, and the preset feature extraction model, determine the loss value of each historical carrier object corresponding to each historical carrier class for writing to the historical model.
[0067] In implementation, the method for determining the first loss value described above can be referred to. Based on the trained first steganography model, the trained first extraction model, and the preset feature extraction model, determine the loss value of the historical carrier object corresponding to each historical carrier class when writing to the historical model.
[0068] In S214, based on the loss value of the historical carrier object corresponding to each historical carrier class when writing to the historical model, determine the first return value brought by determining to select any action in the first action set during the reinforcement learning process.
[0069] In implementation, the first return value brought by determining to select any action in the first action set during the reinforcement learning process can be determined through the Reward function and the loss value of the historical carrier object corresponding to each historical carrier class when writing to the historical model. For example, the smaller the loss value of the historical carrier object corresponding to the selected nth historical carrier class when writing to the historical model, the greater the first return value of the corresponding action.
[0070] In S216, based on the first action set and the first return value, train the carrier class determination model to obtain the trained carrier class determination model.
[0071] Among them, the target carrier class can include the first carrier class and the second carrier class, the target carrier object can include the first carrier object determined based on the first carrier class and the second carrier object determined based on the second carrier class, the written carrier object can include the first carrier object written to the model structure of the target model and the second carrier object written to the model weights of the target model, and the carrier class determination model can be a model constructed based on the Deep Q-learning (DQN) algorithm.
[0072] In S218, perform encoding processing on the model structure of the target model to obtain the encoded model structure, and based on the pre-trained carrier class determination model and the encoded model structure, determine the first carrier class corresponding to the encoded model structure in the candidate carrier classes.
[0073] In implementation, the model structure of the target model can be encoded based on a preset encoding rule to obtain the encoded model structure. For example, assuming that the preset encoding rule is to encode based on the type, number of layers, number of input channels, and number of output channels of the target model. If the model structure of the target model is a 3*3 convolutional layer, there are 128 input channels, and 156 output channels, then the encoded model structure of the target model can be 0001030301280256, where 0001 indicates that the target model is a convolutional model, 0303 indicates that the number of layers of the target model is 3*3, 0128 indicates that the target model has 128 input channels, and 0256 can indicate that the target model has 256 output channels.
[0074] The above method for encoding the model structure of the target model is an optional and implementable method. In actual application scenarios, there can be various different methods, which can vary according to different actual application scenarios. The embodiments of this specification do not make specific limitations on this.
[0075] The model and the encoded model structure can be determined based on the pre-trained carrier class, and the first carrier class corresponding to the encoded model structure in the candidate carrier classes can be determined.
[0076] In S220, the model and the model weights of the target model are determined based on the pre-trained carrier class, and the second carrier class corresponding to the model weights of the target model in the candidate carrier classes is determined.
[0077] In implementation, since the model weights themselves are data information, the model weights can be directly input into the pre-trained carrier class determination model to determine the second carrier class corresponding to the model weights of the target model in the candidate carrier classes, without the need to encode the model weights.
[0078] In addition, if the target model is large, a carrier class can be determined for the model weights of each layer of the target model, that is, the second carrier class can include multiple subclasses. The model weights of each layer of the target model can be separately input into the pre-trained carrier class determination model to obtain the subclasses corresponding to the model weights of each layer.
[0079] In addition, there can be various methods for determining the subclasses in the above-mentioned second carrier class. For example, the model weights of the target model can be clustered to obtain multiple weight classes, and then based on the pre-trained carrier class determination model, the subclasses corresponding to each weight class can be determined, etc. Different determination methods can be selected according to different actual scenarios. The embodiments of this specification do not make specific limitations on this.
[0080] In S222, based on the pre-trained carrier object determination model, determine the first carrier object in the first carrier class corresponding to the encoded model structure.
[0081] In S224, based on the pre-trained carrier object determination model, determine the second carrier object in the second carrier class corresponding to the model weights of the target model.
[0082] In implementation, if the second carrier class includes multiple subclasses, and each subclass is determined by the model weights of each layer of the target model, then based on the pre-trained carrier object determination model, determine the second carrier object in each subclass corresponding to the model weights of each layer of the target model.
[0083] In S226, obtain the second model and the third carrier class.
[0084] Among them, the model data of the second model may include the model structure and / or model weights of the second model.
[0085] In S228, based on the pre-trained carrier class determination model, determine the fourth carrier class in the third carrier class corresponding to the second model.
[0086] In S230, based on the pre-trained carrier object determination model, determine the fourth carrier object in the fourth carrier class corresponding to the second model.
[0087] In S232, based on the second model, the fourth carrier object, and the preset feature extraction model, train the steganographic model and the second extraction model to obtain the trained steganographic model.
[0088] In implementation, to improve the steganographic effect of the steganographic model, the fourth carrier object corresponding to the second model can be determined through the pre-trained carrier class determination model and the pre-trained carrier object determination model. In this way, the steganographic model can be trained through the second model and the fourth carrier object.
[0089] In addition, in practical applications, the processing method of the above S232 can be various. The following provides an optional implementation method, which can specifically refer to the processing of the following steps 1 to 5:
[0090] Step 1, input the model data of the second model and the fourth carrier object into the steganographic model to obtain the written fourth carrier object.
[0091] Step 2, input the written fourth carrier object into the second extraction model to obtain the extracted model data.
[0092] Step 3: Input the fourth carrier object and the fourth carrier object after writing into the preset feature extraction model respectively to obtain the feature vector of the fourth carrier object and the feature vector of the fourth carrier object after writing.
[0093] Step 4: Based on the preset loss function, the fourth carrier object, the fourth carrier object after writing, the model data of the second model, the extracted model data, the feature vector of the fourth carrier object, and the feature vector of the fourth carrier object after writing, determine the model loss value.
[0094] In implementation, the first sub-loss value can be determined based on the fourth carrier object and the fourth carrier object after writing, the second sub-loss value can be determined based on the model data of the second model and the extracted model data, and then the third sub-loss value can be determined based on the feature vector of the fourth carrier object and the feature vector of the fourth carrier object after writing. Finally, the model loss value can be determined based on the first sub-loss value, the second sub-loss value, and the third sub-loss value.
[0095] For example, the first sub-loss value, the second sub-loss value, and the third sub-loss value can be substituted into the following formula
[0096] L total = L consistency-image + L recover + L consistency-feature
[0097] to obtain the model loss value, where L total is the model loss value, L consistency-image is the first sub-loss value, L recover is the second sub-loss value, and L consistency-fenture is the third sub-loss value.
[0098] In this way, the consistency of the carrier object before and after steganography can be constrained by the first sub-loss value, the accuracy of the written data obtained by recovery can be constrained by the second sub-loss value, and the consistency of the carrier object before and after the writing process can be constrained by the third sub-loss value.
[0099] Step 5: Based on the model loss value, determine whether the steganography model and the second extraction model converge. If they do not converge, the steganography model and the second extraction model can be continuously trained based on the model data of the second model and the fourth carrier object until the steganography model and the second extraction model converge to obtain the trained steganography model.
[0100] In S108, based on the pre-trained steganography model, write the model weights and model structure of the target model to be steganographed into the target carrier object to obtain the carrier object after writing, and send the carrier object after writing to the target device.
[0101] Among them, the carrier object after writing can be used to trigger the target device to obtain a target model based on the carrier object after writing, so as to process the target service based on the target model.
[0102] An embodiment of this specification provides a data processing method, which includes obtaining a target model to be steganographed, determining a model based on a pre-trained carrier category, determining a target carrier category corresponding to the target model in a candidate carrier category. The carrier category determination model can be trained by a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier categories and a first reward value determined by selecting any action in the first action set during the reinforcement learning process. The first reward value is determined by the loss value of writing the carrier object in each historical carrier category to the historical model. Based on a pre-trained carrier object determination model, a target carrier object corresponding to the target model in the target carrier category is determined. The carrier object determination model can be trained by a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value determined by selecting any action in the second action set during the reinforcement learning process. The second reward value can be determined by the loss value of writing the carrier object in each historical carrier object to the historical model. Based on a pre-trained steganography model, the model weights and model structure of the target model to be steganographed are written into the target carrier object to obtain a carrier object after writing, and the carrier object after writing is sent to the target device. The carrier object after writing is used to trigger the target device to obtain a target model based on the carrier object after writing, so as to process the target service based on the target model. In this way, based on the pre-trained carrier category determination model, the target carrier category corresponding to the target model can be determined, and based on the pre-trained carrier object determination model, the target carrier object corresponding to the target model in the target carrier category can be determined, which can improve the determination accuracy and efficiency of the target carrier object used for writing the target model. Then, through the pre-trained carrier object determination model, the model weights and model structure of the target model to be steganographed are written into the target carrier object, which can improve the steganography effect and efficiency of the model in the model steganography scenario.
[0103] Embodiment III
[0104] As Figure 3A and 3B As shown, an embodiment of this specification provides a data processing method. The execution subject of this method can be a target device, and the target device can be a server. Among them, the server can be an independent server or a server cluster composed of multiple servers. The method can specifically include the following steps:
[0105] In S302, receive the carrier object after writing sent by the server.
[0106] Among them, the written carrier object can be obtained by the server writing the model weights and model structure of the target model to be steganographed into the target carrier object based on a pre-trained steganography model. The target carrier object can be the carrier object corresponding to the target model in the target carrier class determined by the server based on the pre-trained carrier object determination model. The target carrier class can be the carrier class corresponding to the target model in the candidate carrier classes determined by the server based on the pre-trained carrier class determination model. The carrier class determination model can be trained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes and a first reward value obtained by determining to select any action in the first action set during the reinforcement learning process. The first reward value can be determined by the loss value of the carrier object in each historical carrier class for writing to the historical model. The carrier object determination model can be trained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value obtained by determining to select any action in the second action set during the reinforcement learning process. The second reward value can be determined by the loss value of the carrier object in each historical carrier object for writing to the historical model.
[0107] In S304, based on a preset extraction model, the written carrier object is extracted to obtain the model weights and model structure of the target model.
[0108] Among them, the preset extraction model can be the trained extraction model sent by the server, and this extraction model can be the extraction model used for training the steganography model and the second extraction model in the second embodiment above.
[0109] In implementation, the target device can also receive the extraction model sent by the server and perform extraction processing on the written carrier object based on this extraction model to obtain the model weights of the target model and the model structure of the target model.
[0110] In addition, if the carrier object includes a first carrier object and a second carrier object, and the written carrier object includes the first carrier object for writing the model structure of the target model and the second carrier object for writing the model weights of the target model, then the target device can perform extraction processing on the first carrier object and the second carrier object based on the extraction model to obtain the model structure and model weights of the target model.
[0111] If the model structure of the obtained template model is the encoded model structure obtained by the server through encoding processing based on a preset encoding rule, the target device can determine the model structure of the target model according to the preset encoding rule sent by the server, and then can input the obtained model weights into the model structure to obtain the target model.
[0112] In S306, based on the model weights and model structure of the target model, determine the target model, and process the target service based on the target model.
[0113] An embodiment of this specification provides a data processing method. Receive the written carrier object sent by the server. The written carrier object is obtained by the server writing the model weights and model structure of the target model to be steganographed into the target carrier object based on a pre-trained steganography model. The target carrier object is the carrier object corresponding to the target model in the target carrier class determined by the server based on the pre-trained carrier object determination model. The target carrier class is the carrier class corresponding to the target model in the candidate carrier classes determined by the server based on the pre-trained carrier class determination model. The carrier class determination model is obtained by training a model constructed by a reinforcement learning algorithm based on the first action set determined by historical carrier classes and the first reward value obtained by determining to select any action in the first action set during the reinforcement learning process. The first reward value is determined by the loss value of the carrier object in each historical carrier class for writing to the historical model. The carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on the second action set determined by historical carrier objects and the second reward value obtained by determining to select any action in the second action set during the reinforcement learning process. The second reward value is determined by the loss value of the carrier object in each historical carrier object for writing to the historical model. Perform extraction processing on the written carrier object based on a preset extraction model to obtain the model weights and model structure of the target model. Based on the model weights and model structure of the target model, determine the target model, and process the target service based on the target model. In this way, since the server determines the target carrier class corresponding to the target model based on the pre-trained carrier class determination model, and then determines the target carrier object corresponding to the target model in the target carrier class determined by the pre-trained carrier object determination model, the accuracy and efficiency of determining the target carrier object for writing the target model can be improved. The server then writes the model weights and model structure of the target model to be steganographed into the target carrier object through the pre-trained carrier object determination model, which can improve the steganography effect and steganography efficiency of the model in the model steganography scenario. The target device can then process the target service based on the obtained target model, improving the service processing efficiency and accuracy.
[0114] Embodiment 4
[0115] An embodiment of this specification provides a data processing system, which includes a server and a target device. The server can be a server, where the server can be an independent server or a server cluster composed of multiple servers. The target device can be a server, where the server can be an independent server or a server cluster composed of multiple servers. The method can specifically include the following steps:
[0116] The server can be used to obtain a first model and a third carrier object. The model data of the first model can include the model structure and / or model weights of the first model. Based on the model data of the first model, the third carrier object, and a preset feature extraction model, train a first steganographic model and a first extraction model to obtain the trained first steganographic model and the trained first extraction model. Then, based on the trained first steganographic model, the trained first extraction model, and the preset feature extraction model, determine the loss value of writing the historical model by the historical carrier object pair corresponding to each historical carrier class.
[0117] In addition, the server can also pre-train a steganographic model and a second extraction model based on the first model, the third carrier object, and the preset feature extraction model to obtain the pre-trained steganographic model and the pre-trained second extraction model.
[0118] Among them, the first steganographic model and the first extraction model can be lightweight models, and the steganographic model and the second extraction model can be standard models. That is, the model structures of the first steganographic model and the steganographic model can be the same, but the number of channels in each layer of the first steganographic model can be less than that in each layer of the steganographic model. For example, the model structures of both the first steganographic model and the steganographic model can be a 16-layer UNET, and the number of channels in each layer of the first steganographic model is only 1 / 4 of that in each layer of the steganographic model, that is, the computational amount of the first steganographic model is only 1 / 16 of that of the steganographic model.
[0119] After obtaining the trained first steganographic model and the trained first extraction model, the server can cluster the historical carrier objects based on the feature vectors of the historical carrier objects to obtain historical carrier classes. Each historical carrier class corresponds to one or more historical carrier objects. Based on the distance between the feature vectors of every two historical carrier classes, determine a target distance matrix, and based on the target distance matrix, determine a first action set. Based on the loss value of writing the historical model by the historical carrier object corresponding to each historical carrier class, determine the first reward value brought by selecting any action in the first action set during the reinforcement learning process. Based on the first action set and the first reward value, train a carrier class determination model to obtain the trained carrier class determination model.
[0120] Similarly, the server can determine a model based on the trained carrier category, determine the carrier category corresponding to the historical model in the historical carrier categories, and then train the carrier object determination model based on the historical model and the historical carrier objects in the carrier category corresponding to the historical model to obtain the trained carrier object determination model. The training process of the carrier object determination model can refer to the above-mentioned training process of the carrier category determination model and will not be elaborated here.
[0121] After the server obtains the trained carrier category determination model and the trained carrier object determination model, it can obtain the second model and the third carrier category, then determine the fourth carrier category corresponding to the second model in the third carrier category based on the pre-trained carrier category determination model, and determine the fourth carrier object corresponding to the second model in the fourth carrier category based on the pre-trained carrier object determination model. Finally, based on the second model, the fourth carrier object, and the preset feature extraction model, train the pre-trained steganography model and the pre-trained second extraction model to obtain the trained steganography model.
[0122] The server is also used to obtain the target model to be steganographed; determine the target carrier category corresponding to the target model in the candidate carrier categories based on the pre-trained carrier category determination model, determine the target carrier object corresponding to the target model in the target carrier category based on the pre-trained carrier object determination model, write the model weights and model structure of the target model to be steganographed into the target carrier object based on the pre-trained steganography model to obtain the written carrier object, and send the written carrier object to the target device.
[0123] Since the number of carrier objects available for model training is limited, as Figure 4 shown, the server can first pre-train the steganography model (i.e., the above-mentioned standard model and lightweight model), then train the carrier category determination model through the lightweight model, and train the carrier object determination model based on the trained carrier type determination model. Then, the steganography model can be optimized through the carrier type determination model and the carrier object determination model.
[0124] The target device is used to perform extraction processing on the written carrier object based on the preset extraction model to obtain the model weights and model structure of the target model, then determine the target model based on the model weights and model structure of the target model, and process the target service based on the target model.
[0125] An embodiment of this specification provides a data processing system, which can determine a model based on a pre-trained carrier category, determine a target carrier category corresponding to the target model, and then determine a target carrier object corresponding to the target model in the target carrier category based on a pre-trained carrier object determination model, which can improve the determination accuracy and efficiency of the target carrier object used for the write processing of the target model. Then, through the pre-trained carrier object determination model, the model weights and model structure of the target model to be steganographed are written into the target carrier object, which can improve the steganography effect and steganography efficiency of the model in the model steganography scenario.
[0126] Embodiment 5
[0127] The above is the data processing method provided by the embodiments of this specification. Based on the same idea, the embodiments of this specification also provide a data processing device, as Figure 5 shown.
[0128] The data processing device includes: a model acquisition module 501, a class determination module 502, an object determination module 503, and a data sending module 504, where:
[0129] The model acquisition module 501 is configured to acquire a target model to be steganographed;
[0130] The class determination module 502 is configured to determine a target carrier class corresponding to the target model in the candidate carrier classes based on a pre-trained carrier class determination model. The carrier class determination model is trained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes and a first reward value determined by selecting any action in the first action set during the reinforcement learning process. The first reward value is determined by the loss value of writing the historical model by the carrier object in each historical carrier class;
[0131] The object determination module 503 is configured to determine a target carrier object corresponding to the target model in the target carrier class based on a pre-trained carrier object determination model. The carrier object determination model is trained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value determined by selecting any action in the second action set during the reinforcement learning process. The second reward value is determined by the loss value of writing the historical model by each historical carrier object;
[0132] A data sending module 504, configured to write the model weights and model structure of the target model to be steganographed into the target carrier object based on a pre-trained steganography model, obtain the carrier object after writing, and send the carrier object after writing to a target device. The carrier object after writing is used to trigger the target device to obtain the target model based on the carrier object after writing, so as to process a target service based on the target model.
[0133] In an embodiment of the present specification, the target carrier class includes a first carrier class and a second carrier class. The target carrier object includes a first carrier object determined based on the first carrier class and a second carrier object determined based on the second carrier class. The carrier object after writing includes a first carrier object written with the model structure of the target model and a second carrier object written with the model weights of the target model.
[0134] In an embodiment of the present specification, the class determination module 502 is configured to:
[0135] Perform encoding processing on the model structure of the target model to obtain an encoded model structure, and determine, based on the pre-trained carrier class determination model and the encoded model structure, a first carrier class corresponding to the encoded model structure in the candidate carrier classes;
[0136] Determine, based on the pre-trained carrier class determination model and the model weights of the target model, a second carrier class corresponding to the model weights of the target model in the candidate carrier classes;
[0137] The object determination module 503 includes:
[0138] Determine, based on the pre-trained carrier object determination model, a first carrier object corresponding to the encoded model structure in the first carrier class;
[0139] Determine, based on the pre-trained carrier object determination model, a second carrier object corresponding to the model weights of the target model in the second carrier class.
[0140] In an embodiment of the present specification, the apparatus further includes:
[0141] A first acquisition module, configured to acquire a historical carrier object and the historical model;
[0142] A clustering module, configured to perform clustering processing on the historical carrier objects based on the feature vectors of the historical carrier objects to obtain the historical carrier classes, and each historical carrier class corresponds to one or more of the historical carrier objects;
[0143] A set determination module, configured to determine a target distance matrix based on the distances between the feature vectors of every two of the historical carrier classes, and determine the first action set based on the target distance matrix;
[0144] A reward determination module, configured to determine a first reward value brought by selecting any action in the first action set during the reinforcement learning process based on the loss value of writing the historical carrier object corresponding to each historical carrier class into the historical model;
[0145] A first training module, configured to train the carrier class determination model based on the first action set and the first reward value to obtain a trained carrier class determination model.
[0146] In an embodiment of the present specification, the apparatus further includes:
[0147] A second acquisition module, configured to acquire a first model and a third carrier object, where the model data of the first model includes the model structure and / or model weights of the first model;
[0148] A second training module, configured to train a first steganography model and a first extraction model based on the model data of the first model, the third carrier object, and a preset feature extraction model to obtain trained first steganography and first extraction models;
[0149] A loss determination module, configured to determine the loss value of writing the historical carrier object corresponding to each historical carrier class into the historical model based on the trained first steganography model, the trained first extraction model, and the preset feature extraction model.
[0150] In an embodiment of the present specification, the apparatus further includes:
[0151] A third acquisition module, configured to acquire a second model and a third carrier class;
[0152] A first determination module, configured to determine a fourth carrier class corresponding to the second model in the third carrier class based on the pre-trained carrier class determination model;
[0153] A second determination module, configured to determine a fourth carrier object corresponding to the second model in the fourth carrier class based on the pre-trained carrier object determination model;
[0154] A third training module, configured to train the steganography model and a second extraction model based on the second model, the fourth carrier object, and the preset feature extraction model to obtain a trained steganography model.
[0155] In an embodiment of the present specification, the third training module is configured to:
[0156] Input the model data of the second model and the fourth carrier object into the steganographic model to obtain the written fourth carrier object;
[0157] Input the written fourth carrier object into the second extraction model to obtain the extracted model data;
[0158] Input the fourth carrier object and the written fourth carrier object into the preset feature extraction model respectively to obtain the feature vector of the fourth carrier object and the feature vector of the written fourth carrier object;
[0159] Based on the preset loss function, the fourth carrier object, the written fourth carrier object, the model data of the second model, the extracted model data, the feature vector of the fourth carrier object, and the feature vector of the written fourth carrier object, determine the model loss value;
[0160] Based on the model loss value, determine whether the steganographic model and the second extraction model converge. If not, continue to train the steganographic model and the second extraction model based on the model data of the second model and the fourth carrier object until the steganographic model and the second extraction model converge to obtain the trained steganographic model.
[0161] In the embodiments of this specification, the third training module is used for:
[0162] Based on the fourth carrier object and the written fourth carrier object, determine the first sub-loss value;
[0163] Based on the model data of the second model and the extracted model data, determine the second sub-loss value;
[0164] Based on the feature vector of the fourth carrier object and the feature vector of the written fourth carrier object, determine the third sub-loss value;
[0165] Based on the first sub-loss value, the second sub-loss value, and the third sub-loss value, determine the model loss value.
[0166] An embodiment of this specification provides a data processing device, which obtains a target model to be steganographed, determines a model based on a pre-trained carrier category, and determines a target carrier category corresponding to the target model in a candidate carrier category. The carrier category determination model can be obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier categories and a first reward value determined by selecting any action in the first action set during the reinforcement learning process. The first reward value is determined by the loss value of writing a carrier object in each historical carrier category to a historical model. Based on a pre-trained carrier object determination model, a target carrier object corresponding to the target model in the target carrier category is determined. The carrier object determination model can be obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value determined by selecting any action in the second action set during the reinforcement learning process. The second reward value can be determined by the loss value of writing a historical carrier object to a historical model. Based on a pre-trained steganography model, the model weights and model structure of the target model to be steganographed are written into the target carrier object to obtain a written carrier object, and the written carrier object is sent to a target device. The written carrier object is used to trigger the target device to obtain the target model based on the written carrier object, so as to process a target service based on the target model. In this way, based on the pre-trained carrier category determination model, the target carrier category corresponding to the target model can be determined, and based on the pre-trained carrier object determination model, the target carrier object corresponding to the target model in the target carrier category can be determined, which can improve the determination accuracy and efficiency of the target carrier object used for writing the target model. Then, through the pre-trained carrier object determination model, the model weights and model structure of the target model to be steganographed are written into the target carrier object, which can improve the steganography effect and efficiency of the model in the model steganography scenario.
[0167] Embodiment Six
[0168] The above is the data processing method provided by the embodiments of this specification. Based on the same idea, the embodiments of this specification also provide a data processing device, as Figure 6 shown.
[0169] The data processing device includes: a data acquisition module 601, an extraction module 602, and a service processing module 603, where:
[0170] A data acquisition module 601, configured to receive the written carrier object sent by the server. The written carrier object is obtained by the server writing the model weights and model structure of the target model to be steganographed into the target carrier object based on a pre-trained steganography model. The target carrier object is the carrier object corresponding to the target model in the target carrier class determined by the server based on the pre-trained carrier object determination model. The target carrier class is the carrier class corresponding to the target model in the candidate carrier classes determined by the server based on the pre-trained carrier class determination model. The carrier class determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes and a first reward value determined by selecting any action in the first action set during the reinforcement learning process. The first reward value is determined by the loss value of the carrier object in each historical carrier class for writing to the historical model. The carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value determined by selecting any action in the second action set during the reinforcement learning process. The second reward value is determined by the loss value of each historical carrier object for writing to the historical model;
[0171] An extraction module 602, configured to perform extraction processing on the written carrier object based on a preset extraction model to obtain the model weights and model structure of the target model;
[0172] A service processing module 603, configured to determine the target model based on the model weights and model structure of the target model, and process the target service based on the target model.
[0173] An embodiment of this specification provides a data processing device, which receives the written carrier object sent by the server. The written carrier object is obtained by the server writing the model weights and model structure of the target model to be steganographed into the target carrier object based on a pre-trained steganography model. The target carrier object is the carrier object corresponding to the target model in the target carrier class determined by the server based on the pre-trained carrier object determination model. The target carrier class is the carrier class corresponding to the target model in the candidate carrier classes determined by the server based on the pre-trained carrier class determination model. The carrier class determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes and a first reward value determined by selecting any action in the first action set during the reinforcement learning process. The first reward value is determined by the loss value of writing the carrier object in each historical carrier class to the historical model. The carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value determined by selecting any action in the second action set during the reinforcement learning process. The second reward value is determined by the loss value of writing the carrier object in each historical carrier object to the historical model. The written carrier object is extracted based on a preset extraction model to obtain the model weights and model structure of the target model. Based on the model weights and model structure of the target model, the target model is determined, and the target service is processed based on the target model. In this way, since the server determines the target carrier class corresponding to the target model based on the pre-trained carrier class determination model, and then determines the target carrier object corresponding to the target model in the target carrier class determined by the pre-trained carrier object determination model, the determination accuracy and efficiency of the target carrier object used for writing the target model can be improved. The server then writes the model weights and model structure of the target model to be steganographed into the target carrier object through the pre-trained carrier object determination model, which can improve the steganography effect and efficiency of the model in the model steganography scenario. The target device can then process the target service based on the obtained target model, improving the service processing efficiency and accuracy.
[0174] Embodiment 7
[0175] Based on the same idea, an embodiment of this specification also provides a data processing device, as Figure 7 shown.
[0176] Data processing devices can vary significantly due to differences in configuration or performance. They can include one or more processors 701 and a memory 702. The memory 702 can store one or more application programs or data. Among them, the memory 702 can be transient storage or persistent storage. The application programs stored in the memory 702 can include one or more modules (not shown in the figure), and each module can include a series of computer-executable instructions for the data processing device. Further, the processor 701 can be set to communicate with the memory 702 and execute a series of computer-executable instructions in the memory 702 on the data processing device. The data processing device can also include one or more power supplies 703, one or more wired or wireless network interfaces 704, one or more input / output interfaces 705, and one or more keyboards 706.
[0177] Specifically, in this embodiment, the data processing device includes a memory and one or more programs. One or more of the programs are stored in the memory, and one or more of the programs can include one or more modules. Each module can include a series of computer-executable instructions for the data processing device and is configured to be executed by one or more processors. The one or more programs include the following computer-executable instructions for:
[0178] Obtain the target model to be steganographed;
[0179] Based on a pre-trained carrier class determination model, determine the target carrier class in the candidate carrier classes corresponding to the target model. The carrier class determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes and a first reward value determined in the reinforcement learning process for selecting any action in the first action set. The first reward value is determined by the loss value of the carrier objects in each historical carrier class for writing to the historical model;
[0180] Based on a pre-trained carrier object determination model, determine the target carrier object in the target carrier class corresponding to the target model. The carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value determined in the reinforcement learning process for selecting any action in the second action set. The second reward value is determined by the loss value of each historical carrier object for writing to the historical model;
[0181] Based on a pre-trained steganography model, write the model weights and model structure of the target model to be steganographed into the target carrier object to obtain the written carrier object, and send the written carrier object to the target device. The written carrier object is used to trigger the target device to obtain the target model based on the written carrier object, so as to process the target service based on the target model.
[0182] Optionally, the target carrier class includes a first carrier class and a second carrier class. The target carrier object includes a first carrier object determined based on the first carrier class and a second carrier object determined based on the second carrier class. The written carrier object includes the first carrier object into which the model structure of the target model is written, and the second carrier object into which the model weights of the target model are written.
[0183] Optionally, the determining, based on a pre-trained carrier class determination model, of the target carrier class corresponding to the target model in the candidate carrier classes includes:
[0184] Perform an encoding process on the model structure of the target model to obtain the encoded model structure, and based on the pre-trained carrier class determination model and the encoded model structure, determine the first carrier class corresponding to the encoded model structure in the candidate carrier classes;
[0185] Based on the pre-trained carrier class determination model and the model weights of the target model, determine the second carrier class corresponding to the model weights of the target model in the candidate carrier classes;
[0186] The determining, based on a pre-trained carrier object determination model, of the target carrier object corresponding to the target model in the target carrier class includes:
[0187] Based on the pre-trained carrier object determination model, determine the first carrier object corresponding to the encoded model structure in the first carrier class;
[0188] Based on the pre-trained carrier object determination model, determine the second carrier object corresponding to the model weights of the target model in the second carrier class.
[0189] Optionally, before the determining, based on a pre-trained carrier class determination model, of the target carrier class corresponding to the target model in the candidate carrier classes, it further includes:
[0190] Obtain the historical carrier object and the historical model;
[0191] Perform clustering processing on the historical carrier objects based on the feature vectors of the historical carrier objects to obtain the historical carrier classes, and each of the historical carrier classes corresponds to one or more of the historical carrier objects;
[0192] Determine a target distance matrix based on the distances between the feature vectors of every two of the historical carrier classes, and determine the first action set based on the target distance matrix;
[0193] Determine the first return value brought by selecting any action in the first action set during the reinforcement learning process based on the loss value of writing the historical carrier objects corresponding to each historical carrier class into the historical model;
[0194] Train the carrier category determination model based on the first action set and the first return value to obtain a trained carrier category determination model.
[0195] Optionally, before the loss value of writing the historical carrier objects corresponding to each historical carrier class into the historical model, it further includes:
[0196] Obtain a first model and a third carrier object, and the model data of the first model includes the model structure and / or model weights of the first model;
[0197] Train a first steganography model and a first extraction model based on the model data of the first model, the third carrier object, and a preset feature extraction model to obtain a trained first steganography model and a trained first extraction model;
[0198] Determine the loss value of writing the historical carrier objects corresponding to each historical carrier class into the historical model based on the trained first steganography model, the trained first extraction model, and the preset feature extraction model.
[0199] Optionally, before writing the model weights and model structure of the target model to be steganographed into the target carrier object based on the pre-trained steganography model to obtain a written carrier object, it further includes:
[0200] Obtain a second model and a third carrier class;
[0201] Determine a fourth carrier class corresponding to the second model in the third carrier class based on the pre-trained carrier category determination model;
[0202] Determine a fourth carrier object corresponding to the second model in the fourth carrier class based on the pre-trained carrier object determination model;
[0203] Based on the second model, the fourth carrier object, and the preset feature extraction model, train the steganography model and the second extraction model to obtain the trained steganography model.
[0204] Optionally, the training of the steganography model and the second extraction model based on the second model, the fourth carrier object, and the preset feature extraction model to obtain the trained steganography model includes:
[0205] Input the model data of the second model and the fourth carrier object into the steganography model to obtain the written fourth carrier object;
[0206] Input the written fourth carrier object into the second extraction model to obtain the extracted model data;
[0207] Input the fourth carrier object and the written fourth carrier object into the preset feature extraction model respectively to obtain the feature vector of the fourth carrier object and the feature vector of the written fourth carrier object;
[0208] Based on the preset loss function, the fourth carrier object, the written fourth carrier object, the model data of the second model, the extracted model data, the feature vector of the fourth carrier object, and the feature vector of the written fourth carrier object, determine the model loss value;
[0209] Based on the model loss value, determine whether the steganography model and the second extraction model converge. If not, continue to train the steganography model and the second extraction model based on the model data of the second model and the fourth carrier object until the steganography model and the second extraction model converge to obtain the trained steganography model.
[0210] Optionally, the determining of the model loss value based on the preset loss function, the fourth carrier object, the written fourth carrier object, the model data of the second model, the extracted model data, the feature vector of the fourth carrier object, and the feature vector of the written fourth carrier object includes:
[0211] Based on the fourth carrier object and the written fourth carrier object, determine the first sub-loss value;
[0212] Based on the model data of the second model and the extracted model data, determine the second sub-loss value;
[0213] Based on the feature vector of the fourth carrier object and the feature vector of the written fourth carrier object, determine the third sub-loss value;
[0214] Determine the model loss value based on the first sub-loss value, the second sub-loss value, and the third sub-loss value.
[0215] In addition, specifically in this embodiment, the data processing device includes a memory and one or more programs. One or more of the programs are stored in the memory, and one or more of the programs may include one or more modules. Each module may include a series of computer-executable instructions in the data processing device and is configured to be executed by one or more processors. The one or more programs include the following computer-executable instructions for:
[0216] Receive the written carrier object sent by the server. The written carrier object is obtained by the server writing the model weights and model structure of the target model to be steganographed into the target carrier object based on a pre-trained steganography model. The target carrier object is the carrier object corresponding to the target model in the target carrier class determined by the server based on the pre-trained carrier object determination model. The target carrier class is the carrier class corresponding to the target model in the candidate carrier classes determined by the server based on the pre-trained carrier class determination model. The carrier class determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes and a first return value determined by selecting any action in the first action set during the reinforcement learning process. The first return value is determined by the loss value of writing the carrier object in each historical carrier class to the historical model. The carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second return value determined by selecting any action in the second action set during the reinforcement learning process. The second return value is determined by the loss value of writing each historical carrier object to the historical model.
[0217] Perform extraction processing on the written carrier object based on a preset extraction model to obtain the model weights and model structure of the target model.
[0218] Determine the target model based on the model weights and model structure of the target model, and process the target service based on the target model.
[0219] An embodiment of this specification provides a data processing device. It can determine a model based on a pre-trained carrier category, determine a target carrier category corresponding to the target model, and then determine a target carrier object corresponding to the target model in the target carrier category based on a pre-trained carrier object determination model. This can improve the determination accuracy and efficiency of the target carrier object used for the write processing of the target model. Then, through the pre-trained carrier object determination model, the model weights and model structure of the target model to be steganographed are written into the target carrier object, which can improve the steganography effect and steganography efficiency of the model in the model steganography scenario.
[0220] Embodiment Seven
[0221] An embodiment of this specification also provides a computer-readable storage medium. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, it implements each process of the above data processing method embodiment and can achieve the same technical effect. To avoid repetition, it will not be elaborated here. Among them, the computer-readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc, etc.
[0222] An embodiment of this specification provides a computer-readable storage medium, which obtains a target model to be steganographed, determines a model based on a pre-trained carrier category, and determines a target carrier category corresponding to the target model in a candidate carrier category. The carrier category determination model can be trained by a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier categories and a first reward value determined by selecting any action in the first action set during the reinforcement learning process. The first reward value is determined by the loss value of writing the carrier object in each historical carrier category to the historical model. Based on a pre-trained carrier object determination model, a target carrier object corresponding to the target model in the target carrier category is determined. The carrier object determination model can be trained by a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value determined by selecting any action in the second action set during the reinforcement learning process. The second reward value can be determined by the loss value of writing the carrier object in each historical carrier object to the historical model. Based on a pre-trained steganography model, the model weights and model structure of the target model to be steganographed are written into the target carrier object to obtain a written carrier object, and the written carrier object is sent to the target device. The written carrier object is used to trigger the target device to obtain the target model based on the written carrier object, so as to process the target service based on the target model. In this way, based on the pre-trained carrier category determination model, the target carrier category corresponding to the target model can be determined, and based on the pre-trained carrier object determination model, the target carrier object corresponding to the target model in the target carrier category can be determined, which can improve the determination accuracy and efficiency of the target carrier object for writing the target model. Then, through the pre-trained carrier object determination model, the model weights and model structure of the target model to be steganographed are written into the target carrier object, which can improve the steganography effect and steganography efficiency of the model in the model steganography scenario.
[0223] The above describes specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be performed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain implementations, multitasking and parallel processing are also possible or may be advantageous.
[0224] In the 1990s, it was obvious to distinguish whether an improvement in a technology was an improvement in hardware (e.g., improvement in circuit structures such as diodes, transistors, switches, etc.) or an improvement in software (improvement in method processes). However, with the development of technology, many improvements in method processes today can be regarded as direct improvements in hardware circuit structures. Almost all designers obtain the corresponding hardware circuit structures by programming the improved method processes into the hardware circuits. Therefore, it cannot be said that an improvement in a method process cannot be implemented with a hardware entity module. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logical function is determined by the user's programming of the device. Designers can program themselves to "integrate" a digital system on a single PLD, without having to ask a chip manufacturer to design and fabricate a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly implemented using "logic compiler" software, which is similar to the software compiler used in program development and writing. The original code before compilation also has to be written in a specific programming language, which is called a Hardware Description Language (HDL), and there is not only one kind of HDL, but many kinds, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used ones currently are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art should also be clear that by simply making a little logical programming of the method process with the above-mentioned several hardware description languages and programming it into an integrated circuit, it is easy to obtain the hardware circuit that implements the logical method process.
[0225] The controller can be implemented in any suitable manner. For example, the controller can take the form of, for example, a microprocessor or a processor and a computer-readable medium storing computer-readable program code (such as software or firmware) executable by the (micro)processor, logic gates, switches, an application specific integrated circuit (ASIC), a programmable logic controller, and an embedded microcontroller. Examples of the controller include, but are not limited to, the following microcontrollers: ARC625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art also know that in addition to implementing the controller in the form of pure computer-readable program code, it is entirely possible to logically program the method steps to enable the controller to be implemented in the form of logic gates, switches, application specific integrated circuits, programmable logic controllers, embedded microcontrollers, etc. to achieve the same function. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be regarded as the structures within the hardware component. Or even, the devices for implementing various functions can be regarded as either software modules for implementing the method or structures within the hardware component.
[0226] The systems, devices, modules, or units illustrated in the above embodiments can be specifically implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, the computer can be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or any combination of these devices.
[0227] For the convenience of description, when describing the above devices, they are described separately as various units according to their functions. Of course, when implementing one or more embodiments of this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0228] Those skilled in the art should understand that the embodiments of this specification can be provided as a method, a system, or a computer program product. Therefore, one or more embodiments of this specification can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, one or more embodiments of this specification can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) containing computer-usable program code.
[0229] Embodiments of this specification are described with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this specification. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to the processors of general-purpose computers, special-purpose computers, embedded processors, or other programmable data processing devices to produce a machine, such that the instructions executed by the processors of the computer or other programmable data processing devices produce means for implementing the functions specified in one or more flows of the flowchart and / or one or more blocks of the block diagram.
[0230] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory produce a manufactured article including instruction means for implementing the functions specified in one or more flows of the flowchart and / or one or more blocks of the block diagram.
[0231] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to produce a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more flows of the flowchart and / or one or more blocks of the block diagram.
[0232] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.
[0233] The memory may include non-permanent memory in the form of computer-readable media, random access memory (RAM), and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of computer-readable media.
[0234] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0235] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0236] It should be understood by those skilled in the art that the embodiments of this specification may be provided as methods, systems or computer program products. Therefore, one or more embodiments of this specification may take the form of a complete hardware embodiment, a complete software embodiment or an embodiment combining software and hardware. Moreover, one or more embodiments of this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program codes.
[0237] One or more embodiments of the present specification may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. One or more embodiments of the present specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.
[0238] The various embodiments in this specification are described in a progressive manner. For the same or similar parts among the various embodiments, reference can be made to each other, and the key point of each embodiment is to illustrate the differences from other embodiments. In particular, for the system embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and for the relevant parts, reference can be made to the partial description of the method embodiments.
[0239] The above is only the embodiments of this specification and is not intended to limit this specification. For those skilled in the art, various modifications and changes can be made to this specification. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this specification shall be included within the scope of the claims of this specification.
Claims
1. A data processing method, comprising: Obtaining a target model to be steganographed; Based on a pre-trained carrier category determination model, determining a target carrier category corresponding to the target model in candidate carrier categories, where the carrier category determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier categories and a first reward value determined in the reinforcement learning process for selecting any action in the first action set, and the first reward value is determined by a loss value of writing a carrier object in each historical carrier category to a historical model; Based on a pre-trained carrier object determination model, determining a target carrier object corresponding to the target model in the target carrier category, where the carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value determined in the reinforcement learning process for selecting any action in the second action set, and the second reward value is determined by a loss value of writing a carrier object in each historical carrier object to the historical model; Based on a pre-trained steganography model, writing the model weights and model structure of the target model to be steganographed to the target carrier object, obtaining a written carrier object, and sending the written carrier object to a target device, where the written carrier object is used to trigger the target device to obtain the target model based on the written carrier object, so as to process a target service based on the target model.
2. The method according to claim 1, where the target carrier category includes a first carrier category and a second carrier category, the target carrier object includes a first carrier object determined based on the first carrier category and a second carrier object determined based on the second carrier category, and the written carrier object includes a first carrier object written with the model structure of the target model and a second carrier object written with the model weights of the target model.
3. The method according to claim 2, where the determining, based on a pre-trained carrier category determination model, a target carrier category corresponding to the target model in candidate carrier categories includes: Performing encoding processing on the model structure of the target model to obtain an encoded model structure, and based on the pre-trained carrier category determination model and the encoded model structure, determining a first carrier category corresponding to the encoded model structure in the candidate carrier categories; Based on the pre-trained carrier category determination model and the model weights of the target model, determining a second carrier category corresponding to the model weights of the target model in the candidate carrier categories; The determining, based on a pre-trained carrier object determination model, a target carrier object corresponding to the target model in the target carrier category includes: Based on the pre-trained carrier object determination model, determining a first carrier object corresponding to the encoded model structure in the first carrier category; Based on the pre-trained carrier object determination model, determining a second carrier object corresponding to the model weights of the target model in the second carrier category.
4. The method according to claim 3, before determining, based on the pre-trained carrier class determination model, the target carrier class corresponding to the target model in the candidate carrier classes, further includes: Obtaining historical carrier objects and the historical model; Performing clustering processing on the historical carrier objects based on the feature vectors of the historical carrier objects to obtain the historical carrier classes, and each of the historical carrier classes corresponds to one or more of the historical carrier objects; Determining a target distance matrix based on the distances between the feature vectors of every two of the historical carrier classes, and determining the first action set based on the target distance matrix; Determining a first return value brought by selecting any action in the first action set during the reinforcement learning process based on the loss value of writing the historical model by the historical carrier objects corresponding to each of the historical carrier classes; Training the carrier class determination model based on the first action set and the first return value to obtain a trained carrier class determination model.
5. The method according to claim 4, before the loss value of writing the historical model by the historical carrier objects corresponding to each of the historical carrier classes, further includes: Obtaining a first model and a third carrier object, where the model data of the first model includes the model structure and / or model weights of the first model; Training a first steganography model and a first extraction model based on the model data of the first model, the third carrier object, and a preset feature extraction model to obtain trained first steganography and first extraction models; Determining the loss value of writing the historical model by the historical carrier objects corresponding to each of the historical carrier classes based on the trained first steganography model, the trained first extraction model, and the preset feature extraction model.
6. The method according to claim 5, before writing the model weights and model structure of the target model to be steganographed into the target carrier object based on the pre-trained steganography model to obtain a written carrier object, further includes: Obtaining a second model and a third carrier class; Determining, based on the pre-trained carrier class determination model, a fourth carrier class corresponding to the second model in the third carrier class; Determining, based on the pre-trained carrier object determination model, a fourth carrier object corresponding to the second model in the fourth carrier class; Training the steganography model and a second extraction model based on the second model, the fourth carrier object, and the preset feature extraction model to obtain a trained steganography model.
7. The method according to claim 6, the training the steganography model and the second extraction model based on the second model, the fourth carrier object, and the preset feature extraction model to obtain a trained steganography model includes: Inputting the model data of the second model and the fourth carrier object into the steganography model to obtain a written fourth carrier object; Inputting the written fourth carrier object into the second extraction model to obtain extracted model data; Input the fourth carrier object and the fourth carrier object after writing into the preset feature extraction model respectively to obtain the feature vector of the fourth carrier object and the feature vector of the fourth carrier object after writing; Determine the model loss value based on the preset loss function, the fourth carrier object, the fourth carrier object after writing, the model data of the second model, the extracted model data, the feature vector of the fourth carrier object, and the feature vector of the fourth carrier object after writing; Based on the model loss value, determine whether the steganography model and the second extraction model converge. If not, continue to train the steganography model and the second extraction model based on the model data of the second model and the fourth carrier object until the steganography model and the second extraction model converge to obtain the trained steganography model.
8. The method according to claim 7, wherein the determining the model loss value based on the preset loss function, the fourth carrier object, the fourth carrier object after writing, the model data of the second model, the extracted model data, the feature vector of the fourth carrier object, and the feature vector of the fourth carrier object after writing comprises: Determine a first sub-loss value based on the fourth carrier object and the fourth carrier object after writing; Determine a second sub-loss value based on the model data of the second model and the extracted model data; Determine a third sub-loss value based on the feature vector of the fourth carrier object and the feature vector of the fourth carrier object after writing; Determine the model loss value based on the first sub-loss value, the second sub-loss value, and the third sub-loss value.
9. A data processing method, comprising: Receiving the carrier object after writing sent by the server, where the carrier object after writing is obtained by the server writing the model weights and model structure of the target model to be steganographed into the target carrier object based on a pre-trained steganography model, the target carrier object is the carrier object corresponding to the target model in the target carrier class determined by the server based on a pre-trained carrier object determination model, the target carrier class is the carrier class corresponding to the target model in the candidate carrier classes determined by the server based on a pre-trained carrier class determination model, the carrier class determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes and a first return value determined by selecting any action in the first action set during the reinforcement learning process, the first return value is determined by the loss value of writing the carrier object in each historical carrier class to the historical model, the carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second return value determined by selecting any action in the second action set during the reinforcement learning process, and the second return value is determined by the loss value of writing each historical carrier object to the historical model; Performing extraction processing on the written carrier object based on a preset extraction model to obtain the model weights and model structure of the target model; Based on the model weights and model structure of the target model, determining the target model and processing a target service based on the target model.
10. A data processing device, comprising: A model acquisition module, configured to acquire a target model to be steganographically hidden; A class determination module, configured to determine a target carrier class corresponding to the target model in candidate carrier classes based on a carrier class determination model that is pre-trained. The carrier class determination model is trained by a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes and a first reward value determined by selecting any action in the first action set during the reinforcement learning process. The first reward value is determined by the loss value of the writing process of the historical model by the carrier object in each historical carrier class; An object determination module, configured to determine a target carrier object corresponding to the target model in the target carrier class based on a carrier object determination model that is pre-trained. The carrier object determination model is trained by a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value determined by selecting any action in the second action set during the reinforcement learning process. The second reward value is determined by the loss value of the writing process of the historical model by each historical carrier object; A data sending module, configured to write the model weights and model structure of the target model to be steganographically hidden into the target carrier object based on a pre-trained steganography model to obtain a written carrier object, and send the written carrier object to a target device. The written carrier object is used to trigger the target device to obtain the target model based on the written carrier object, so as to process a target service based on the target model.
11. A data processing device, comprising: A data acquisition module, configured to receive the written carrier object sent by the server. The written carrier object is obtained by the server writing the model weights and model structure of the target model to be steganographed into the target carrier object based on a pre-trained steganography model. The target carrier object is the carrier object corresponding to the target model in the target carrier class determined by the server based on the pre-trained carrier object determination model. The target carrier class is the carrier class corresponding to the target model in the candidate carrier classes determined by the server based on the pre-trained carrier class determination model. The carrier class determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes and a first reward value determined by selecting any action in the first action set during the reinforcement learning process. The first reward value is determined by the loss value of writing the carrier object in each historical carrier class to the historical model. The carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value determined by selecting any action in the second action set during the reinforcement learning process. The second reward value is determined by the loss value of writing each historical carrier object to the historical model; An extraction module, configured to perform extraction processing on the written carrier object based on a preset extraction model to obtain the model weights and model structure of the target model; A service processing module, configured to determine the target model based on the model weights and model structure of the target model, and process the target service based on the target model.
12. A data processing device, the data processing device includes: A processor; And A memory arranged to store computer-executable instructions, the executable instructions, when executed, cause the processor to: Obtain a target model to be steganographed; Based on a pre-trained carrier class determination model, determine the target carrier class corresponding to the target model in the candidate carrier classes. The carrier class determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes and a first reward value determined by selecting any action in the first action set during the reinforcement learning process. The first reward value is determined by the loss value of writing the carrier object in each historical carrier class to the historical model; Based on a pre-trained carrier object determination model, determine the target carrier object corresponding to the target model in the target carrier class. The carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value determined by selecting any action in the second action set during the reinforcement learning process. The second reward value is determined by the loss value of writing each historical carrier object to the historical model; Based on a pre-trained steganography model, write the model weights and model structure of the target model to be steganographed into the target carrier object to obtain the written carrier object, and send the written carrier object to the target device. The written carrier object is used to trigger the target device to obtain the target model based on the written carrier object, so as to process the target service based on the target model.
13. A data processing device, the data processing device includes: A processor; And A memory arranged to store computer-executable instructions, the executable instructions, when executed, cause the processor to: Receive the written carrier object sent by the server. The written carrier object is obtained by the server writing the model weights and model structure of the target model to be steganographed into the target carrier object based on a pre-trained steganography model. The target carrier object is the carrier object corresponding to the target model in the target carrier class determined by the server based on the pre-trained carrier object determination model. The target carrier class is the carrier class corresponding to the target model in the candidate carrier classes determined by the server based on the pre-trained carrier class determination model. The carrier class determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes and a first reward value determined in the reinforcement learning process for selecting any action in the first action set. The first reward value is determined by the loss value of each carrier object in the historical carrier class for writing to the historical model. The carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second reward value determined in the reinforcement learning process for selecting any action in the second action set. The second reward value is determined by the loss value of each historical carrier object for writing to the historical model; Perform extraction processing on the written carrier object based on a preset extraction model to obtain the model weights and model structure of the target model; Determine the target model based on the model weights and model structure of the target model, and process the target service based on the target model.
14. A storage medium, the storage medium is used to store computer-executable instructions, and the executable instructions, when executed, implement the following process: Obtain a target model to be steganographed; Based on a pre-trained carrier class determination model, determine the target carrier class corresponding to the target model in the candidate carrier classes. The carrier class determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes and a first reward value determined in the reinforcement learning process for selecting any action in the first action set. The first reward value is determined by the loss value of each carrier object in the historical carrier class for writing to the historical model; Based on a pre-trained carrier object determination model, determine the target carrier object corresponding to the target model in the target carrier class. The carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second return value determined in the reinforcement learning process for selecting any action in the second action set. The second return value is determined by the loss value of each historical carrier object for writing to the historical model. Based on a pre-trained steganography model, write the model weights and model structure of the target model to be steganographed into the target carrier object to obtain a written carrier object, and send the written carrier object to the target device. The written carrier object is used to trigger the target device to obtain the target model based on the written carrier object, so as to process the target service based on the target model.
15. A storage medium for storing computer-executable instructions, and the executable instructions, when executed, implement the following process: Receive the written carrier object sent by the server. The written carrier object is obtained by the server writing the model weights and model structure of the target model to be steganographed into the target carrier object based on a pre-trained steganography model. The target carrier object is the carrier object corresponding to the target model in the target carrier class determined by the server based on a pre-trained carrier object determination model. The target carrier class is the carrier class corresponding to the target model in the candidate carrier classes determined by the server based on a pre-trained carrier class determination model. The carrier class determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a first action set determined by historical carrier classes and a first return value determined in the reinforcement learning process for selecting any action in the first action set. The first return value is determined by the loss value of each carrier object in each historical carrier class for writing to the historical model. The carrier object determination model is obtained by training a model constructed by a reinforcement learning algorithm based on a second action set determined by historical carrier objects and a second return value determined in the reinforcement learning process for selecting any action in the second action set. The second return value is determined by the loss value of each historical carrier object for writing to the historical model. Perform extraction processing on the written carrier object based on a preset extraction model to obtain the model weights and model structure of the target model. Determine the target model based on the model weights and model structure of the target model, and process the target service based on the target model.
Citation Information
Patent Citations
Deep learning technique in steganography with multimedia network security for health care
AU2021102689A4
Information steganography method and device and information detection method and device
CN112487365A