Anomaly computing power federation detection method and system in edge computing power network and medium

By establishing a computing power anomaly detection mechanism and a federated detection framework of the CNN-BILSTM model in the edge computing power network, the problem of anomaly detection of edge computing power nodes is solved, and efficient, secure and reliable anomaly detection of edge computing systems is achieved.

CN116502162BActive Publication Date: 2025-11-28HEBEI UNIV OF ENG
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310378971.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-11
Publication Date
2025-11-28
Estimated Expiration
2043-04-11

AI Technical Summary

Technical Problem

In edge computing networks, abnormal computing power of nodes can lead to slower computing speeds and task failures, affecting system performance and reliability. Furthermore, existing anomaly detection methods cannot be effectively applied to edge computing nodes, resulting in high data transmission latency and energy consumption issues.

Method used

This paper proposes a federated detection method for abnormal computing power in edge computing power networks. By scheduling resources on demand, an abnormal computing power detection operation mechanism is established. The CNN-BILSTM anomaly detection model is adopted, and a federated anomaly detection framework that aggregates edge service nodes and edge nodes is combined to perform real-time anomaly detection.

Benefits of technology

This achieves improved performance and reliability of edge computing systems, reduced economic losses, and ensured user business experience while ensuring data and privacy security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116502162B_ABST
    Figure CN116502162B_ABST
Patent Text Reader

Abstract

The application discloses an abnormal computing power federation detection method and system in an edge computing power network and a medium, comprising the following steps: the edge computing power network guarantees the user service experience by on-demand, flexible and efficient joint scheduling of network resources and computing power resources, performs computing power anomaly monitoring on an edge resource pool, and establishes a computing power anomaly detection operation mechanism; a federal anomaly detection framework for communication between aggregated edge service nodes and edge nodes is proposed; for the problem of computing power anomaly of the edge computing power network computing power node, an abnormal detection model based on CNN-BILSTM is proposed to identify abnormal computing power; HDFS data sets and PageRank data sets are prepared, an experimental environment is prepared for local training, precision, recall and F1 value evaluation indexes are used, and experimental results and analysis are obtained. By using the application, data and privacy safety are ensured on the edge computing power node, real-time anomaly detection is performed, and the performance and reliability of the edge computing system are effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of edge computing network, and particularly relates to an abnormal computing power federation detection method and system in an edge computing network and a medium. BACKGROUND

[0002] The edge computing network is mainly constructed by edge computing nodes (which can be smart phones, routers, Internet of Things devices, etc.) and network devices, aiming to connect the distributed edge computing nodes to each other, schedule and distribute computing tasks to the devices in the network, optimize and efficiently utilize the network and computing resources, and provide the best resource allocation and connection scheme for users. Therefore, the edge computing network has broad prospects in various application scenarios, such as intelligent manufacturing, smart city, intelligent transportation, etc.

[0003] In the actual application process of the edge computing network, a large amount of data transmission and processing is often involved. In the edge computing network, nodes are widely distributed, and each node can contain different data and privacy information, which is not suitable for being directly transmitted to a centralized server for processing and analysis, because this can cause data leakage and privacy infringement. Due to the resource limitations of the edge computing nodes, such as computing power, storage capacity and bandwidth, the computing power of the nodes is abnormal from time to time. The abnormal computing power can cause the computing speed of the nodes to slow down, the task execution to fail, and further affect the performance and reliability of the entire system.

[0004] At present, there are few studies on edge computing power anomaly detection, and traditional anomaly detection methods cannot be directly applied to edge computing nodes, because these methods can require a large amount of data transmission and central processing, which can cause high delay and energy consumption. Therefore, how to ensure data and privacy security and perform real-time anomaly detection on edge computing nodes to improve the performance and reliability of the edge computing system is a problem to be solved at present. SUMMARY

[0005] The main purpose of the present application is to provide an abnormal computing power federation detection method and system in an edge computing network, which can ensure data and privacy security and perform real-time anomaly detection on edge computing nodes to improve the performance and reliability of the edge computing system.

[0006] In order to achieve the above purpose, an abnormal computing power federation detection method and system in an edge computing network are provided, which includes the following steps:

[0007] S1. The edge computing network guarantees user service experience by on-demand, flexible and efficient joint scheduling of network resources and computing resources, monitors the computing power of the edge resource pool for abnormalities, establishes a computing power anomaly detection operation mechanism, including user service request, demand analysis module analyzes user service demand, resource scheduling module manages edge resource pool and edge gateway, service deployment and fault monitoring module assists demand analysis module to determine service deployment location and resources, and detects abnormalities in the edge resource pool;

[0008] S2. A federated anomaly detection framework for communication between aggregated edge service nodes and edge nodes is proposed, which includes three elements: aggregated edge service nodes, edge nodes and an anomaly detection system, the anomaly detection system includes: client request computing power registration, server node initializes global model, server node selects client local training, server node model aggregation, client computing power anomaly detection;

[0009] S3. An anomaly detection model based on CNN-BILSTM is used to identify abnormal computing power;

[0010] S4. Prepare HDFS dataset and PageRank dataset, prepare experimental environment for local training, use precision, recall and F1 value evaluation indicators to obtain experimental results and analysis.

[0011] As a preferred embodiment of the present application, the step S1 of the abnormal computing power federated detection method in the edge computing network of the present application is specifically as follows:

[0012] First, the user service request, the demand analysis module analyzes the user service demand, converts the user service demand into computing power demand and network demand, and determines the service deployment location and resource information;

[0013] The resource scheduling module manages the edge resource pool and the edge gateway, and allocates corresponding computing, storage and network resources to the user flexibly according to the result of the demand analysis module;

[0014] The service deployment routes the user computing task to the processing node through the mutual cooperation of network scheduling and resource scheduling in the resource scheduling module;

[0015] The fault monitoring module assists the demand analysis module to determine the service deployment location and resources, and detects abnormalities in the edge resource pool. When an abnormality occurs in a certain edge computing node during processing of the computing task, the fault monitoring module, in combination with the demand module result, provides the user with service deployment location and resources again.

[0016] As a preferred embodiment of the present application, the step S2 of the abnormal computing power federated detection method in the edge computing network of the present application is specifically as follows:

[0017] The aggregation edge service node is a server node in a federated anomaly detection architecture, and functions to initialize a pre-training model and a federated anomaly detection global model; and aggregates parameters uploaded by an edge resource pool until any one of the following conditions is met: the model converges or the maximum number of communications is reached.

[0018] The edge node is a client in the federated anomaly detection architecture, and functions to perform user service calculation, local data collection, receive an initialized global model issued by the server, and then iteratively train the local model using the global model, and receive the pre-training model sent by the server.

[0019] The anomaly detection system deploys a global anomaly detection model on each client to detect abnormal computing power, and once an abnormality occurs, sends warning information to a fault monitoring module to assist the computing power scheduling system in scheduling computing resources.

[0020] As a preferred embodiment of the present application, the specific operation of the client requesting computing power registration in S2 of the anomaly computing power federated detection method in the step edge computing power network is as follows:

[0021] Suppose there are K clients and one server node S, the clients are represented by K = {1, 2,..., K}, the registration time of each client i is r i , the storage size of the client i is represented by m i , and the computing power size of the client i is represented by c i :

[0022]

[0023] Where f i represents the number of floating point operations completed by the client i in a time window, t i is the length of the time window, c i represents the number of floating point operations per second of the client i; the distance from the client i to the server node is represented by d i,S :

[0024]

[0025] Where (x i , y i ) represents the position of the client i, and (x S , y S ) represents the position of the server node S.

[0026] The server node initializes the global model in step S2 of the abnormal computing power federal detection method in the edge computing power network, including a bert word embedding layer, a convolution layer, a bidirectional LSTM layer, and a linear layer. The input of the model is a batch_size size text sequence, where each text is represented as a matrix with a shape of sequence_length, 768. The output of the model is the probability of each text belonging to one of the two categories, which is calculated by a softmax function.

[0027] Assuming that w0 is the initial parameter of the global model, the server node initializes the global model parameter at the beginning of the federal learning by using the expression ;

[0028] wherein, w0 represents the initial global model parameter, communication is required between the server node and the clients, the maximum communication rounds are T, the communication period is t, and the value of the communication period t is 1 at the beginning.

[0029] The server node selects the client local training in step S2 of the abnormal computing power federal detection method in the edge computing power network, specifically: in the communication period t, the server node S randomly selects k clients to participate in the training, wherein k≤K, the server node S sends the initialized global model w0 to the selected clients, and assumes that each client i has a data set wherein [1, k] represents an integer range, each client i performs local training according to the local data set and generates a local model parameter wherein is the loss function obtained by the client i by using the local data for training, represents the gradient of the loss function with respect to the model parameter , η represents a learning rate, and the local training iteration number of the client i is represented by l i .

[0030] As a preferred embodiment of the present application, the server node model aggregation in step S2 of the abnormal computing power federal detection method in the edge computing power network of the present application is specifically: at the communication period t, the client model parameter set wherein represents the model parameter of the client i at the communication period t, and the aggregation global model parameter update is represented as:

[0031]

[0032] Where |D| represents the local data volume of all clients, and this formula represents a weighted average, the contribution of each client i is determined by its sample size |D i |Weighted; when t=T, the final global model parameters are sent to each client for anomaly detection until the model converges, otherwise the server node selects the client local training is continued.

[0033] As a preferred embodiment of the present application, the client power anomaly detection in step S2 of the abnormal power federated detection method in the edge power network of the present application is specifically: all client nodes participating in federated training use the final aggregated model weight parameters completed and issued by the server node Update the local global network model, that is, Process the local data, and judge whether the classification result is an abnormal type through the anomaly detection model. If yes, it is an abnormal power, otherwise it is a normal power.

[0034] As a preferred embodiment of the present application, the CNN-BILSTM anomaly detection model based on the abnormal power federated detection method in the edge power network of the present application in step S3 is specifically:

[0035] It includes data collection and data analysis. The data collection analyzes the unstructured log data output by the edge computing node, uses the Drain method for structured processing, and the log analysis deletes redundant information from the structured raw log fragments generated from the HDFS, extracts log event time information and content information;

[0036] It also includes that when the client processes the local data, the overall model encodes the input text through the BERT pre-training model, and extracts features and classifies through the convolutional neural network CNN and the bidirectional long short-term memory network BiLSTM.

[0037] As a preferred embodiment of the present application, step S4 of the abnormal power federated detection method in the edge power network of the present application is specifically:

[0038] S401. Prepare the HDFS data set, which contains various types of log data, and the log data contains various events and error information; prepare the Pagerank log data set, which is used to test the performance and scalability of the distributed computing framework, analyze the log data set, extract the communication between nodes, and perform power anomaly detection;

[0039] S402. Prepare the experimental environment, and the federated anomaly detection architecture parameter settings are as follows: the number of clients K=2, the maximum number of communications T=20, the initial value t=1, and the number of client i local training iterations li = 2, the number of clients selected for each communication is 2, the learning rate η = 0.1, and each client i uses the HDFS and the PageRank dataset for local training, and the dataset is divided according to 7:3, which is represented as the client training set and the client validation set, respectively;

[0040] S403. Precision, Recall and F1 value are used as evaluation indexes, and the calculation formula is:

[0041]

[0042]

[0043]

[0044] wherein TP represents the amount of successfully detected abnormal log sequences, FP represents the number of normal log sequences judged as abnormal by the detection model, and FN represents the number of abnormal log sequences judged as normal by the abnormal detection model;

[0045] S404. Multiple clients use HDFS and PageRank partial datasets for verification, and three measurement standards of precision, recall and F1 value are used, and three current log analysis-based anomaly detection algorithms, principal component analysis (PCA), LogAnomaly and DeepLog, are compared.

[0046] An abnormal computing power federated detection system in an edge computing power network adopts the abnormal computing power federated detection method in the edge computing power network as claimed in any one of claims 1 to 8, and the detection system comprises:

[0047] A demand analysis module is configured to analyze user business demands, convert them into computing power demands and network demands, determine business deployment locations and resource information;

[0048] A resource scheduling module is configured to manage edge resource pools and edge gateways, and according to the results of the demand analysis module, to flexibly allocate corresponding computing, storage and network resources to users;

[0049] A business deployment module is configured to route user computing tasks to processing nodes through the cooperation of network scheduling and resource scheduling in the resource scheduling module;

[0050] A fault monitoring module is configured to assist the demand analysis module in determining business deployment locations and resources, and to perform abnormal detection on edge resource pools, and when an abnormality occurs in a certain edge computing power node during the processing of computing tasks, to provide users with business deployment locations and resources again in combination with the results of the demand module;

[0051] Further comprising a federal anomaly detection framework, the federal anomaly detection framework comprising three elements of an aggregation edge service node, an edge node and an anomaly detection system;

[0052] The aggregation edge service node is a server node in the federal anomaly detection architecture, and its functions are to initialize a pre-training model and a federal anomaly detection global model; aggregate parameters uploaded by an edge resource pool until any one of model convergence and reaching a maximum number of communications;

[0053] The edge node is a client in the federal anomaly detection architecture, and its functions are to perform user business calculation, local data collection, receive an initialized global model issued by a server, and then cyclically iterate a local training of the global model, and receive a pre-training model sent by the server;

[0054] The anomaly detection system comprises: the system deploys a global anomaly detection model on each client to detect abnormal computing power, and once an anomaly occurs, timely sends warning information to a fault monitoring module to assist a computing power arrangement system to schedule computing resources.

[0055] A computer readable medium, the program is executed by the processor to realize the anomaly computing power federal detection method in the edge computing power network as claimed in any one of claims 1 to 8.

[0056] The beneficial effects of the present application are:

[0057] 1、In the present application, the computing power anomaly detection running mechanism is established to ensure efficient use of computing power resources.

[0058] 2、In the present application, the edge computing power network guarantees user service experience by on-demand, flexible and efficient joint scheduling of network resources and computing power resources, ensures data and privacy security and performs real-time anomaly detection on the edge computing power node before granting it the qualification to provide computing power services, effectively improving the performance and reliability of the edge computing system.

[0059] 3、In the present application, the anomaly detection system is adopted to help users reduce economic losses. BRIEF DESCRIPTION OF DRAWINGS

[0060] Figure 1 is the computing power anomaly detection running mechanism of the present application;

[0061] Figure 2 is the computing power anomaly federal detection architecture of the present application;

[0062] Figure 3 is the ACFL accuracy curve of the present application;

[0063] Figure 4 is the ACFL loss curve of the present application;

[0064] Figure 5 ACFL client 1 performance index result graph of the present application;

[0065] Figure 6 ACFL client 2 performance index result graph of the present application; DETAILED DESCRIPTION

[0066] The preferred embodiments of the present application are described below in conjunction with the accompanying drawings of the specification, it should be understood that the preferred embodiments described herein are only used to illustrate and explain the present application, and are not used to limit the present application, and the embodiments in the present application and the features in the embodiments can be combined with each other without conflict.

[0067] An abnormal computing power federation detection method, system and medium in an edge computing power network of the present application, as shown in Figures 1-6 The abnormal computing power federation detection method in the edge computing power network includes the following steps:

[0068] S1. The edge computing power network guarantees user service experience by on-demand, flexible and efficient joint scheduling of network resources and computing power resources, and monitors the computing power of the edge resource pool for abnormality, establishes a computing power abnormality detection operation mechanism, which includes user service request, demand analysis module analyzes user service demand, resource scheduling module manages edge resource pool and edge gateway, service deployment and fault monitoring module assists demand analysis module to determine service deployment location and resources, and detects abnormality of the edge resource pool;

[0069] S2. A federated anomaly detection framework for communication between aggregated edge service nodes and edge nodes is proposed, which includes three elements of aggregated edge service nodes, edge nodes and anomaly detection systems, and the anomaly detection system includes: client request computing power registration, server node initializes global model, server node selects client local training, server node model aggregation, and client computing power anomaly detection;

[0070] S3. For the problem of computing power anomaly of the computing power nodes of the edge computing power network, an abnormality detection model based on CNN-BILSTM is proposed to identify abnormal computing power;

[0071] Wherein, the computing power anomaly detection running mechanism is established in the application to ensure efficient use of computing power resources; according to the characteristics of node dispersion and heterogeneity between nodes in the edge computing power network, a federal anomaly detection framework is proposed, which trains an anomaly detection model of computing power under the premise of ensuring data security of edge computing power nodes, to more accurately detect anomalies in computing power nodes; for the problem of computing power anomaly in edge computing power network nodes, an anomaly detection model based on CNN-BILSTM is proposed to identify abnormal computing power, which greatly improves the performance and reliability of the edge computing power system and provides better services for future intelligent applications.

[0072] S4. Prepare the HDFS data set and the PageRank data set, prepare the experimental environment for local training, use the precision, recall and F1 value evaluation indicators to obtain the experimental results and analysis.

[0073] An optional implementation, an abnormal computing power federal detection system in an edge computing power network, as shown in Figure 1 The abnormal computing power federal detection method in the edge computing power network is adopted, which is: first, a user business request module;

[0074] The demand analysis module is used to analyze user business demand and convert it into computing power demand and network demand, determine the business deployment location and resource information;

[0075] The resource scheduling module is used to manage edge resource pools and edge gateways, and according to the results of the demand analysis module, it is used to flexibly allocate corresponding computing, storage and network resources for users;

[0076] The business deployment module routes user computing tasks to processing nodes through the cooperation of network scheduling and resource scheduling in the resource scheduling module;

[0077] The fault monitoring module is used to assist the demand analysis module in determining the business deployment location and resources, and to perform anomaly detection on the edge resource pool; when an abnormality occurs in a certain edge computing power node during the processing of computing tasks, the fault monitoring module, in combination with the demand module result, provides the user with a business deployment location and resources again;

[0078] Wherein, the edge computing power network in the application guarantees user business experience through on-demand, flexible and efficient joint scheduling of network resources and computing power resources, and performs computing power anomaly monitoring on the edge resource pool before giving it the qualification to provide computing power services, to ensure the reliability of the computing power services; the fault monitoring module assists the demand analysis module in determining the business deployment location and resources, and performs anomaly detection on the edge resource pool, which covers the entire orchestration and management stage, and can help build a reliable and secure orchestration and management system.

[0079] An optional embodiment, as shown in Figure 2 The specific steps of step S2 of the abnormal computing power federation detection method in the edge computing power network are as follows: when facing the situation of unstable edge computing resources, strong dispersion and large heterogeneity, the application proposes a federal abnormal detection framework for communication between aggregated edge service nodes and edge nodes, specifically, the framework includes the following three elements:

[0080] The aggregated edge service node is a server node in the federal abnormal detection architecture, and its functions are to initialize the pre-trained model and the federal abnormal detection global model; and to aggregate the parameters uploaded by the edge resource pool until any one of the following conditions is met: the model converges and the maximum number of communications is reached.

[0081] The edge node is a client in the federal abnormal detection architecture, and its functions are to perform user business computing, local data collection, receive the initialized global model issued by the server, and then iteratively train the local model with the global model, and receive the pre-trained model sent by the server.

[0082] The abnormal detection system deploys a global abnormal detection model on each client to detect abnormal computing power conditions, and sends warning information to the fault monitoring module in a timely manner once an abnormality occurs to assist the computing power scheduling system in scheduling computing resources.

[0083] In the application, the aggregated edge service node serves as a server node in the federal abnormal detection architecture and has large computing resources and storage resources; the edge node serves as a client in the federal abnormal detection architecture and has relatively small computing and storage resources, and uses the abnormal detection system to help users reduce economic losses.

[0084] An optional embodiment, as shown in Figure 2 The specific operation of the client request computing power registration in step S2 of the abnormal computing power federation detection method in the edge computing power network is as follows:

[0085] Suppose there are K clients and one server node S, the clients are represented by K={1, 2,..., K}, and the registration time of each client i is r i , the storage size of the client i is represented by m i , and the computing power size is represented by c i :

[0086]

[0087] Where f i represents the number of floating point operations completed by the client i in a time window, t i is the length of the time window, and ci represents the number of floating point operations per second of client i; the distance of client i to the server node is denoted by d i,S represents:

[0088]

[0089] where (x i ,y i ) represents the position of client i, and (x S ,y S ) represents the position of server node S.

[0090] In an optional implementation, the server node initializes the global model in step S2 of the abnormal computing power federation detection method in the edge computing power network includes a bert word embedding layer, a convolutional layer, a bidirectional LSTM layer, and a linear layer.

[0091] wherein the convolutional layer is specifically a ModuleList containing three two-dimensional convolutional layers Conv2d, the input channel number of the three convolutional layers is 1, the output channel number is 256, different sizes of convolutional kernels 2x768, 3x768, and 4x768 are used respectively, and the step length is 1; these convolutional layers are used to extract local features in the text because different lengths of n-grams may have different importance for the expression of the text.

[0092] wherein the bidirectional LSTM layer is specifically a bidirectional long short-term memory network containing an LSTM layer, the input size is 768, and the output size is 128. The LSTM layer is set to batch_first = True, so the shape of the input is batch_size, sequence_length, 768, where batch_size is the size of each batch, and sequence_length is the length of the text sequence; this bidirectional LSTM layer is used to capture global features in the text because it can effectively model long-term dependencies in the text sequence.

[0093] wherein the linear layer is specifically: a linear layer Linear that maps the input 256-dimensional vector to a 2-dimensional vector (i.e., the output size is 2) for final classification; this linear layer is used to combine the extracted local and global features for classification.

[0094] In summary, the input of this model is a batch_size size text sequence, where each text is represented as a matrix with a shape of sequence_length, 768, and the output of the model is the probability of each text belonging to one of the two categories, which is calculated by the softmax function;

[0095] Assuming w0 is the initial parameter of the global model, the server node initializes the global model parameter with the expression at the beginning of federated learning;

[0096] wherein, represents the initial global model parameter, communication is required between the server node and the client, the maximum number of communications is T, and the period of each communication is t. At the beginning, the value of the communication period t is 1.

[0097] An optional implementation, as shown in Figure 2 , the server node model aggregation in step S2 of the abnormal computing power federated detection method in the edge computing power network is specifically: the server node selects the client local training, and in the communication period t, the server node S randomly selects k clients to participate in the training, wherein k≤K, and the server node S sends the initial global model w0 to these selected clients. Let each client i have a data set where [1, k] represents the integer range, each client i performs local training according to its own local data set and generates a local model parameter wherein is the loss function obtained by the client i using the local data for training, represents the gradient of the loss function with respect to the model parameter , η represents the learning rate, and the local training iteration number of the client i is represented by l i .

[0098] An optional implementation, as shown in Figure 2 , the server node model aggregation in step S2 of the abnormal computing power federated detection method in the edge computing power network is specifically: server node model aggregation, when the communication period is t, the client model parameter set wherein represents the model parameter of the client i in the communication period t, and the aggregation of the global model parameter update is represented as:

[0099]

[0100] where |D| represents the local data amount of all clients. This formula represents a weighted average, and the contribution of each client i is weighted by its sample number |D i |; when t=T, the final global model parameter is sent to each client until the model converges, and abnormal detection is performed, otherwise the server node selects the client local training is executed.

[0101] An optional implementation, as shown in Figure 2As shown, the client abnormal computing power detection in step S2 of the abnormal computing power federation detection method in the edge computing power network is specifically: all client nodes participating in the federation training use the server node to finally aggregate and complete and issue the model weight parameters updating the local global network model, that is, processing the local data, judging whether the classification result is an abnormal type through the abnormal detection model, if yes, it is an abnormal computing power, otherwise, it is a normal computing power.

[0102] An optional embodiment is as follows: Figure 2 As shown, the CNN-BILSTM abnormal detection model in step S3 of the abnormal computing power federation detection method in the edge computing power network is specifically:

[0103] It includes data collection and data analysis. The data collection analyzes the unstructured log data output by the edge computing node, uses the Drain method for structured processing, and deletes redundant information from the structured original log segment generated in the HDFS, extracts log event time information and content information.

[0104] When the client processes the local data, the overall model encodes the input text through the BERT pre-training model, and extracts features and classifies through the convolutional neural network CNN and the bidirectional long short-term memory network BiLSTM.

[0105] In the present application, the local data processing and local model training scheme of the client i is as follows:

[0106] In the data collection stage, the unstructured log data output by the edge computing node is analyzed in the present application, and such logs can represent system state and running information. In production, the software and hardware possessed by the edge resource pool are different, and the log information output by them is also different in syntax. Each statement generally contains time stamp, message identification, detailed information and different format text information. Each edge computing node saves the original log information in the local storage through data stream transmission. In the log analysis stage, the unstructured log data is analyzed into structured log event data, and the Drain method is used for structured processing in the present application. At present, the general method of analyzing logs is to extract templates from log messages, but template extraction still has errors, thereby affecting the robustness of log detection. The present application provides an example of a structured original log segment generated in the HDFS (Hadoop Distributed File System), which contains time stamp, message level, process and component information. Log analysis extracts log event time information and content information by deleting redundant information, as shown in Table 1:

[0107]

[0108]

[0109] Table 1

[0110] When the client processes the local data, the overall model encodes the input text by the BERT pre-training model, and extracts and classifies features by the convolutional neural network (CNN) and bidirectional long short-term memory network (BiLSTM); when using the BERT pre-training model as an input encoder, the language representation ability learned by the pre-training model on a large-scale corpus can be fully utilized, so that the input text data can be better represented; and in this model, the encoded text can be further processed and analyzed through the feature extraction and classification process of the convolutional neural network (CNN) and bidirectional long short-term memory network (BiLSTM), so as to achieve the task goal. In addition, the model also uses a combination of local pooling and global pooling to more comprehensively utilize the feature information extracted by the convolutional layer, and improve the performance of the model. Therefore, the model can better process text data and perform efficient and accurate task processing on it.

[0111] Specifically D i contains all the training samples on the client i, each sample contains a text sequence x composed of L words i = [x i,1 , x i,2 ,..., x i,L ] and a corresponding label y i ={0,1}, define a binary classification model f(x; θ), θ represents the model parameters, x represents the input sample, for a given sample sequence x i , calculate its corresponding intermediate representation as where represents the vector space of input data, and then it is mapped to the probability space by the softmax function to obtain the probability of the sample sequence x i as normal and abnormal respectively:

[0112]

[0113]

[0114] where, is the parameter of the sorftmax function. If P(y i =0|h i )>P(y i =1|h i) it is classified as normal, otherwise, it is classified as abnormal.

[0115] Specifically,

[0116] For a text sequence x, a fixed-length vector z = BERT(x) is obtained through the encoding of the BERT model, a one-dimensional convolutional neural network CNN is used to extract local features of z, and an output vector h CNN is obtained, using RELU(x) = max(0, x), the convolution kernel size is u, the number of convolution kernels is j, and specifically, for the convolution kernel i, the weight is The bias is Then where z i:i+k-1 represents a continuous subsequence in z, and finally, j output vectors are spliced together to obtain h CNN .

[0117] The features learned by the CNN network have translational invariance and lack context semantic information, so on the basis of extracting local features, h CNN is used as input to further learn the timing context features using a bidirectional long short-term memory network (BiLSTM), and an output vector h BILSTM is obtained. Specifically, h CNN,t is used as the forward and reverse LSTM input at time t, respectively, to obtain the hidden states of the forward and reverse LSTM, respectively and The calculation formula is where represents the BiLSTM output vector at time t, W t represents the weight matrix, b t represents the bias vector at time t, and finally a fully connected layer is used to map h BILSTM to the target category, i.e. computing power abnormal or computing power normal, and perform softmax processing to obtain the probability distribution of each category y = softmax(Wh BiLSTM +b), where W is the weight matrix of the fully connected layer, and b is the bias vector. The cross-entropy function is used for loss calculation, and the calculation formula is as follows:

[0118]

[0119] where D i represents the local data set owned by the client i, |D i | represents the number of samples owned by the local data set, x is the input sample, y is the corresponding true label, f θ (x) is the prediction result obtained by forward calculation based on the local model parameter θ on the current client i, is the inverse of the number of samples, representing the average loss per sample.

[0120] An optional embodiment, as shown in Figures 3-6 The step S4 of the abnormal computing power federation detection method in the edge computing power network is specifically:

[0121] S401. Prepare the HDFS dataset, which contains various types of log data containing various events and error information; prepare the Pagerank log dataset, which is used to test the performance and scalability of the distributed computing framework, analyze the log dataset to extract the communication between nodes, and perform computing power anomaly detection;

[0122] HDFS refers to Hadoop Distributed File System, which is one of the core components of Hadoop, a distributed file system for storing and processing large amounts of data on large-scale clusters; the HDFS dataset contains various types of log data, which contains various events and error information, such as file reading and writing, block replication, disk errors, network connections, etc. By analyzing these log data, we can obtain various performance indicators and abnormal conditions of the system, such as disk I / O delay, network bandwidth bottleneck, node failure, etc. It covers log data collected from multiple nodes, with a time span of about 38.7h.

[0123] S402. Prepare the experimental environment, the federation anomaly detection architecture parameter settings are as follows: the number of clients K = 2, the maximum number of communications T = 20, the initial value t = 1, the local training iteration number of client i l i = 2, the number of client selection for each communication is 2, the learning rate η = 0.1, and client i uses HDFS and PageRank dataset for local training, respectively, and the dataset is divided according to 7:3, representing the client training set and the client validation set, respectively;

[0124] In this application, the experimental environment is 64-bit Windows 11, 4-core i5-1135G7 512G 4GHZ CPU, the model is based on Pytorch deep learning framework version 1.12.1, the development environment is Anaconda 4.14.0, and the Python version is 3.9.12.

[0125] S403. Precision, recall and F1 value are used as evaluation indexes, and the calculation formula is:

[0126]

[0127]

[0128]

[0129] Wherein, TP represents the quantity of successfully detected abnormal log sequences, FP represents the quantity of normal log sequences judged as abnormal by the detection model, and FN represents the quantity of abnormal log sequences judged as normal by the abnormal detection model.

[0130] S404. The plurality of clients respectively use HDFS and PageRank partial data sets for verification, adopt three measurement standards of precision, recall and F1 value, and select three current log analysis-based abnormal detection algorithms: principal component analysis (PCA), LogAnomaly and DeepLog for comparison.

[0131] In the application, in order to verify the effect of the federated computing abnormal detection model ACFL (Abnormal of Computing Federated Learning), the accuracy of the training process is as shown in Figure 3 , and the loss value is as shown in Figure 4 . In order to detect the accuracy and effectiveness of the aggregated model, HDFS and PageRank partial data sets are used for verification for the client 1 and the client 2 respectively, three measurement standards of precision, recall and F1 value are adopted, and it can be seen from Figure 5 that the precision of the client 1 is 0.97, the recall is 0.97, and the F1 value is 0.96, and it can be seen from Figure 6 that the precision of the client 2 is 1.0, the recall is 1.0, and the F1 value is 1.0, and three current advanced log analysis-based abnormal detection algorithms: principal component analysis (PCA), LogAnomaly and DeepLog are selected for comparison.

[0132] The above detailed disclosure has been described, and it is obvious that the above detailed disclosure is only used as an example and does not limit the present specification for the person skilled in the art. Although it is not explicitly stated herein, the person skilled in the art can make various modifications, improvements and deviations to the present specification. Such modifications, improvements and deviations are suggested in the present specification, so such modifications, improvements and deviations still belong to the spirit and scope of the exemplary embodiments of the present specification.

[0133] Moreover, as will be appreciated by those skilled in the art, the various aspects of the present description can be embodied as a method, system, or computer program product. Accordingly, aspects of the present description can take the form of an entirely hardware embodiment, an entirely software embodiment (including firmware, resident software, micro-code, etc.) or an embodiment combining software and hardware aspects that can all generally be referred to herein as a "circuit," "module" or "system." Furthermore, aspects of the present description can take the form of a program of instructions (i.e., computer program product) embodied in any tangible medium of expression that can be executed by a processor. Such a program can be stored in any tangible medium of expression, which can include, but is not limited to, RAM, ROM, EEPROM, solid state drives (SSDs), flash memory, or any other memory technology, CD-ROM, memory sticks, or any other medium of expression suitable to the task.

[0134] It is to be understood that the description, definitions, and / or terminology employed herein throughout this description is intended to be interpreted in an accordant manner with the description, definitions, and / or terminology as set forth in this description.

[0135] Finally, it should be noted that the embodiments described herein are merely intended to illustrate the principles of the embodiments described herein. Other variations can also be possible within the scope of the present description. Thus, alternative configurations of the embodiments described herein can be considered as consistent with the teachings of the present description. Accordingly, the embodiments described herein are not limited to the embodiments explicitly introduced and described herein.

Claims

1. A method for detecting abnormal computing power federation in an edge computing power network, characterized in that, Includes the following steps: S1. The edge computing network ensures user service experience by coordinating network resources and computing resources on demand, flexibly and efficiently. It monitors computing power anomalies in the edge resource pool and establishes a computing power anomaly detection mechanism, including user service requests, a demand analysis module to analyze user service requirements, a resource scheduling module to manage the edge resource pool and edge gateway, and a service deployment and fault monitoring module to assist the demand analysis module in determining the service deployment location and resources, and to detect anomalies in the edge resource pool. S2. A federated anomaly detection framework for aggregating edge service nodes and communication between edge nodes is proposed. The framework includes three elements: aggregating edge service nodes, edge nodes, and an anomaly detection system. The anomaly detection system includes: client requesting computing power registration, server node initializing global model, server node selecting client for local training, server node model aggregation, and client computing power anomaly detection. S3. Identify abnormal computing power using an anomaly detection model based on CNN-BILSTM; S4. Prepare the HDFS dataset and PageRank dataset, set up the experimental environment for local training, use precision, recall and F1 score as evaluation metrics, and obtain experimental results and analysis. Among them, (x i ,y i ) represents the position of client i, (x S ,y S ) indicates the location of server node S; In step S2 of the abnormal computing power federated detection method in the edge computing power network, the server node initializes the global model, which includes a BERT word embedding layer, a convolutional layer, a bidirectional LSTM layer, and a linear layer. The input of this model is a text sequence of size batch_size, where each text is represented as a matrix of shape sequence_length, 768. The output of the model is the probability of each text belonging to one of two categories, which is calculated by the softmax function. Assuming w0 is the initial parameter of the global model, then the server node uses the expression at the start of federated learning. To initialize global model parameters; in, This represents the initial global model parameters. Communication is required between the server node and the client. The maximum number of communication sessions is T, and the period of each communication session is t. Initially, the communication period t is 1. Step S2 of the abnormal computing power federated detection method in the edge computing power network, specifically the server node selecting clients for local training, involves the following: Within a communication period t, server node S randomly selects k clients to participate in training, where k ≤ K. Server node S sends the initialized global model w0 to these selected clients. Assume each client i has a dataset. Where [1, k] represents the integer range, each client i performs local training based on its own local dataset and generates a local model parameter. in It is the loss function obtained by client i using local data for training. This indicates that the loss function is relative to the model parameters. The gradient, η represents the learning rate, and l represents the number of local training iterations for client i. i express.

2. The abnormal computing power federation detection method in the edge computing power network according to claim 1, characterized in that, The specific steps of step S1 in the abnormal computing power federation detection method in the edge computing power network are as follows: First, the user's business request is analyzed by the requirement parsing module, which converts the user's business requirements into computing power requirements and network requirements, and determines the business deployment location and resource information. The resource scheduling module manages the edge resource pool and edge gateway, and elastically allocates corresponding computing, storage, and network resources to users based on the results of the demand parsing module. Business deployment involves the collaboration between network scheduling and resource scheduling within the resource scheduling module to route user computing tasks to processing nodes. The fault monitoring module assists the requirement analysis module in determining the service deployment location and resources, and performs anomaly detection on the edge resource pool. When an anomaly occurs in the process of processing computing tasks on an edge computing node, the fault monitoring module, in conjunction with the results of the requirement module, provides the user with a new service deployment location and resources.

3. The abnormal computing power federation detection method in the edge computing power network according to claim 1, characterized in that, The specific steps of step S2 in the abnormal computing power federation detection method in the edge computing power network are as follows: The aggregated edge service node is a server node in the federated anomaly detection architecture. Its functions include initializing the pre-trained model and the global federated anomaly detection model; and aggregating parameters uploaded from the edge resource pool until either the model converges or the maximum number of communications is reached. The edge node is a client in the federated anomaly detection architecture. Its functions include performing user business calculations, collecting local data, receiving the initial global model sent by the server, training the global model locally in subsequent iterations, and receiving the pre-trained model sent by the server. The anomaly detection system deploys a global anomaly detection model on each client to detect abnormal computing power. Once an anomaly occurs, it promptly sends warning information to the fault monitoring module to assist the computing power orchestration system in scheduling computing resources.

4. The abnormal computing power federation detection method in the edge computing power network according to claim 1, characterized in that, The server node model aggregation in step S2 of the abnormal computing power federation detection method in the edge computing power network specifically involves: selecting a client model parameter set when the communication period is t. in, The model parameters of client i during communication period t are represented as follows: The aggregated global model parameter update is expressed as: Where |D| represents the amount of local data for all clients, this formula represents a weighted average, and the contribution of each client i is determined by its sample size |D|. i |Weighted; When t=T and until the model converges, send the final global model parameters to each client for anomaly detection; otherwise, continue with the server node selecting the client for local training.

5. The abnormal computing power federation detection method in the edge computing power network according to claim 1, characterized in that, The abnormal computing power federated detection method in the edge computing power network, specifically step S2, involves detecting abnormal client computing power: all client nodes participating in federated training are finally aggregated and distributed to the model weight parameters by the server node. Update the local global network model, i.e. The local data is processed, and the anomaly detection model is used to determine whether the classification result is an anomaly. If it is, it is considered abnormal computing power; otherwise, it is considered normal computing power.

6. The abnormal computing power federation detection method in the edge computing power network according to claim 1, characterized in that, The CNN-BILSTM-based anomaly detection model in step S3 of the abnormal computing power federation detection method in the edge computing power network is specifically as follows: This includes data acquisition and data parsing. The data acquisition analyzes the unstructured log data output by the edge computing nodes and performs structured processing using the Drain method. The log parsing removes redundant information from the structured raw log fragments generated from HDFS and extracts log event time information and content information. It also includes the fact that when the client processes local data, the overall model encodes the input text using a BERT pre-trained model, and performs feature extraction and classification using a convolutional neural network (CNN) and a bidirectional long short-term memory network (BiLSTM).

7. The abnormal computing power federation detection method in the edge computing power network according to claim 1, characterized in that, Step S4 of the abnormal computing power federation detection method in the edge computing power network is as follows: S401. Prepare an HDFS dataset, which contains various types of log data, including various events and error messages; Prepare a Pagerank log dataset, which is used to test the performance and scalability of the distributed computing framework. By analyzing the log dataset, the communication between nodes can be extracted to detect computing power anomalies. S402. Prepare the experimental environment. The parameters of the federated anomaly detection architecture are set as follows: number of clients K=2, maximum number of communications T=20, initial value t=1, and number of local training iterations for client i l. i =2, the number of clients selected in each communication is 2, the learning rate η = 0.1, and the client i is trained locally using the HDFS and PageRank datasets respectively. The datasets are divided in a 7:3 ratio, which are represented as the client training set and the client validation set respectively. S403. Precision, Recall, and F1 score are used as evaluation metrics, and the calculation formula is as follows: Wherein, TP represents the number of successfully detected abnormal log sequences, FP represents the number of normal log sequences that are judged as abnormal by a detection model, and FN represents the number of abnormal log sequences that are judged as normal by an anomaly detection model. S404. Multiple clients were validated using partial datasets from HDFS and PageRank, with precision, recall, and F1 score as the three metrics. Three current log-based anomaly detection algorithms—Principal Component Analysis (PCA), LogAnomaly, and DeepLog—were selected for comparison.

8. An abnormal computing power federation detection system in an edge computing power network, characterized in that, The abnormal computing power federation detection method in the edge computing power network as described in any one of claims 1 to 7 is adopted, wherein the detection system comprises: The requirements analysis module is used to analyze user business requirements, convert them into computing power requirements and network requirements, and determine the business deployment location and resource information. The resource scheduling module manages the edge resource pool and edge gateway, and elastically allocates corresponding computing, storage, and network resources to users based on the results of the demand parsing module. The business deployment module, through the collaboration of network scheduling and resource scheduling in the resource scheduling module, routes user computing tasks to processing nodes; The fault monitoring module is used to assist the demand parsing module in determining the business deployment location and resources, and to perform anomaly detection on the edge resource pool. When an anomaly occurs in the process of processing computing tasks, the module combines the results of the demand module to provide the user with the business deployment location and resources again. It also includes a federated anomaly detection framework, which comprises three elements: aggregated edge service nodes, edge nodes, and an anomaly detection system. The aggregated edge service node is a server node in the federated anomaly detection architecture. Its functions include initializing the pre-trained model and the federated anomaly detection global model; aggregating parameters uploaded from the edge resource pool until either the model converges or the maximum number of communications is reached. The edge node is a client in the federated anomaly detection architecture. Its functions include performing user business calculations, collecting local data, receiving the initial global model sent by the server, training the global model locally in subsequent iterations, and receiving the pre-trained model sent by the server. The anomaly detection system includes: deploying a global anomaly detection model on each client to detect computing power anomalies; and sending warning messages to the fault monitoring module in a timely manner once an anomaly occurs to assist the computing power orchestration system in scheduling computing resources.

9. A computer-readable medium, characterized in that, It stores a computer program, wherein when the program is executed by a processor, it implements the abnormal computing power federation detection method in the edge computing power network as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • SDN (Software Defined Network) abnormal traffic cooperative detection method based on federated learning

    CN114499979A