An anti-data detection method, device, equipment and storage medium
By deploying various complex neural network models in the cloud and utilizing cloud computing power, the problems of limited storage space and insufficient computing power of power edge devices have been solved, enabling efficient detection and defense against adversarial data and enhancing the network security of the power system.
Patent Information
- Application Number
- CN202411695601.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-25
- Publication Date
- 2026-02-10
- Estimated Expiration
- 2044-11-25
AI Technical Summary
Due to their limited storage space and insufficient computing power, power edge devices suffer from low robustness when deploying lightweight neural networks, making them difficult to effectively defend against attacks and increasing the risk to power grid security.
Deploy various complex neural network models in the cloud, utilize cloud computing power, and conduct adversarial data detection and defense through the collaborative work of edge devices and cloud computing platforms.
It improves the detection and defense effectiveness against adversarial data, enhances the network security of the power system, and reduces the risk of equipment being maliciously controlled.
Smart Images

Figure CN119623571B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to the technical field of power safety, and particularly relate to an adversarial data detection method, device, equipment and storage medium. BACKGROUND
[0002] Power business has the characteristics of flexibility, openness, extensive interconnection, etc. These characteristics expand the network attack surface and reduce the difficulty of network attack, so that power business has to face the increasingly severe network security form and new security risks. The data value of new low-voltage control business has high quality, so it often faces more frequent attack threats.
[0003] Under the impact of Internet attacks, power grid edge devices are facing increasingly serious problems. Data leakage and device malicious control incidents occur from time to time, and even may trigger a chain reaction, leading to power grid accidents and threatening the stability of the entire power system. At the same time, the problem of lagging software and firmware updates cannot be ignored. Many power grid edge devices lack automatic update functions and rely on manual intervention. This outdated update method causes the device to run old version software containing known vulnerabilities for a long time, which increases the security risk of the power grid.
[0004] In addition, lightweight neural networks are vulnerable to adversarial samples, which poses a security risk. Limited by small storage space and insufficient computing power, power edge devices often deploy these lightweight neural network models. Lightweight neural networks have low robustness, which leads to poor ability to defend against adversarial attacks, and thus causes losses to the power system. SUMMARY
[0005] Embodiments of the present application provide an adversarial data detection method, device, equipment and storage medium, which deploys multiple complex neural network models in the cloud, and uses the computing power of the cloud to achieve the detection and defense effect of adversarial data.
[0006] In a first aspect, embodiments of the present application provide an adversarial data detection method, which is executed by an adversarial data detection system, the system including an edge device and a cloud computing platform; comprising:
[0007] Obtaining business data of a user;
[0008] Inputting the business data into a pre-trained lightweight-based convolutional neural network model to output a first prediction result; the lightweight-based convolutional neural network model is deployed in the edge device;
[0009] input the service data into a pre-trained prediction model based on an integrated plurality of neural network models, and output a second prediction result; wherein the training data set of the prediction model based on the lightweight convolutional neural network model is a set number of images and characters and corresponding adversarial data samples are generated; the prediction model is deployed in the cloud computing platform; and detection algorithms of any two neural network models are different;
[0010] based on a comparison result of the first prediction result and the second prediction result, determine the type of the service data; the type of the service data includes normal data or adversarial data.
[0011] In a second aspect, an embodiment of the present application also provides an adversarial data detection device, which comprises:
[0012] a data acquisition module configured to acquire service data of a user;
[0013] a first prediction module configured to input the service data into a pre-trained lightweight convolutional neural network model, and output a first prediction result; the lightweight convolutional neural network model is deployed in the edge device;
[0014] a second prediction module configured to input the service data into a pre-trained prediction model based on an integrated plurality of neural network models, and output a second prediction result; wherein the training data set of the prediction model based on the lightweight convolutional neural network model is a set number of images and characters and corresponding adversarial data samples are generated; the prediction model is deployed in the cloud computing platform; and detection algorithms of any two neural network models are different;
[0015] a type determination module configured to determine the type of the service data based on a comparison result of the first prediction result and the second prediction result; the type includes normal data and adversarial data.
[0016] In a third aspect, an embodiment of the present application also provides an electronic device, which comprises:
[0017] one or more processors;
[0018] a storage device configured to store one or more programs,
[0019] when the one or more programs are executed by the one or more processors, the one or more processors implement the adversarial data detection method provided by the embodiments of the present application.
[0020] In a fourth aspect, an embodiment of the present application also provides a storage medium containing computer executable instructions, which, when executed by a computer processor, are used to perform the adversarial data detection method provided by the embodiments of the present application.
[0021] In a fifth aspect, the present disclosure also provides a computer program product comprising a computer program which, when executed by a processor, implements the method for detecting adversarial data provided by the present disclosure.
[0022] The present application discloses a kind of adversarial data detection method, device, equipment and storage medium, the method is executed by adversarial data detection system, the system includes edge device and cloud computing platform;Including: obtaining the service data of user;The service data is input to the pre-trained based on light weight convolutional neural network model, and first prediction result is output;The based on light weight convolutional neural network model is deployed in the edge device;The service data is input to the pre-trained prediction model based on integrated multiple neural network model, and second prediction result is output;Wherein, the training data set of the based on light weight convolutional neural network model and prediction model is set number of image and character and generates corresponding adversarial data sample;The prediction model is deployed in the cloud computing platform;The detection algorithm of any two neural network models is different;Based on the comparison result of the first prediction result and the second prediction result, the type of the service data is determined;The type of the service data includes normal data or adversarial data.This method is used: by deploying multiple complex neural network models in cloud, using the computing power of cloud, the detection defense effect for adversarial data is realized. BRIEF DESCRIPTION OF DRAWINGS
[0023] The above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, like reference numerals will be used to designate like elements. It should be understood that the drawings are schematic and elements are not necessarily drawn to scale.
[0024] Figure 1 A flowchart of an adversarial data detection method provided by the present disclosure;
[0025] Figure 2 A flowchart of an adversarial data detection method provided by the present disclosure;
[0026] Figure 3 A structural schematic diagram of an adversarial data detection device provided by the present disclosure;
[0027] Figure 4 A structural schematic diagram of an electronic device provided by the present disclosure. DETAILED DESCRIPTION
[0028] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. While certain embodiments of the present disclosure are shown in the drawings, it is understood that the present disclosure can be embodied in various forms and should not be interpreted as being limited to the embodiments set forth herein; rather, these embodiments are provided so as to more completely and thoroughly understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for illustrative purposes and are not intended to limit the scope of protection of the present disclosure.
[0029] It should be understood that each of the steps recited in the method embodiments of the present disclosure can be performed in different orders and / or in parallel. In addition, the method embodiments can include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.
[0030] The term "comprising" and variations thereof as used herein are open-ended, that is "including but not limited to". The term "based on" is "based, at least in part, on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". Related terms are defined in the following description.
[0031] It should be noted that the terms "first", "second", and the like in the present disclosure are only used to distinguish different devices, modules or units, and are not intended to limit the order or interdependence of the functions performed by these devices, modules or units.
[0032] It should be noted that the adjectives "one", "more" mentioned in the present disclosure are illustrative and not limiting, and those skilled in the art should understand that "one or more" should be understood unless the context clearly indicates otherwise.
[0033] The names of the messages or information exchanged between the devices in the embodiments of the present disclosure are only for illustrative purposes, and are not intended to limit the scope of the messages or information.
[0034] It can be understood that, before using the technical solutions disclosed in the embodiments of the present disclosure, the type, scope of use, use scenario, etc. of the personal information involved in the present disclosure should be informed to the user and the authorization of the user should be obtained in accordance with relevant laws and regulations.
[0035] For example, when responding to the active request of the user, the user is sent a prompt message to explicitly prompt the user that the operation requested to be performed will require the acquisition and use of the personal information of the user. Thus, the user can voluntarily choose whether to provide personal information to the software or hardware, such as electronic devices, application programs, servers or storage media, etc. that perform the operation of the technical solutions of the present disclosure according to the prompt message.
[0036] As an optional but non-limiting implementation, in response to receiving the active request of the user, the manner of sending the prompt information to the user may be, for example, a pop-up window manner, in which the prompt information may be presented in the form of text. In addition, the pop-up window may also carry a selection control for the user to select "agree" or "disagree" to provide personal information to the electronic device.
[0037] It can be understood that the above notification and user authorization process is only illustrative and does not limit the implementation of the present disclosure. Other ways that meet relevant laws and regulations can also be applied to the implementation of the present disclosure.
[0038] It can be understood that the data involved in the present technical solution (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of relevant laws and regulations and relevant provisions.
[0039] Embodiment one
[0040] Figure 1 A flowchart of an adversarial data detection method provided by the embodiments of the present disclosure, the embodiments of the present disclosure are applicable to providing a solution to the problem that the edge device of the power business is limited by small storage space, insufficient computing power, etc., and often deploys these lightweight neural network models. Lightweight neural networks have low robustness and poor ability to defend against adversarial attacks. The method can be executed by an adversarial data detection method device. The device can be realized in the form of software and / or hardware. Optionally, it is realized by an electronic device, which can be a mobile terminal, a PC terminal, or a server, etc.
[0041] As shown in Figure 1 The adversarial data detection method provided by the embodiments of the present disclosure is executed by an adversarial data detection system, which includes an edge device and a cloud computing platform. Specifically, it can include the following steps:
[0042] S110, obtaining the business data of the user.
[0043] In the present embodiment, the business data can be picture, text, etc. uploaded by the user.
[0044] Specifically, this step is used to obtain the business data of the user.
[0045] On the basis of the above embodiment, obtaining the business data of the user includes the following steps:
[0046] a1) obtaining the business data received in the edge device.
[0047] b1) copying the business data and uploading the copied business data to the cloud computing platform.
[0048] In embodiments, the edge device can refer to a computing device deployed at the user side or the distributed energy side in a power system. The cloud computing platform can be an infrastructure that provides computing resources, storage resources and application services through the Internet.
[0049] Specifically, the service data received in the edge device is acquired, the service data is copied, and the copied service data is uploaded to the cloud computing platform.
[0050] S120, input the service data into the pre-trained lightweight-based convolutional neural network model to output a first prediction result.
[0051] The lightweight-based convolutional neural network model is deployed in the edge device.
[0052] In this embodiment, the lightweight-based convolutional neural network model can be a lightweight neural network model, for example, a MobileNetV3-Small model.
[0053] In this embodiment, this step is used to output a prediction result by the lightweight neural network deployed in the edge device.
[0054] S130, input the service data into the pre-trained prediction model based on the integrated multiple neural network models to output a second prediction result.
[0055] The training data set of the lightweight-based convolutional neural network model and the prediction model is a set number of images and characters and corresponding adversarial data samples; the prediction model is deployed in the cloud computing platform; and the detection algorithms of any two neural network models are different.
[0056] In this embodiment, the training data set can be 1000 images selected from the ILSVRC2012 validation set to generate adversarial data samples. 1000 clean pictures and 1000 adversarial data samples are sent to the edge device for training.
[0057] Specifically, the cloud computing platform is known for its elastic and scalable computing resources, providing strong support for deploying and running complex neural network models. A plurality of neural network models are deployed in the prediction model, and the detection algorithms of any two neural network models are different. For example, the neural network models in the prediction model can be Inception-v3, VGG16, ResNet50, Inception-v4 and InceptionRseNet-v2 models, respectively.
[0058] Specifically, the business data is input into the pre-trained prediction model based on the integrated multiple neural network models, and a prediction result set is output, wherein the prediction result set includes the prediction results output by each neural network model respectively, and the most possible prediction result is selected from the prediction result set as the second prediction result by using the maximum likelihood algorithm.
[0059] On the basis of the above embodiment, the business data is input into the pre-trained prediction model based on the integrated multiple neural network models, and the second prediction result is output, which specifically includes the following steps:
[0060] a2) inputting the business data into each neural network model in the prediction model to output a prediction result set;
[0061] wherein the prediction result set includes the prediction results output by each neural network model respectively.
[0062] b2) determining the second prediction result from the prediction result set.
[0063] On the basis of the above embodiment, the second prediction result can be determined from the prediction result set, which specifically can be that the prediction result with the most occurrences in the prediction result set is taken as the second prediction result.
[0064] Exemplarily, Figure 2 A flowchart of an example of an adversarial data detection method provided by the embodiment of the present disclosure is shown in FIG. 1. Figure 2 As shown in FIG. 1, after the business data is input into the Inception-v3, VGG16, ResNet50, Inception-v4 and InceptionRseNet-v2 models and undergoes a series of processing, five output results are obtained, wherein the output g1(x) of the VGG16 model is equal to "bird", the output g2(x) of the Inception-v3 model is equal to "fish", the output g3(x) of the ResNet50 model is equal to "fish", the output g4(x) of the Inception-v4 model is equal to "fish", and the output g5(x) of the InceptionRseNet-v2 model is equal to "fish", and the second prediction result is "fish".
[0065] S140, determining the type of the business data based on the comparison result of the first prediction result and the second prediction result.
[0066] In the embodiment, the type can be whether the business data is adversarial data.
[0067] Specifically, the first prediction result is compared with the second prediction result, if the first prediction result is the same as the second prediction result, the type of the business data is normal data, and if the first prediction result is different from the second prediction result, the type of the business data is adversarial data.
[0068] On the basis of the above-mentioned embodiments, the determination of the type of the service data based on the comparison result of the first prediction result and the second prediction result specifically comprises the following steps:
[0069] a3) comparing the first prediction result with the second prediction result.
[0070] b3) if the first prediction result is the same as the second prediction result, the type of the service data is normal data.
[0071] c3) if the first prediction result is different from the second prediction result, the type of the service data is adversarial data.
[0072] In the present embodiment, the type of the service data includes normal data or adversarial data.
[0073] Specifically, the first prediction result is compared with the second prediction result, if the first prediction result is the same as the second prediction result, the type of the service data is normal data, if the first prediction result is different from the second prediction result, the type of the service data is adversarial data
[0074] On the basis of the above-mentioned embodiments, after determining the type of the service data, the method further comprises:
[0075] If the type of the service data is adversarial data, the adversarial data detection system takes the measures of cutting off the application programming interface of the edge device and banning the user's account.
[0076] Specifically, if the type of the service data is adversarial data, the adversarial data detection system takes a series of defense measures, such as cutting off the connection of the application programming interface and carrying out relevant banning and handling of the user's account.
[0077] The present application discloses an adversarial data detection method, which is executed by an adversarial data detection system, the system comprising an edge device and a cloud computing platform; comprising: obtaining service data of a user; inputting the service data into a pre-trained lightweight convolutional neural network model to output a first prediction result; the lightweight convolutional neural network model is deployed in the edge device; inputting the service data into a pre-trained prediction model based on multiple integrated neural network models to output a second prediction result; wherein the training data set of the lightweight convolutional neural network model and the prediction model is a set number of images and characters and corresponding adversarial data samples; the prediction model is deployed in the cloud computing platform; the detection algorithms of any two neural network models are different; determining the type of the service data based on the comparison result of the first prediction result and the second prediction result; the type of the service data includes normal data or adversarial data. By using the method: by deploying multiple complex neural network models in the cloud, the detection and defense effect on adversarial data is realized by using the computing power of the cloud.
[0078] Figure 3 The application also provides a method and device structure diagram for detecting adversarial data. Figure 3 The data acquisition module 210, the first prediction module 220, the second prediction module 230, and the type determination module 240 are shown.
[0079] The data acquisition module 210 is configured to acquire service data of a user.
[0080] The first prediction module 220 is configured to input the service data into a pre-trained lightweight convolutional neural network model to output a first prediction result; and the lightweight convolutional neural network model is deployed on an edge device.
[0081] The second prediction module 230 is configured to input the service data into a prediction model based on multiple integrated neural network models to output a second prediction result; the training data set of the lightweight convolutional neural network model and the prediction model includes a set number of images and characters and corresponding adversarial data samples; the prediction model is deployed on a cloud computing platform; and the detection algorithms of any two neural network models are different.
[0082] The type determination module 240 is configured to determine the type of the service data based on a comparison result of the first prediction result and the second prediction result; and the type of the service data includes normal data or adversarial data.
[0083] The technical solution provided by the embodiments of the present disclosure uses the method: by deploying multiple complex neural network models on the cloud, the detection and defense effect on adversarial data is achieved by using the computing power of the cloud.
[0084] Further, the port acquisition module 210 can be configured to:
[0085] acquire the service data received by the edge device;
[0086] copy the service data and upload the copied service data to the cloud computing platform.
[0087] Further, the second prediction module 230 can be configured to:
[0088] input the service data into each neural network model in the prediction model to output a prediction result set; the prediction result set includes the prediction results output by each neural network model;
[0089] determine the second prediction result from the prediction result set.
[0090] Further, the second prediction module 230 can be configured to:
[0091] The prediction result with the most occurrences in the prediction result set is taken as the second prediction result.
[0092] Further, the type determination module 240 can also be configured to:
[0093] compare the first prediction result with the second prediction result;
[0094] if the first prediction result is the same as the second prediction result, the type of the service data is the normal data;
[0095] if the first prediction result is not the same as the second prediction result, the type of the service data is the adversarial data.
[0096] Further, the apparatus can also be configured to:
[0097] after determining the type of the service data, the apparatus further comprises:
[0098] if the type of the service data is the adversarial data, the adversarial data detection system takes measures to cut off the application programming interface of the edge device and ban the user's account.
[0099] The apparatus can perform the method provided by all the foregoing embodiments of the present application, and has the corresponding function modules and beneficial effects of performing the foregoing method. Technical details not described in the present embodiment can be found in the method provided by all the foregoing embodiments of the present application.
[0100] Figure 4 A structural schematic diagram of an electronic device 10 that can be used to implement embodiments of the present application is given. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular telephones, smart phones, wearable devices (e.g., headsets, glasses, watches, etc.), and other similar computing devices. The components shown here, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the implementations of the present application described and / or claimed in this document.
[0101] As Figure 4As shown, the electronic device 10 includes at least one processor 11, and a memory, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., communicatively connected to the at least one processor 11, where the memory stores a computer program executable by the at least one processor. The processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0102] Various components in the electronic device 10 are connected to the I / O interface 15, including an input unit 16, such as a keyboard, a mouse, etc., an output unit 17, such as various types of displays, a speaker, etc., a storage unit 18, such as a magnetic disk, an optical disk, etc., and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.
[0103] The processor 11 can be various general and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 performs various methods and processes described above, such as the adversarial data detection method.
[0104] In some embodiments, the adversarial data detection method can be implemented as a computer program tangibly embodied in a computer readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded onto the RAM 13 and executed by the processor 11, one or more steps of the adversarial data detection method described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to perform the adversarial data detection method by any other appropriate means, such as by means of firmware.
[0105] The various embodiments of the systems and techniques described above can be implemented in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a load programmable logic device (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.
[0106] Computer programs used to implement the processes of the application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer program, when executed, can cause instructions defined in the flow charts and / or block diagrams to be implemented. The computer program can be executed entirely on a machine, partially on a machine, partially on a machine as a standalone software package and partially on a remote machine or entirely on a remote machine or server.
[0107] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store computer programs for use by or in connection with an instruction execution system, apparatus, or device. Computer-readable storage media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium will include one or more lines of electrical connections, portable computer disks, hard disk drives, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or Flash memory), optical fibers, portable compact disc read-only memories (CD-ROMs), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0108] To provide for interaction with a user, the systems and techniques described here can be implemented on an electronic device having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.
[0109] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.
[0110] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. A server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system, to solve the defects of large management difficulty and weak business scalability in traditional physical host and VPS service.
[0111] It should be understood that the various forms of flow shown above can be re-ordered, added to, or deleted from without departing from the scope of the present disclosure. For example, the steps recited in the present disclosure can be executed in parallel, executed in sequence, or executed in a different order, as long as the desired results of the present disclosure are achieved, and the present disclosure is not limited herein.
[0112] The specific embodiments described above are not intended to be limiting, and persons skilled in the art will appreciate that various modifications, combinations, sub-combinations and alternatives can be made to the specific embodiments without departing from the spirit and principles of the disclosure. Accordingly, the disclosure is not limited to the specific embodiments described above, but only by the scope of the appended claims.
Claims
1. A method for adversarial data detection, characterized in that, The method is executed by an adversarial data detection system, which includes edge devices and a cloud computing platform; including: Obtain user business data; The business data is input into a pre-trained lightweight convolutional neural network model, which outputs a first prediction result; the lightweight convolutional neural network model is deployed on the edge device. The business data is input into a pre-trained prediction model based on multiple integrated convolutional neural network models, and a second prediction result is output; wherein, the training dataset of the lightweight convolutional neural network model and the prediction model consists of a set number of images and characters and corresponding adversarial data samples; the prediction model is deployed in the cloud computing platform; the detection algorithms of any two neural network models are different; Based on the comparison between the first prediction result and the second prediction result, the type of the business data is determined; the type of business data includes normal data or adversarial data.
2. The method according to claim 1, characterized in that, The acquisition of user business data includes: Obtain the service data received from the edge device; The business data is copied, and the copied business data is uploaded to the cloud computing platform.
3. The method according to claim 1, characterized in that, The business data is input into a pre-trained prediction model based on an integration of multiple neural network models, and a second prediction result is output, including: The business data is input into each neural network model in the prediction model, and a prediction result set is output; the prediction result set includes the prediction results output by each of the neural network models respectively; The second prediction result is determined from the set of prediction results.
4. The method according to claim 3, characterized in that, include: Determining the second prediction result from the prediction result set includes: The prediction result that appears most frequently in the prediction result set is taken as the second prediction result.
5. The method according to claim 1, characterized in that, Determining the type of business data based on the comparison between the first prediction result and the second prediction result includes: Compare the first prediction result with the second prediction result; If the first prediction result is the same as the second prediction result, then the type of the business data is the normal data; If the first prediction result is different from the second prediction result, then the type of the business data is the adversarial data.
6. The method according to claim 1, characterized in that, After determining the type of the business data, the method further includes: If the type of business data is adversarial data, the adversarial data detection system will cut off the application programming interface of the edge device and ban the user's account.
7. A data detection device for combating data, characterized in that, include: The data acquisition module is used to acquire users' business data; The first prediction module is used to input the business data into a pre-trained lightweight convolutional neural network model and output a first prediction result; the lightweight convolutional neural network model is deployed on an edge device. The second prediction module is used to input the business data into a pre-trained prediction model based on multiple integrated neural network models and output a second prediction result; wherein, the training dataset of the lightweight convolutional neural network model and the prediction model consists of a set number of images and characters and corresponding adversarial data samples; the prediction model is deployed on a cloud computing platform; and the detection algorithms of any two neural network models are different. The type determination module is used to determine the type of the business data based on the comparison result between the first prediction result and the second prediction result; the type of business data includes normal data or adversarial data.
8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the adversarial data detection method according to any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the adversarial data detection method according to any one of claims 1-6.
10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the adversarial data detection method according to any one of claims 1-6.
Citation Information
Patent Citations
Neural network automatic training method and device based on cloud platform and model recommendation
CN109376844A
Visual question and answer network model training method and device, equipment and storage medium
CN115270987A