Self-learning defense method, device and equipment facing power system artificial intelligence model backdoor attack, storage medium and program product
By introducing a self-learning defense method into the artificial intelligence model of the power system, using pre-filters and data detection models to identify and update abnormal data, the problem that backdoor attack defense in the existing technology is difficult to ensure model accuracy, and the effect of improving model security without reducing model accuracy is achieved.
Patent Information
- Application Number
- CN202510066138.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-16
- Publication Date
- 2025-05-06
Smart Images

Figure CN119939351A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a self-learning defense method, device, equipment, storage medium and program product for backdoor attacks on artificial intelligence models of power systems. Background Art
[0002] Backdoor attacks usually occur during the training phase of a model (machine learning model or deep learning model), which may be caused by the use of an insecure third-party pre-trained model or training data. The backdoor can be considered as a hidden mode of the trained model. When activated by a certain "trigger", it will produce the output expected by the attacker, but it will not be detected as abnormal under normal circumstances. In the intrusion detection model, the attacker can use the backdoor to make the malicious traffic with the "trigger" added be recognized as normal traffic by the model, while the traffic without the "trigger" will not be classified as abnormal, so the attack is not easy to detect. If this model is applied to the power system, it will seriously threaten the security of the power system.
[0003] At present, backdoor defense for neural networks in power systems focuses on identifying and adjusting neurons that may be activated when processing backdoor inputs, which usually means screening and intervening in the entire model. However, in practice, it is found that some cleaned or fine-tuned neurons not only play a role in processing backdoor inputs, but also participate in the information processing process under normal input scenarios. Therefore, removing or changing the state of these neurons may lead to a decrease in the prediction performance of the neural network for normal samples, thereby causing a decline in the accuracy of the overall model.
[0004] Therefore, how to improve the security of the smart grid artificial intelligence model while ensuring its accuracy has become an urgent problem to be solved. Summary of the invention
[0005] The embodiments of the present application provide a self-learning defense method, device, equipment, storage medium and program product for backdoor attacks on power system artificial intelligence models, which can improve the security of the model while ensuring the accuracy of the smart grid artificial intelligence model.
[0006] In a first aspect, an embodiment of the present application provides a self-learning defense method for backdoor attacks on an artificial intelligence model of a power system, the method comprising:
[0007] Filter the information in the current power data through the pre-filter and determine whether abnormal information is filtered out;
[0008] When it is determined that abnormal information has been screened out, the current power data is stored and input into a data detection model to obtain a predicted category for the current power data;
[0009] Based on the predicted category, determine a label for the current power data;
[0010] In the case where the label is abnormal power data, the integrated learning model is trained and updated based on the abnormal power data; the updated integrated learning model is used to detect the power data input next time.
[0011] In one of the embodiments, based on the predicted category, a label for the current power data is determined, including: displaying the predicted category in a user interface so that a user can input a label for the current power data in the user interface based on the predicted category and the actual category of the current power data; and determining the label entered for the current power data in the user interface.
[0012] In one of the embodiments, if the label is abnormal power data, it indicates that the predicted category is different from the actual category of the current power data.
[0013] In one of the embodiments, the method further includes: when it is determined that no abnormal information has been screened out, inputting the current power data into an artificial intelligence model to obtain data features of the current power data; and determining a prediction category for the current power data based on the data features of the current power data and a predetermined mean of the data features of a plurality of clean sample power data.
[0014] In one of the embodiments, based on data features of the current power data and a predetermined mean value of data features of multiple clean sample power data, a prediction category for the current power data is determined, including: when it is determined that the cosine distance between the data features of the current power data and a predetermined mean value of data features of multiple clean sample power data is greater than a preset threshold, determining that the prediction category of the current power data is abnormal power data.
[0015] In the second aspect, the present application provides a self-learning defense device for backdoor attacks on artificial intelligence models of power systems, the device comprising a pre-filtering module, an abnormal input recording and processing module, and a post-self-learning filtering module; wherein,
[0016] The pre-filtering module is used to filter the information in the current power data and write the abnormal information into the abnormal input recording module when abnormal information is filtered out;
[0017] The abnormal input recording and processing module is used to store abnormal information and input the current power data into the data detection model to obtain the predicted category for the current power data;
[0018] The abnormal input recording and processing module is also used to determine a label for the current power data based on the predicted category;
[0019] The post-self-learning filtering module is used to train and update the integrated learning model based on the abnormal power data when the label is abnormal power data; the updated integrated learning model is used to detect the power data input next time.
[0020] In one of the embodiments, the pre-filtering module is further used to input the current power data into the post-self-learning filtering module when it is determined that no abnormal information has been screened out; the post-self-learning filtering module is further used to input the current power data into the artificial intelligence model to obtain data features of the current power data, and determine a prediction category for the current power data based on the data features of the current power data and a predetermined mean value of the data features of multiple clean sample power data; the post-self-learning filtering module is further used to write the current power data into the abnormal input recording and processing module when it is determined that the prediction category for the current power data is abnormal power data.
[0021] In a third aspect, the present application provides another self-learning defense device for backdoor attacks on artificial intelligence models of power systems, the device comprising:
[0022] An information screening module is used to screen the information in the current power data through a pre-filter and determine whether abnormal information is screened out;
[0023] A storage and detection module is used to store the current power data and input the current power data into a data detection model to obtain a predicted category for the current power data when abnormal information is determined to be filtered out;
[0024] A determination module, used for determining a label for current power data based on the predicted category;
[0025] The model training and updating module is used to train and update the integrated learning model based on the abnormal power data when the label is abnormal power data; the updated integrated learning model is used to detect the power data input next time.
[0026] In a fourth aspect, the present application provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:
[0027] Filter the information in the current power data through the pre-filter and determine whether abnormal information is filtered out;
[0028] When it is determined that abnormal information has been screened out, the current power data is stored and input into a data detection model to obtain a predicted category for the current power data;
[0029] Based on the predicted category, determine a label for the current power data;
[0030] In the case where the label is abnormal power data, the integrated learning model is trained and updated based on the abnormal power data; the updated integrated learning model is used to detect the power data input next time.
[0031] In a fifth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the following steps are implemented:
[0032] Filter the information in the current power data through the pre-filter and determine whether abnormal information is filtered out;
[0033] When it is determined that abnormal information has been screened out, the current power data is stored and input into a data detection model to obtain a predicted category for the current power data;
[0034] Based on the predicted category, determine a label for the current power data;
[0035] In the case where the label is abnormal power data, the integrated learning model is trained and updated based on the abnormal power data; the updated integrated learning model is used to detect the power data input next time.
[0036] In a sixth aspect, the present application further provides a computer program product, including a computer program, which implements the following steps when executed by a processor:
[0037] Filter the information in the current power data through the pre-filter and determine whether abnormal information is filtered out;
[0038] When it is determined that abnormal information has been screened out, the current power data is stored and input into a data detection model to obtain a predicted category for the current power data;
[0039] Based on the predicted category, determine a label for the current power data;
[0040] In the case where the label is abnormal power data, the integrated learning model is trained and updated based on the abnormal power data; the updated integrated learning model is used to detect the power data input next time.
[0041] The above-mentioned self-learning defense method, device, equipment, storage medium and program product for backdoor attacks on artificial intelligence models of power systems, the computer equipment can filter the information in the current power data through the pre-filter and determine whether abnormal information is filtered out; when it is determined that abnormal information is filtered out, the current power data is stored, and the current power data is input into the data detection model to obtain a predicted category for the current power data; based on the predicted category, a label for the current power data is determined; when the label is abnormal power data, the integrated learning model is trained and updated based on the abnormal power data; the updated integrated learning model is used to detect the power data input next time. By adopting this method, the computer equipment can preliminarily screen the information of the current power data through a pre-filter before inputting the current power data into the power intelligent model, identify and intercept potential abnormal information, thereby reducing the possibility of the model being attacked and ensuring that a large amount of abnormal information is intercepted and recorded. Afterwards, by analyzing and archiving the abnormal information, a label for the current power data is obtained, and when the label is abnormal power data, the integrated learning model is trained and updated based on the abnormal power data. Therefore, not only can the robustness of the power system artificial intelligence model be improved, but also the integrated learning model can be continuously adjusted and optimized according to various abnormal power data encountered in actual operation, so that the model can adapt to the ever-changing backdoor attack methods, and thus, the security of the model can be improved while ensuring the accuracy of the smart grid artificial intelligence model. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the drawings required for use in the embodiments of the present application or related technical descriptions will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0043] Figure 1 It is a schematic diagram of an application scenario of a self-learning defense method for backdoor attacks on an artificial intelligence model of a power system provided in an embodiment of the present application;
[0044] Figure 2 It is a flowchart of a self-learning defense method for backdoor attacks on an artificial intelligence model of a power system provided in an embodiment of the present application;
[0045] Figure 3 It is a flowchart of another self-learning defense method for backdoor attacks on artificial intelligence models of power systems provided in an embodiment of the present application;
[0046] Figure 4It is a process diagram of a self-learning defense method for backdoor attacks on an artificial intelligence model of a power system provided by an embodiment of the present application;
[0047] Figure 5 It is a structural schematic diagram of a self-learning defense device for backdoor attacks on an artificial intelligence model of a power system provided in an embodiment of the present application;
[0048] Figure 6 It is a structural schematic diagram of another self-learning defense device for power system artificial intelligence model backdoor attack provided by an embodiment of the present application;
[0049] Figure 7 It is a structural diagram of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0050] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0051] The following introduces the application scenarios of the self-learning defense method for backdoor attacks on artificial intelligence models in power systems provided in the embodiments of the present application.
[0052] See also Figure 1 , Figure 1 Schematic diagram of an application scenario of a self-learning defense method for backdoor attacks on an artificial intelligence model of a power system provided by an embodiment of the present application. Figure 1 As shown, the computer device 101 ( Figure 1 In the figure, the computer device 101 is drawn as an example of a terminal device) and a database server 102, wherein data can be transmitted between the computer device 101 and the database server 102 via a network.
[0053] The database server 102 may be used to store power data.
[0054] The computer device 101 can first obtain the current power data from the database server 102, and then filter the information in the current power data through a pre-filter to determine whether abnormal information is filtered out; if it is determined that the abnormal information is filtered out, the current power data is stored, and the current power data is input into the data detection model to obtain a predicted category for the current power data; then, based on the predicted category, a label for the current power data is determined; finally, if the label is abnormal power data, the integrated learning model is trained and updated based on the abnormal power data; wherein the updated integrated learning model is used to detect the power data input next time. By adopting this method, the computer equipment can preliminarily screen the information of the current power data through a pre-filter before inputting the current power data into the power intelligent model, identify and intercept potential abnormal information, thereby reducing the possibility of the model being attacked and ensuring that a large amount of abnormal information is intercepted and recorded. Afterwards, by analyzing and archiving the abnormal information, a label for the current power data is obtained, and when the label is abnormal power data, the integrated learning model is trained and updated based on the abnormal power data. Therefore, not only can the robustness of the power system artificial intelligence model be improved, but also the integrated learning model can be continuously adjusted and optimized according to various abnormal power data encountered in actual operation, so that the model can adapt to the ever-changing backdoor attack methods, thereby ensuring the accuracy of the smart grid artificial intelligence model while improving the security of the model.
[0055] Optionally, the computer device 101 may be a terminal device or a server. The terminal device mentioned here may include but is not limited to: a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart watch, a smart TV, a smart car terminal, etc. The server mentioned here may be an independent physical server, or a server cluster or a distributed system composed of multiple physical servers.
[0056] See also Figure 2 , Figure 2 1 is a flowchart of a self-learning defense method for backdoor attacks on an artificial intelligence model of a power system provided by an embodiment of the present application. The method can be executed by a computer device (for example, the above-mentioned computer device 101). Figure 2 As shown, the self-learning defense method for backdoor attacks on power system artificial intelligence models may include but is not limited to the following steps:
[0057] S201. Filter information in current power data through a pre-filter and determine whether abnormal information is filtered out.
[0058] Optionally, the current power data may be a power image, power information, power text, etc., which is not limited here.
[0059] Optionally, the information in the current power data may include, but is not limited to, input information such as an input account number, an input Internet Protocol (IP) address, and an input time.
[0060] Taking the case where the current power data is a power image as an example, the computer device filters the information in the current power data through a pre-filter, which may be to perform Fourier transform on the currently input power image to obtain a frequency domain signal corresponding to the currently input power image; when it is determined that the frequency domain signal includes a high-frequency signal, it is determined that there is abnormal information in the currently input power image. In this case, the computer device may intercept the currently input power image and store the intercepted currently input power image.
[0061] S202: When it is determined that abnormal information has been screened out, the current power data is stored and the current power data is input into a data detection model to obtain a predicted category for the current power data.
[0062] In this way, by performing secondary detection on the current power data intercepted by the pre-filter, it is helpful to improve the accuracy of identifying the current power data.
[0063] S203: Determine a label for current power data based on the predicted category.
[0064] S204: When the label is abnormal power data, the integrated learning model is trained and updated based on the abnormal power data; the updated integrated learning model is used to detect the power data input next time.
[0065] Optionally, the integrated learning model may be a model integrating support vector machine (SVM), clustering, and cosine distance, or a model integrating other multiple algorithms, which is not limited here.
[0066] In an embodiment of the present application, the computer device can filter the information in the current power data through a pre-filter and determine whether abnormal information is filtered out; when it is determined that abnormal information is filtered out, the current power data is stored and the current power data is input into a data detection model to obtain a predicted category for the current power data; based on the predicted category, a label for the current power data is determined; when the label is abnormal power data, the integrated learning model is trained and updated based on the abnormal power data; the updated integrated learning model is used to detect the power data input next time. By adopting this method, the computer equipment can preliminarily screen the information of the current power data through a pre-filter before inputting the current power data into the power intelligent model, identify and intercept potential abnormal information, thereby reducing the possibility of the model being attacked and ensuring that a large amount of abnormal information is intercepted and recorded. Afterwards, by analyzing and archiving the abnormal information, a label for the current power data is obtained, and when the label is abnormal power data, the integrated learning model is trained and updated based on the abnormal power data. Therefore, not only can the robustness of the power system artificial intelligence model be improved, but also the integrated learning model can be continuously adjusted and optimized according to various abnormal power data encountered in actual operation, so that the model can adapt to the ever-changing backdoor attack methods, and thus, the security of the model can be improved while ensuring the accuracy of the smart grid artificial intelligence model.
[0067] See also Figure 3 , Figure 3 1 is a flowchart of another self-learning defense method for power system artificial intelligence model backdoor attack provided by the embodiment of the present application. Figure 2 Compared with the self-learning defense method for backdoor attacks on power system artificial intelligence models shown in Figure 3 The method also describes how the computer device obtains the predicted category for the current power data when it determines that no abnormal information has been screened out, and how the computer device determines the label for the current power data based on the predicted category. Figure 3 As shown, the self-learning defense method for backdoor attacks on power system artificial intelligence models may include but is not limited to the following steps:
[0068] S301. Filter the information in the current power data through a pre-filter and determine whether abnormal information is filtered out. If so, execute steps S302 and S305-S307; if not, execute steps S303 to S307.
[0069] In an optional implementation, the relevant description of step S301 can refer to the description of the aforementioned step S201, which will not be repeated here.
[0070] S302: Store the current power data, and input the current power data into a data detection model to obtain a predicted category for the current power data.
[0071] The computer device may store the current power data, including but not limited to storing the input account, IP address, input time, etc. corresponding to the current power data.
[0072] S303: Input the current power data into the artificial intelligence model to obtain data features of the current power data.
[0073] Optionally, in the present application, the data feature of the current power data may also be referred to as an activation value of the current power data.
[0074] S304: Determine a prediction category for the current power data based on data features of the current power data and pre-determined data feature means of a plurality of clean sample power data.
[0075] In an optional embodiment, before step S304, the computer device may also input multiple clean sample power data into the artificial intelligence model to obtain data features of each clean sample power data, and then determine the data feature mean of the multiple clean sample power data based on the data features of each clean sample power data.
[0076] Optionally, in the present application, the data feature mean of multiple clean sample power data may also be referred to as the activation value of multiple clean sample power data.
[0077] S305 . Display the predicted category on the user interface, so that the user can input a label for the current power data on the user interface based on the predicted category and the actual category of the current power data.
[0078] Since the current power data has no label (or category label) in the actual application process, the computer device can output the predicted category of the current power data to the user interface after determining the predicted category of the current power data, so that the user can input the label of the current power data in the user interface based on the predicted category and the real category of the current power data determined by the user. The label of the current power data can be clean power data or abnormal power data.
[0079] Among them, when the user inputs a label for the current power data in the user interface, if the predicted category of the current power data is consistent with the actual category (or matches), the label for the current power data can be entered in the user interface as clean power data; if the predicted category of the current power data is inconsistent with the actual category (or does not match), the label for the current power data can be entered in the user interface as abnormal power data.
[0080] S306: Determine a label for the current power data input in the user interface.
[0081] S307: When the label is abnormal power data, the integrated learning model is trained and updated based on the abnormal power data; the updated integrated learning model is used to detect the power data input next time.
[0082] In this way, as the system runs, the computer equipment can use the new abnormal power data to continuously fine-tune the integrated learning model, and continuously learn and optimize the integrated learning model by learning the data characteristics of the new abnormal power data. Therefore, the strategy can be continuously adjusted and optimized according to the abnormal situations encountered in actual operation, so that the system can adapt to the ever-changing attack methods and maintain long-term effectiveness.
[0083] Optionally, the integrated learning model may be a model integrating support vector machine (SVM), clustering, and cosine distance, or a model integrating other multiple algorithms, which is not limited here.
[0084] In the embodiment of the present application, the computer device filters the information in the current power data through a pre-filter and determines whether abnormal information is filtered out. If so, the current power data is stored and input into the data detection model to obtain the predicted category for the current power data; if not, the current power data is input into the artificial intelligence model to obtain the data features of the current power data; based on the data features of the current power data and the data feature mean of a plurality of pre-determined clean sample power data, the predicted category for the current power data is determined. Afterwards, the predicted category of the current power data is submitted to manual review to determine the label for the current power data. Finally, in the case where the label is abnormal power data, the integrated learning model is trained and updated based on the abnormal power data; the updated integrated learning model is used to detect the power data input next time. By adopting the embodiments of the present application, on the one hand, the computer device can perform preliminary screening of the information of the current power data through a pre-filter before inputting the current power data into the power intelligent model, identify and intercept potential abnormal information, thereby reducing the possibility of the model being attacked and ensuring that a large amount of abnormal information is intercepted and recorded, thereby improving the robustness of the model. On the other hand, in the case of abnormal power data labeled, the integrated learning model is trained and updated based on the abnormal power data, so that the computer device can continuously adjust and optimize the integrated learning model according to various abnormal power data encountered in actual operation, so that the model can adapt to the ever-changing backdoor attack methods, and thus, the security of the model can be improved while ensuring the accuracy of the smart grid artificial intelligence model.
[0085] See also Figure 4 , Figure 4 It is a process diagram of a self-learning defense method for backdoor attacks on artificial intelligence models of power systems provided in an embodiment of the present application.
[0086] like Figure 4 As shown, the computer device may first determine the current power data currently input, and then input the current power data into the pre-filter to filter out abnormal information in the current power data; if the abnormal information is filtered out, the current power data is input into the data detection model to determine the predicted category of the current power data; if the abnormal information is not filtered out, the current power data is input into the artificial intelligence model (such as the artificial intelligence model) to obtain the data features (or activation values) of the current power data, and determine the cosine distance between the data features of the current power data and the data feature mean of the predetermined clean sample power data, and when it is determined that the cosine distance is greater than the preset threshold, the predicted category of the current power data is determined to be abnormal power data. Then, the computer device may display the predicted category in the user interface, so that the user can input a label for the current power data in the user interface based on the predicted category and the actual category of the current power data (i.e., manually review the predicted category and determine the label for the current power data). Afterwards, when the label of the current power data is abnormal power data, the current power data is input into the integrated learning model to train and update the integrated learning model based on the abnormal power data; the updated integrated learning model is used to detect the power data input next time.
[0087] The computer device may also determine that the predicted category for the current power data is clean power data when no abnormal information is screened out and the cosine distance between the data feature of the current power data and the pre-determined data feature mean of the clean sample power data is less than or equal to a preset threshold. In this case, the computer device may also output the predicted category for the current power data.
[0088] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.
[0089] Based on the same inventive concept, the embodiment of the present application also provides a self-learning defense device for power system artificial intelligence model backdoor attacks for implementing the above-mentioned self-learning defense method for power system artificial intelligence model backdoor attacks. The implementation scheme for solving the problem provided by the device is similar to the implementation scheme recorded in the above-mentioned method, so the specific limitations in one or more embodiments of the self-learning defense device for power system artificial intelligence model backdoor attacks provided below can be found in the above-mentioned limitations on the self-learning defense method for power system artificial intelligence model backdoor attacks, and will not be repeated here.
[0090] See also Figure 5 , Figure 5 Schematic diagram of the structure of a self-learning defense device for power system artificial intelligence model backdoor attack provided by the embodiment of the present application. Figure 5 As shown, the self-learning defense device for backdoor attacks on power system artificial intelligence models may include but is not limited to a pre-filtering module 501, an abnormal input recording and processing module 502, and a post-self-learning filtering module 503: wherein,
[0091] The pre-filtering module 501 is used to filter the information in the current power data and write the abnormal information into the abnormal input recording module when abnormal information is filtered out;
[0092] The abnormal input recording and processing module 502 is used to store abnormal information and input the current power data into the data detection model to obtain the prediction category for the current power data;
[0093] The abnormal input recording and processing module 502 is also used to determine a label for the current power data based on the predicted category;
[0094] The post-self-learning filtering module 503 is used to train and update the integrated learning model based on the abnormal power data when the label is abnormal power data; wherein the updated integrated learning model is used to detect the power data input next time.
[0095] In one embodiment, the pre-filtering module 501 is also used to input the current power data into the post-self-learning filtering module when it is determined that no abnormal information has been screened out; the post-self-learning filtering module 503 is also used to input the current power data into the artificial intelligence model to obtain the data features of the current power data, and determine the prediction category for the current power data based on the data features of the current power data and the data feature means of a plurality of predetermined clean sample power data; the post-self-learning filtering module 503 is also used to write the current power data into the abnormal input recording and processing module 502 when it is determined that the prediction category for the current power data is abnormal power data.
[0096] The self-learning defense device for backdoor attack of the power system artificial intelligence model provided by the embodiment of the present application realizes efficient protection of the smart grid artificial intelligence model through non-invasive design (adding external modules (i.e., the pre-filtering module 501, the abnormal input recording and processing module 502, and the post-self-learning filtering module 503) without modifying the original model structure and parameters), modular architecture (through modular design, the pre-filtering module, the abnormal input recording and processing module, and the post-self-learning filtering module can provide comprehensive protection for the model like a firewall, which not only facilitates the individual maintenance and upgrading of each module, but also enables the smart grid artificial intelligence model to flexibly expand new functional modules as needed), and self-learning ability (dynamically adjusting and optimizing the filtering strategy by learning the data in the abnormal input recording and processing module). In this way, the security of the smart grid artificial intelligence model can be improved while ensuring the accuracy of the original model. In addition, the long-term effectiveness of the smart grid artificial intelligence model (even in the face of new attack methods, the smart grid artificial intelligence model can respond quickly) and maintainability can be guaranteed, that is, it provides comprehensive protection for the safe and stable operation of the smart grid artificial intelligence model.
[0097] See also Figure 6 , Figure 6 Schematic diagram of another self-learning defense device for power system artificial intelligence model backdoor attack provided by the embodiment of the present application. Figure 6 As shown, the self-learning defense device for backdoor attacks on power system artificial intelligence models may include but is not limited to:
[0098] The information screening module 601 is used to screen the information in the current power data through a pre-filter and determine whether abnormal information is screened out;
[0099] The storage and detection module 602 is used to store the current power data and input the current power data into the data detection model to obtain the prediction category for the current power data when abnormal information is determined to be filtered out;
[0100] A determination module 603, configured to determine a label for current power data based on the predicted category;
[0101] The model training and updating module 604 is used to train and update the integrated learning model based on the abnormal power data when the label is abnormal power data; wherein the updated integrated learning model is used to detect the power data input next time.
[0102] In one embodiment, when the determination module 403 is used to determine the label for the current power data based on the predicted category, it is specifically used to: display the predicted category in the user interface so that the user can input the label for the current power data in the user interface based on the predicted category and the actual category of the current power data; determine the label entered for the current power data in the user interface.
[0103] In one embodiment, if the label is abnormal power data, it indicates that the predicted category is different from the actual category of the current power data.
[0104] In one embodiment, the storage and detection module 602 is also used to: when it is determined that no abnormal information has been screened out, input the current power data into the artificial intelligence model to obtain data features of the current power data; based on the data features of the current power data and the data feature means of multiple predetermined clean sample power data, determine the prediction category for the current power data.
[0105] In one embodiment, when the storage and detection module 602 is used to determine the prediction category for the current power data based on the data features of the current power data and the pre-determined mean values of the data features of multiple clean sample power data, it is specifically used to: when it is determined that the cosine distance between the data features of the current power data and the pre-determined mean values of the data features of multiple clean sample power data is greater than a preset threshold, determine that the prediction category of the current power data is abnormal power data.
[0106] Each module in the above self-learning defense device for backdoor attacks on power system artificial intelligence models can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above modules can be embedded in or independent of the processor in the terminal device in the form of hardware, or can be stored in the memory in the terminal device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.
[0107] In an exemplary embodiment, the present application provides a computer device, which may be a terminal, and its internal structure diagram may be as follows: Figure 7 As shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit and an input device. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface, the display unit and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and the external device. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, near field communication (Near Field Communication, NFC) or other technologies. When the computer program is executed by the processor, a self-learning defense method for backdoor attacks on artificial intelligence models of power systems is implemented.
[0108] Those skilled in the art will understand that Figure 7 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0109] In an exemplary embodiment, the present application provides a computer device, including a memory and a processor, wherein a computer program is stored in the memory, and when the processor executes the computer program, the following steps are implemented:
[0110] Filter the information in the current power data through the pre-filter and determine whether abnormal information is filtered out;
[0111] When it is determined that abnormal information has been screened out, the current power data is stored and input into a data detection model to obtain a predicted category for the current power data;
[0112] Based on the predicted category, determine a label for the current power data;
[0113] In the case where the label is abnormal power data, the integrated learning model is trained and updated based on the abnormal power data; wherein the updated integrated learning model is used to detect the power data input next time.
[0114] In one embodiment, when the processor executes a computer program to determine a label for current power data based on a predicted category, the following steps are specifically implemented: the predicted category is displayed in a user interface so that a user can input a label for the current power data in the user interface based on the predicted category and the actual category of the current power data; and the label entered for the current power data in the user interface is determined.
[0115] In one embodiment, if the label is abnormal power data, it indicates that the predicted category is different from the actual category of the current power data.
[0116] In one embodiment, the processor executes the computer program to further implement the following steps: when it is determined that no abnormal information has been screened out, the current power data is input into the artificial intelligence model to obtain data features of the current power data; based on the data features of the current power data and the data feature means of a plurality of predetermined clean sample power data, a prediction category for the current power data is determined.
[0117] In one embodiment, the processor executes a computer program to determine the prediction category for the current power data based on the data features of the current power data and the pre-determined mean values of the data features of multiple clean sample power data, and specifically implements the following steps: when it is determined that the cosine distance between the data features of the current power data and the pre-determined mean values of the data features of multiple clean sample power data is greater than a preset threshold, determine that the prediction category of the current power data is abnormal power data.
[0118] In an exemplary embodiment, the present application provides a computer-readable storage medium having a computer program stored thereon, and when the computer program is executed by a processor, the following steps are implemented:
[0119] Filter the information in the current power data through the pre-filter and determine whether abnormal information is filtered out;
[0120] When it is determined that abnormal information has been screened out, the current power data is stored and input into a data detection model to obtain a predicted category for the current power data;
[0121] Based on the predicted category, determine a label for the current power data;
[0122] In the case where the label is abnormal power data, the integrated learning model is trained and updated based on the abnormal power data; wherein the updated integrated learning model is used to detect the power data input next time.
[0123] In one embodiment, when a computer program is executed by a processor to determine a label for current power data based on a predicted category, the following steps are specifically implemented: the predicted category is displayed in a user interface so that a user can input a label for the current power data in the user interface based on the predicted category and the actual category of the current power data; and the label entered for the current power data in the user interface is determined.
[0124] In one embodiment, if the label is abnormal power data, it indicates that the predicted category is different from the actual category of the current power data.
[0125] In one embodiment, when the computer program is executed by the processor, the following steps are also implemented: when it is determined that no abnormal information has been screened out, the current power data is input into the artificial intelligence model to obtain data features of the current power data; based on the data features of the current power data and the data feature means of a plurality of predetermined clean sample power data, a prediction category for the current power data is determined.
[0126] In one embodiment, a computer program is executed by a processor to implement, when determining a prediction category for current power data based on data features of the current power data and a predetermined mean value of data features of multiple clean sample power data, the following steps are specifically implemented: when it is determined that the cosine distance between the data features of the current power data and a predetermined mean value of data features of multiple clean sample power data is greater than a preset threshold, the prediction category of the current power data is determined to be abnormal power data.
[0127] In an exemplary embodiment, the present application provides a computer program product, including a computer program, which implements the following steps when executed by a processor:
[0128] Filter the information in the current power data through the pre-filter and determine whether abnormal information is filtered out;
[0129] When it is determined that abnormal information has been screened out, the current power data is stored and input into a data detection model to obtain a predicted category for the current power data;
[0130] Based on the predicted category, determine a label for the current power data;
[0131] In the case where the label is abnormal power data, the integrated learning model is trained and updated based on the abnormal power data; wherein the updated integrated learning model is used to detect the power data input next time.
[0132] In one embodiment, when a computer program is executed by a processor to determine a label for current power data based on a predicted category, the following steps are specifically implemented: the predicted category is displayed in a user interface so that a user can input a label for the current power data in the user interface based on the predicted category and the actual category of the current power data; and the label entered for the current power data in the user interface is determined.
[0133] In one embodiment, if the label is abnormal power data, it indicates that the predicted category is different from the actual category of the current power data.
[0134] In one embodiment, when the computer program is executed by the processor, the following steps are also implemented: when it is determined that no abnormal information has been screened out, the current power data is input into the artificial intelligence model to obtain data features of the current power data; based on the data features of the current power data and the data feature means of a plurality of predetermined clean sample power data, a prediction category for the current power data is determined.
[0135] In one embodiment, a computer program is executed by a processor to implement, when determining a prediction category for current power data based on data features of the current power data and a predetermined mean value of data features of multiple clean sample power data, the following steps are specifically implemented: when it is determined that the cosine distance between the data features of the current power data and a predetermined mean value of data features of multiple clean sample power data is greater than a preset threshold, the prediction category of the current power data is determined to be abnormal power data.
[0136] It should be noted that the data involved in this application (including but not limited to current power data, abnormal information, clean sample power data, etc.) are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.
[0137] A person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment method can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., but are not limited to this.
[0138] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0139] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.
Claims
1. A self-learning defense method for backdoor attacks on artificial intelligence models in power systems, characterized in that: Filter the information in the current power data through the pre-filter and determine whether abnormal information is filtered out; In the case where it is determined that abnormal information has been screened out, the current power data is stored, and the current power data is input into a data detection model to obtain a predicted category for the current power data; Based on the predicted category, determining a label for the current power data; In the case where the label is abnormal power data, the integrated learning model is trained and updated based on the abnormal power data; the updated integrated learning model is used to detect the power data input next time.
2. The method according to claim 1, characterized in that The step of determining a label for the current power data based on the predicted category includes: Displaying the predicted category on a user interface so that a user inputs a label for the current power data on the user interface based on the predicted category and a real category of the current power data; A label is determined for the current power data input in the user interface.
3. The method according to claim 2, characterized in that If the label is abnormal power data, it indicates that the predicted category is different from the actual category of the current power data.
4. The method according to claim 1, characterized in that The method further comprises: In the case where it is determined that no abnormal information has been screened out, the current power data is input into an artificial intelligence model to obtain data features of the current power data; Based on the data features of the current power data and a predetermined mean value of the data features of a plurality of clean sample power data, a prediction category for the current power data is determined.
5. The method according to claim 4, characterized in that The step of determining a prediction category for the current power data based on the data feature of the current power data and a predetermined mean value of the data feature of a plurality of clean sample power data comprises: When it is determined that the cosine distance between the data feature of the current power data and the data feature means of a plurality of predetermined clean sample power data is greater than a preset threshold, the predicted category of the current power data is determined to be abnormal power data.
6. A self-learning defense device for backdoor attacks on artificial intelligence models of power systems, characterized in that: The device includes a pre-filtering module, an abnormal input recording and processing module, and a post-self-learning filtering module: The pre-filtering module is used to filter the information in the current power data, and when abnormal information is filtered out, write the abnormal information into the abnormal input recording and processing module; The abnormal input recording and processing module is used to store the abnormal information and input the current power data into the data detection model to obtain the predicted category for the current power data; The abnormal input recording and processing module is further used to determine a label for the current power data based on the predicted category; The post-self-learning filtering module is used to train and update the integrated learning model based on the abnormal power data when the label is abnormal power data; the updated integrated learning model is used to detect the power data input next time.
7. The device according to claim 6, characterized in that The pre-filtering module is further configured to input the current power data into the post-self-learning filtering module when it is determined that no abnormal information has been filtered out; The post-self-learning filtering module is further used to input the current power data into the artificial intelligence model to obtain data features of the current power data, and determine a prediction category for the current power data based on the data features of the current power data and a pre-determined mean value of data features of a plurality of clean sample power data; The post-self-learning filtering module is further used to write the current power data into the abnormal input recording and processing module when it is determined that the predicted category of the current power data is abnormal power data.
8. A self-learning defense device for backdoor attacks on artificial intelligence models of power systems, characterized in that: The device comprises: An information screening module is used to screen the information in the current power data through a pre-filter and determine whether abnormal information is screened out; A storage and detection module, for storing the current power data and inputting the current power data into a data detection model to obtain a predicted category for the current power data when abnormal information is determined to be screened out; A determination module, configured to determine a label for the current power data based on the predicted category; The model training and updating module is used to train and update the integrated learning model based on the abnormal power data when the label is abnormal power data; the updated integrated learning model is used to detect the power data input next time.
9. A computer device, characterized in that: The method comprises a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of the method according to any one of claims 1 to 5 when executing the computer program.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 5 are implemented.
Citation Information
Cited By
Power grid security defense system based on artificial intelligence and block chain
CN121333665A
A power grid security defense system based on artificial intelligence and blockchain
CN121333665B