Backdoor attack defense method and system based on bagging algorithm

Through the backdoor attack defense method based on the bagging algorithm, the effective subclassifier is identified and the voting strategy is processed, the problem of the inability to adjust the model for different training situations in the existing technology is solved, and the accurate backdoor attack prediction and defense of the deep neural network model is achieved, which improves the security and reliability of the model.

CN119939409APending Publication Date: 2025-05-06BEIHANG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411836303.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-13
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

The existing backdoor attack defense methods cannot select the optimal method for model adjustment based on different performance adjustment results of deep neural network models under different training conditions, resulting in reduced reliability and stability of model operation.

Method used

Based on the bagging algorithm, an effective subclassifier that meets the preset training conditions is identified from the classifier set, the backdoor attack inference results of all valid subclassifiers are processed by voting strategy, the final backdoor attack prediction results are determined, and the deep neural network model is adjusted hidden layer based on this result.

Benefits of technology

Accurate backdoor attack prediction of deep neural network models is realized, the model's defense ability against backdoor attacks is enhanced, and the model's operation is ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939409A_ABST
    Figure CN119939409A_ABST
Patent Text Reader

Abstract

The invention provides a bagging algorithm-based backdoor attack defense method and system, and the method comprises the steps: recognizing effective sub-classifiers meeting a preset training condition from a classifier set, carrying out the voting strategy processing of backdoor attack reasoning results corresponding to all effective sub-classifiers, and determining a final backdoor attack prediction result. According to the method, the back door attack condition of the model is accurately predicted, so that hidden layer adjustment is performed on the deep neural network model, an optimized deep neural network model is obtained, the defense capability of the model to the back door attack is enhanced, and the operation safety and reliability of the model are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of neural networks, and in particular to a backdoor attack defense method and system based on a bagging algorithm. Background Art

[0002] The deep neural network model DNN is vulnerable to backdoor attacks. Attackers embed hidden layers (i.e., backdoors) in the deep neural network model and activate the backdoor function through inputs (i.e., triggers). Currently, the toxic samples in the data set and test samples can be filtered out through data set cleaning defense and test data preprocessing defense respectively, so as to diagnose whether the model is implanted with backdoors and refuse to use the model with implanted backdoors. The complexity and unknowability of the deep neural network model make it difficult to detect the model once the backdoor is implanted. When the attacker uses the input with triggers to attack the model, the model will misclassify the input, and the classification model will classify the model with triggers into the attacker's target label, thereby realizing the attack. The existing backdoor attack defense methods are all to adjust the neural network model in a predetermined and unique way. It is impossible to select the optimal method to adjust the model according to the different performance adjustment results of the neural network model under different training conditions, and it is impossible to accurately and comprehensively defend the neural network model from backdoor attacks, which reduces the reliability and stability of the model operation. Summary of the invention

[0003] The purpose of the present invention is to provide a backdoor attack defense method and system based on a bagging algorithm, which identifies valid sub-classifiers that meet preset training conditions from a classifier set, performs voting strategy processing on the backdoor attack inference results corresponding to all valid sub-classifiers, determines the final backdoor attack prediction result, and accurately predicts the backdoor attack situation suffered by the model, thereby adjusting the hidden layer of the deep neural network model to obtain an optimized deep neural network model, enhance the model's defense capability against backdoor attacks and ensure the safety and reliability of the model operation.

[0004] The present invention is achieved through the following technical solutions: Backdoor attack defense methods based on bagging algorithms include: Identify all sub-classifiers under the classifier set and determine all valid sub-classifiers that meet the preset training conditions; The backdoor attack inference results corresponding to all valid sub-classifiers are processed by voting strategy to determine the final backdoor attack prediction result; based on the final backdoor attack prediction result, the hidden layer of the deep neural network model is adjusted to obtain an optimized deep neural network model.

[0005] Optionally, all sub-classifiers under the classifier set are identified to determine all valid sub-classifiers that meet preset training conditions, including: Obtain the historical work logs of all sub-classifiers under the classifier set, analyze the historical work logs, and obtain the historical data training status information of the sub-classifier; wherein the historical data training status information includes the data training speed information and the data training computing power resource usage information of the sub-classifier during the historical data training process; based on the historical data training status information, obtain the historical data training efficiency value of the sub-classifier, and determine the sub-classifier whose historical data training efficiency value exceeds the preset efficiency threshold as a valid sub-classifier.

[0006] Optionally, before obtaining the historical data training efficiency value, using the historical data training state information of the sub-classifier to determine the sub-classifier training quality includes: Extracting data training speed information and data training computing power resource usage information of the sub-classifier during the historical data training process; Extracting a maximum data training speed and a minimum data training speed of the sub-classifier during the historical data training process; Obtaining a speed difference between the maximum data training speed and the minimum data training speed of the sub-classifier during the historical data training process by using the maximum data training speed and the minimum data training speed of the sub-classifier during the historical data training process; comparing the speed difference with a preset speed difference threshold; When the speed difference exceeds a preset speed difference threshold, the data training speed information and the data training computing power resource usage information are retrieved to obtain the training quality evaluation coefficient; The training quality evaluation coefficient is obtained by the following formula: Where S represents the training quality evaluation coefficient; n represents the number of unit times experienced by the subclassifier training, and the unit time is 1s; V i V represents the training speed value corresponding to the i-th unit time; c represents the speed difference between the maximum data training speed and the minimum data training speed of the sub-classifier during the historical data training process; V max and V min represent the maximum value and the minimum value of the data training speed of the sub-classifier in the historical data training process respectively; P max represents the maximum resource utilization rate corresponding to the data training computing resource usage information; K represents the adjustment coefficient, and the adjustment coefficient is obtained by the following formula: Where K represents the adjustment coefficient; V i V represents the training speed value corresponding to the i-th unit time; birepresents the standard deviation of the training speed corresponding to the i-th unit time; P i V represents the resource utilization rate corresponding to the i-th unit time; max and V min Respectively represent the maximum value and the minimum value of the data training speed of the sub-classifier during the historical data training process; Comparing the training quality evaluation coefficient with a preset coefficient threshold; When the training quality evaluation coefficient is not lower than the preset coefficient threshold, it is determined that the sub-classifier training quality is abnormal, and an abnormal warning is issued.

[0007] Optionally, a voting strategy is performed on the backdoor attack reasoning results corresponding to all valid sub-classifiers to determine a final backdoor attack prediction result; based on the final backdoor attack prediction result, a hidden layer of the deep neural network model is adjusted to obtain an optimized deep neural network model, including: A hard voting strategy is applied to the backdoor attack inference results corresponding to all valid sub-classifiers to determine the result type corresponding to the highest number of occurrences among all the backdoor inference results, and the backdoor inference result corresponding to the result type is used as the final backdoor attack prediction result; Based on the backdoor attack data flow change information corresponding to the final backdoor attack prediction result, the hidden layer where the attack event occurs inside the deep neural network model is determined, and the hidden layer where the attack event occurs is deleted, so as to obtain an optimized deep neural network model.

[0008] Backdoor attack defense system based on bagging algorithm, including: The sub-classifier screening module is used to identify all sub-classifiers under the classifier set and determine all valid sub-classifiers that meet the preset training conditions; The backdoor attack prediction module is used to process the backdoor attack reasoning results corresponding to all valid sub-classifiers through voting strategies to determine the final backdoor attack prediction results; The model optimization module is used to adjust the hidden layer of the deep neural network model based on the final backdoor attack prediction result, so as to obtain an optimized deep neural network model.

[0009] Optionally, the sub-classifier screening module is used to identify all sub-classifiers under the classifier set and determine all valid sub-classifiers that meet preset training conditions, including: Obtain the historical work logs of all sub-classifiers under the classifier set, analyze the historical work logs, and obtain the historical data training status information of the sub-classifier; wherein the historical data training status information includes the data training speed information and the data training computing power resource usage information of the sub-classifier during the historical data training process; based on the historical data training status information, obtain the historical data training efficiency value of the sub-classifier, and determine the sub-classifier whose historical data training efficiency value exceeds the preset efficiency threshold as a valid sub-classifier.

[0010] Optionally, before obtaining the historical data training efficiency value, using the historical data training state information of the sub-classifier to determine the sub-classifier training quality includes: Extracting data training speed information and data training computing power resource usage information of the sub-classifier during the historical data training process; Extracting a maximum data training speed and a minimum data training speed of the sub-classifier during the historical data training process; Obtaining a speed difference between the maximum data training speed and the minimum data training speed of the sub-classifier during the historical data training process by using the maximum data training speed and the minimum data training speed of the sub-classifier during the historical data training process; comparing the speed difference with a preset speed difference threshold; When the speed difference exceeds a preset speed difference threshold, the data training speed information and the data training computing power resource usage information are retrieved to obtain the training quality evaluation coefficient; The training quality evaluation coefficient is obtained by the following formula: Where S represents the training quality evaluation coefficient; n represents the number of unit times experienced by the subclassifier training, and the unit time is 1s; V i V represents the training speed value corresponding to the i-th unit time; c represents the speed difference between the maximum data training speed and the minimum data training speed of the sub-classifier during the historical data training process; V max and V min represent the maximum value and the minimum value of the data training speed of the sub-classifier in the historical data training process respectively; P max represents the maximum resource utilization rate corresponding to the data training computing resource usage information; K represents the adjustment coefficient, and the adjustment coefficient is obtained by the following formula: Where K represents the adjustment coefficient; V i V represents the training speed value corresponding to the i-th unit time; birepresents the standard deviation of the training speed corresponding to the i-th unit time; P i V represents the resource utilization rate corresponding to the i-th unit time; max and V min Respectively represent the maximum value and the minimum value of the data training speed of the sub-classifier during the historical data training process; Comparing the training quality evaluation coefficient with a preset coefficient threshold; When the training quality evaluation coefficient is not lower than the preset coefficient threshold, it is determined that the sub-classifier training quality is abnormal, and an abnormal warning is issued.

[0011] Optionally, the backdoor attack prediction module is used to perform voting strategy processing on the backdoor attack inference results corresponding to all valid sub-classifiers to determine the final backdoor attack prediction result, including: A hard voting strategy is applied to the backdoor attack inference results corresponding to all valid sub-classifiers to determine the result type corresponding to the highest number of occurrences among all the backdoor inference results, and the backdoor inference result corresponding to the result type is used as the final backdoor attack prediction result; The model optimization module is used to adjust the hidden layer of the deep neural network model based on the final backdoor attack prediction result, so as to obtain an optimized deep neural network model, including: Based on the backdoor attack data flow change information corresponding to the final backdoor attack prediction result, the hidden layer where the attack event occurs inside the deep neural network model is determined, and the hidden layer where the attack event occurs is deleted, so as to obtain an optimized deep neural network model.

[0012] Compared with the prior art, the present invention has the following beneficial effects: The backdoor attack defense method and system based on the bagging algorithm provided in the present application identify valid sub-classifiers that meet preset training conditions from a set of classifiers, perform voting strategy processing on the backdoor attack inference results corresponding to all valid sub-classifiers, determine the final backdoor attack prediction results, and accurately predict the backdoor attack situation suffered by the model, thereby adjusting the hidden layer of the deep neural network model to obtain an optimized deep neural network model, thereby enhancing the model's defense capability against backdoor attacks and ensuring the security and reliability of the model operation. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the prior art descriptions. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. Among them: Figure 1 A schematic flow chart of the backdoor attack defense method based on the bagging algorithm provided by the present invention.

[0014] Figure 2 A schematic diagram of the structure of the backdoor attack defense system based on the bagging algorithm provided by the present invention. DETAILED DESCRIPTION

[0015] In order to make the above-mentioned purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are described in detail below in conjunction with the accompanying drawings. It is understandable that the specific embodiments described herein are only used to explain the present application, rather than to limit the present application. It should also be noted that, for ease of description, only some structures related to the present application are shown in the accompanying drawings, rather than all structures. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.

[0016] The terms "including" and "having" and any variations thereof in this application are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device comprising a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units not listed, or may optionally include other steps or units inherent to these processes, methods, products or devices.

[0017] Reference to "embodiments" herein means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the present application. The appearance of the phrase in various locations in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0018] See also Figure 1 As shown, an embodiment of the present application provides a backdoor attack defense method based on a bagging algorithm. The backdoor attack defense method based on a bagging algorithm includes: Identify all sub-classifiers under the classifier set and determine all valid sub-classifiers that meet the preset training conditions; The backdoor attack inference results corresponding to all valid sub-classifiers are processed by voting strategy to determine the final backdoor attack prediction result; based on the final backdoor attack prediction result, the hidden layer of the deep neural network model is adjusted to obtain an optimized deep neural network model.

[0019] The beneficial effects of the above embodiments are as follows: the backdoor attack defense method based on the bagging algorithm identifies valid sub-classifiers that meet preset training conditions from a set of classifiers, performs voting strategy processing on the backdoor attack inference results corresponding to all valid sub-classifiers, determines the final backdoor attack prediction result, and accurately predicts the backdoor attack situation suffered by the model, thereby adjusting the hidden layer of the deep neural network model to obtain an optimized deep neural network model, thereby enhancing the model's defense capability against backdoor attacks and ensuring the safety and reliability of the model operation.

[0020] In another embodiment, all sub-classifiers under the classifier set are identified to determine all valid sub-classifiers that meet the preset training conditions, including: Obtain the historical work log of each sub-classifier under the classifier set, analyze the historical work log, and obtain the historical data training status information of the sub-classifier; wherein the historical data training status information includes the data training speed information and the data training computing power resource usage information of the sub-classifier during the historical data training process; based on the historical data training status information, obtain the historical data training efficiency value of the sub-classifier, and determine the sub-classifier whose historical data training efficiency value exceeds the preset efficiency threshold as a valid sub-classifier.

[0021] The beneficial effect of the above embodiment is that the classifier set contains multiple sub-classifiers, each sub-classifier can use its own internal network structure for data training to obtain corresponding inference results, and the inference results of different sub-classifiers can be the same or different, and the corresponding matching training data of different sub-classifiers are also different according to their own internal network structures. To this end, the historical work logs of all sub-classifiers under the classifier set are analyzed to obtain the data training speed information and data training computing power resource usage information of the sub-classifier during the historical data training process, so as to provide a reliable data basis for the data training performance evaluation of the sub-classifier, and then based on the data training speed information and data training computing power resource usage information, the historical data training efficiency value of the sub-classifier is obtained, so that the sub-classifier whose historical data training efficiency value exceeds the preset efficiency threshold is determined as a valid sub-classifier, ensuring that only valid sub-classifiers will be assigned corresponding training data and their own internal network structure for training, ensuring the reliability of data training.

[0022] In another embodiment, before obtaining the historical data training efficiency value, using the historical data training state information of the sub-classifier to determine the sub-classifier training quality includes: Extracting data training speed information and data training computing power resource usage information of the sub-classifier during the historical data training process; Extracting a maximum data training speed and a minimum data training speed of the sub-classifier during the historical data training process; Obtaining a speed difference between the maximum data training speed and the minimum data training speed of the sub-classifier during the historical data training process by using the maximum data training speed and the minimum data training speed of the sub-classifier during the historical data training process; comparing the speed difference with a preset speed difference threshold; When the speed difference exceeds a preset speed difference threshold, the data training speed information and the data training computing power resource usage information are retrieved to obtain the training quality evaluation coefficient; The training quality evaluation coefficient is obtained by the following formula: Where S represents the training quality evaluation coefficient; n represents the number of unit times experienced by the subclassifier training, and the unit time is 1s; V i V represents the training speed value corresponding to the i-th unit time; c represents the speed difference between the maximum data training speed and the minimum data training speed of the sub-classifier during the historical data training process; V max and V min represent the maximum value and the minimum value of the data training speed of the sub-classifier in the historical data training process respectively; P max represents the maximum resource utilization rate corresponding to the data training computing resource usage information; K represents the adjustment coefficient, and the adjustment coefficient is obtained by the following formula: Where K represents the adjustment coefficient; V i V represents the training speed value corresponding to the i-th unit time; bi represents the standard deviation of the training speed corresponding to the i-th unit time; P i V represents the resource utilization rate corresponding to the i-th unit time; max and V min Respectively represent the maximum value and the minimum value of the data training speed of the sub-classifier during the historical data training process; Comparing the training quality evaluation coefficient with a preset coefficient threshold; When the training quality evaluation coefficient is not lower than the preset coefficient threshold, it is determined that the sub-classifier training quality is abnormal, and an abnormal warning is issued.

[0023] The beneficial effect of the above embodiment is that by extracting the data training speed information and data training computing power resource usage information of the sub-classifier during the historical data training process, the scheme can comprehensively evaluate the training efficiency of the sub-classifier. In particular, by calculating the maximum and minimum values ​​of the data training speed and the speed difference between them, the fluctuation of the training speed can be intuitively understood. By comparing the speed difference with the preset speed difference threshold, it is possible to preliminarily judge whether the training process is stable. When the speed difference exceeds the threshold, a detailed evaluation is further performed through the training quality evaluation coefficient to ensure the accuracy of the judgment. The calculation formula of the training quality evaluation coefficient S comprehensively considers the training speed, computing power resource usage and their fluctuations. By introducing the training speed value Vi, speed difference Vc, speed maximum value Vmax and minimum value Vmin, and resource utilization maximum value Pmax per unit time, the coefficient can comprehensively reflect the efficiency and quality of the training process. The introduction of the adjustment coefficient K further enhances the flexibility of the evaluation coefficient, so that it can be adjusted according to the fluctuation of the training speed and the actual situation of resource utilization, thereby more accurately reflecting the training quality. When the training quality evaluation coefficient is not lower than the preset coefficient threshold, the solution can immediately determine that the sub-classifier training quality is abnormal and issue an abnormal warning. This timely warning mechanism helps to promptly discover and solve problems in the training process and avoid further decline in training quality. Through this solution, sub-classifiers with poor training quality can be discovered in a timely manner and optimized or adjusted. This helps to improve the overall training efficiency and ensure the stability and reliability of model performance. By monitoring and evaluating the use of computing resources, the solution helps to optimize resource allocation and avoid unnecessary waste of resources. This can not only reduce training costs, but also improve the overall utilization efficiency of resources.

[0024] In summary, this technical solution achieves comprehensive monitoring and management of the sub-classifier training quality by accurately determining the sub-classifier training quality, scientifically calculating the training quality evaluation coefficient, timely warning of anomalies, and optimizing the training process and resource utilization.

[0025] In another embodiment, a voting strategy is performed on the backdoor attack reasoning results corresponding to all valid sub-classifiers to determine a final backdoor attack prediction result; based on the final backdoor attack prediction result, a hidden layer of the deep neural network model is adjusted to obtain an optimized deep neural network model, including: A hard voting strategy is applied to the backdoor attack inference results corresponding to all valid sub-classifiers to determine the result type corresponding to the highest number of occurrences among all backdoor inference results, and the backdoor inference result corresponding to the result type is used as the final backdoor attack prediction result; Based on the backdoor attack data flow change information corresponding to the final backdoor attack prediction result, the hidden layer where the attack event occurs inside the deep neural network model is determined, and the hidden layer where the attack event occurs is deleted to obtain an optimized deep neural network model.

[0026] The beneficial effect of the above embodiment is that in actual operation, the backdoor attack reasoning results corresponding to all valid sub-classifiers are processed by hard voting strategy, the result type corresponding to the highest number of occurrences among all backdoor reasoning results is determined, and the backdoor reasoning result corresponding to the result type is used as the final backdoor attack prediction result, so that the final backdoor attack prediction result can be guaranteed to truly reflect the backdoor attack situation suffered by the model, wherein the hard voting strategy processing belongs to the commonly used voting processing strategy in the pocket algorithm, and is not described in detail here. In addition, based on the backdoor attack data flow change information corresponding to the final backdoor attack prediction result, the hidden layer where the attack event occurs inside the deep neural network model is determined, and the hidden layer where the attack event occurs is deleted, thereby obtaining an optimized deep neural network model, so that the deep neural network model can be quickly adjusted, the robustness of the deep neural network model to backdoor attacks is improved, and the security and reliability of the deep neural network model in practical applications are ensured.

[0027] See also Figure 2 As shown, a backdoor attack defense system based on a bagging algorithm is provided in one embodiment of the present application. The backdoor attack defense system based on a bagging algorithm includes: The sub-classifier screening module is used to identify all sub-classifiers under the classifier set and determine all valid sub-classifiers that meet the preset training conditions; The backdoor attack prediction module is used to process the backdoor attack reasoning results corresponding to all valid sub-classifiers through voting strategies to determine the final backdoor attack prediction results; The model optimization module is used to adjust the hidden layer of the deep neural network model based on the final backdoor attack prediction result, so as to obtain an optimized deep neural network model.

[0028] The beneficial effects of the above embodiments are as follows: the backdoor attack defense system based on the bagging algorithm identifies valid sub-classifiers that meet preset training conditions from a set of classifiers, performs voting strategy processing on the backdoor attack inference results corresponding to all valid sub-classifiers, determines the final backdoor attack prediction results, and accurately predicts the backdoor attack situation suffered by the model, thereby adjusting the hidden layer of the deep neural network model to obtain an optimized deep neural network model, thereby enhancing the model's defense capability against backdoor attacks and ensuring the safety and reliability of the model operation.

[0029] In another embodiment, the sub-classifier screening module is used to identify all sub-classifiers under the classifier set and determine all valid sub-classifiers that meet the preset training conditions, including: Obtain the historical work log of each sub-classifier under the classifier set, analyze the historical work log, and obtain the historical data training status information of the sub-classifier; wherein the historical data training status information includes the data training speed information and the data training computing power resource usage information of the sub-classifier during the historical data training process; based on the historical data training status information, obtain the historical data training efficiency value of the sub-classifier, and determine the sub-classifier whose historical data training efficiency value exceeds the preset efficiency threshold as a valid sub-classifier.

[0030] The beneficial effect of the above embodiment is that the classifier set contains multiple sub-classifiers, each sub-classifier can use its own internal network structure for data training to obtain corresponding inference results, and the inference results of different sub-classifiers can be the same or different, and the corresponding matching training data of different sub-classifiers are also different according to their own internal network structures. To this end, the historical work logs of all sub-classifiers under the classifier set are analyzed to obtain the data training speed information and data training computing power resource usage information of the sub-classifier during the historical data training process, so as to provide a reliable data basis for the data training performance evaluation of the sub-classifier, and then based on the data training speed information and data training computing power resource usage information, the historical data training efficiency value of the sub-classifier is obtained, so that the sub-classifier whose historical data training efficiency value exceeds the preset efficiency threshold is determined as a valid sub-classifier, ensuring that only valid sub-classifiers will be assigned corresponding training data and their own internal network structure for training, ensuring the reliability of data training.

[0031] In another embodiment, before obtaining the historical data training efficiency value, using the historical data training state information of the sub-classifier to determine the sub-classifier training quality includes: Extracting data training speed information and data training computing power resource usage information of the sub-classifier during the historical data training process; Extracting a maximum data training speed and a minimum data training speed of the sub-classifier during the historical data training process; Obtaining a speed difference between the maximum data training speed and the minimum data training speed of the sub-classifier during the historical data training process by using the maximum data training speed and the minimum data training speed of the sub-classifier during the historical data training process; comparing the speed difference with a preset speed difference threshold; When the speed difference exceeds a preset speed difference threshold, the data training speed information and the data training computing power resource usage information are retrieved to obtain the training quality evaluation coefficient; The training quality evaluation coefficient is obtained by the following formula: Where S represents the training quality evaluation coefficient; n represents the number of unit times experienced by the subclassifier training, and the unit time is 1s; V i V represents the training speed value corresponding to the i-th unit time; c represents the speed difference between the maximum data training speed and the minimum data training speed of the sub-classifier during the historical data training process; V max and V min represent the maximum value and the minimum value of the data training speed of the sub-classifier in the historical data training process respectively; P max represents the maximum resource utilization rate corresponding to the data training computing resource usage information; K represents the adjustment coefficient, and the adjustment coefficient is obtained by the following formula: Where K represents the adjustment coefficient; V i V represents the training speed value corresponding to the i-th unit time; bi represents the standard deviation of the training speed corresponding to the i-th unit time; P i V represents the resource utilization rate corresponding to the i-th unit time; max and V min Respectively represent the maximum value and the minimum value of the data training speed of the sub-classifier during the historical data training process; Comparing the training quality evaluation coefficient with a preset coefficient threshold; When the training quality evaluation coefficient is not lower than the preset coefficient threshold, it is determined that the sub-classifier training quality is abnormal, and an abnormal warning is issued.

[0032] The beneficial effect of the above embodiment is that by extracting the data training speed information and data training computing power resource usage information of the sub-classifier during the historical data training process, the scheme can comprehensively evaluate the training efficiency of the sub-classifier. In particular, by calculating the maximum and minimum values ​​of the data training speed and the speed difference between them, the fluctuation of the training speed can be intuitively understood. By comparing the speed difference with the preset speed difference threshold, it is possible to preliminarily judge whether the training process is stable. When the speed difference exceeds the threshold, a detailed evaluation is further performed through the training quality evaluation coefficient to ensure the accuracy of the judgment. The calculation formula of the training quality evaluation coefficient S comprehensively considers the training speed, computing power resource usage and their fluctuations. By introducing the training speed value Vi, speed difference Vc, speed maximum value Vmax and minimum value Vmin, and resource utilization maximum value Pmax per unit time, the coefficient can comprehensively reflect the efficiency and quality of the training process. The introduction of the adjustment coefficient K further enhances the flexibility of the evaluation coefficient, so that it can be adjusted according to the fluctuation of the training speed and the actual situation of resource utilization, thereby more accurately reflecting the training quality. When the training quality evaluation coefficient is not lower than the preset coefficient threshold, the solution can immediately determine that the sub-classifier training quality is abnormal and issue an abnormal warning. This timely warning mechanism helps to promptly discover and solve problems in the training process and avoid further decline in training quality. Through this solution, sub-classifiers with poor training quality can be discovered in a timely manner and optimized or adjusted. This helps to improve the overall training efficiency and ensure the stability and reliability of model performance. By monitoring and evaluating the use of computing resources, the solution helps to optimize resource allocation and avoid unnecessary waste of resources. This can not only reduce training costs, but also improve the overall utilization efficiency of resources.

[0033] In summary, this technical solution achieves comprehensive monitoring and management of the sub-classifier training quality by accurately determining the sub-classifier training quality, scientifically calculating the training quality evaluation coefficient, timely warning of anomalies, and optimizing the training process and resource utilization.

[0034] In another embodiment, the backdoor attack prediction module is used to perform voting strategy processing on the backdoor attack reasoning results corresponding to all valid sub-classifiers to determine the final backdoor attack prediction result, including: A hard voting strategy is applied to the backdoor attack inference results corresponding to all valid sub-classifiers to determine the result type corresponding to the highest number of occurrences among all backdoor inference results, and the backdoor inference result corresponding to the result type is used as the final backdoor attack prediction result; The model optimization module is used to adjust the hidden layer of the deep neural network model based on the final backdoor attack prediction result, so as to obtain an optimized deep neural network model, including: Based on the backdoor attack data flow change information corresponding to the final backdoor attack prediction result, the hidden layer where the attack event occurs inside the deep neural network model is determined, and the hidden layer where the attack event occurs is deleted to obtain an optimized deep neural network model.

[0035] The beneficial effect of the above embodiment is that in actual operation, the backdoor attack reasoning results corresponding to all valid sub-classifiers are processed by hard voting strategy, the result type corresponding to the highest number of occurrences among all backdoor reasoning results is determined, and the backdoor reasoning result corresponding to the result type is used as the final backdoor attack prediction result, so that the final backdoor attack prediction result can be guaranteed to truly reflect the backdoor attack situation suffered by the model, wherein the hard voting strategy processing belongs to the commonly used voting processing strategy in the pocket algorithm, and is not described in detail here. In addition, based on the backdoor attack data flow change information corresponding to the final backdoor attack prediction result, the hidden layer where the attack event occurs inside the deep neural network model is determined, and the hidden layer where the attack event occurs is deleted, thereby obtaining an optimized deep neural network model, so that the deep neural network model can be quickly adjusted, the robustness of the deep neural network model to backdoor attacks is improved, and the security and reliability of the deep neural network model in practical applications are ensured.

[0036] In general, the backdoor attack defense method and system based on the bagging algorithm identifies valid sub-classifiers that meet the preset training conditions from the classifier set, performs voting strategy processing on the backdoor attack inference results corresponding to all valid sub-classifiers, determines the final backdoor attack prediction results, and accurately predicts the backdoor attack situation of the model. In this way, the hidden layer of the deep neural network model is adjusted to obtain an optimized deep neural network model, thereby enhancing the model's defense capability against backdoor attacks and ensuring the security and reliability of the model operation.

[0037] The above is only a specific implementation of the present invention, and any other improvements made based on the concept of the present invention are considered to be within the protection scope of the present invention.

Claims

1. The backdoor attack defense method based on the bagging algorithm is characterized by: include: Identify all sub-classifiers under the classifier set and determine all valid sub-classifiers that meet the preset training conditions; The backdoor attack inference results corresponding to all valid sub-classifiers are processed by voting strategy to determine the final backdoor attack prediction result; Based on the final backdoor attack prediction result, the hidden layer of the deep neural network model is adjusted to obtain an optimized deep neural network model.

2. The backdoor attack defense method based on the bagging algorithm as claimed in claim 1, characterized in that: Identify all sub-classifiers under the classifier set and determine all valid sub-classifiers that meet the preset training conditions, including: Obtain the historical work logs of all sub-classifiers under the classifier set, analyze the historical work logs, and obtain the historical data training status information of the sub-classifier; wherein the historical data training status information includes the data training speed information and the data training computing power resource usage information of the sub-classifier during the historical data training process; based on the historical data training status information, obtain the historical data training efficiency value of the sub-classifier, and determine the sub-classifier whose historical data training efficiency value exceeds the preset efficiency threshold as a valid sub-classifier.

3. The backdoor attack defense method based on the bagging algorithm as claimed in claim 2, characterized in that: Before obtaining the historical data training efficiency value, the historical data training state information of the sub-classifier is used to determine the training quality of the sub-classifier, including: Extracting data training speed information and data training computing power resource usage information of the sub-classifier during the historical data training process; Extracting a maximum data training speed and a minimum data training speed of the sub-classifier during the historical data training process; Obtaining a speed difference between the maximum data training speed and the minimum data training speed of the sub-classifier during the historical data training process by using the maximum data training speed and the minimum data training speed of the sub-classifier during the historical data training process; comparing the speed difference with a preset speed difference threshold; When the speed difference exceeds a preset speed difference threshold, the data training speed information and the data training computing power resource usage information are retrieved to obtain the training quality evaluation coefficient; The training quality evaluation coefficient is obtained by the following formula: Where S represents the training quality evaluation coefficient; n represents the number of unit times experienced by the subclassifier training, and the unit time is 1s; V i V represents the training speed value corresponding to the i-th unit time; c represents the speed difference between the maximum data training speed and the minimum data training speed of the sub-classifier during the historical data training process; V max and V min represent the maximum value and the minimum value of the data training speed of the sub-classifier in the historical data training process respectively; P max represents the maximum resource utilization rate corresponding to the data training computing resource usage information; K represents the adjustment coefficient, and the adjustment coefficient is obtained by the following formula: Where K represents the adjustment coefficient; V i V represents the training speed value corresponding to the i-th unit time; bi represents the standard deviation of the training speed corresponding to the i-th unit time; P i V represents the resource utilization rate corresponding to the i-th unit time; max and V min Respectively represent the maximum value and the minimum value of the data training speed of the sub-classifier during the historical data training process; Comparing the training quality evaluation coefficient with a preset coefficient threshold; When the training quality evaluation coefficient is not lower than the preset coefficient threshold, it is determined that the sub-classifier training quality is abnormal, and an abnormal warning is issued.

4. The backdoor attack defense method based on the bagging algorithm as claimed in claim 2, characterized in that: The backdoor attack inference results corresponding to all valid sub-classifiers are processed by voting strategy to determine the final backdoor attack prediction result; Based on the final backdoor attack prediction result, the hidden layer of the deep neural network model is adjusted to obtain an optimized deep neural network model, including: A hard voting strategy is applied to the backdoor attack inference results corresponding to all valid sub-classifiers to determine the result type corresponding to the highest number of occurrences among all the backdoor inference results, and the backdoor inference result corresponding to the result type is used as the final backdoor attack prediction result; Based on the backdoor attack data flow change information corresponding to the final backdoor attack prediction result, the hidden layer where the attack event occurs inside the deep neural network model is determined, and the hidden layer where the attack event occurs is deleted, so as to obtain an optimized deep neural network model.

5. The backdoor attack defense system based on the bagging algorithm is characterized by: include: The sub-classifier screening module is used to identify all sub-classifiers under the classifier set and determine all valid sub-classifiers that meet the preset training conditions; The backdoor attack prediction module is used to process the backdoor attack reasoning results corresponding to all valid sub-classifiers through voting strategies to determine the final backdoor attack prediction results; The model optimization module is used to adjust the hidden layer of the deep neural network model based on the final backdoor attack prediction result, so as to obtain an optimized deep neural network model.

6. The backdoor attack defense system based on the bagging algorithm as claimed in claim 4, characterized in that: The sub-classifier screening module is used to identify all sub-classifiers under the classifier set and determine all valid sub-classifiers that meet the preset training conditions, including: Obtain the historical work logs of all sub-classifiers under the classifier set, analyze the historical work logs, and obtain the historical data training status information of the sub-classifier; wherein the historical data training status information includes the data training speed information and the data training computing power resource usage information of the sub-classifier during the historical data training process; based on the historical data training status information, obtain the historical data training efficiency value of the sub-classifier, and determine the sub-classifier whose historical data training efficiency value exceeds the preset efficiency threshold as a valid sub-classifier.

7. The backdoor attack defense system based on the bagging algorithm as claimed in claim 5, characterized in that: Before obtaining the historical data training efficiency value, the historical data training state information of the sub-classifier is used to determine the training quality of the sub-classifier, including: Extracting data training speed information and data training computing power resource usage information of the sub-classifier during the historical data training process; Extracting a maximum data training speed and a minimum data training speed of the sub-classifier during the historical data training process; Obtaining a speed difference between the maximum data training speed and the minimum data training speed of the sub-classifier during the historical data training process by using the maximum data training speed and the minimum data training speed of the sub-classifier during the historical data training process; comparing the speed difference with a preset speed difference threshold; When the speed difference exceeds a preset speed difference threshold, the data training speed information and the data training computing power resource usage information are retrieved to obtain the training quality evaluation coefficient; The training quality evaluation coefficient is obtained by the following formula: Where S represents the training quality evaluation coefficient; n represents the number of unit times experienced by the subclassifier training, and the unit time is 1s; V i V represents the training speed value corresponding to the i-th unit time; c represents the speed difference between the maximum data training speed and the minimum data training speed of the sub-classifier during the historical data training process; V max and V min represent the maximum value and the minimum value of the data training speed of the sub-classifier in the historical data training process respectively; P max represents the maximum resource utilization rate corresponding to the data training computing resource usage information; K represents the adjustment coefficient, and the adjustment coefficient is obtained by the following formula: Where K represents the adjustment coefficient; V i V represents the training speed value corresponding to the i-th unit time; bi represents the standard deviation of the training speed corresponding to the i-th unit time; P i V represents the resource utilization rate corresponding to the i-th unit time; max and V min Respectively represent the maximum value and the minimum value of the data training speed of the sub-classifier during the historical data training process; Comparing the training quality evaluation coefficient with a preset coefficient threshold; When the training quality evaluation coefficient is not lower than the preset coefficient threshold, it is determined that the sub-classifier training quality is abnormal, and an abnormal warning is issued.

8. The backdoor attack defense system based on the bagging algorithm as claimed in claim 5, characterized in that: The backdoor attack prediction module is used to perform voting strategy processing on the backdoor attack reasoning results corresponding to all valid sub-classifiers to determine the final backdoor attack prediction result, including: A hard voting strategy is applied to the backdoor attack inference results corresponding to all valid sub-classifiers to determine the result type corresponding to the highest number of occurrences among all the backdoor inference results, and the backdoor inference result corresponding to the result type is used as the final backdoor attack prediction result; The model optimization module is used to adjust the hidden layer of the deep neural network model based on the final backdoor attack prediction result, so as to obtain an optimized deep neural network model, including: Based on the backdoor attack data flow change information corresponding to the final backdoor attack prediction result, the hidden layer where the attack event occurs inside the deep neural network model is determined, and the hidden layer where the attack event occurs is deleted, so as to obtain an optimized deep neural network model.