Application program security protection method and system based on federated learning
By adopting federated learning technology in application security protection, each distribution automation terminal independently trains the model and uploads parameters to generate a global anomaly detection model, solving the problem that traditional centralized evaluation mode is difficult to adapt to data growth and privacy leakage, and achieving a trust evaluation system that efficiently evaluates and strictly protects privacy.
Patent Information
- Application Number
- CN202411715241.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-27
- Publication Date
- 2025-05-06
AI Technical Summary
The traditional centralized evaluation model is difficult to adapt to the rapid growth of data volume and is prone to privacy leakage problems, which violates the privacy protection concept of zero-trust architecture.
Using the application security protection method based on federated learning, each distribution automation terminal independently trains the model based on locally collected operating status data, and the updated local anomaly detection model parameters are uploaded to the central aggregation server, and a global anomaly detection model is generated and distributed back to the terminal.
A trust evaluation system with efficient evaluation and strict privacy protection has been realized. By integrating multi-party data resources to build a more comprehensive and accurate trust evaluation model, the robustness and universality of the model are enhanced.
Smart Images

Figure CN119939442A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of software-defined security technology, and in particular to a method and system for application security protection based on federated learning. Background Art
[0002] Although the zero-trust architecture is regarded as the future direction of the network security field, with the surge in network users and the acceleration of data circulation, the traditional centralized evaluation model is difficult to adapt to the rapid growth of data volume. What is more difficult is that centralized data processing is very likely to lead to privacy leakage, which is very different from the privacy protection concept advocated by the zero-trust architecture. Therefore, it is urgent to develop a new trust evaluation system that can ensure efficient evaluation and strictly protect privacy.
[0003] In this context, federated learning, as an innovative learning model, provides a unique way to solve the challenges of data sharing and privacy protection. Its significant advantage is that data privacy can be guaranteed without the need to transmit the original data to a central server. Each participant can independently process and analyze their own data locally, and only needs to pass model updates or gradient information to the central coordination point to ensure the security of the original data. This approach not only protects the privacy of the data, but also builds a more comprehensive and accurate trust assessment system by integrating data resources from multiple parties, providing solid support for the zero-trust architecture. Summary of the invention
[0004] The purpose of this section is to summarize some aspects of embodiments of the present invention and briefly introduce some preferred embodiments. Some simplifications or omissions may be made in this section and the specification abstract and the invention title of this application to avoid blurring the purpose of this section, the specification abstract and the invention title, and such simplifications or omissions cannot be used to limit the scope of the present invention.
[0005] In view of the above existing problems, the present invention is proposed.
[0006] Therefore, the present invention provides an application security protection method and system based on federated learning, which can solve the problems mentioned in the background technology.
[0007] In order to solve the above technical problems, the present invention provides the following technical solutions:
[0008] In a first aspect, the present invention provides an application security protection method based on federated learning, which includes: each distribution automation terminal independently performs model training based on locally collected operating status data, and uploads updated local anomaly detection model parameters to a central aggregation server;
[0009] The central aggregation server receives and summarizes the local anomaly detection model parameters uploaded by each distribution automation terminal, generates a global anomaly detection model according to the local anomaly detection model parameters, and distributes the global anomaly detection model back to each distribution automation terminal;
[0010] Each distribution automation terminal uses the updated global anomaly detection model to perform anomaly detection on the newly collected operating status data, and generates warning information when an anomaly is detected;
[0011] The central aggregation server receives the early warning information sent by each distribution automation terminal, automatically dispatches work orders to the corresponding maintenance personnel according to preset rules, and feeds back the processing results to each distribution automation terminal to complete the early warning dispatch management.
[0012] As a preferred solution of the application security protection method based on federated learning described in the present invention, wherein: the operating status data includes current, voltage, temperature, device operating time, load condition and ambient humidity;
[0013] Based on the operating status data, each distribution automation terminal uses a preset anomaly detection algorithm to train a local anomaly detection model; the anomaly detection algorithm adopts a linear enhanced neural network model, and combines an embedding layer, a linear layer and a ReLU activation function to construct a lightweight architecture.
[0014] As a preferred solution of the application security protection method based on federated learning described in the present invention, the local anomaly detection model training includes:
[0015] The local device independently trains its local anomaly detection model based on the local login database, red and blue team adversarial training data, and security intelligence sources;
[0016] By using the six core features of the Kpiling method (WHO, WHAT, WHEN, WHERE, WHY, HOW) as input, the local device captures the key features of network traffic and performs model training based on the key features;
[0017] The local login database is the user login data of each SDP controller itself, including login time, login point, and login device;
[0018] The red-blue team confrontation training data includes the red team simulating real attack behaviors, and the blue team providing normal behavior data of legitimate users;
[0019] The security intelligence sources include vulnerability libraries and the latest security threat information from threat intelligence platforms.
[0020] As a preferred solution of the application security protection method based on federated learning described in the present invention, wherein: the generation of the global anomaly detection model includes:
[0021] The central aggregation server receives local anomaly detection model parameters uploaded by each distribution automation terminal, wherein the local anomaly detection model parameters are independently trained by each terminal based on local operation status data;
[0022] The central aggregation server verifies all received local anomaly detection model parameters;
[0023] The central aggregation server calculates the global anomaly detection model parameters using an aggregation algorithm based on the verified local anomaly detection model parameters. The aggregation algorithm uses a weighted average method, and the weight is determined based on the number of samples of each terminal.
[0024] The central aggregation server constructs a global anomaly detection model based on the calculated global anomaly detection model parameters, wherein the model uses a cross entropy loss function and an ADAM optimizer to optimize model performance;
[0025] The central aggregation server distributes the constructed global anomaly detection model back to each distribution automation terminal.
[0026] As a preferred solution of the application security protection method based on federated learning described in the present invention, the training optimization of the global anomaly detection model includes:
[0027] Initialize the global anomaly detection model parameters ω and the first-order and second-order momentum estimates m, v of the ADAM optimizer;
[0028] Calculate the cross entropy loss of the sample in the i-th local device, and the calculation formula is as follows:
[0029]
[0030] Among them, m i is the number of samples of the i-th local device, y ω (x ij ) is the prediction result of the jth sample in the i-th local device, y ij is the label of the jth sample in the i-th local device, Li(ω) is the cross entropy loss;
[0031] The cross entropy loss function is defined as:
[0032] L(y ω (x ij ),y ij )=-y ij log(y ω (x ij ))-(1-y ij)log(1-y ω (x ij ))
[0033] Calculate the gradient of each local device with respect to the model parameter ω and update it. The calculation formula is as follows:
[0034] ω←ω-α·g i (ω)
[0035] Among them, α is the learning rate, g i (ω) is the gradient of the cross entropy loss function with respect to the model parameter ω, defined as:
[0036]
[0037] Local devices will each have their own gradient g i (ω)(i∈1,2,...,n) is sent to the central server;
[0038] The central server aggregates the gradients uploaded by local devices and calculates the global gradient G(ω). The calculation formula is as follows:
[0039]
[0040] Where n is the number of all local devices;
[0041] The ADAM optimizer updates the model parameters, and the calculation formula is as follows:
[0042]
[0043] Among them, β1 and β2 are ADAM optimizer parameters;
[0044] Repeat the iterations, update the parameters based on the current momentum estimate, and determine the optimal solution through multiple rounds of aggregation operations.
[0045] As a preferred solution of the application security protection method based on federated learning described in the present invention, wherein: the generating of warning information includes:
[0046] Each distribution automation terminal receives the global anomaly detection model distributed by the central aggregation server and integrates it into the local system;
[0047] Each distribution automation terminal collects new operating status data and uses the updated global anomaly detection model to perform real-time analysis on the newly collected operating status data to assess whether the data is abnormal;
[0048] If an abnormal situation is detected, the distribution automation terminal generates warning information according to preset rules, and the warning information at least includes key information such as abnormality type, occurrence time, and location;
[0049] The generated warning information is sent to the central aggregation server through a secure channel.
[0050] As a preferred solution of the application security protection method based on federated learning described in the present invention, the early warning dispatch management includes:
[0051] The central aggregation server receives warning information sent from each distribution automation terminal, and the warning information includes abnormal type, occurrence time, and location;
[0052] The central aggregation server parses the received warning information, extracts the exception details, and matches them with the preset exception handling rules;
[0053] Based on the matching results, the central aggregation server automatically creates a work order, which includes exception details, handling suggestions, and designated maintenance personnel;
[0054] The central aggregation server sends the created work order to the designated maintenance personnel through a secure channel;
[0055] After receiving the work order, the maintenance personnel will conduct on-site inspection and repair work according to the instructions of the work order, and feedback the processing results to the central aggregation server;
[0056] The central aggregation server will organize the received processing results and feed them back to the corresponding distribution automation terminals through secure channels to complete the early warning dispatch management.
[0057] In a second aspect, the present invention provides an application security protection system based on federated learning, which includes: a local training module, a global training module, an anomaly detection module, and a feedback processing module;
[0058] The local training module is used for each distribution automation terminal to independently perform model training based on the locally collected operating status data, and upload the updated local anomaly detection model parameters to the central aggregation server;
[0059] The global training module is used for the central aggregation server to receive and summarize the local anomaly detection model parameters uploaded by each distribution automation terminal, generate a global anomaly detection model according to the local anomaly detection model parameters, and distribute the global anomaly detection model back to each distribution automation terminal;
[0060] The anomaly detection module is used for each distribution automation terminal to use the updated global anomaly detection model to perform anomaly detection on the newly collected operating status data, and generate warning information when an anomaly is detected;
[0061] The feedback processing module is used for the central aggregation server to receive the early warning information sent by each distribution automation terminal, automatically dispatch work orders to the corresponding maintenance personnel according to preset rules, and at the same time feed back the processing results to each distribution automation terminal to complete the early warning dispatch management.
[0062] In a third aspect, the present invention provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: when the processor executes the computer program, the steps of the application security protection method based on federated learning are implemented.
[0063] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, the steps of a method for protecting application security based on federated learning are implemented.
[0064] Compared with the prior art, the beneficial effect of the present invention is that the SDP trust assessment model based on federated learning incorporates the six core attributes of Kpling as input parameters, aiming to deepen the model's understanding of the nature of network behavior and its background, and enhance its ability to identify abnormal activities. In order to flexibly respond to the ever-changing network security situation, the model integrates multi-source information such as external threat intelligence and internal security data to achieve real-time updates and flexible adjustments. In deployment practice, the model exhibits the characteristics of convenient deployment and high adaptability. Relying on federated learning technology, it can synchronously coordinate multiple SDF controller data for training, which not only protects the security of sensitive user data in each controller, but also enhances the robustness and versatility of the model. In addition, the deployment of the system adopts a strategy of gradually introducing a federated learning mechanism in stages to ensure a smooth transition of system operation and effectively prevent potential risks that may be caused by model updates. BRIEF DESCRIPTION OF THE DRAWINGS
[0065] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0066] Figure 1 A method flow chart of a method and system for application security protection based on federated learning provided in one embodiment of the present invention;
[0067] Figure 2 An internal structural diagram of a computer device of a method and system for application security protection based on federated learning provided by one embodiment of the present invention;
[0068] Figure 3A system deployment diagram of an application security protection method and system based on federated learning provided by one embodiment of the present invention;
[0069] Figure 4 A curve diagram of the recognition accuracy of a trust assessment model of an application security protection method and system based on federated learning provided by one embodiment of the present invention;
[0070] Figure 5 A curve chart of the loss value of a trust assessment model of an application security protection method and system based on federated learning provided in one embodiment of the present invention. DETAILED DESCRIPTION
[0071] In order to make the above-mentioned purposes, features and advantages of the present invention more understandable, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, but not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary persons in the art without creative work should fall within the scope of protection of the present invention.
[0072] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.
[0073] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The term "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive with other embodiments.
[0074] Example 1
[0075] Reference Figure 1-Figure 5 , which is the first embodiment of the present invention, and provides an application security protection method based on federated learning, including:
[0076] This application provides a method that can effectively solve the above-mentioned problems. Next, we will combine multiple embodiments to explain in detail how to implement the application security protection method based on federated learning;
[0077] Figure 1 A method flow chart of an application security protection method and system based on federated learning is shown, including:
[0078] S1: Each distribution automation terminal independently trains an anomaly detection model based on the locally collected operating status data, and uploads the updated local anomaly detection model parameters to the central aggregation server;
[0079] Furthermore, each distribution automation terminal collects local operating status data, and the operating status data at least includes but is not limited to key indicators such as current, voltage, and temperature.
[0080] Based on the operating status data, each distribution automation terminal uses a preset anomaly detection algorithm to train a local anomaly detection model. The anomaly detection algorithm uses a linear enhancement neural network model, combined with an embedding layer, a linear layer, and a ReLU activation function to build a lightweight architecture; specifically, a linear enhancement neural network model is used to train local devices, combined with an embedding layer, a linear layer, and a ReLU activation function to build a lightweight architecture that can run efficiently on resource-constrained clients. The pseudo code of the neural network is as follows:
[0081]
[0082] At the same time, combined with the ADAM algorithm, resource consumption during training is further controlled, and key parameters such as the model's learning rate and batch processing are dynamically adjusted according to the real-time resource status of the local device to ensure that while maintaining model performance, the use of client resources is minimized, thereby achieving a more stable and efficient training process.
[0083] During the training process, each distribution automation terminal dynamically adjusts key parameters such as the model's learning rate and batch processing according to local resource conditions to ensure that the client's resource usage is minimized while maintaining model performance;
[0084] After completing the local anomaly detection model training, each distribution automation terminal will upload the updated local anomaly detection model parameters to the central aggregation server. Encryption measures are taken during the uploading process to ensure the security of data transmission.
[0085] Further, the local anomaly detection model training includes,
[0086] The local device (SDP controller) independently trains its local anomaly detection model based on the local login database, red and blue team training data, and security intelligence sources; by using the six core features of the Kpiling method (WHO, WHAT, WHEN, WHERE, WHY, HOW) as input, the local device can capture the key features of network traffic and train the model accordingly.
[0087] Furthermore, the local login database is the user login data of each SDP controller, including key information such as login time, login point, login device, etc. These data reflect the actual situation of the local network environment;
[0088] The red team and the blue team compete against each other in training data. The red team simulates real attack behaviors, while the blue team provides normal behavior data of legitimate users to help the model learn and distinguish the key features of malicious attacks and normal behaviors.
[0089] Security intelligence sources include the latest security threat information provided by vulnerability libraries, threat intelligence platforms, etc. These external data can make the model sensitive and alert to new attack methods.
[0090] S2: The central aggregation server receives and summarizes the local anomaly detection model parameters uploaded by each distribution automation terminal, generates a global anomaly detection model according to the local anomaly detection model parameters, and distributes the global anomaly detection model back to each distribution automation terminal;
[0091] Furthermore, the central aggregation server receives local anomaly detection model parameters uploaded from each distribution automation terminal, and the local anomaly detection model parameters are independently trained by each terminal based on local operating status data.
[0092] The central aggregation server verifies all received local anomaly detection model parameters to ensure the integrity and security of the parameters.
[0093] The central aggregation server calculates the global anomaly detection model parameters using an aggregation algorithm based on the verified local anomaly detection model parameters. The aggregation algorithm uses a weighted average method, and the weights are determined based on the number of samples from each terminal.
[0094] The central aggregation server constructs a global anomaly detection model based on the calculated global anomaly detection model parameters, wherein the model uses a cross entropy loss function and an ADAM optimizer to optimize model performance;
[0095] The central aggregation server distributes the constructed global anomaly detection model back to each distribution automation terminal to ensure that each terminal can update the model in time for subsequent anomaly detection tasks.
[0096] Furthermore, the optimization steps of the global anomaly detection model training include:
[0097] Initialize the global anomaly detection model parameters ω and the first-order and second-order momentum estimates m, v of the ADAM optimizer.
[0098] Calculate the cross entropy loss of the sample in the i-th local device, and the calculation formula is as follows:
[0099]
[0100] Among them, m i is the number of samples of the i-th local device, y ω (xij ) is the prediction result of the jth sample in the i-th local device, y ij is the label of the jth sample in the i-th local device, L i (ω) is the cross entropy loss;
[0101] The cross entropy loss function is defined as:
[0102] L(y ω (x ij ),y ij )=-y ij log(y ω (x ij ))-(1-y ij )log(1-y ω (x ij ))
[0103] Calculate the gradient of each local device with respect to the model parameter ω and update it. The calculation formula is as follows:
[0104] ω←ω-α·g i (ω)
[0105] Among them, α is the learning rate, g i (ω) is the gradient of the cross entropy loss function with respect to the model parameter ω, defined as:
[0106]
[0107] Local devices will each have their own gradient g i (ω)(i∈1,2,...,n) is sent to the central server;
[0108] The central server aggregates the gradients uploaded by local devices and calculates the global gradient G(ω). The calculation formula is as follows:
[0109]
[0110] Where n is the number of all local devices;
[0111] The ADAM optimizer updates the model parameters, and the calculation formula is as follows:
[0112]
[0113] Among them, β1 and β2 are ADAM optimizer parameters;
[0114] Repeat the iterations, update the parameters according to the current momentum estimate, and gradually approach the optimal solution through multiple rounds of aggregation operations.
[0115] S3: Each distribution automation terminal uses the updated global anomaly detection model to perform anomaly detection on the newly collected operating status data, and generates warning information when an anomaly is detected;
[0116] Furthermore, each distribution automation terminal receives the global anomaly detection model distributed by the central aggregation server and integrates it into the local system, ready for anomaly detection tasks.
[0117] Each distribution automation terminal continues to collect new operating status data, and the operating status data at least includes but is not limited to key indicators such as current, voltage, and temperature.
[0118] Using the updated global anomaly detection model, each distribution automation terminal analyzes the newly collected operating status data in real time to evaluate whether the data is abnormal.
[0119] If an abnormal situation is detected, the distribution automation terminal generates warning information according to preset rules, and the warning information at least includes key information such as the abnormality type, occurrence time, and location.
[0120] The generated warning information is sent to the central aggregation server through a secure channel for further processing.
[0121] S4: The central aggregation server receives the warning information sent by each distribution automation terminal, automatically dispatches work orders to the corresponding maintenance personnel according to the preset rules, and feeds back the processing results to each distribution automation terminal to complete the warning dispatch management.
[0122] Furthermore, the central aggregation server receives warning information sent from each distribution automation terminal, and the warning information includes key information such as abnormality type, occurrence time, and location. By automatically receiving the warning information, the system can obtain abnormal conditions in real time, avoiding delays caused by manual intervention and improving response speed.
[0123] The central aggregation server analyzes the received warning information, extracts the exception details, and matches them with the preset exception handling rules; the automated analysis and matching rules reduce human intervention, avoid mis-dispatching or missed dispatches, and improve the accuracy and reliability of dispatches;
[0124] Based on the matching results, the central aggregation server automatically creates a work order, which contains information such as exception details, handling suggestions, and designated maintenance personnel. Automatic creation of work orders ensures the timeliness and accuracy of work orders, avoids errors in manual dispatch, and improves the efficiency of fault handling.
[0125] The central aggregation server sends the created work order to the designated maintenance personnel through a secure channel to ensure the safe transmission of information. The work order is transmitted through a secure channel to ensure the security of information transmission, prevent information leakage or tampering, and protect the data security of the system.
[0126] After receiving the work order, the maintenance personnel will conduct on-site inspection and maintenance work according to the instructions of the work order, and feedback the processing results to the central aggregation server; the maintenance personnel will handle the work order in a timely manner and feedback the processing results, ensuring the timeliness and effectiveness of fault handling and improving the overall response speed of the system.
[0127] The central aggregation server will collate the received processing results and feed them back to the corresponding distribution automation terminals through secure channels, completing the closed loop of early warning dispatch management; through closed-loop management, the system can promptly feed back processing results, forming a complete management closed loop and improving the overall management efficiency and reliability of the system.
[0128] Furthermore, this embodiment also provides an application security protection system based on federated learning, including: a local training module, a global training module, an anomaly detection module and a feedback processing module;
[0129] The local training module is used for each distribution automation terminal to independently perform model training based on the locally collected operating status data, and upload the updated local anomaly detection model parameters to the central aggregation server;
[0130] The global training module is used for the central aggregation server to receive and summarize the local anomaly detection model parameters uploaded by each distribution automation terminal, generate a global anomaly detection model according to the local anomaly detection model parameters, and distribute the global anomaly detection model back to each distribution automation terminal;
[0131] The anomaly detection module is used by each distribution automation terminal to perform anomaly detection on the newly collected operation status data using the updated global anomaly detection model, and generate warning information when an anomaly is detected;
[0132] The feedback processing module is used by the central aggregation server to receive the early warning information sent by each distribution automation terminal, automatically dispatch work orders to the corresponding maintenance personnel according to preset rules, and at the same time feed back the processing results to each distribution automation terminal to complete the early warning dispatch management.
[0133] This embodiment also provides a computer device, which may be a terminal, and its internal structure diagram may be as shown in FIG. Figure 2As shown. The computer device includes a processor, a memory, a communication interface, a display screen and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, an operator network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, a method for application security protection based on federated learning is implemented. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device can be a touch layer covered on the display screen, or a button, trackball or touchpad set on the computer device housing, or an external keyboard, touchpad or mouse, etc.
[0134] This embodiment further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0135] Each distribution automation terminal independently conducts model training based on the locally collected operating status data and uploads the updated local anomaly detection model parameters to the central aggregation server;
[0136] The central aggregation server receives and summarizes the local anomaly detection model parameters uploaded by each distribution automation terminal, generates a global anomaly detection model according to the local anomaly detection model parameters, and distributes the global anomaly detection model back to each distribution automation terminal;
[0137] Each distribution automation terminal uses the updated global anomaly detection model to perform anomaly detection on the newly collected operating status data, and generates warning information when an anomaly is detected;
[0138] The central aggregation server receives the warning information sent by each distribution automation terminal, automatically dispatches work orders to the corresponding maintenance personnel according to the preset rules, and feeds back the processing results to each distribution automation terminal to complete the warning dispatch management
[0139] Example 2, reference Figure 1 - Figure 2 , which is the second embodiment of the present invention, provides an application security protection method based on federated learning. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through economic benefit calculation and simulation experiments.
[0140] Next, the function of the present invention is verified, and the experimental environment is as shown in the following table:
[0141] Table 1 Experimental environment
[0142] project Configuration parameters equipment Lenovo LAPTOP-HCATUAJP processor AMD Ryzen 5 4600U with Radeon Graphics,2.10GHz Integrated Development Environment PyCharm Community Edition 2020.1.3x64 Python interpreter Python 3.9
[0143] Some examples of experimental data sets are shown in the following table:
[0144] Table 2 Experimental data table
[0145] UserID DetinationID AppID ContentID WHEN WHERE ACTION Fin Finser HTTPS Content NS HQ deny Fin Finser HTTPS Content NS Remote deny HR Finser SSH Content WH * deny Med Finser HTTPS Content NS HQ deny Reg Finser * Content WH * allow Tech Finser SSH * WH HQ allow Tech Finser SSH Content NS HQ deny
[0146] The goal of this experiment is to comprehensively and deeply measure the performance of the global anomaly detection model by repeatedly training the SDP trust evaluation model. During the training period, we pay special attention to the model's error rate (i.e., loss value) and recognition accuracy. Figure 3 is a curve chart of the recognition accuracy of the trust assessment model provided by an embodiment of the present invention;
[0147] Figure 4 It is a curve chart of the loss value of the trust assessment model provided by an embodiment of the present invention. The diagram intuitively reveals the dynamic changes in performance during the model training process. As the number of iterations increases, the loss value shows a clear decreasing trend, while the recognition accuracy gradually increases, which indicates that the prediction ability of the model in the training stage continues to improve, the error continues to decrease, and the accuracy continues to increase. By the 75th iteration, the global anomaly detection model reached the best state, at which time the loss value dropped to 0.45467231, and the recognition accuracy was as high as 81.49%. In addition, the average time consumed for each 10 rounds of local anomaly detection model iteration and 1 round of global anomaly detection model iteration is 43.01431 seconds. These data show that under the federated learning architecture, the SDP trust assessment model constructed by the present invention exhibits excellent convergence speed and overall performance. At the system deployment level, a progressive deployment strategy is adopted to ensure the stable operation and smooth transition of the system, which means that it can adapt and optimize more quickly in practical applications, effectively reducing the risk of system interruption caused by model updates. Although the accuracy was low in the initial stage, the final model outperformed the centralized model, proving that federated learning can provide more accurate and reliable trust assessments in long-term applications, effectively improving security protection efficiency. By integrating the diversity of multi-source data, the model's ability to resist overfitting is enhanced, improving the model's adaptability in new scenarios.
[0148] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.
[0149] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of complete hardware embodiments, complete software embodiments, or embodiments in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code. The scheme in the embodiments of the present application can be implemented in various computer languages, for example, object-oriented programming language Java and literal scripting language JavaScript, etc.
[0150] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0151] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0152] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0153] Although the preferred embodiments of the present application have been described, those skilled in the art may make other changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications falling within the scope of the present application.
[0154] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.
Claims
1. An application security protection method based on federated learning, characterized in that: include, Each distribution automation terminal independently conducts model training based on the locally collected operating status data and uploads the updated local anomaly detection model parameters to the central aggregation server; The central aggregation server receives and summarizes the local anomaly detection model parameters uploaded by each distribution automation terminal, generates a global anomaly detection model according to the local anomaly detection model parameters, and distributes the global anomaly detection model back to each distribution automation terminal; Each distribution automation terminal uses the updated global anomaly detection model to perform anomaly detection on the newly collected operating status data, and generates warning information when an anomaly is detected; The central aggregation server receives the early warning information sent by each distribution automation terminal, automatically dispatches work orders to the corresponding maintenance personnel according to preset rules, and feeds back the processing results to each distribution automation terminal to complete the early warning dispatch management.
2. The application security protection method based on federated learning according to claim 1, characterized in that: The operating status data includes current, voltage, temperature, equipment operating time, load condition and ambient humidity; Based on the operating status data, each distribution automation terminal uses a preset anomaly detection algorithm to train a local anomaly detection model; the anomaly detection algorithm adopts a linear enhanced neural network model, and combines an embedding layer, a linear layer and a ReLU activation function to construct a lightweight architecture.
3. The application security protection method based on federated learning according to claim 2, characterized in that: The local anomaly detection model training includes: The local device independently trains its local anomaly detection model based on the local login database, red and blue team adversarial training data, and security intelligence sources; By using the six core features of the Kpiling method (WHO, WHAT, WHEN, WHERE, WHY, HOW) as input, the local device captures the key features of network traffic and performs model training based on the key features; The local login database is the user login data of each SDP controller itself, including login time, login point, and login device; The red-blue team confrontation training data includes the red team simulating real attack behaviors, and the blue team providing normal behavior data of legitimate users; The security intelligence sources include vulnerability libraries and the latest security threat information from threat intelligence platforms.
4. The application security protection method based on federated learning according to claim 3, characterized in that: The generating of the global anomaly detection model comprises: The central aggregation server receives local anomaly detection model parameters uploaded by each distribution automation terminal, wherein the local anomaly detection model parameters are independently trained by each terminal based on local operation status data; The central aggregation server verifies all received local anomaly detection model parameters; The central aggregation server calculates the global anomaly detection model parameters using an aggregation algorithm based on the verified local anomaly detection model parameters. The aggregation algorithm uses a weighted average method, and the weight is determined based on the number of samples of each terminal. The central aggregation server constructs a global anomaly detection model based on the calculated global anomaly detection model parameters, wherein the model uses a cross entropy loss function and an ADAM optimizer to optimize model performance; The central aggregation server distributes the constructed global anomaly detection model back to each distribution automation terminal.
5. The application security protection method based on federated learning according to claim 4, characterized in that: The training optimization of the global anomaly detection model includes: Initialize the global anomaly detection model parameters ω and the first-order and second-order momentum estimates m, v of the ADAM optimizer; Calculate the cross entropy loss of the sample in the i-th local device, and the calculation formula is as follows: Among them, m i is the number of samples of the i-th local device, y ω (x ij ) is the prediction result of the jth sample in the i-th local device, y ij is the label of the jth sample in the i-th local device, Li(ω) is the cross entropy loss; The cross entropy loss function is defined as: L(and ω (x ij ),and ij )=-y ij log(y ω (x ij ))-(1-and ij )log(1-y ω (x ij )) Calculate the gradient of each local device with respect to the model parameter ω and update it. The calculation formula is as follows: ω←ω-α·g i (oh) Among them, α is the learning rate, g i (ω) is the gradient of the cross entropy loss function with respect to the model parameter ω, defined as: Local devices will each have their own gradient g i (ω)(i∈1,2,...,n) is sent to the central server; The central server aggregates the gradients uploaded by local devices and calculates the global gradient G(ω). The calculation formula is as follows: Where n is the number of all local devices; The ADAM optimizer updates the model parameters, and the calculation formula is as follows: Among them, β1 and β2 are ADAM optimizer parameters; Repeat the iterations, update the parameters based on the current momentum estimate, and determine the optimal solution through multiple rounds of aggregation operations.
6. The application security protection method based on federated learning according to claim 5, characterized in that: The generating of warning information comprises: Each distribution automation terminal receives the global anomaly detection model distributed by the central aggregation server and integrates it into the local system; Each distribution automation terminal collects new operating status data and uses the updated global anomaly detection model to perform real-time analysis on the newly collected operating status data to assess whether the data is abnormal; If an abnormal situation is detected, the distribution automation terminal generates warning information according to preset rules, and the warning information at least includes key information such as abnormality type, occurrence time, and location; The generated warning information is sent to the central aggregation server through a secure channel.
7. The application security protection method based on federated learning according to claim 6, characterized in that: The early warning dispatch management includes: The central aggregation server receives warning information sent from each distribution automation terminal, and the warning information includes abnormal type, occurrence time, and location; The central aggregation server parses the received warning information, extracts the exception details, and matches them with the preset exception handling rules; Based on the matching results, the central aggregation server automatically creates a work order, which includes exception details, handling suggestions, and designated maintenance personnel; The central aggregation server sends the created work order to the designated maintenance personnel through a secure channel; After receiving the work order, the maintenance personnel will conduct on-site inspection and repair work according to the instructions of the work order, and feedback the processing results to the central aggregation server; The central aggregation server will organize the received processing results and feed them back to the corresponding distribution automation terminals through secure channels to complete the early warning dispatch management.
8. An application security protection system based on federated learning, based on the application security protection method based on federated learning according to any one of claims 1 to 7, characterized in that: Including local training module, global training module, anomaly detection module and feedback processing module; The local training module is used for each distribution automation terminal to independently perform model training based on the locally collected operating status data, and upload the updated local anomaly detection model parameters to the central aggregation server; The global training module is used for the central aggregation server to receive and summarize the local anomaly detection model parameters uploaded by each distribution automation terminal, generate a global anomaly detection model according to the local anomaly detection model parameters, and distribute the global anomaly detection model back to each distribution automation terminal; The anomaly detection module is used for each distribution automation terminal to use the updated global anomaly detection model to perform anomaly detection on the newly collected operating status data, and generate warning information when an anomaly is detected; The feedback processing module is used for the central aggregation server to receive the early warning information sent by each distribution automation terminal, automatically dispatch work orders to the corresponding maintenance personnel according to preset rules, and at the same time feed back the processing results to each distribution automation terminal to complete the early warning dispatch management.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the application security protection method based on federated learning according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the application security protection method based on federated learning described in any one of claims 1 to 7 are implemented.
Citation Information
Cited By
Federal learning-based intelligent terminal network anomaly detection method and system
CN120498867A