Secure migration method and device of model

By using potential hazard models for prediction and weight calculation in the model adaptive migration task, and retraining the migration model, the defense problem of backdoor poisoning attacks in the label-free target domain data is solved, and the model's secure migration and normal task performance are achieved.

CN119989342APending Publication Date: 2025-05-13INST OF AUTOMATION CHINESE ACAD OF SCI
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510064446.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-15
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The prior art is difficult to defend against backdoor poisoning attacks in model adaptive migration tasks based on label-free target domain data, especially without access to source domain data.

Method used

By obtaining the model to be migrated, the target domain sample data and the corresponding noise sample data, the potential hazard model is used to predict the model separately, the category weights of each sample category are calculated, and the migration model is retrained based on these weights to obtain the target domain model.

Benefits of technology

It realizes effective defense against potential backdoor attacks from the target domain, while ensuring the normal task performance of the target domain model, and is suitable for model adaptive migration tasks with label-free target domain data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989342A_ABST
    Figure CN119989342A_ABST
Patent Text Reader

Abstract

The invention provides a safe migration method and device of a model, and the method comprises the steps: carrying out the model prediction through target domain sample data and noise sample data based on a potential risk model, obtaining a target prediction vector and a noise prediction vector, and obtaining the potential risk model through the training of a to-be-migrated model and the target domain sample data; based on the target prediction vector and the noise prediction vector corresponding to the target domain sample data under each sample category, performing calculation to obtain a category weight of each sample category; and based on the target domain sample data and the category weight, retraining the to-be-migrated model to obtain a target domain model. According to the method provided by the invention, weights are allocated to all target domain sample data by utilizing the phenomenon that potential backdoor samples are relatively robust to noise interference; and on the basis of the target domain sample data and the category weight of each sample category, the to-be-migrated model is retrained, so that the potential backdoor attack from the target domain is effectively defended, and the normal task performance of the target domain model is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security technology, and in particular to a model security migration method and device. Background Art

[0002] Model adaptive migration technology aims to solve the model migration problem by using only the source domain model and the target domain data without accessing the source domain data. With the increasing awareness of data privacy and the consideration of the storage cost of large-scale data transmission, model adaptive migration technology has received widespread attention in more and more environments, especially in security-sensitive scenarios. In the existing methods of model adaptive tasks, it is generally believed that the unsupervised test data of the target domain is a clean data sample, ignoring the risk of its contamination, such as the possibility of backdoor poisoning attacks by the target domain data provider using unlabeled data. At present, the defense against backdoor poisoning attacks is mainly achieved through attack defense methods such as network pruning, knowledge distillation, and model fine-tuning.

[0003] However, the above attack defense methods require a certain amount of identically distributed labeled training data during their deployment, while the sample data used in the current model adaptive migration task is unlabeled target domain data. Therefore, the above attack defense methods are not applicable to the model adaptive migration task. Summary of the invention

[0004] The present invention provides a method and device for secure migration of a model, so as to solve the defect in the prior art that it is difficult to defend against backdoor poisoning attacks in the task of adaptively migrating a model based on unlabeled target domain data.

[0005] The present invention provides a model security migration method, comprising: Acquire a model to be migrated, target domain sample data, and noise sample data corresponding to the target domain sample data one by one; Based on a potential danger model, the target domain sample data and the noise sample data are respectively applied to perform model prediction to obtain a target prediction vector and a noise prediction vector, wherein the potential danger model is trained based on the model to be transferred and the target domain sample data; Based on the target prediction vector and the noise prediction vector corresponding to the target domain sample data under each sample category, the category weight of each sample category is calculated; Based on the target domain sample data and the category weights of each sample category, the model to be transferred is retrained to obtain a target domain model.

[0006] According to a secure migration method of a model provided by the present invention, the target prediction vector and the noise prediction vector corresponding to the target domain sample data under each sample category are calculated to obtain the category weight of each sample category, including: Based on the target prediction vector, classifying the target domain sample data to obtain the sample categories; Performing distance calculation based on the target prediction vector and the noise prediction vector under each sample category to obtain the prediction distance of the target domain sample data under each sample category; The prediction distance of the target domain sample data under each sample category is calculated to obtain the category weight of each sample category.

[0007] According to a secure migration method of a model provided by the present invention, the model to be migrated is retrained based on the target domain sample data and the category weights of each sample category to obtain the target domain model, including: Sampling data from the target domain sample data to obtain current sample data; Based on the category weights of the sample categories and the current sample data, a redistribution weight of each current sample data is calculated; Applying the current sample data based on the model to be migrated to obtain a retraining prediction loss for each current sample data; Based on the retraining prediction loss and the reallocation weight, a reallocation prediction loss is calculated; With the goal of minimizing the reallocation prediction loss, the parameters of the model to be migrated are adjusted until the target domain model is obtained.

[0008] According to a model security migration method provided by the present invention, the redistribution weight of each current sample data is calculated based on the category weight of each sample category and the current sample data, including: Based on the category weights of the sample categories, query and obtain the category weight of the current sample category contained in the current sample data; The category weights of the current sample categories are normalized to calculate the redistribution weights of the current sample data.

[0009] According to a model security migration method provided by the present invention, the step of obtaining the potential risk model includes: Based on the target domain sample data, applying any model adaptive fine-tuning algorithm to train the model to be migrated to obtain the potential risk model; The step of retraining the model to be migrated based on the target domain sample data and the category weights of each sample category to obtain a target domain model further includes: Based on the target domain sample data, the category weights of the sample categories, and any one of the model adaptive fine-tuning algorithms, the model to be migrated is retrained to obtain the target domain model.

[0010] According to a model security migration method provided by the present invention, the step of acquiring noise sample data includes: Extracting the original vector of the target domain sample data; Acquire a noise vector, wherein the size of the noise vector is the same as the size of the original vector; The noise vector and the original vector are concatenated to obtain the noise sample data.

[0011] The present invention also provides a model security migration device, comprising: An acquisition unit, which acquires a model to be migrated, target domain sample data, and noise sample data corresponding to the target domain sample data one by one; A noise interference unit, which performs model prediction by applying the target domain sample data and the noise sample data respectively based on a potential danger model to obtain a target prediction vector and a noise prediction vector, wherein the potential danger model is trained based on the model to be migrated and the target domain sample data; A weight allocation unit, which calculates the category weight of each sample category based on the target prediction vector and the noise prediction vector corresponding to the target domain sample data under each sample category; A retraining unit is configured to retrain the model to be transferred based on the target domain sample data and the category weights of each sample category to obtain a target domain model.

[0012] The present invention also provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, a method for securely migrating a model as described above is implemented.

[0013] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the method for secure migration of a model as described in any one of the above.

[0014] The present invention also provides a computer program product, comprising a computer program, wherein when the computer program is executed by a processor, the method for securely migrating a model as described in any one of the above is implemented.

[0015] The model security migration method and device provided by the present invention respectively apply the target domain sample data and the noise sample data to perform model prediction through the potential danger model to obtain the target prediction vector and the noise prediction vector; based on the target prediction vector and the noise prediction vector corresponding to the target domain sample data under each sample category, the category weight of each sample category is calculated; based on the target domain sample data and the category weight of each sample category, the model to be migrated is retrained to obtain the target domain model, thereby achieving effective defense against potential backdoor attacks from the target domain and ensuring the normal task performance of the target domain model. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0017] Figure 1 This is one of the flow charts of the safe migration method of the model provided by the present invention; Figure 2 This is the second flow chart of the safe migration method of the model provided by the present invention; Figure 3 It is a structural schematic diagram of a safe migration device of a model provided by the present invention; Figure 4 It is a structural schematic diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION

[0018] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0019] With the continuous development of deep learning technology, deep neural networks have made significant breakthroughs in computer vision, natural language processing, and many other application fields, and are widely used in multiple scenarios such as autonomous driving, content generation, and medical assisted diagnosis. However, in the actual deployment process, the target domain data of the test scenario usually has a distribution difference from the labeled source domain data used for model pre-training, resulting in a significant decrease in the test performance of the source domain model on the target domain compared to expectations. Therefore, model adaptation methods that use unlabeled target domain data to improve cross-domain performance have become a hot topic in current research.

[0020] It should be noted that the goal of the model adaptation task is to enable users to improve their performance in the target domain by using pre-trained models and target domain data without accessing the source domain data. Compared with traditional unsupervised domain adaptation methods that require access to both source and target domain data, model adaptation technology can effectively protect the privacy of source domain data while reducing the cost of data transmission and storage devices. More importantly, although it uses fewer resources, it can still achieve performance comparable to that of unsupervised domain adaptation methods and has received increasing attention and exploration.

[0021] Currently, model adaptation has been widely used in multiple task areas, such as image classification, semantic segmentation, object detection, multimodal learning, and image restoration. With the increasing amount of model training data, using existing models for model adaptation has become an efficient and practical solution.

[0022] It should also be noted that in the existing methods of model adaptation tasks, the unsupervised test data of the target domain is generally considered to be a clean data sample, ignoring the risk of its contamination. The target domain data provider is in the process of protecting their own data or due to pseudo-correlation features that appear during data collection, the unlabeled target domain dataset may contain backdoor trigger patterns associated with specific categories. This kind of data contamination is not easy to detect because users cannot obtain the target domain data labels, and the existence of distribution offset increases the recognition of backdoor trigger patterns at the dataset level. In fact, it is found through experiments that when the target domain data contains the above trigger patterns according to certain contamination rules, the target domain model optimized by the model adaptation algorithm will be successfully implanted with a neural backdoor. At the same time, the target domain model has normal migration performance on clean target domain samples, and only gives the attack preset output for poisoned samples with the same trigger model.

[0023] Therefore, users unconditionally use the target domain data directly for model adaptive migration, which shows that this type of attack is very risky and highly concealed, and may lead to backdoor poisoning attacks by the target domain data provider using unlabeled data. This attack is very risky and relatively concealed, and is a serious security vulnerability in existing model adaptive migration technology.

[0024] Since model security issues are becoming increasingly important in actual deployment, especially in many sensitive scenarios, currently, defense against backdoor poisoning attacks is mainly achieved through attack defense methods such as network pruning, knowledge distillation, and model fine-tuning, or by detecting backdoor test samples. However, most of the above methods require a certain amount of identically distributed labeled training data during their deployment process, and therefore cannot be applied to the adaptive migration task of the model.

[0025] In response to the above problems, the present invention provides a model security migration method to achieve defense against backdoor poisoning attacks in unlabeled target domain sample data and improve the model security after model adaptive migration. Figure 1 This is one of the flow charts of the safe migration method of the model provided by the present invention, such as Figure 1 As shown, the method includes: Step 110, obtaining a model to be migrated, target domain sample data, and noise sample data corresponding to the target domain sample data one by one; Here, the model to be transferred refers to a general model based on a deep neural network that has been trained with source domain sample data. It has the ability to automatically extract useful feature representations from the original input data, and then use these feature representations for subsequent classification, regression and other tasks. Therefore, the model to be transferred has a strong generalization ability and can show certain performance on unseen data. In addition, although the model to be transferred is trained on source domain sample data, the model to be transferred has a certain adaptability and can be fine-tuned or retrained on target domain sample data to adapt to new task requirements, that is, to achieve adaptive and safe migration to the tasks corresponding to the target domain.

[0026] In addition, the target domain sample data here refers to the sample data corresponding to the target application scenario for safe migration of the model to be migrated, which can be text data or image data. For example, if the target application scenario of the model to be migrated is autonomous driving decision-making, the target domain sample data can be image data obtained in the autonomous driving scenario, and the image data includes elements such as vehicles, street buildings, and pedestrians.

[0027] Specifically, the model to be migrated can be obtained by pre-training the existing source domain sample data, and the unlabeled sample data of the target application scenario of the model to be migrated in actual deployment can be obtained as the target domain sample data. Then, noise data can be added to the obtained target domain sample data to obtain noise sample data corresponding to each target domain sample data.

[0028] It should be noted that the target domain sample data is unlabeled, so that without accessing the source domain sample data, the model migration can be solved by only using the model to be migrated and the target domain sample data, thereby effectively protecting the privacy and security of the source domain sample data and reducing the storage cost of large-scale data transmission.

[0029] Step 120, based on a potential danger model, the target domain sample data and the noise sample data are respectively applied to perform model prediction to obtain a target prediction vector and a noise prediction vector, wherein the potential danger model is trained based on the model to be transferred and the target domain sample data; Here, the potentially dangerous model refers to the target model obtained by directly migrating the model to be migrated through the target domain sample data. The potentially dangerous model here may give an attack preset output for the input with backdoor poisoning attack, that is, the security of the potentially dangerous model is relatively low.

[0030] Specifically, the target domain sample data can be input into the potential danger model, and the target domain sample data can be predicted by the potential danger model to obtain the target prediction vector corresponding to the target domain sample data. In addition, the noise sample data can also be input into the potential danger model, and the noise sample data can be predicted by the potential danger model to obtain the noise prediction vector corresponding to the noise sample data.

[0031] It should be noted that the target prediction vector here can be used to reflect the prediction probability that the target domain sample data belongs to a certain category. Similarly, the noise prediction vector here can be used to reflect the prediction probability that the noise sample data belongs to a certain category.

[0032] Step 130, calculating the category weight of each sample category based on the target prediction vector and the noise prediction vector corresponding to the target domain sample data under each sample category; Here, the category weight of each sample category can be used to reflect the gap between the target prediction vector and the noise prediction vector corresponding to the target domain sample data under each sample category, and then reflect the probability of backdoor poisoning attack in the target domain sample data under each sample category.

[0033] Specifically, the target domain samples can be classified by the target prediction vector corresponding to the target domain sample data to obtain the target domain sample data under each sample category. Then, for the target domain sample data under a single sample category, the category weight of the sample category can be calculated by the vector distance between all target prediction vectors and noise prediction vectors under the sample category. For example, the vector distances between all target prediction vectors and noise prediction vectors under the sample category can be averaged and the calculation result can be used as the category weight of the sample category. The category weight here can be any value such as 0.8, 2.4, etc.

[0034] It should be noted that if there is a backdoor poisoning attack in the target domain sample data, the target domain sample data has stronger anti-interference ability than the target domain sample data without the backdoor poisoning attack. Therefore, the larger the vector distance between the target prediction vector and the noise prediction vector corresponding to the target domain sample data, the larger the gap between the target prediction vector and the noise prediction vector, which means that the influence of the noise on the original target domain sample data is greater, which means that the possibility of the original target domain sample data containing the backdoor poisoning attack is smaller. Conversely, the smaller the vector distance between the target prediction vector and the noise prediction vector corresponding to the target domain sample data, which means that the gap between the target prediction vector and the noise prediction vector is smaller, which means that the influence of the noise on the original target domain sample data is smaller, which means that the possibility of the original target domain sample data containing the backdoor poisoning attack is greater.

[0035] Step 140: retrain the model to be transferred based on the target domain sample data and the category weights of each sample category to obtain a target domain model.

[0036] Specifically, the target domain sample data can be used as retraining sample data for model migration. During the training process, the model to be migrated can be retrained according to the category weights of each sample category to obtain the target domain model.

[0037] Therefore, the category weight here affects the proportion of target domain sample data for retraining the data of each sample category in the sample to be migrated, that is, affects the depth of learning of the target domain sample data of each sample category in the adaptive migration process of the model to be migrated. It can be understood that the smaller the category weight, the greater the possibility that the target domain sample data of the sample category contains backdoor poisoning attacks, and the smaller the training depth of the target domain sample data of the sample category, the stronger the defense capability of the obtained target domain model against backdoor attacks and the higher the security; conversely, the larger the category weight, the smaller the possibility that the target domain sample data of the sample category contains backdoor poisoning attacks, and the greater the training depth of the target domain sample data of the sample category, the better the performance of the obtained target domain model in the target application scenario.

[0038] It should be noted that by utilizing the phenomenon that target domain sample data with potential backdoors are more robust to noise interference, weights are assigned to all target domain sample data, and the model to be transferred obtained by source domain training is retrained based on the category weights to obtain a safe target domain model. The method provided in the embodiment of the present invention does not require a powerful pre-trained model, and can be combined with existing model adaptation methods and applied to any deep neural network architecture to achieve effective defense against potential backdoor attacks from the target domain, while maintaining normal task performance in non-attack scenarios and clean target domain samples. In addition, the method provided in the embodiment of the present invention does not require the design of defense methods for specific attack triggering methods and data pollution strategies, does not require the acquisition of attacker information in advance, and can be used in non-attack scenarios, which is more in line with the needs of actual scenarios.

[0039] The method provided by the embodiment of the present invention uses the target domain sample data and the noise sample data to perform model prediction through the potential danger model, thereby obtaining a target prediction vector and a noise prediction vector; based on the target prediction vector and the noise prediction vector corresponding to the target domain sample data under each sample category, the category weight of each sample category is calculated; based on the target domain sample data and the category weight of each sample category, the model to be migrated is retrained to obtain a target domain model, thereby achieving effective defense against potential backdoor attacks from the target domain and ensuring the normal task performance of the target domain model.

[0040] Based on any of the above embodiments, step 130 includes: Based on the target prediction vector, classifying the target domain sample data to obtain the sample categories; Performing distance calculation based on the target prediction vector and the noise prediction vector under each sample category to obtain the prediction distance of the target domain sample data under each sample category; The prediction distance of the target domain sample data under each sample category is calculated to obtain the category weight of each sample category.

[0041] Specifically, first, all target domain sample data can be classified by the sample category to which the target prediction vector corresponding to each target domain sample data belongs, and the sample categories contained in all target domain sample data can be obtained. That is, it can be considered that the target prediction vector corresponding to the target domain sample data is used as a pseudo-label for the target domain sample data, and the target domain sample data is classified to obtain the sample categories contained in all target domain sample data. It should be noted that the sample category here is determined according to the target application scenario corresponding to the target domain sample data. For example, it can be the classification of animals such as cats and dogs, or the classification of pedestrians, vehicles, traffic signs, etc.

[0042] Then, for the target domain sample data under a single sample category, the prediction distance of each target domain sample data under the sample category can be obtained by performing distance calculation on the target prediction vector corresponding to each target domain sample data under the sample category and the noise prediction vector of the noise sample data corresponding to the target domain sample data.

[0043] Furthermore, in order to make the calculated category weight more accurately reflect the possibility of backdoor poisoning attack in the target domain sample data under the sample category, the predicted distances of each target domain sample data under a single sample category can be averaged and the calculated value can be used as the category weight of the sample category.

[0044] The method provided by the embodiment of the present invention classifies the target domain sample data by using the target prediction vector of the target domain sample data as the pseudo label of the target domain sample data, and obtains each sample category contained in the target domain sample data. Then, the category weight of each sample category is calculated by the prediction distance between the target prediction vector and the noise prediction vector corresponding to each target domain sample data under each sample category, that is, the target domain sample data of the potential backdoor is more robust to noise interference, and weights are assigned to all target domain sample data, thereby achieving effective defense against the target domain sample data of the potential backdoor.

[0045] Based on any of the above embodiments, step 140 includes: Sampling data from the target domain sample data to obtain current sample data; Based on the category weights of the sample categories and the current sample data, a redistribution weight of each current sample data is calculated; Applying the current sample data based on the model to be migrated to obtain a retraining prediction loss for each current sample data; Based on the retraining prediction loss and the reallocation weight, a reallocation prediction loss is calculated; With the goal of minimizing the reallocation prediction loss, the parameters of the model to be migrated are adjusted until the target domain model is obtained.

[0046] Specifically, first, data sampling can be performed from the target domain sample data through a sampling algorithm to obtain current sample data for the current training round, so as to achieve retraining of the model to be migrated.

[0047] Then, the category weight corresponding to each current sample category can be obtained from the category weight query of each sample category through the current sample category included in the current sample data. In addition, the category weight corresponding to each current sample category is calculated, such as normalized, to obtain the redistribution weight of each current sample category, that is, to obtain the redistribution weight of each current sample data corresponding to each current sample category.

[0048] Next, the current sample data is input into the model to be migrated with the initialized parameters, and the model adaptive migration technology is applied to the model to be migrated to calculate the retraining prediction loss corresponding to the current sample data. For example, the retraining prediction loss can be calculated through loss functions such as mean square error and mean absolute error.

[0049] Furthermore, the redistribution prediction loss can be calculated by multiplying the retraining prediction loss corresponding to each current sample data with the redistribution weight. Then, by minimizing the redistribution prediction loss as the goal, the parameters of the model to be migrated are adjusted to obtain the model to be migrated after the parameter adjustment of the current training round. Then, the next round of model migration retraining is carried out, the current sample data of the next training round is obtained, and the redistribution prediction loss of the training round is calculated. Similarly, the parameters of the model to be migrated are adjusted with the goal of minimizing the redistribution prediction loss until the number of training iterations meets the preset conditions, or the redistribution prediction loss of the training round meets the preset conditions, then the retraining process is terminated and the model of the training round is used as the final target domain model.

[0050] The method provided by the embodiment of the present invention obtains current sample data by sampling data from target domain sample data, calculates the redistribution weights of each current sample data, applies the current sample data based on the model to be migrated, obtains the retraining prediction loss of each current sample data; calculates the redistribution prediction loss based on the retraining prediction loss and the redistribution weights; and adjusts the parameters of the model to be migrated with the goal of minimizing the redistribution prediction loss, reduces the learning depth of the model to be migrated for the current sample data that may have backdoor attacks, and at the same time ensures the learning depth of the model to be migrated for normal current sample data, so that the security of the target domain model finally obtained is greatly improved, and the processing performance of the target domain model for normal data is guaranteed.

[0051] Based on any of the above embodiments, based on the category weights of the sample categories and the current sample data, calculating the redistribution weights of the current sample data includes: Based on the category weights of the sample categories, query and obtain the category weight of the current sample category contained in the current sample data; The category weights of the current sample categories are normalized to calculate the redistribution weights of the current sample data.

[0052] Specifically, first, the category weight of the current sample category contained in the current sample data can be queried from the category weights of each sample category. Then, the category weight of the current sample category can be normalized, and the normalized weight value of the current sample category can be used as the redistribution weight of the current sample category. Thus, the redistribution weight of each current sample data is obtained according to the current sample category to which each current sample data belongs.

[0053] It should be noted that the numerical values ​​corresponding to the category weights of the current sample categories contained in the current sample data obtained by querying may have large differences, and the redistributed weights after normalizing the category weights of the current sample categories are smoother, avoiding excessive differences between the weights of each current sample data from having a negative impact on model training, which helps to balance category importance, optimize model performance, and improve the generalization ability of the model, thereby improving the training performance of the model to be migrated during retraining.

[0054] Based on any of the above embodiments, the step of obtaining the potential risk model includes: Based on the target domain sample data, applying any model adaptive fine-tuning algorithm to train the model to be migrated to obtain the potential risk model; Step 140 also includes: Based on the target domain sample data, the category weights of the sample categories, and any one of the model adaptive fine-tuning algorithms, the model to be migrated is retrained to obtain the target domain model.

[0055] Specifically, the target domain sample data can be input into the model to be migrated with parameter initialization, the model to be migrated performs model prediction, and any pre-selected model adaptive fine-tuning algorithm is applied to perform parameter adjustment to obtain the final potential danger model. Similarly, after obtaining the category weights, the initial model to be migrated can be retrained according to the category weights using the target domain sample data. During the retraining process, the fine-tuning algorithm of the model must be consistent with the fine-tuning algorithm used to obtain the potential danger model, so as to ensure that the category weights calculated by the potential danger model can be more accurately used in the retraining process based on the category weights, so as to achieve accurate defense against the target domain sample data that may be subject to backdoor attacks, thereby improving the security of the trained target domain model.

[0056] Among them, the model adaptive fine-tuning algorithm can be any one of the fine-tuning algorithms such as the fine-tuning algorithm based on gradient descent, the fine-tuning algorithm based on freezing and thawing, and the learning rate decay algorithm. It should be emphasized that the safe migration method of the model provided in the embodiment of the present invention does not limit the model fine-tuning algorithm and can be applied to any model adaptive fine-tuning algorithm. In other words, the method provided in the embodiment of the present invention can be combined with any existing model adaptive migration algorithm, will not change the optimization logic of the algorithm, and does not introduce optimization goals that may be repeated or conflicting with the algorithm process, and effectively improves the robustness of the adaptive algorithm. At the same time, the method provided in the embodiment of the present invention can be applied to the model to be migrated of any deep neural network structure.

[0057] Based on any of the above embodiments, the step of acquiring the noise sample data includes: Extracting the original vector of the target domain sample data; Acquire a noise vector, wherein the size of the noise vector is the same as the size of the original vector; The noise vector and the original vector are concatenated to obtain the noise sample data.

[0058] Specifically, first, the original vector of each target domain sample data can be extracted. In addition, a noise vector with the same size as the original vector of the target domain sample data can be sampled from a uniform distribution. Furthermore, the noise vector and the original vector can be concatenated, and the concatenated vector can be used as noise sample data to achieve fast noise data construction, thereby improving the efficiency of the model for security migration.

[0059] Based on any of the above embodiments, in order to enhance the defense of the target domain model against the target domain backdoor attack, without affecting the task performance of the clean sample, it can be combined with the existing model adaptation method and applied to any deep neural network architecture. Figure 2 This is the second flow chart of the safe migration method of the model provided by the present invention. Figure 2 As shown, the method includes: First, the pre-trained source domain model (model to be migrated) can be directly adaptively migrated through the unlabeled target domain data (target domain sample data) to obtain a potentially dangerous target domain model (potentially dangerous model). Then, the potentially contaminated unlabeled target domain data and noise sample data can be input into the potentially dangerous target domain model, and the target prediction vector and noise prediction vector can be output through the potentially dangerous target domain model. Among them, the noise sample data is obtained by splicing random noise to the unlabeled target domain data, and the random noise is obtained by uniformly distributed sampling.

[0060] Furthermore, the distance between the target prediction vector and the noise prediction vector caused by noise can be calculated by calculating the output space between the target prediction vector and the noise prediction vector corresponding to each unlabeled target domain data. Then, the unlabeled target domain data is divided according to categories, and the distance between the target prediction vector and the noise prediction vector corresponding to the unlabeled target domain data under each category is averaged to calculate the category weight of each category.

[0061] Finally, the original pre-trained source domain model is securely and adaptively migrated through the category weights of each category and the unlabeled target domain data to obtain a secure target domain model.

[0062] The method provided by the embodiment of the present invention obtains a potential risk target domain model by training with a model adaptive migration algorithm, utilizes the characteristic that backdoor samples have additional feature coupling, uses the output vector distance interfered by random noise to weight all target domain samples by category, and finally uses the model adaptive migration algorithm combined with the target domain data set with assigned weights for retraining, so as to complete the defense against potential backdoor attacks while maintaining the target domain task performance.

[0063] Based on any of the above embodiments, Figure 3 It is a schematic diagram of the structure of the safe migration device of the model provided by the present invention. Figure 3 As shown, the device comprises: An acquisition unit 310 acquires a model to be migrated, target domain sample data, and noise sample data corresponding to the target domain sample data one by one; A noise interference unit 320, which performs model prediction by applying the target domain sample data and the noise sample data respectively based on a potential danger model to obtain a target prediction vector and a noise prediction vector, wherein the potential danger model is trained based on the model to be transferred and the target domain sample data; The weight allocation unit 330 calculates the category weight of each sample category based on the target prediction vector and the noise prediction vector corresponding to the target domain sample data under each sample category; The retraining unit 340 retrains the model to be transferred based on the target domain sample data and the category weights of each sample category to obtain a target domain model.

[0064] The device provided by the embodiment of the present invention uses the target domain sample data and the noise sample data to perform model prediction through the potential danger model, thereby obtaining a target prediction vector and a noise prediction vector; based on the target prediction vector and the noise prediction vector corresponding to the target domain sample data under each sample category, the category weight of each sample category is calculated; based on the target domain sample data and the category weight of each sample category, the model to be migrated is retrained to obtain a target domain model, thereby achieving effective defense against potential backdoor attacks from the target domain and ensuring the normal task performance of the target domain model.

[0065] Figure 4 An example of a physical structure diagram of an electronic device is shown in FIG. Figure 4 As shown, the electronic device may include: a processor 410, a communication interface 420, a memory 430 and a communication bus 440, wherein the processor 410, the communication interface 420 and the memory 430 communicate with each other through the communication bus 440. The processor 410 may call the logic instructions in the memory 430 to execute the model security migration method, which includes: obtaining a model to be migrated, target domain sample data and noise sample data corresponding to the target domain sample data; applying the target domain sample data and the noise sample data to perform model prediction based on a potential danger model to obtain a target prediction vector and a noise prediction vector, wherein the potential danger model is trained based on the model to be migrated and the target domain sample data; calculating the category weights of the sample categories based on the target prediction vector and the noise prediction vector corresponding to the sample data in the target domain under each sample category; retraining the model to be migrated based on the target domain sample data and the category weights of the sample categories to obtain a target domain model.

[0066] In addition, the logic instructions in the above-mentioned memory 430 can be implemented in the form of a software functional unit and can be stored in a computer-readable storage medium when it is sold or used as an independent product. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, etc. Various media that can store program codes.

[0067] On the other hand, the present invention also provides a computer program product, which includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the safe migration method of the model provided by the above-mentioned methods, which includes: obtaining a model to be migrated, target domain sample data, and noise sample data corresponding to the target domain sample data one by one; based on a potential danger model, applying the target domain sample data and the noise sample data to perform model prediction respectively to obtain a target prediction vector and a noise prediction vector, and the potential danger model is trained based on the model to be migrated and the target domain sample data; based on the target prediction vector and the noise prediction vector corresponding to the target domain sample data under each sample category, the category weight of each sample category is calculated; based on the target domain sample data and the category weights of each sample category, the model to be migrated is retrained to obtain a target domain model.

[0068] On the other hand, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to execute the safe migration method of the model provided by the above-mentioned methods, the method comprising: obtaining a model to be migrated, target domain sample data, and noise sample data corresponding one-to-one to the target domain sample data; applying the target domain sample data and the noise sample data to perform model prediction based on a potential danger model, respectively, to obtain a target prediction vector and a noise prediction vector, wherein the potential danger model is trained based on the model to be migrated and the target domain sample data; calculating the category weights of each sample category based on the target prediction vector and the noise prediction vector corresponding to the target domain sample data under each sample category; retraining the model to be migrated based on the target domain sample data and the category weights of each sample category to obtain a target domain model.

[0069] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Ordinary technicians in this field can understand and implement it without paying creative labor.

[0070] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, can also be implemented by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the prior art can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0071] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for secure migration of a model, characterized in that: include: Acquire a model to be migrated, target domain sample data, and noise sample data corresponding to the target domain sample data one by one; Based on a potential danger model, the target domain sample data and the noise sample data are respectively applied to perform model prediction to obtain a target prediction vector and a noise prediction vector, wherein the potential danger model is trained based on the model to be transferred and the target domain sample data; Based on the target prediction vector and the noise prediction vector corresponding to the target domain sample data under each sample category, the category weight of each sample category is calculated; Based on the target domain sample data and the category weights of each sample category, the model to be transferred is retrained to obtain a target domain model.

2. The secure migration method of the model according to claim 1, characterized in that: The calculating the category weight of each sample category based on the target prediction vector and the noise prediction vector corresponding to the target domain sample data under each sample category includes: Based on the target prediction vector, classifying the target domain sample data to obtain the sample categories; Performing distance calculation based on the target prediction vector and the noise prediction vector under each sample category to obtain the prediction distance of the target domain sample data under each sample category; The prediction distance of the target domain sample data under each sample category is calculated to obtain the category weight of each sample category.

3. The secure migration method of the model according to claim 1, characterized in that: The step of retraining the model to be migrated based on the target domain sample data and the category weights of each sample category to obtain a target domain model includes: Sampling data from the target domain sample data to obtain current sample data; Based on the category weights of the sample categories and the current sample data, a redistribution weight of each current sample data is calculated; Applying the current sample data based on the model to be migrated to obtain a retraining prediction loss for each current sample data; Based on the retraining prediction loss and the reallocation weight, a reallocation prediction loss is calculated; With the goal of minimizing the reallocation prediction loss, the parameters of the model to be migrated are adjusted until the target domain model is obtained.

4. The method for secure migration of a model according to claim 3, characterized in that: The calculating, based on the category weights of the sample categories and the current sample data, the redistribution weights of the current sample data comprises: Based on the category weights of the sample categories, query and obtain the category weight of the current sample category contained in the current sample data; The category weights of the current sample categories are normalized to calculate the redistribution weights of the current sample data.

5. The method for secure migration of a model according to any one of claims 1 to 4, characterized in that: The step of obtaining the potential danger model includes: Based on the target domain sample data, applying any model adaptive fine-tuning algorithm to train the model to be migrated to obtain the potential risk model; The step of retraining the model to be migrated based on the target domain sample data and the category weights of each sample category to obtain a target domain model further includes: Based on the target domain sample data, the category weights of the sample categories, and any one of the model adaptive fine-tuning algorithms, the model to be migrated is retrained to obtain the target domain model.

6. The method for secure migration of a model according to any one of claims 1 to 4, characterized in that: The step of acquiring the noise sample data comprises: Extracting the original vector of the target domain sample data; Acquire a noise vector, wherein the size of the noise vector is the same as the size of the original vector; The noise vector and the original vector are concatenated to obtain the noise sample data.

7. A safe migration device for a model, characterized in that: include: An acquisition unit, which acquires a model to be migrated, target domain sample data, and noise sample data corresponding to the target domain sample data one by one; A noise interference unit, which performs model prediction by applying the target domain sample data and the noise sample data respectively based on a potential danger model to obtain a target prediction vector and a noise prediction vector, wherein the potential danger model is trained based on the model to be migrated and the target domain sample data; A weight allocation unit, which calculates the category weight of each sample category based on the target prediction vector and the noise prediction vector corresponding to the target domain sample data under each sample category; A retraining unit is configured to retrain the model to be transferred based on the target domain sample data and the category weights of each sample category to obtain a target domain model.

8. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the method for secure migration of the model as claimed in any one of claims 1 to 6 is implemented.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method for secure migration of a model as claimed in any one of claims 1 to 6 is implemented.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method for secure migration of a model as claimed in any one of claims 1 to 6 is implemented.