Mobile equipment risk detection method and device for guaranteeing user privacy

By adjusting and optimizing the pre-trained artificial intelligence model on the server to adapt to user data on mobile devices, the problems of insufficient computing power and risk adaptation of mobile devices are solved, and efficient privacy protection and risk detection are achieved.

CN119989393AActive Publication Date: 2025-05-13INDUSTRIAL AND COMMERCIAL BANK OF CHINA
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202311549274.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-20
Publication Date
2025-05-13
Estimated Expiration
2043-11-20

AI Technical Summary

Technical Problem

The processing power and battery life of mobile devices are limited, making it difficult to meet the computing needs of artificial intelligence models; the risks faced by different mobile devices are different, so how to adapt and migrate the pre-trained artificial intelligence model to different mobile devices is also a problem; if there is user data on the mobile device that cannot be recognized by the pre-trained artificial intelligence model, how to deal with it is also a difficult problem.

Method used

By obtaining the complete detection model containing M sub-models trained by the server, user data on the mobile device is collected, user data is input into the complete detection model to obtain unrecognized data, and the complete detection model is adjusted based on these data, making it a local detection model to be optimized containing M+P sub-models, and optimization and compression are performed to obtain the local detection model.

Benefits of technology

It reduces the risk of privacy data leakage, reduces the computing pressure on mobile devices, adapts to the needs of different mobile devices, and reduces the volume and storage space of local risk detection models, and improves the operation and processing speed of the model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989393A_ABST
    Figure CN119989393A_ABST
Patent Text Reader

Abstract

The invention provides a mobile equipment risk detection method and device for guaranteeing user privacy, and relates to the technical field of artificial intelligence, and the method comprises the steps: obtaining a complete detection model which is trained by a server and comprises M sub-models, collecting user data stored on mobile equipment, and inputting the user data into the complete detection model, obtaining P pieces of user data which cannot be recognized; adjusting the complete detection model based on the P pieces of user data to enable the complete detection model to become a to-be-optimized local detection model containing M + P sub-models; compressing the local detection sub-model to be optimized to obtain a local detection model; and carrying out risk detection on the mobile equipment based on the local detection model. According to the invention, the privacy data of the user does not need to be sent to the server, the risk of privacy data leakage is reduced, the pre-training of the model is completed by the server, so that the calculation pressure of the mobile user equipment can be reduced, finally, the method can adapt to the requirements of different mobile equipment, and the size of the local risk detection model is also reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence and risk detection technology, and in particular to a mobile device risk detection method and device for protecting user privacy. Background Art

[0002] In recent years, with the continuous development of Internet technology, mobile banking and mobile payment have become one of the main ways for people to conduct financial transactions. However, due to the convenience and openness of mobile devices, risks such as fake payment websites and wrong transfer codes also need to be paid attention to. These risks may cause losses to users' property. Therefore, the study of mobile device security issues has important practical significance and theoretical value.

[0003] Artificial intelligence models can be applied to risk detection on mobile devices. Artificial intelligence models can be deployed on the server side to receive privacy and sensitive information transmitted by user devices and perform risk detection on them; artificial intelligence models can also be deployed on the user device side to perform risk detection on privacy and sensitive information locally on the user device. In order to protect privacy and sensitive information, artificial intelligence models performing risk detection locally on user devices is a feasible option to avoid the risk of leaking user privacy.

[0004] Deploying AI models directly on mobile devices and using local user information on mobile devices for local training requires solving the following technical problems:

[0005] 1. Model pre-training requires a lot of computing power and energy consumption. The processing power and battery life of mobile devices are relatively limited and may not be able to meet the computing requirements of these models.

[0006] 2. Different mobile devices face different risks. How to adapt and migrate pre-trained artificial intelligence models to different mobile devices also needs to be solved.

[0007] 3. If there is user data on the mobile device that cannot be recognized by the pre-trained AI model, how to deal with it also needs to be solved. Summary of the invention

[0008] In view of this, the present invention provides a mobile device risk detection method and apparatus for protecting user privacy to solve at least one of the above-mentioned problems.

[0009] In order to achieve the above object, the present invention adopts the following scheme:

[0010] According to a first aspect of the present invention, there is provided a method for risk detection of mobile devices for protecting user privacy, the method comprising: obtaining a complete detection model including M sub-models trained by a server, where M is a positive integer; collecting user data stored on a mobile device; inputting the user data into the complete detection model to obtain P pieces of user data that cannot be recognized by the complete detection model, where P is a positive integer; adjusting the complete detection model based on the P pieces of user data to make it a local detection model to be optimized including M+P sub-models; optimizing and compressing the local detection sub-models to be optimized to obtain a local detection model; and performing risk detection on the user's mobile device based on the local detection model.

[0011] As an embodiment of the present invention, collecting user data stored on a mobile device in the above method includes: obtaining a user's permission instruction for data collection; and collecting user data from a device log, text message or web browsing history when a designated collection opportunity is triggered.

[0012] As an embodiment of the present invention, the user data stored on the mobile device collected in the above method is data collected multiple times within a set time period.

[0013] As an embodiment of the present invention, after collecting user data from device logs, text messages or web browsing records when a specified collection opportunity is triggered in the above method, the method also includes: preprocessing the collected data to remove noise and outliers; and desensitizing the preprocessed user data.

[0014] As an embodiment of the present invention, the above method adjusts the complete detection model based on the P pieces of user data to make it a local detection model to be optimized containing M+P sub-models, including: adding a new output layer outside the original output layer of the complete detection model, the original output layer contains M nodes, and the new output layer contains M+P nodes; connecting the M nodes of the new output layer one-to-one to the M nodes of the original output layer, and connecting the P nodes of the new output layer to the M nodes of the original output layer in a weighted manner.

[0015] As an embodiment of the present invention, the weights of the P nodes in the above method are A p There are M items in , where:

[0016] A p =[A p1 , A p2 , ..., A pm , ..., A p(M-1) , A pM ], the value range of p is between 1 and P;

[0017] In the above formula, Ap represents the pth M-dimensional vector, each entry of the vector corresponds to a sub-model, A pm Indicates A p The m-th item corresponds to the m-th sub-model.

[0018] As an embodiment of the present invention, the above method optimizes and compresses the local detection sub-model to be optimized to obtain the local detection model, including: determining the sub-model information required by the mobile device; selecting a corresponding number of corresponding output nodes in the local detection sub-model to be optimized according to the sub-model information required by the mobile device, and deleting the remaining output nodes; selecting task data related to the sub-model information required by the mobile device to train the local detection sub-model to be optimized to fine-tune the local detection sub-model to be optimized; obtaining relevant nodes associated with the deleted output nodes according to the training results, and deleting the relevant nodes to obtain the local detection model; and using the same evaluation indicators as the complete detection model to perform performance evaluation on the local detection model.

[0019] According to a second aspect of the present invention, there is provided a risk detection device for a mobile device for protecting user privacy, the device comprising: a model acquisition unit for acquiring a complete detection model including M sub-models trained by a server; a data collection unit for collecting user data stored on a mobile device; an input unit for inputting the user data into the complete detection model to acquire P pieces of user data that cannot be recognized by the complete detection model; a model adjustment unit for adjusting the complete detection model based on the P pieces of user data to make it a local detection model to be optimized including M+P sub-models; a model compression unit for optimizing and compressing the local detection sub-models to be optimized to obtain a local detection model; and a risk detection unit for performing risk detection on the user's mobile device based on the local detection model.

[0020] As an embodiment of the present invention, the above-mentioned data collection unit includes: an instruction acquisition module, used to obtain the user's permission instruction for data collection; a data collection module, used to collect user data from device logs, text messages or web browsing records when the specified collection opportunity is triggered.

[0021] As an embodiment of the present invention, the user data collected by the data collection unit is data collected multiple times within a set time period.

[0022] As an embodiment of the present invention, the above-mentioned data acquisition unit also includes: a preprocessing module, which is used to preprocess the collected data to remove noise and abnormal values; and a desensitization processing module, which is used to desensitize the preprocessed user data.

[0023] As an embodiment of the present invention, the above-mentioned model adjustment unit includes: an output layer adjustment module, used to add a new output layer outside the original output layer of the complete detection model, the original output layer includes M nodes, and the new output layer includes M+P nodes; a connection module, used to connect the M nodes of the new output layer to the M nodes of the original output layer one by one, and connect the P nodes of the new output layer to the M nodes of the original output layer in a weighted manner.

[0024] As an embodiment of the present invention, the weights of the above P nodes are A p There are M items in , where:

[0025] A p =[A p1 , A p2 , ..., A pm , ..., A p(M-1) , A pM ];

[0026] In the above formula, A p represents the pth M-dimensional vector, each entry of the vector corresponds to a sub-model, A pm Indicates A p The mth item corresponds to the mth sub-model, and the value range of p is between 1 and P.

[0027] As an embodiment of the present invention, the above-mentioned model compression unit includes: an information determination module, which is used to determine the sub-model information required by the mobile device; an output node selection module, which is used to select a corresponding number of corresponding output nodes in the local detection sub-model to be optimized according to the sub-model information required by the mobile device, and delete the remaining output nodes; a fine-tuning module, which is used to select task data related to the sub-model information required by the mobile device to train the local detection sub-model to be optimized to fine-tune the local detection sub-model to be optimized; an associated node deletion module, which is used to obtain related nodes associated with the deleted output nodes according to the training results, and delete the related nodes to obtain a local detection model; a performance evaluation module, which is used to perform performance evaluation on the local detection model using the same evaluation indicators as the complete detection model.

[0028] According to a third aspect of the present invention, there is provided an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above method when executing the computer program.

[0029] According to a fourth aspect of the present invention, there is provided a computer-readable storage medium having a computer program stored thereon, wherein the computer program implements the steps of the above method when executed by a processor.

[0030] It can be seen from the above technical scheme that the mobile device risk detection method and device for protecting user privacy provided by the present invention, the risk detection model is run on the mobile user device, so the user's privacy data does not need to be sent to the server, reducing the risk of privacy data leakage, and the pre-training of the risk detection model is completed by the server, so the computing pressure of the mobile user device can be reduced. Finally, the local risk detection model running on the mobile device of the present application is a model that is further optimized based on the personalized data of the local mobile device on the basis of the complete detection model. It can not only adapt to the needs of different mobile devices, but also reduce the size of the local risk detection model, reduce the storage space occupied by the local risk detection model, and improve the running processing speed of the model. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the prior art descriptions. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work. In the drawings:

[0032] Figure 1 It is a flowchart of a mobile device risk detection method for protecting user privacy provided in an embodiment of the present application;

[0033] Figure 2 It is a schematic diagram of a process of adjusting a complete detection model provided in an embodiment of the present application;

[0034] Figure 3 is a flowchart of a mobile device risk detection method for protecting user privacy provided by another embodiment of the present application;

[0035] Figure 4 It is a schematic diagram of the model compression process provided in the embodiment of the present application;

[0036] Figure 5 It is a structural schematic diagram of a mobile device risk detection device for protecting user privacy provided by an embodiment of the present application;

[0037] Figure 6 It is a structural schematic diagram of a data acquisition unit provided by an embodiment of the present application;

[0038] Figure 7 is a structural schematic diagram of a model adjustment unit provided by an embodiment of the present application;

[0039] Figure 8 It is a model compression unit provided by an embodiment of the present application;

[0040] Fig. 9 It is a schematic block diagram of the system structure of the electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0041] To make the purpose, technical solution and advantages of the embodiments of the present invention more clear, the embodiments of the present invention are further described in detail below in conjunction with the accompanying drawings. Here, the exemplary embodiments of the present invention and their descriptions are used to explain the present invention, but are not intended to limit the present invention.

[0042] The acquisition, storage, use, and processing of data in the technical solution of this application are in compliance with the relevant provisions of national laws and regulations. The user information in the embodiments of this application is obtained through legal and compliant channels, and the acquisition, storage, use, and processing of user information are authorized and agreed by the customer.

[0043] Since artificial intelligence models are currently deployed directly on mobile devices and local training is performed using local user information on mobile devices, the following technical problems need to be solved: 1. Pre-training of models requires a lot of computing power and energy consumption. The processing power and battery life of mobile devices are relatively limited and may not be able to meet the computing needs of these models. 2. Different mobile devices face different risks. How to adapt and migrate pre-trained artificial intelligence models to different mobile devices also needs to be solved. 3. If there is user data on the mobile device that cannot be recognized by the pre-trained artificial intelligence model, how to deal with it also needs to be solved. The purpose of this application is to provide a safe driving method and device for an autonomous driving pre-training model, which can collect various sensor data in real time, perform secondary processing, and conduct a comprehensive safety assessment, and then instruct various components of the car (brake control components, speed control components, direction control components, horn control components, signal light control components, voice prompt control components, etc.) to make a comprehensive response.

[0044] Based on the above purpose, Figure 1 The figure is a flow chart of a mobile device risk detection method for protecting user privacy provided by an embodiment of the present application. This embodiment is an explanation of the present application from the user's mobile device side. The method includes the following steps:

[0045] Step S101: Obtain a complete detection model including M sub-models trained by the server.

[0046] In this embodiment, the server completes the pre-training of the complete detection model, which can handle most risk detections. The complete detection model is described as follows:

[0047] The complete detection model pre-trained by the server in this application includes M sub-models, for example, it may include 1000 sub-models or 10000 sub-models. The sub-models cover different aspects of security detection, for example, a sub-model for detecting the first network attack; a sub-model for detecting the second network attack; a sub-model for detecting the third network attack; a sub-model for detecting overseas calls; a sub-model for verifying ID card numbers; a sub-model for detecting fake e-commerce customer service, etc.

[0048] Preferably, the pre-trained complete detection model may be a deep neural network. More preferably, the pre-trained complete detection model may be a feed-forward neural network. More preferably, the pre-trained complete detection model may include an input layer, a hidden layer, and an output layer.

[0049] For example, for a deep neural network including 1000 output categories, this embodiment can design a structure as follows:

[0050] Input layer: The number of nodes in the input layer is determined based on the number of features of the specific problem. For example, if the problem has 100 features, then the input layer can have 100 nodes.

[0051] Hidden layer: Multiple hidden layers can be designed to increase the nonlinear expression ability of the network.

[0052] 1. For example, two hidden layers can be designed, each with 512 nodes.

[0053] 2. For another example, 10 hidden layers can be designed, each with 512 nodes.

[0054] 3. For another example, 10 hidden layers can be designed, and the number of nodes in each hidden layer is different. For example, the first hidden layer has 128 nodes, the second hidden layer has 256 nodes, the third hidden layer has 512 nodes, and so on, the last hidden layer has 4096 nodes. Nonlinear activation functions such as ReLU or sigmoid functions are used between each hidden layer.

[0055] Output layer: Since there are 1000 output categories, the number of nodes in the output layer should be 1000. Each node corresponds to a category, and the softmax activation function can be used to map the output value of the node to the [0,1] interval, indicating the probability that the sample belongs to this category.

[0056] Step S102: Collect user data stored on the mobile device.

[0057] This application also focuses on the characteristics of user devices. Since each user device has its own characteristics, for example, some user devices are mainly involved in the threat of network attacks, while some user devices are mainly involved in more transfer operations, so the risks they face are also different. The user data collected in this step is used to adjust the complete detection model to make it a local detection model that is more suitable for this mobile device.

[0058] Step S103: input the user data into the complete detection model to obtain P pieces of user data that cannot be recognized by the complete detection model.

[0059] If the user data obtained in the above step S102 is N, it can be known that P is less than or equal to N. The unrecognizable here means that after the user data is input into the complete detection model, it cannot be recognized or no valid output can be obtained, for example, the output results of all sub-models do not meet the preset threshold. It should be pointed out that the P pieces of user data need to represent different types of risks, rather than data with different values ​​in the same risk.

[0060] Step S104: adjusting the complete detection model based on the P pieces of user data to make it a local detection model to be optimized including M+P sub-models.

[0061] Since the P pieces of user data cannot be identified in the above steps, if the mobile device wants to effectively identify the P pieces of user data, it is necessary to add a sub-model to complete the identification work. The present application expresses P new categories through the weighting of multiple sub-models, so that the changes to the complete detection model are relatively small, and the waste of resources during training is also relatively small. For example, suppose there is a sub-model used to identify the first network attack, and another sub-model is used to identify the second network attack, and there is a new user data on the user's mobile device, which first jumps to a regular forwarding website through the second network attack, and then jumps to a high-risk website involved in the first network attack. Therefore, when it is necessary to identify this new user data, a new sub-model is required, and the new sub-model involves both the first network attack and the second network attack.

[0062] like Figure 2 The figure is a schematic diagram of a process of adjusting a complete detection model provided in an embodiment of the present application, comprising the following steps:

[0063] Step S1041: adding a new output layer outside the original output layer of the complete detection model, wherein the original output layer includes M nodes, and the new output layer includes M+P nodes.

[0064] Step S1042: Connect the M nodes of the new output layer to the M nodes of the original output layer one by one, and connect the P nodes of the new output layer to the M nodes of the original output layer in a weighted manner.

[0065] For example, the original output layer includes 1000 nodes, corresponding to 1000 sub-models.

[0066] Through the adjustment of this application, the new output layer includes 1000+P nodes, corresponding to 1000+P sub-models. The first 1000 nodes of the new output layer are directly connected to the 1000 nodes of the original output layer one by one. The last P new output layer nodes are connected to the 1000 nodes of the original output layer in a weighted manner, and the weight of the P nodes is the M (1000) items in Ap, where the output of P user data is represented as P M-dimensional vectors. Each value of the M-dimensional vector represents the weight of a sub-model:

[0067] A p =[A p1 , A p2 , ..., A pm , ..., A p(M-1) , A pM ];

[0068] In the above formula, A p represents the pth M-dimensional vector, each entry of the vector corresponds to a sub-model, A pm Indicates A p The mth item of corresponds to the mth sub-model. In the above formula, the value of M is 1000, the value of P is a positive integer, and the size of P is not limited here. The value of p is between 1 and P. Therefore, through A p 1000 items, A can be represented by 1000 submodels p The corresponding p-th user data.

[0069] Step S105: Optimize and compress the local detection sub-model to be optimized to obtain a local detection model.

[0070] Since mobile devices have different characteristics and face different risks, the local detection sub-model to be optimized obtained in the above steps can already meet the needs of mobile devices, but its functions are redundant for mobile devices, and the pre-trained model requires a lot of storage space and memory to store and run. For example, some large pre-trained models may require several GB or even tens of GB of storage space. The storage and memory resources of mobile devices are relatively limited, so it is necessary to compress them so that they can not only meet the needs in terms of function, but also reduce the storage volume and reduce the burden on the storage capacity of mobile devices.

[0071] Step S106: Perform risk detection on the user's mobile device based on the local detection model.

[0072] That is, when a user encounters a risk while using a mobile device, the risk faced by the user is detected by obtaining relevant user data and inputting the local detection model, and the detection results are output to prompt the user's risk index, such as when using online banking or receiving high-risk text messages.

[0073] It can be seen from the above technical scheme that the mobile device risk detection method for protecting user privacy provided by the present invention, the risk detection model is run on the mobile user device, so the user's privacy data does not need to be sent to the server, reducing the risk of privacy data leakage, and the pre-training of the risk detection model is completed by the server, so the computing pressure of the mobile user device can be reduced. Finally, the local risk detection model running on the mobile device of the present application is a model that is further optimized based on the personalized data of the local mobile device on the basis of the complete detection model. It can not only adapt to the needs of different mobile devices, but also reduce the size of the local risk detection model, reduce the storage space occupied by the local risk detection model, and improve the running processing speed of the model.

[0074] like Figure 3 FIG. 1 is a flow chart of a mobile device risk detection method for protecting user privacy provided by another embodiment of the present application. This embodiment also describes the present application from the user's mobile device side. The method includes the following steps:

[0075] Step S301: Obtain a complete detection model including M sub-models trained by the server.

[0076] Step S302: Obtain the user's permission instruction for data collection.

[0077] Since this application needs to collect user data, relevant data protection laws and policies must be strictly observed when collecting user data to ensure that the user's privacy is respected. Therefore, this application first obtains the user's permission for data collection.

[0078] Step S303: Collect user data from device logs, text messages or web browsing records when the designated collection opportunity is triggered.

[0079] In order to improve the accuracy of the collected data, the collection time may be a specific time designated in advance, such as the time of using online banking, the time of receiving a high-risk text message, and so on.

[0080] In order to more comprehensively reflect the user's usage habits, including the impact of various time factors on usage habits, this application can collect data multiple times within a period of time, rather than collecting data intensively on a certain day or a certain period of time.

[0081] Step S304: pre-process the collected data to remove noise and outliers, such as removing duplicate data points, processing missing values, or normalizing the data.

[0082] Step S305: desensitizing the pre-processed user data.

[0083] Step S306: input the user data into the complete detection model to obtain P pieces of user data that cannot be recognized by the complete detection model.

[0084] Step S307: adjusting the complete detection model based on the P pieces of user data to make it a local detection model to be optimized that includes M+P sub-models.

[0085] Step S308: Optimize and compress the local detection sub-model to be optimized to obtain a local detection model.

[0086] Preferably, the optimization of this step can adopt some common optimization algorithms, such as stochastic gradient descent (SGD), Adam, etc., to minimize the error and loss of the model when running on the device side. During the training and optimization process, some regularization techniques, such as Dropout, L1 / L2 regularization, etc., can also be used to avoid the occurrence of overfitting.

[0087] Further preferably, Figure 4 As shown, the model compression in this step may include the following sub-steps:

[0088] Step S401: Determine the sub-model information required by the mobile device.

[0089] Step S402: selecting a corresponding number of corresponding output nodes in the local detection sub-model to be optimized according to the sub-model information required by the mobile device, and deleting the remaining output nodes.

[0090] Step S403: Select task data related to the sub-model information required by the mobile device to train the local detection sub-model to be optimized to fine-tune the local detection sub-model to be optimized.

[0091] Step S404: Obtain relevant nodes associated with the deleted output nodes according to the training results, and delete the relevant nodes to obtain a local detection model.

[0092] Step S405: Use the same evaluation index as the complete detection model to evaluate the performance of the local detection model.

[0093] For example, the local detection model to be optimized contains a neural network with 1020 output nodes. If the user's mobile device only uses 100 sub-models, a sub-network containing 100 output nodes can be obtained by model compression. Specifically, the following steps can be taken:

[0094] 1. Select output nodes: for example, select 100 nodes corresponding to a specific category or task.

[0095] 2. Adjust the network structure: After selecting 100 output nodes, adjust the network structure accordingly. Remove the remaining output nodes from the network and keep only the selected 100 nodes.

[0096] 3. Train the sub-network: After building the sub-network, you need to train it. At this time, you do not need to use the same complete data set as the original network for training. Instead, you can use data related to a specific task to fine-tune it for a specific task. The training process can use the same optimization algorithm and loss function as the original network.

[0097] 4. Adjust the network structure and delete irrelevant nodes. During the training process, since 900 output nodes were deleted, the nodes related to these nodes can be deleted according to the training results.

[0098] 5. Evaluate performance: After training is completed, the performance of the sub-network needs to be evaluated. The same evaluation indicators as the original network can be used, such as accuracy, recall, etc.

[0099] Step S309: Perform risk detection on the user's mobile device based on the local detection model.

[0100] It can be seen from the above technical scheme that the mobile device risk detection method for protecting user privacy provided by the present invention, the risk detection model is run on the mobile user device, so the user's privacy data does not need to be sent to the server, reducing the risk of privacy data leakage, and the pre-training of the risk detection model is completed by the server, so the computing pressure of the mobile user device can be reduced. Finally, the local risk detection model running on the mobile device of the present application is a model that is further optimized based on the personalized data of the local mobile device on the basis of the complete detection model. It can not only adapt to the needs of different mobile devices, but also reduce the size of the local risk detection model, reduce the storage space occupied by the local risk detection model, and improve the running processing speed of the model.

[0101] like Figure 5The figure shows a schematic diagram of the structure of a mobile device risk detection device for protecting user privacy provided by an embodiment of the present application. The device includes: a model acquisition unit 510, a data collection unit 520, an input unit 530, a model adjustment unit 540, a model compression unit 550 and a risk detection unit 560, which are connected in sequence.

[0102] The model acquisition unit 510 is used to acquire a complete detection model including M sub-models trained by the server.

[0103] The data collection unit 520 is used to collect user data stored in the mobile device.

[0104] The input unit 530 is used to input the user data into the complete detection model to obtain P pieces of user data that cannot be recognized by the complete detection model.

[0105] The model adjustment unit 540 is used to adjust the complete detection model based on the P pieces of user data to make it a local detection model to be optimized that includes M+P sub-models.

[0106] The model compression unit 550 is used to optimize and compress the local detection sub-model to be optimized to obtain a local detection model.

[0107] The risk detection unit 560 is used to perform risk detection on the user's mobile device based on the local detection model.

[0108] Preferably, Figure 6 As shown, the data collection unit 520 includes: an instruction acquisition module 521, which is used to obtain the user's permission instruction for data collection; a data collection module 522, which is used to collect user data from device logs, text messages or web browsing records when a specified collection opportunity is triggered.

[0109] Preferably, the user data collected by the data collection unit 520 is data collected multiple times within a set time period.

[0110] Preferably, Figure 6 As shown, the data acquisition unit 520 further includes: a preprocessing module 523 for preprocessing the collected data to remove noise and abnormal values; and a desensitization processing module 524 for desensitizing the preprocessed user data.

[0111] Preferably, Figure 7As shown, the above-mentioned model adjustment unit 540 includes: an output layer adjustment module 541, used to add a new output layer outside the original output layer of the complete detection model, the original output layer includes M nodes, and the new output layer includes M+P nodes; a connection module 542, used to connect the M nodes of the new output layer to the M nodes of the original output layer one by one, and connect the P nodes of the new output layer to the M nodes of the original output layer in a weighted manner.

[0112] Preferably, the weights of the above P nodes are A p There are M items in , where:

[0113] A p =[A p1 , A p2 , ..., A pm , ..., A p(M-1) , A pM ];

[0114] In the above formula, A p represents the pth M-dimensional vector, each entry of the vector corresponds to a sub-model, A pm Indicates A p The mth item corresponds to the mth sub-model, where P and M are positive integers and the value of p ranges from 1 to P.

[0115] Preferably, Figure 8 As shown, the above-mentioned model compression unit 550 includes: an information determination module 551, which is used to determine the sub-model information required by the mobile device; an output node selection module 552, which is used to select a corresponding number of corresponding output nodes in the local detection sub-model to be optimized according to the sub-model information required by the mobile device, and delete the remaining output nodes; a fine-tuning module 553, which is used to select task data related to the sub-model information required by the mobile device to train the local detection sub-model to be optimized to fine-tune the local detection sub-model to be optimized; an associated node deletion module 554, which is used to obtain the associated nodes associated with the deleted output nodes according to the training results, and delete the associated nodes to obtain the local detection model; a performance evaluation module 555, which is used to perform performance evaluation on the local detection model using the same evaluation indicators as the complete detection model.

[0116] The detailed description of each of the above units and modules can be found in the corresponding description in the aforementioned method embodiment, which will not be further elaborated here.

[0117] It can be seen from the above technical scheme that the mobile device risk detection device for protecting user privacy provided by the present invention, the risk detection model is run on the mobile user device, so the user's privacy data does not need to be sent to the server, reducing the risk of privacy data leakage, and the pre-training of the risk detection model is completed by the server, so the computing pressure of the mobile user device can be reduced. Finally, the local risk detection model running on the mobile device of the present application is a model that is further optimized based on the personalized data of the local mobile device on the basis of the complete detection model. It can not only adapt to the needs of different mobile devices, but also reduce the size of the local risk detection model, reduce the storage space occupied by the local risk detection model, and improve the running processing speed of the model.

[0118] An embodiment of the present invention further provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the above method is implemented when the processor executes the program.

[0119] An embodiment of the present invention further provides a computer-readable storage medium, which stores a computer program for executing the above method.

[0120] like Fig. 9 As shown, the electronic device 600 may further include: a communication module 110, an input unit 120, an audio processor 130, a display 160, and a power supply 170. It is worth noting that the electronic device 600 does not necessarily have to include Fig. 9 In addition, the electronic device 600 may also include Fig. 9 For components not shown, reference may be made to the prior art.

[0121] like Fig. 9 As shown, the central processor 100 is sometimes also referred to as a controller or an operation control, and may include a microprocessor or other processor devices and / or logic devices. The central processor 100 receives inputs and controls the operations of various components of the electronic device 600.

[0122] The memory 140 may be, for example, one or more of a cache, a flash memory, a hard drive, a removable medium, a volatile memory, a non-volatile memory or other suitable devices. The above-mentioned information related to the failure may be stored, and a program for executing the relevant information may also be stored. The CPU 100 may execute the program stored in the memory 140 to implement information storage or processing.

[0123] The input unit 120 provides input to the CPU 100. The input unit 120 is, for example, a key or a touch input device. The power supply 170 is used to provide power to the electronic device 600. The display 160 is used to display display objects such as images and text. The display may be, for example, an LCD display, but is not limited thereto.

[0124] The memory 140 may be a solid-state memory, such as a read-only memory (ROM), a random access memory (RAM), a SIM card, etc. It may also be a memory that saves information even when the power is off, can be selectively erased, and is provided with more data, examples of which are sometimes referred to as EPROMs, etc. The memory 140 may also be some other type of device. The memory 140 includes a buffer memory 141 (sometimes referred to as a buffer). The memory 140 may include an application / function storage unit 142, which is used to store applications and function programs or processes for executing the operation of the electronic device 600 through the central processor 100.

[0125] The memory 140 may also include a data storage unit 143 for storing data, such as contacts, digital data, pictures, sounds, and / or any other data used by the electronic device. The driver storage unit 144 of the memory 140 may include various drivers for communication functions of the electronic device and / or for executing other functions of the electronic device (such as messaging applications, address book applications, etc.).

[0126] The communication module 110 is a transmitter / receiver 110 that transmits and receives signals via an antenna 111. The communication module (transmitter / receiver) 110 is coupled to the central processor 100 to provide input signals and receive output signals, which may be the same as the case of a conventional mobile communication terminal.

[0127] Based on different communication technologies, multiple communication modules 110 may be provided in the same electronic device, such as a cellular network module, a Bluetooth module and / or a wireless LAN module. The communication module (transmitter / receiver) 110 is also coupled to a speaker 131 and a microphone 132 via an audio processor 130 to provide an audio output via the speaker 131 and receive an audio input from the microphone 132, thereby realizing a common telecommunication function. The audio processor 130 may include any suitable buffer, decoder, amplifier, etc. In addition, the audio processor 130 is also coupled to the central processor 100, so that the sound can be recorded on the local machine through the microphone 132, and the sound stored on the local machine can be played through the speaker 131.

[0128] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0129] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0130] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0131] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0132] The present invention uses specific embodiments to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea. At the same time, for those skilled in the art, according to the idea of ​​the present invention, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present invention.

Claims

1. A mobile device risk detection method for protecting user privacy, characterized in that: The method comprises: Get the complete detection model containing M sub-models trained by the server; Collect user data stored on mobile devices; Inputting the user data into the complete detection model to obtain P pieces of user data that cannot be recognized by the complete detection model; Adjust the complete detection model based on the P pieces of user data to make it a local detection model to be optimized including M+P sub-models; Optimizing and compressing the local detection sub-model to be optimized to obtain a local detection model; Risk detection is performed on the user's mobile device based on the local detection model.

2. The mobile device risk detection method for protecting user privacy as claimed in claim 1, characterized in that: The collecting of user data stored on the mobile device comprises: Obtaining the user's permission for data collection; Collect user data from device logs, SMS messages, or web browsing records when the specified collection opportunity is triggered.

3. The mobile device risk detection method for protecting user privacy as claimed in claim 2, characterized in that: The user data stored on the collected mobile device is data collected multiple times within a set time period.

4. The mobile device risk detection method for protecting user privacy as claimed in claim 2, characterized in that: After collecting user data from device logs, text messages or web browsing records when the specified collection opportunity is triggered, the method further includes: Preprocess the collected data to remove noise and outliers; Desensitize the pre-processed user data.

5. The mobile device risk detection method for protecting user privacy as claimed in claim 1, characterized in that: The adjusting the complete detection model based on the P pieces of user data to make it a local detection model to be optimized including M+P sub-models includes: Adding a new output layer outside the original output layer of the complete detection model, wherein the original output layer includes M nodes, and the new output layer includes M+P nodes; The M nodes of the new output layer are connected to the M nodes of the original output layer in a one-to-one correspondence, and the P nodes of the new output layer are connected to the M nodes of the original output layer in a weighted manner.

6. The mobile device risk detection method for protecting user privacy as claimed in claim 5, characterized in that: The weight of the P nodes is A p There are M items in , where: A p =[A p1 ,A p2 ,……,A pm ,……,A p(M-1) ,A pM ]; In the above formula, A p represents the pth M-dimensional vector, each entry of the vector corresponds to a sub-model, A pm Indicates A p The m-th item corresponds to the m-th sub-model.

7. The mobile device risk detection method for protecting user privacy as claimed in claim 1, characterized in that: The optimizing and compressing the local detection model to be optimized to obtain the local detection model comprises: Determine the sub-model information required for the mobile device; Selecting a corresponding number of corresponding output nodes in the local detection submodel to be optimized according to the submodel information required by the mobile device, and deleting the remaining output nodes; Selecting task data related to the sub-model information required by the mobile device to train the local detection sub-model to be optimized to fine-tune the local detection sub-model to be optimized; Acquire relevant nodes associated with the deleted output nodes according to the training results, and delete the relevant nodes to obtain a local detection model; The performance of the local detection model is evaluated using the same evaluation metrics as the complete detection model.

8. A mobile device risk detection device for protecting user privacy, characterized in that: The device comprises: A model acquisition unit, used to acquire a complete detection model including M sub-models trained by the server; A data collection unit, used to collect user data stored on the mobile device; An input unit, used to input the user data into the complete detection model, and obtain P pieces of user data that cannot be recognized by the complete detection model; A model adjustment unit, configured to adjust the complete detection model based on the P pieces of user data to make it a local detection model to be optimized including M+P sub-models; A model compression unit, used for optimizing and compressing the local detection sub-model to be optimized to obtain a local detection model; The risk detection unit is used to perform risk detection on the user's mobile device based on the local detection model.

9. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Model training method, cross-age face recognition method and corresponding devices

    CN107480575A

  • Online service implementation method, device and system, server and storage medium

    CN111343248A

  • Data privacy protection method and device based on edge computing and storage medium

    CN114676456A

  • Risk detection method and device, storage medium and electronic equipment

    CN116776114A

  • Method, apparatus, and electronic device for detecting model security

    US20200065479A1