Data privacy trusted computing method and system

Through the multi-stage federated learning backdoor defense method, combined with robust aggregation algorithm, trigger reverse engineering, backdoor judge and backdoor forgetting technology, a federated learning backdoor defense system is built, solving the limitations of traditional methods in dealing with heterogeneous data and defending against complex backdoor attacks, and achieving efficient data privacy protection and model security.

CN120030582APending Publication Date: 2025-05-23YUNNAN POWER GRID CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202411849769.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-16
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

Traditional federated learning methods have limitations when processing heterogeneous data, making it difficult to effectively protect data privacy, especially when facing complex distributed backdoor attacks, existing defense methods seem unscrupulous.

Method used

The multi-stage federated learning backdoor defense method is adopted, including a robust aggregation algorithm to filter the models uploaded by users, trigger reverse engineering and backdoor judges to detect whether the model has a backdoor, and the backdoor forgetting technology repairs the model with a backdoor, and build a federated learning backdoor defense system.

Benefits of technology

Through the multi-level defense mechanism, the detection and defense capabilities of backdoor attacks are significantly improved, the false alarm rate and missed alarm rate are reduced, the stability of model performance is maintained, and the dynamic optimization of defense strategies is achieved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030582A_ABST
    Figure CN120030582A_ABST
Patent Text Reader

Abstract

The invention discloses a data privacy trusted computing method and system, and relates to the technical field of data security and privacy protection.The method comprises the steps that a data privacy trusted computing engine is established in a federal learning mode; performing backdoor defense on the data privacy trusted computing engine by adopting a multi-stage federated learning backdoor defense mode; the multi-stage federated learning backdoor defense mode comprises the steps of screening a model uploaded by a user by adopting a robust aggregation algorithm, detecting whether the model has a backdoor by adopting trigger reverse engineering and a backdoor judging device, and repairing the model with the backdoor by adopting a backdoor forgetting technology; and constructing a federated learning backdoor defense system according to processing results of a robust aggregation algorithm, trigger reverse engineering, a backdoor judger and a backdoor forgetting technology. According to the method, the technical problems of low heterogeneous data processing efficiency and insufficient backdoor defense are effectively solved by constructing a multi-modal federal learning architecture and a multi-level self-adaptive defense system, and reliable technical support is provided for data security sharing in the power industry.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security and privacy protection, and in particular to a data privacy trusted computing method and system. Background Art

[0002] As a new distributed machine learning paradigm, federated learning provides a new technical path for data privacy protection by allowing participants to conduct model training and knowledge sharing under the premise of protecting data privacy. In the data sharing scenario of the power industry, federated learning has received widespread attention due to its unique decentralized characteristics. Existing federated learning technologies mainly include three paradigms: horizontal federated learning, vertical federated learning, and federated transfer learning, which are respectively applicable to scenarios with the same feature space, the same sample space, and both different. However, traditional federated learning methods have obvious limitations in processing heterogeneous data: for tabular data, existing methods often use a unified neural network model, ignoring the advantages of tree models in feature learning; for graph data, existing technologies are difficult to effectively capture complex network topology features; for image data, traditional methods are difficult to maintain high recognition accuracy while protecting privacy.

[0003] What is more serious is that the distributed nature of federated learning makes it vulnerable to backdoor attacks. Existing backdoor defense methods mainly focus on single-dimensional defense strategies, such as anomaly detection based on model parameter distribution or simple model repair. These methods are powerless in the face of complex distributed backdoor attacks: first, anomaly detection of a single indicator is prone to defensive blind spots; second, static defense strategies are difficult to cope with attack patterns; finally, existing model repair methods often lead to significant degradation of model performance. These technical problems seriously restrict the practical application of federated learning in the power industry. Summary of the invention

[0004] In view of the above-mentioned problems, the present invention is proposed.

[0005] Therefore, the present invention provides a data privacy trusted computing method and system, which can solve the problems mentioned in the background technology.

[0006] In order to solve the above technical problems, the present invention provides the following technical solutions: a data privacy trusted computing method, comprising: establishing a data privacy trusted computing engine by adopting a federated learning method;

[0007] A multi-stage federated learning backdoor defense method is used to perform backdoor defense on the data privacy trusted computing engine; the multi-stage federated learning backdoor defense method includes using a robust aggregation algorithm to screen models uploaded by users, using trigger reverse engineering and a backdoor judger to detect whether the model has a backdoor, and using a backdoor forgetting technology to repair the model with a backdoor;

[0008] According to the processing results of the robust aggregation algorithm, the trigger reverse engineering, the backdoor determiner and the backdoor forgetting technology, a federated learning backdoor defense system is constructed.

[0009] As a preferred solution of the data privacy trusted computing method described in the present invention, the federated learning method includes using a tree model-based federated learning method to process tabular data, using a graph neural network model-based federated learning method to process graph data, and using a convolutional neural network model-based federated learning method to process image data.

[0010] As a preferred solution of the data privacy trusted computing method described in the present invention, a data privacy trusted computing engine is established by adopting a federated learning method, including the following steps:

[0011] Identify the input data and classify the data into table data, graph data and image data;

[0012] Corresponding federated learning models are established for different types of data: if the data is tabular data, the tree model is used to train the tabular data; if the data is graph data, the graph neural network model is used to train the graph data; if the data is image data, the convolutional neural network model is used to train the image data;

[0013] The training results of the tree model, the graph neural network model and the convolutional neural network model are integrated into the data privacy trusted computing engine.

[0014] As a preferred solution of the data privacy trusted computing method described in the present invention, a multi-stage federated learning backdoor defense method is used to perform backdoor defense on the data privacy trusted computing engine, including the following steps:

[0015] Receiving the model uploaded by the user, calculating the L1 norm, L2 norm and cosine distance of the model using the robust aggregation algorithm, and generating a first detection result;

[0016] Performing multi-stage defense processing according to the first detection result, specifically, if the L1 norm, the L2 norm, and the cosine distance are all lower than their corresponding defense thresholds, performing deep detection using the trigger reverse engineering and the backdoor determiner to generate a second detection result;

[0017] If any one of the L1 norm, the L2 norm and the cosine distance is higher than the corresponding defense threshold, the backdoor forgetting technique is directly used to repair the model;

[0018] A backdoor repair strategy is determined according to the second detection result. Specifically, if the second detection result shows the existence of backdoor features, the trigger sample generated by the trigger reverse engineering is input into the backdoor forgetting technology for targeted repair; otherwise, the model is marked as a safe model.

[0019] As a preferred solution of the data privacy trusted computing method described in the present invention, a defense evaluation index is established according to the second detection result and the model repair effect:

[0020] If the repair effect of the backdoor forgetting technology is lower than the first preset threshold, the trigger reverse engineering is re-adopted to generate a new trigger sample;

[0021] If the repair effect is higher than the first preset threshold, the repaired model is stored in a security model library.

[0022] As a preferred solution of the data privacy trusted computing method described in the present invention, a federated learning backdoor defense system is constructed according to the processing results of the robust aggregation algorithm, the trigger reverse engineering, the backdoor determiner and the backdoor forgetting technology, including the following steps:

[0023] Establishing a model evaluation index system according to the processing result of the robust aggregation algorithm, wherein the model evaluation index system includes a combined score of the L1 norm, the L2 norm and the cosine distance;

[0024] Performing security assessment on the reverse engineering of the trigger and the processing results of the backdoor determiner;

[0025] Update the defense strategy according to the repair result of the backdoor forgetting technique;

[0026] The federated learning backdoor defense system is constructed based on the data of the model evaluation index system, the defense strategy library and the normal sample library.

[0027] As a preferred solution of the data privacy trusted computing method of the present invention, the reverse engineering of the trigger and the security assessment of the processing results of the backdoor determiner include:

[0028] If the trigger sample generated by the reverse engineering of the trigger is determined as a backdoor feature in the backdoor determiner, the trigger sample and its corresponding defense solution are stored in a defense strategy library;

[0029] If the trigger sample generated by the reverse engineering of the trigger is not determined to be a backdoor feature, storing the trigger sample in a normal sample library;

[0030] The updating of the defense strategy according to the repair result of the backdoor forgetting technology includes:

[0031] If the performance index of the repaired model is higher than a second preset threshold, adding the repair solution to the defense strategy library;

[0032] If the performance index of the repaired model is lower than the second preset threshold, the parameters of the repair scheme are adjusted and the repair process is re-executed.

[0033] To further solve the above technical problems, the present invention provides the following technical solutions: A data privacy trusted computing system, comprising: a federated learning data processing module, for establishing a data privacy trusted computing engine using a federated learning method, and processing table data, graph data, and image data;

[0034] A security defense module, used to perform backdoor defense on the data privacy trusted computing engine using a multi-stage federated learning backdoor defense method;

[0035] The defense system building module is used to build a federated learning backdoor defense system based on the processing results of the robust aggregation algorithm, the trigger reverse engineering, the backdoor determiner and the backdoor forgetting technology.

[0036] A computer device includes a memory and a processor, wherein the memory stores a computer program, and wherein the processor implements the steps of the above-mentioned data privacy trusted computing method when executing the computer program.

[0037] A computer-readable storage medium having a computer program stored thereon, characterized in that when the computer program is executed by a processor, the steps of the data privacy trusted computing method as described above are implemented.

[0038] Beneficial effects of the present invention: The present invention has achieved significant technological breakthroughs by combining a variety of federated learning models with a multi-level backdoor defense mechanism. At the data processing level, a dedicated federated learning method is designed for different types of data, breaking through the limitations of the traditional single model and improving the processing efficiency of heterogeneous data. At the security defense level, an innovative multi-level defense system including rapid screening, deep detection and adaptive repair is constructed. Through a dynamically updated defense strategy library and an adaptive parameter optimization mechanism, the blind spot problem of traditional backdoor defense methods in the face of complex attacks is effectively solved. Especially in the actual application scenarios of the power industry, the solution ensures the accuracy of data processing and maintains the security of the model through the comprehensive use of tree models, graph neural networks and convolutional neural networks, while realizing the dynamic optimization of defense strategies and the stability of model performance, providing a comprehensive technical solution for the secure sharing of data in the power industry. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other accompanying drawings can be obtained based on these accompanying drawings without paying creative work.

[0040] Figure 1 This is a schematic diagram of the overall process of a data privacy trusted computing method proposed by the present invention;

[0041] Figure 2 A diagram of computer equipment in a data privacy trusted computing method proposed in the present invention. DETAILED DESCRIPTION

[0042] In order to make the above-mentioned purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary persons in the art without creative work should fall within the scope of protection of the present invention.

[0043] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0044] Example 1, reference Figure 1 , as an embodiment of the present invention, provides a data privacy trusted computing method.

[0045] S1: Use federated learning to establish a data privacy trusted computing engine.

[0046] Among them, the federated learning methods include using a tree model-based federated learning method to process tabular data, using a graph neural network model-based federated learning method to process graph data, and using a convolutional neural network model-based federated learning method to process image data.

[0047] S1.1: Identify the input data and classify it into table data, graph data and image data;

[0048] S1.2: Establish corresponding federated learning models for different types of data:

[0049] If the data is tabular data, the tree model is used to train the tabular data;

[0050] If the data is graph data, the graph neural network model is used to train the graph data;

[0051] If the data is image data, a convolutional neural network model is used to train the image data.

[0052] S1.3: Integrate the training results of the tree model, graph neural network model, and convolutional neural network model into a data privacy trusted computing engine.

[0053] It should be noted that in the data sharing scenario of the power industry, the present invention solves the technical problem that the traditional federated learning method is insufficient in processing heterogeneous data by designing a dedicated federated learning method for different data types. Specifically: the federated learning method using a tree model for tabular data is unique in that it makes full use of the advantages of the tree model over the neural network in feature learning. Experiments have shown that when processing tabular data such as power consumption behavior of power users, the tree model can provide better feature expression capabilities than the neural network model. This method not only reduces the computational complexity, but also ensures the model performance, so that the efficiency of federated learning in processing structured data is significantly improved. In terms of graph data processing, the use of a graph neural network model to process power network topological structure data has unique advantages. The model can effectively capture the spatial relationship and topological characteristics between nodes, which is of great significance for understanding the connection mode and load distribution of the power network. Compared with traditional data processing methods, the graph neural network model can better learn network structure information while maintaining data privacy, and improves the model's ability to understand the dynamic characteristics of the power network. For image data, the federated learning method using a convolutional neural network model is of special value. In the processing of power equipment monitoring images, this method can complete the learning task through the interaction of model parameters without centrally collecting original images. This design not only protects the privacy of sensitive data, but also maintains the high accuracy of image recognition, which is particularly suitable for processing power equipment monitoring data in distributed scenarios.

[0054] Through this multimodal federated learning architecture design, the present invention successfully solves the privacy protection problem in data sharing in the power industry, while ensuring the accuracy of processing different types of data.

[0055] S2: Use a multi-stage federated learning backdoor defense method to perform backdoor defense on the data privacy trusted computing engine.

[0056] Among them, the multi-stage federated learning backdoor defense method includes: using a robust aggregation algorithm to screen models uploaded by users, using trigger reverse engineering and backdoor judgement to detect whether the model has a backdoor, and using backdoor forgetting technology to repair models with backdoors.

[0057] S2.1: Receive the model uploaded by the user, use the robust aggregation algorithm to calculate the L1 norm, L2 norm and cosine distance of the model, and generate the first detection result.

[0058] S2.2: Perform multi-stage defense processing based on the first detection result. Specifically, if the L1 norm, L2 norm and cosine distance are all lower than their corresponding defense thresholds, use trigger reverse engineering and backdoor determiner to perform deep detection to generate a second detection result.

[0059] If any of the L1 norm, L2 norm and cosine distance is higher than the corresponding defense threshold, the backdoor forgetting technique is directly used to repair the model.

[0060] S2.3: Determine the backdoor repair strategy based on the second detection result. Specifically, if the second detection result shows the existence of backdoor features, the trigger sample generated by the trigger reverse engineering is input into the backdoor forgetting technology for targeted repair; otherwise, the model is marked as a safe model.

[0061] According to the second detection results and the model repair effect, the defense evaluation index is established:

[0062] If the repair effect of the backdoor forgetting technology is lower than the first preset threshold, the trigger reverse engineering is used again to generate a new trigger sample;

[0063] If the repair effect is higher than the first preset threshold, the repaired model is stored in the security model library.

[0064] It should be noted that the present invention adopts a triple defense mechanism to form progressive protection: First, the robust aggregation algorithm constructs a rapid screening mechanism by calculating the L1 norm, L2 norm and cosine distance of the model. This multi-dimensional evaluation method improves the detection accuracy and reduces the misjudgment rate compared with the traditional single indicator screening. Especially in the power data scenario, this method can effectively identify the abnormal model parameter distribution and provide a reliable basis for subsequent defense. Secondly, the synergistic mechanism of trigger reverse engineering and backdoor judge solves the problem of concealment of backdoor attacks. By reversely restoring possible trigger patterns and combining the precise identification of the judge, the scheme can discover potential backdoors that are difficult to detect by traditional methods. This dual detection mechanism can improve the backdoor recognition rate. Finally, the directional repair scheme of the backdoor forgetting technology breaks through the limitations of traditional model repair. By using the trigger information obtained by reverse engineering, accurate backdoor elimination is achieved, which not only maintains the performance of the model on normal samples, but also significantly improves the repair efficiency. Overall, the defense scheme ensures the comprehensiveness of defense and realizes the organic coordination of each stage through triple progressive protection. In terms of solving technical problems, it has successfully overcome the problems of detection blind spots and low repair efficiency in traditional backdoor defense, providing reliable guarantees for the safe application of federated learning in the power industry.

[0065] S3: Based on the processing results of the robust aggregation algorithm, trigger reverse engineering, backdoor judgement and backdoor forgetting technology, a federated learning backdoor defense system is constructed.

[0066] S3.1: A model evaluation index system is established based on the processing results of the robust aggregation algorithm. The model evaluation index system includes a combined score of the L1 norm, the L2 norm and the cosine distance.

[0067] S3.2: Perform security assessment on the processing results of the trigger reverse engineering and backdoor judgement:

[0068] If the trigger sample generated by the trigger reverse engineering is determined as a backdoor feature in the backdoor judger, the trigger sample and its corresponding defense solution are stored in the defense strategy library;

[0069] If the trigger sample generated by the trigger reverse engineering is not determined to be a backdoor feature, the trigger sample is stored in the normal sample library.

[0070] S3.3: Update the defense strategy based on the repair results of the backdoor forgetting technique:

[0071] If the performance index of the repaired model is higher than the second preset threshold, the repair solution is added to the defense strategy library;

[0072] If the performance index of the repaired model is lower than the second preset threshold, the parameters of the repair scheme are adjusted and the repair process is re-executed.

[0073] S3.4: Construct a federated learning backdoor defense system based on the data of the model evaluation indicator system, defense strategy library, and normal sample library.

[0074] It should be noted that the step S3 of the present invention establishes an adaptive federated learning backdoor defense system. The system integrates the L1 norm, L2 norm and cosine distance through a combined scoring mechanism, overcoming the problem that the traditional single indicator evaluation method is prone to blind spots. Especially in the face of distributed backdoor attacks, the multi-dimensional evaluation system can capture different types of abnormal features. In terms of the construction of the defense strategy library, the present invention establishes a correspondence between trigger samples and defense schemes to form a dynamically updated knowledge base. This design enables the defense system to quickly adjust strategies for emerging attack patterns, breaking through the limitations of traditional static defense schemes. The adaptive optimization mechanism of the backdoor forgetting technology is another important innovation. Through feedback adjustment of performance indicators, the system can automatically optimize the repair parameters. This closed-loop design significantly improves the repair efficiency while ensuring that the basic performance of the model will not be severely degraded due to the repair process.

[0075] Preferably, in a specific embodiment of the present invention, the construction of the federated learning backdoor defense system adopts a multi-level adaptive architecture. First, the system evaluates the model in an all-round way through a combined scoring mechanism. This mechanism is different from the traditional single indicator evaluation method, but a weighted combination of L1 norm, L2 norm and cosine distance. This design enables the evaluation system to capture the abnormal features of the model in different dimensions at the same time, effectively improving the accuracy of anomaly detection. Secondly, the present invention establishes a dynamically updated defense strategy library. When the sample generated by the reverse engineering of the trigger is determined to be a backdoor feature, the system not only stores the sample itself, but also records the corresponding defense scheme. The establishment of this mapping relationship enables the system to respond quickly to similar attack modes, greatly improving the defense efficiency. At the same time, the establishment of a normal sample library provides the system with reliable benchmark data, which helps to reduce the misjudgment rate. In the backdoor repair link, the present invention designs an adaptive parameter optimization mechanism. The system automatically adjusts the repair parameters by continuously monitoring the performance indicators of the repaired model. This closed-loop design not only ensures the repair effect, but also maintains the basic performance of the model. In particular, when dealing with complex distributed backdoor attacks, this mechanism shows significant advantages. Finally, the entire defense system forms an organic and unified defense network by integrating the data of model evaluation indicators, defense strategy library and normal sample library. This multi-level defense architecture not only improves the defense capability of the system, but also realizes the dynamic optimization of defense strategy, providing reliable protection for the safe application of federated learning.

[0076] In summary, the present invention has achieved significant technological breakthroughs by combining multiple federated learning models with multi-level backdoor defense mechanisms. At the data processing level, a dedicated federated learning method is designed for different types of data, breaking through the limitations of the traditional single model and improving the processing efficiency of heterogeneous data. At the security defense level, an innovative multi-level defense system including rapid screening, deep detection and adaptive repair is constructed. Through a dynamically updated defense strategy library and an adaptive parameter optimization mechanism, the blind spot problem of traditional backdoor defense methods in the face of complex attacks is effectively solved. Especially in the actual application scenarios of the power industry, the solution ensures the accuracy of data processing and maintains the security of the model through the comprehensive use of tree models, graph neural networks and convolutional neural networks. At the same time, it realizes the dynamic optimization of defense strategies and the stability of model performance, providing a comprehensive technical solution for the secure sharing of data in the power industry.

[0077] Embodiment 2 is an embodiment of the present invention, which provides a data privacy trusted computing system, including:

[0078] The federated learning data processing module is used to establish a data privacy trusted computing engine using a federated learning approach to process tabular data, graph data, and image data;

[0079] The security defense module is used to perform backdoor defense on the data privacy trusted computing engine using a multi-stage federated learning backdoor defense method;

[0080] The defense system building module is used to build a federated learning backdoor defense system based on the processing results of the robust aggregation algorithm, trigger reverse engineering, backdoor judgement and backdoor forgetting technology.

[0081] Example 3, reference Figure 2 , is an embodiment of the present invention, which is different from the previous embodiment in that: if the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk and other media that can store program codes.

[0082] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or in conjunction with such instruction execution systems, devices or apparatuses. For the purposes of this specification, "computer-readable medium" can be any device that can contain, store, communicate, propagate or transmit a program for use by an instruction execution system, device or apparatus, or in conjunction with such instruction execution systems, devices or apparatuses.

[0083] More specific examples of computer-readable media (a non-exhaustive list) include the following: an electrical connection with one or more wires (electronic device), a portable computer disk case (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable and programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disk read-only memory (CDROM). In addition, the computer-readable medium may even be a paper or other suitable medium on which the program is printed, since the program may be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, deciphering or, if necessary, processing in another suitable manner, and then stored in a computer memory.

[0084] It should be understood that the various parts of the present invention can be implemented by hardware, software, firmware or a combination thereof. In the above-mentioned embodiments, a plurality of steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented by hardware, as in another embodiment, it can be implemented by any one of the following technologies known in the art or their combination: a discrete logic circuit having a logic gate circuit for implementing a logic function for a data signal, a dedicated integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0085] Example 4 is an embodiment of the present invention, which provides a data privacy trusted computing method. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through economic benefit calculation and simulation experiments.

[0086] In order to verify the effectiveness of the present invention, a set of comprehensive experiments is designed in this embodiment. The experimental environment adopts a distributed computing cluster, which includes 10 computing nodes, and each node is configured with the same hardware environment. The experimental data set includes power user electricity consumption behavior table data, power grid topology map data, and equipment monitoring image data. In order to simulate real scenarios, this embodiment designs a variety of backdoor attack schemes, including traditional data poisoning attacks, model replacement attacks, and distributed collaborative attacks. The experiment evaluated the performance of the multimodal federated learning scheme and multi-level backdoor defense mechanism of the present invention. In terms of data processing, the processing efficiency and model accuracy of different types of data are focused on; in terms of security defense, the system's defense effect against different types of backdoor attacks is evaluated.

[0087] The control group adopted the traditional single-model federated learning scheme and the backdoor defense method based on statistical features. During the experiment, this embodiment set up training data sets of different sizes and attack scenarios of different intensities to comprehensively evaluate the performance of the system under various conditions. Special attention was paid to key indicators such as model training efficiency, defense accuracy, false alarm rate, and missed alarm rate. At the same time, performance parameters such as system resource usage and response time were monitored. To ensure the reliability of the experiment, each group of experiments was repeated multiple times, and the average value was taken as the final result.

[0088] Table 1 Experimental index comparison table

[0089] Evaluation Metrics Traditional Solution Solution of the present invention Performance Improvements Heterogeneous data processing time (relative value) 1.00 0.65 35% Model training accuracy medium Higher Significant Backdoor attack detection rate Low high obvious False Positive Rate high Low Significantly reduce System response time (relative value) 1.00 0.70 30% Defense strategy update efficiency Low high Significant Model performance retention rate medium Higher obvious Resource Utilization Lower Higher Significant

[0090] As shown in Table 1, in terms of heterogeneous data processing efficiency, the present invention reduces the processing time by 35% through targeted model selection; in terms of backdoor attack defense, the multi-level defense mechanism significantly improves the attack detection rate and greatly reduces the false alarm rate. It is particularly noteworthy that while maintaining a high defense effect, the present invention well maintains the model performance through an adaptive parameter optimization mechanism, which is difficult to achieve with traditional solutions. The system response time is reduced by 30%, and the resource utilization rate is significantly improved, indicating that the present invention has strong engineering value in practical applications. The dynamic update mechanism of the defense strategy also shows good adaptability and can effectively respond to new attack modes. These experimental data fully demonstrate the technical advantages and practical value of the present invention in practical applications.

[0091] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A data privacy trusted computing method, characterized in that: include: Use federated learning to build a data privacy trusted computing engine; A multi-stage federated learning backdoor defense method is used to perform backdoor defense on the data privacy trusted computing engine; The multi-stage federated learning backdoor defense method includes using a robust aggregation algorithm to screen models uploaded by users, using trigger reverse engineering and a backdoor judger to detect whether a model has a backdoor, and using a backdoor forgetting technique to repair a model with a backdoor. According to the processing results of the robust aggregation algorithm, the trigger reverse engineering, the backdoor determiner and the backdoor forgetting technology, a federated learning backdoor defense system is constructed.

2. The data privacy trusted computing method according to claim 1, characterized in that: The federated learning method includes using a tree model-based federated learning method to process tabular data, using a graph neural network model-based federated learning method to process graph data, and using a convolutional neural network model-based federated learning method to process image data.

3. The data privacy trusted computing method according to claim 2, characterized in that: Using federated learning to establish a data privacy trusted computing engine includes the following steps: Identify the input data and classify the data into table data, graph data and image data; Corresponding federated learning models are established for different types of data: if the data is tabular data, the tree model is used to train the tabular data; if the data is graph data, the graph neural network model is used to train the graph data; if the data is image data, the convolutional neural network model is used to train the image data; The training results of the tree model, the graph neural network model and the convolutional neural network model are integrated into the data privacy trusted computing engine.

4. The data privacy trusted computing method according to claim 3, characterized in that: The data privacy trusted computing engine is backdoor-protected by adopting a multi-stage federated learning backdoor defense method, including the following steps: Receiving the model uploaded by the user, calculating the L1 norm, L2 norm and cosine distance of the model using the robust aggregation algorithm, and generating a first detection result; Performing multi-stage defense processing according to the first detection result, specifically, if the L1 norm, the L2 norm, and the cosine distance are all lower than their corresponding defense thresholds, performing deep detection using the trigger reverse engineering and the backdoor determiner to generate a second detection result; If any one of the L1 norm, the L2 norm and the cosine distance is higher than the corresponding defense threshold, the backdoor forgetting technique is directly used to repair the model; A backdoor repair strategy is determined according to the second detection result. Specifically, if the second detection result shows the existence of backdoor features, the trigger sample generated by the trigger reverse engineering is input into the backdoor forgetting technology for targeted repair; otherwise, the model is marked as a safe model.

5. The data privacy trusted computing method according to claim 4, characterized in that: According to the second detection result and the model repair effect, a defense evaluation index is established: If the repair effect of the backdoor forgetting technology is lower than the first preset threshold, the trigger reverse engineering is re-adopted to generate a new trigger sample; If the repair effect is higher than the first preset threshold, the repaired model is stored in a security model library.

6. The data privacy trusted computing method according to claim 5, characterized in that: According to the processing results of the robust aggregation algorithm, the trigger reverse engineering, the backdoor determiner and the backdoor forgetting technology, a federated learning backdoor defense system is constructed, including the following steps: Establishing a model evaluation index system according to the processing result of the robust aggregation algorithm, wherein the model evaluation index system includes a combined score of the L1 norm, the L2 norm and the cosine distance; Performing security assessment on the reverse engineering of the trigger and the processing results of the backdoor determiner; Update the defense strategy according to the repair result of the backdoor forgetting technique; The federated learning backdoor defense system is constructed based on the data of the model evaluation index system, the defense strategy library and the normal sample library.

7. The data privacy trusted computing method according to claim 6, characterized in that: The reverse engineering of the trigger and the processing result of the backdoor determiner are subjected to security assessment, including: If the trigger sample generated by the reverse engineering of the trigger is determined as a backdoor feature in the backdoor determiner, the trigger sample and its corresponding defense solution are stored in a defense strategy library; If the trigger sample generated by the reverse engineering of the trigger is not determined to be a backdoor feature, storing the trigger sample in a normal sample library; The updating of the defense strategy according to the repair result of the backdoor forgetting technology includes: If the performance index of the repaired model is higher than a second preset threshold, adding the repair solution to the defense strategy library; If the performance index of the repaired model is lower than the second preset threshold, the parameters of the repair scheme are adjusted and the repair process is re-executed.

8. A data privacy trusted computing system, based on the data privacy trusted computing method according to any one of claims 1 to 7, characterized in that: include, The federated learning data processing module is used to establish a data privacy trusted computing engine using a federated learning approach to process tabular data, graph data, and image data; A security defense module, used to perform backdoor defense on the data privacy trusted computing engine using a multi-stage federated learning backdoor defense method; The defense system building module is used to build a federated learning backdoor defense system based on the processing results of the robust aggregation algorithm, the trigger reverse engineering, the backdoor determiner and the backdoor forgetting technology.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the data privacy trusted computing method described in any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the data privacy trusted computing method described in any one of claims 1 to 7 are implemented.

Citation Information

Cited By

  • Federal learning backdoor attack defense method based on multi-layer cooperative defense strategy

    CN120434054A

  • A federated learning backdoor attack defense method based on multi-layer collaborative defense strategy

    CN120434054B