Model training system and method for removing endogenous features, and computer program product

By removing endogenous features related to external operations and retraining the model, the problem of device features and external operation behavior is solved, the accuracy of the recognition of the model is improved, and the platform information security is ensured.

CN120105089APending Publication Date: 2025-06-06SHANGHAI QIYUE INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411987968.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-06-06

AI Technical Summary

Technical Problem

In the prior art, device features are associated with external operational behaviors provided by the platform, resulting in changes in model identification results, affecting the identification accuracy, and thus threatening the platform information security.

Method used

By collecting changes before and after the device features, it is determined whether the identification result distribution is consistent. If it is inconsistent, the endogenous features related to external operations will be removed and the predictive identification model will be retrained.

Benefits of technology

The impact of endogenous features on model identification results is eliminated, the accuracy of model identification is improved, and the platform information security is ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120105089A_ABST
    Figure CN120105089A_ABST
Patent Text Reader

Abstract

The invention discloses a model training system and method for removing endogenous features and a computer program product. The system comprises a first judgment module, a second judgment module and a third judgment module, wherein the first judgment module judges whether distribution of first recognition results of a device set before and after external operation is provided is consistent or not; and if not, after the null module nulls the equipment characteristics related to the external operation in the equipment characteristics, whether second identification result distribution of the equipment set before and after the external operation is provided is consistent is judged through a second judgment module, and a prediction model is trained. The method comprises: determining whether first identification result distribution is consistent; if not, nulling the equipment characteristics related to the external operation in the equipment characteristics; further judging whether the second identification result distribution is consistent or not; and if the device features are consistent, indicating that the null device features are just endogenous features associated with the external operation, removing the endogenous features from the device features, and training a prediction identification model for safety supervision, thereby eliminating the influence of the endogenous features on a model identification result, and guaranteeing the platform information safety.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer application technology, and in particular to a model training system, method and computer program product for removing endogenous features. Background Art

[0002] Internet service platforms make profits by providing goods or services to users, but at the same time they may also suffer from violations by some bad users (such as data theft, fraud, overdue payments, etc.), which seriously affect the information security of the platform.

[0003] In the prior art, the device features related to the above-mentioned violations are mainly analyzed through the analysis model of device data, so as to identify the above-mentioned violations and ensure the information security of the platform. However, some of the collected device features are related to the external operation behaviors provided by the platform to users in order to reduce the possible harm and risks to the data and platform, or to promote products, etc., which causes the model's recognition results of users to change after the platform provides external operations to users, affecting the recognition accuracy. Take the rental platform as an example. The platform provides users with corresponding rentable products based on the user's own abnormal score / security status score. At first, the model identifies the user's abnormal score as 500 by analyzing the user's device features. When the platform adds rentable products to the user, the user's rental rate for the product will suddenly drop. At this time, the model collects the user's device features for analysis, and the abnormal score of the user is higher than 500. In fact, the user's own security level has not changed before and after the platform adds rentable products to the user.

[0004] Therefore, it is necessary to optimize the training process of the model through data prediction analysis to find and remove the device features associated with the external operations provided by the platform, improve the recognition accuracy of the model, and ensure the information security of the platform. Summary of the invention

[0005] In view of this, the main purpose of the present invention is to propose a model training system, method and computer program product for removing endogenous features, in order to at least partially solve at least one of the above-mentioned technical problems.

[0006] In order to solve the above technical problems, the first aspect of the present invention proposes a model training system for removing endogenous features, the system comprising:

[0007] A collection module, used to provide external operations to each device in the device set, and collect device characteristics of each device before and after the external operations are provided;

[0008] A determination module, configured to determine a first recognition result distribution of the device set before and after providing the external operation according to device characteristics of each device before and after providing the external operation;

[0009] A first determination module, used to determine whether the distribution of the first recognition results of the device set before and after providing the external operation is consistent;

[0010] A clearing module, configured to clear the device features related to the external operation in the device features if the first recognition result distribution of the device set before and after the external operation is provided is inconsistent, and then determine the second recognition result distribution of the device set before and after the external operation is provided according to the device features of each device before and after the external operation is provided;

[0011] A second determination module, used to determine whether the distribution of the second recognition results of the device set before and after providing the external operation is consistent;

[0012] The training module is used to remove the endogenous features from the device features if the second recognition result distribution of the device set before and after the external operation is provided is consistent, and train a prediction recognition model based on the device features with the endogenous features removed.

[0013] According to a preferred embodiment of the present invention, the determining module includes:

[0014] An input module is used to input the device characteristics of each device before and after the external operation into the initial prediction model, and output the safety score of each device before and after the external operation;

[0015] The statistical module is used to respectively count the proportions of the security scores of all devices before and after the external operation is provided in different predetermined intervals, and obtain the first recognition result distribution of the device set before and after the external operation is provided.

[0016] According to a preferred embodiment of the present invention, the first judgment module includes:

[0017] A comparison module, used to compare whether the difference in the proportion of the security scores of all devices before and after providing the external operation in different predetermined intervals is within a threshold;

[0018] The sub-determination module is used to provide a consistent distribution of the first recognition results of the device set before and after the external operation if the distribution ratio difference is less than or equal to a threshold; if the distribution ratio difference is greater than the threshold, then the first recognition result distribution of the device set before and after the external operation is inconsistent.

[0019] According to a preferred embodiment of the present invention, the system further comprises:

[0020] The identification module is used to identify the safety of the device based on the initial prediction recognition model if the first recognition result distribution of the device set before and after the external operation is provided is consistent; if the second recognition result distribution of the device set before and after the external operation is provided is consistent, identify the safety of the device based on the trained prediction recognition model.

[0021] Device security involves the security status of the device's hardware structure, data and other features, such as whether there are abnormalities / possible abnormalities, whether there are security risks and hazards that endanger the platform and platform data information, etc. The security score also involves, for example, whether there are abnormalities (scores of abnormal status, degree of abnormality, etc.), whether there is a risk of endangering security risks (scores of whether there are risks and security risks), etc.

[0022] In order to solve the above technical problems, the second aspect of the present invention provides a model training method for removing endogenous features, the method comprising:

[0023] Provide external operations to each device in the device set, and collect device characteristics of each device before and after providing the external operations;

[0024] Determine the first recognition result distribution of the device set before and after providing the external operation according to the device characteristics of each device before and after providing the external operation;

[0025] Determining whether the distribution of the first recognition results of the device set is consistent before and after providing the external operation;

[0026] If the distribution of the first recognition results of the device set before and after the external operation is provided is inconsistent, after the device features related to the external operation in the device features are cleared, the second recognition result distribution of the device set before and after the external operation is provided is determined according to the device features of each device before and after the external operation is provided;

[0027] Determining whether the distribution of the second recognition results of the device set before and after providing the external operation is consistent;

[0028] If the distribution of the second recognition results of the device set before and after the external operation is provided is consistent, the endogenous features are removed from the device features, and a prediction recognition model is trained based on the device features with the endogenous features removed.

[0029] According to a preferred embodiment of the present invention, determining the first recognition result distribution of the device set before and after providing the external operation according to the device characteristics of each device before and after providing the external operation includes:

[0030] Input the device characteristics of each device before and after the external operation into the initial prediction model, and output the safety score of each device before and after the external operation;

[0031] The proportions of the security scores of all devices in different predetermined intervals before and after the external operation is provided are respectively counted to obtain the first recognition result distribution of the device set before and after the external operation is provided.

[0032] According to a preferred embodiment of the present invention, the determining whether the distribution of the first recognition results of the device set before and after providing the external operation is consistent includes:

[0033] Compare the differences in the proportions of the security scores of all devices before and after providing the external operation in different predetermined intervals to see whether they are within the threshold;

[0034] If the distribution ratio difference is less than or equal to the threshold, the distribution of the first recognition results of the device set before and after the external operation is provided is consistent;

[0035] If the distribution ratio difference is greater than a threshold, the distribution of the first recognition results of the device set before and after the external operation is provided is inconsistent.

[0036] According to a preferred embodiment of the present invention, the method further comprises:

[0037] If the distribution of the first recognition results of the device set before and after the external operation is provided is consistent, identifying the device safety based on the initial prediction recognition model;

[0038] If the distribution of the second identification results of the device set before and after the external operation is provided is consistent, the device is identified to be safe based on the trained predictive identification model.

[0039] In order to solve the above technical problems, the third aspect of the present invention provides an electronic device, including:

[0040] Processor; and

[0041] A memory storing computer executable instructions, which when executed cause the processor to perform any of the methods described above.

[0042] In order to solve the above technical problem, the fourth aspect of the present invention provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements any of the methods described above.

[0043] In summary, the present invention provides external operations for each device in a device set, and collects device features before and after each device provides the external operation; determines the first recognition result distribution of the device set before and after the external operation is provided according to the device features before and after each device provides the external operation; judges whether the first recognition result distribution of the device set before and after the external operation is provided is consistent; if the first recognition result distribution is inconsistent, it indicates that there are endogenous features associated with the external operation in the device features, then the device features related to the external operation in the device features are cleared, and then the second recognition result distribution of the device set before and after the external operation is provided is determined according to the device features before and after each device provides the external operation; further judges whether the second recognition result distribution of the device set before and after the external operation is consistent; if the second recognition result distribution is consistent, it indicates that the cleared device features are the endogenous features associated with the external operation, remove the endogenous features from the device features, and train a predictive recognition model based on the device features without the endogenous features, thereby eliminating the influence of the endogenous features on the model recognition results, thereby improving the recognition accuracy of the model and ensuring the platform information security. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to make the technical problems solved by the present invention, the technical means adopted and the technical effects achieved more clearly, the specific embodiments of the present invention will be described in detail with reference to the accompanying drawings. However, it should be noted that the drawings described below are only drawings of exemplary embodiments of the present invention, and those skilled in the art can obtain drawings of other embodiments based on these drawings without creative work.

[0045] Figure 1 It is a schematic diagram of the structural framework of a model training system for removing endogenous features provided by an embodiment of the present invention;

[0046] Figure 2 It is a flow chart of a model training method for removing endogenous features provided by an embodiment of the present invention;

[0047] Figure 3 is a structural block diagram of an exemplary embodiment of an electronic device according to the present invention;

[0048] Figure 4 is a schematic diagram of an embodiment of a computer readable medium of the present invention. DETAILED DESCRIPTION

[0049] Under the premise of conforming to the technical concept of the present invention, the structure, performance, effect or other characteristics described in a specific embodiment may be combined with one or more other embodiments in any appropriate manner.

[0050] In the process of introducing specific embodiments, the detailed description of the structure, performance, effect or other features is to enable those skilled in the art to fully understand the embodiments. However, it does not exclude that those skilled in the art can implement the present invention with a technical solution that does not contain the above-mentioned structure, performance, effect or other features under certain circumstances. The figures in the accompanying drawings are only an exemplary demonstration, and do not mean that the solution of the present invention must include all the contents, operations and steps in the figures, nor do they mean that they must be executed in the order shown in the figures.

[0051] refer to Figure 1 , Figure 1 A schematic diagram of the structural framework of a model training system for removing endogenous features provided by an embodiment of the present invention is shown in FIG. Figure 1 As shown, the system comprises:

[0052] The collection module 11 is used to provide external operations to each device in the device set, and collect device characteristics of each device before and after providing the external operations;

[0053] A determination module 12, configured to determine a first recognition result distribution of the device set before and after providing the external operation according to device characteristics of each device before and after providing the external operation;

[0054] A first determination module 13, used to determine whether the distribution of the first recognition results of the device set before and after providing the external operation is consistent;

[0055] A blanking module 14 is used for, if the first recognition result distribution of the device set before and after the external operation is provided is inconsistent, blanking the device features related to the external operation in the device features, and then determining the second recognition result distribution of the device set before and after the external operation is provided according to the device features of each device before and after the external operation is provided;

[0056] A second determination module 15 is used to determine whether the distribution of the second recognition results of the device set before and after providing the external operation is consistent;

[0057] The training module 16 is used to remove the endogenous features from the device features if the second recognition result distribution of the device set before and after the external operation is provided is consistent, and train a prediction recognition model based on the device features with the endogenous features removed.

[0058] In a specific implementation, the determination module 12 includes:

[0059] An input module is used to input the device characteristics of each device before and after the external operation into the initial prediction model, and output the safety score of each device before and after the external operation;

[0060] The statistical module is used to respectively count the proportions of the security scores of all devices before and after the external operation is provided in different predetermined intervals, and obtain the first recognition result distribution of the device set before and after the external operation is provided.

[0061] The first determination module 13 includes:

[0062] A comparison module, used to compare whether the difference in the proportion of the security scores of all devices before and after providing the external operation in different predetermined intervals is within a threshold;

[0063] The sub-determination module is used to provide a consistent distribution of the first recognition results of the device set before and after the external operation if the distribution ratio difference is less than or equal to a threshold; if the distribution ratio difference is greater than the threshold, then the first recognition result distribution of the device set before and after the external operation is inconsistent.

[0064] In a preferred example, the system further includes:

[0065] The identification module is used to identify the safety of the device based on the initial prediction recognition model if the first recognition result distribution of the device set before and after the external operation is provided is consistent; if the second recognition result distribution of the device set before and after the external operation is provided is consistent, identify the safety of the device based on the trained prediction recognition model.

[0066] based on Figure 1 The model training system for removing endogenous features, the embodiment of the present invention also provides a model training method for removing endogenous features, the endogenous features refer to device features associated with external operations provided by the platform to the user device, the device features are used to predict whether the user device has stolen data, modified data, defrauded, overdue and other violations. Figure 2 , the model training method based on the relationship network includes:

[0067] S1. Provide external operations to each device in the device set, and collect device characteristics of each device before and after providing the external operations;

[0068] In this embodiment, the external operation may be an operation provided by the platform to the user device in order to reduce the abnormal harm caused by illegal behavior, such as: reducing the number of goods that can be rented by the user device, reducing the period for returning goods by the user device, increasing the cost of renting goods by the user device, etc. The external operation may also be an operation provided by the platform to the user device in order to promote products, such as: increasing the number of goods that can be rented by the user device, increasing the period for returning goods by the user device, reducing the cost of renting goods by the user device, etc.

[0069] The device characteristics may be any device-related data that the user chooses to make public or that has been desensitized. It may include at least one of: the device's location, device purchase or return records, device communication records, device user information, and device behavior information;

[0070] Among them, the device purchase record refers to the record of the device purchasing goods on the platform. The device return record refers to the record of whether the goods are returned on time after the device applies for platform goods, which may include the number of rented goods, return period, number of returns, etc. The goods can be physical goods, virtual goods, services, etc., and the present invention does not make specific limitations. The device communication record may include communication-related information such as address book contacts stored in the device, communication records stored in the device, etc. The device user information may include: gender, age, education, fraud record, violation record, etc. of the user using the device. The device behavior information refers to the operation information of the device on the platform, such as: browsing, visiting, collecting, clicking, etc.

[0071] In this embodiment, since the external operations can be varied, for each external operation, the device features selected when training the model may or may not have associated endogenous features; at the same time, the device features selected for training the prediction model may also be different, so for the same external operation, the situations where endogenous features are associated with it in different device features are also different. Therefore, it is necessary to determine whether there are endogenous features associated with the current external operation in the device features for the current external operation and the current device features.

[0072] S2, determining a first recognition result distribution of the device set before and after providing the external operation according to the device characteristics of each device before and after providing the external operation;

[0073] Exemplarily, this step may include:

[0074] S21, inputting the device characteristics of each device before and after the external operation into the initial prediction model, and outputting the safety score of each device before and after the external operation;

[0075] The initial prediction model is a model trained by pre-collecting the device features of historical devices for identifying whether the device has illegal behavior. The device features of historical devices are the same as the device features of each device collected in step S1. For example, the device location, device return record, device communication record, and device behavior information are all used as device features.

[0076] In this step, the device characteristics before the device provides external operation can be input into the initial prediction model, and the output can be the safety score of each device before the external operation is provided; then the device characteristics after the device provides external operation can be input into the initial prediction model, and the output can be the safety score of each device after the external operation is provided.

[0077] S22. Count the proportions of the security scores of all devices in different predetermined intervals before and after the external operation is provided, and obtain a first recognition result distribution of the device set before and after the external operation is provided.

[0078] Among them, the predetermined interval can be configured according to the range of the recognition result. For example, if the recognition result is between 100 and 700, the predetermined interval can be: [100-300], [300-500], [500-700].

[0079] This step can count the proportion of security scores of all devices before providing external operation in different predetermined intervals, and obtain the first recognition result distribution of the device set before providing external operation. Then count the proportion of security scores of all devices after providing external operation in different predetermined intervals, and obtain the first recognition result distribution of the device set after providing external operation. For example: there are 10 devices with security scores falling into [100-300], 20 devices with security scores falling into [300-500], and 15 devices with security scores falling into [500-700]. The first recognition result distribution is 10 / 45, 20 / 45, and 15 / 45.

[0080] S3, determining whether the distribution of the first recognition results of the device set before and after providing the external operation is consistent;

[0081] Exemplarily, it is possible to compare whether the difference in the proportion of the security scores of all devices before and after the external operation in different predetermined intervals is within a threshold; if the distribution proportion difference is less than or equal to the threshold, the distribution of the first recognition results of the device set before and after the external operation is consistent; if the distribution proportion difference is greater than the threshold, the distribution of the first recognition results of the device set before and after the external operation is inconsistent.

[0082] Among them: the difference in the proportion of the security scores of all devices before and after the external operation is provided in different predetermined intervals may be the sum of the difference in the proportion of the security scores of all devices in each predetermined interval before and after the external operation is provided; the difference in the proportion of the predetermined interval may be the difference between the proportion of devices whose security scores fall into the interval before the external operation is provided and the proportion of devices whose security scores fall into the interval after the external operation is provided.

[0083] S4. If the distribution of the first recognition results of the device set before and after the external operation is provided is inconsistent, after the device features related to the external operation in the device features are cleared, the second recognition result distribution of the device set before and after the external operation is provided is determined according to the device features of each device before and after the external operation is provided;

[0084] In this embodiment, if the first recognition result distribution is inconsistent, it indicates that there are endogenous features associated with external operations in the device features. In this step, device features related to external operations (referred to as "relevant features") can be first screened out from the device features, and the relevant features included in the device features of each device before providing the external operation are cleared. The second recognition result distribution of the device set before providing the external operation is determined based on the device features of each device before providing the external operation and the relevant features have been cleared. At the same time, the relevant features included in the device features of each device after providing the external operation can be cleared, and the second recognition result distribution of the device set after providing the external operation is determined based on the device features of each device after providing the external operation and the relevant features have been cleared.

[0085] Among them: blanking means setting the value of the device feature to the same fixed value, so that when the prediction model analyzes the device features, the blanked device features have the same impact on the recognition results. In other words, the second recognition result distribution is obtained by analyzing the device features except the blanked related features through the prediction model, and has nothing to do with the blanked related features. Therefore, if the second recognition result distribution is consistent, it means that there are no features associated with external operations in the device features, and the blanked related features in this step are the endogenous features associated with external operations. If the second recognition result distribution is inconsistent, it means that there are still features associated with external operations in the device features. In addition to the blanked related features in this step, there are also endogenous features associated with external operations in the device features. The device features related to external operations can be further screened out from the device features and blanked. Steps S4 and S5 are executed repeatedly until the second recognition result distribution of the device set before and after the external operation is provided is consistent.

[0086] S5. Determine whether the distribution of the second recognition results of the device set before and after providing the external operation is consistent;

[0087] This step is the same as step S3 and will not be repeated here.

[0088] S6. If the distribution of the second recognition results of the device set before and after the external operation is provided is consistent, remove the endogenous features from the device features, and train a prediction recognition model based on the device features with the endogenous features removed.

[0089] After experimental verification, the model indicators of the prediction model retrained after removing the endogenous features from the device features are the same as those of the initial prediction model trained with all device features (that is, the model effect is the same). Therefore, in this embodiment, if the distribution of the second recognition result is consistent, it indicates that the device features that are set blank are the endogenous features associated with external operations. The endogenous features are removed from the device features, and the prediction recognition model is trained based on the device features without the endogenous features, thereby eliminating the influence of the endogenous features on the model recognition results, thereby improving the recognition accuracy of the model and ensuring the information security of the platform.

[0090] Furthermore, the prediction model trained by the present invention can be used to identify the security of platform equipment, and the equipment security can also be identified based on the trained prediction model. Specifically: if the first recognition result distribution of the equipment set before and after the external operation is provided is consistent, indicating that there are no endogenous features associated with the external operation in the equipment characteristics, then the equipment security is identified based on the initial prediction recognition model; if the second recognition result distribution of the equipment set before and after the external operation is provided is consistent, indicating that there are no endogenous features associated with the external operation in the equipment characteristics, and the blanked related features are the endogenous features associated with the external operation, then the equipment security is identified based on the trained prediction recognition model.

[0091] Those skilled in the art will appreciate that the modules in the above system embodiments may be distributed in the system as described, or may be changed accordingly and distributed in one or more systems different from the above embodiments. The modules in the above embodiments may be combined into one module, or may be further split into multiple sub-modules.

[0092] The electronic device embodiment of the present invention is described below, and the electronic device can be regarded as a physical implementation of the method and device embodiments of the present invention described above. The details described in the electronic device embodiment of the present invention should be regarded as a supplement to the above method or device embodiments; details not disclosed in the electronic device embodiment of the present invention can be implemented with reference to the above method or device embodiments.

[0093] Figure 3 is a structural block diagram of an exemplary embodiment of an electronic device according to the present invention. Figure 3 The electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present invention.

[0094] like Figure 3 As shown, the electronic device 300 of this exemplary embodiment is in the form of a general data processing device. The components of the electronic device 300 may include, but are not limited to: at least one processing unit 310, at least one storage unit 3320, a bus 330 connecting different electronic device components (including the storage unit 320 and the processing unit 310), a display unit 340, etc.

[0095] The storage unit 320 stores a computer-readable program, which may be a source program or a code of a read-only program. The program may be executed by the processing unit 310, so that the processing unit 310 performs the steps of various embodiments of the present invention. For example, the processing unit 310 may perform the following steps: Figure 2 Steps shown.

[0096] Bus 330 may represent one or more of several types of bus structures, including a memory unit bus or memory unit controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of a variety of bus architectures.

[0097] The electronic device 300 may also communicate with one or more external devices 100 (e.g., keyboard, display, network device, Bluetooth device, etc.) so that a user can interact with the electronic device 300 via these external devices 100, and / or the electronic device 300 can communicate with one or more other data processing devices (e.g., router, modem, etc.). Such communication may be performed through an input / output (I / O) interface 350, and may also be performed through a network adapter 360 with one or more networks (e.g., a local area network (LAN), a wide area network (WAN), and / or a public network. The network adapter 360 may communicate with other modules of the electronic device 300 through the bus 330.

[0098] Figure 4 Schematic diagram of a computer readable medium embodiment of the present invention. Figure 4 As shown, the computer program can be stored on one or more computer-readable media. The computer-readable medium can be a readable signal medium or a readable storage medium. When the computer program is executed by one or more data processing devices, the computer-readable medium can implement the above method of the present invention, namely: provide external operations to each device in the device set, and collect device features before and after each device provides the external operation; determine the first recognition result distribution of the device set before and after the external operation is provided according to the device features before and after each device provides the external operation; determine whether the first recognition result distribution of the device set before and after the external operation is provided is consistent; if the first recognition result distribution of the device set before and after the external operation is inconsistent, after the device features related to the external operation in the device features are emptied, determine the second recognition result distribution of the device set before and after the external operation is provided according to the device features before and after each device provides the external operation; determine whether the second recognition result distribution of the device set before and after the external operation is consistent; if the second recognition result distribution of the device set before and after the external operation is consistent, remove the endogenous features from the device features, and train the prediction recognition model based on the device features after removing the endogenous features.

[0099] The present invention also provides a computer program product, comprising a computer program, wherein when the computer program is executed by a processor, Figure 2 The method described.

[0100] In summary, the present invention can be implemented by a method, system, electronic device or computer readable medium that executes a computer program. In practice, a general data processing device such as a microprocessor or a digital signal processor (DSP) can be used to implement some or all functions of the present invention.

[0101] The specific embodiments described above further describe the purpose, technical solutions and beneficial effects of the present invention in detail. It should be understood that the present invention is not inherently related to any specific computer, virtual device or electronic device, and various general devices can also implement the present invention. The above description is only a specific embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. A model training system for removing endogenous features, characterized in that: The system comprises: A collection module, used to provide external operations to each device in the device set, and collect device characteristics of each device before and after the external operations are provided; A determination module, configured to determine a first recognition result distribution of the device set before and after providing the external operation according to device characteristics of each device before and after providing the external operation; A first determination module, used to determine whether the distribution of the first recognition results of the device set before and after providing the external operation is consistent; A clearing module, configured to clear the device features related to the external operation in the device features if the first recognition result distribution of the device set before and after the external operation is provided is inconsistent, and then determine the second recognition result distribution of the device set before and after the external operation is provided according to the device features of each device before and after the external operation is provided; A second determination module, used to determine whether the distribution of the second recognition results of the device set before and after providing the external operation is consistent; The training module is used to remove the endogenous features from the device features if the second recognition result distribution of the device set before and after the external operation is provided is consistent, and train a prediction recognition model based on the device features with the endogenous features removed.

2. The system according to claim 1, characterized in that The determination module comprises: An input module is used to input the device characteristics of each device before and after the external operation into the initial prediction model, and output the safety score of each device before and after the external operation; The statistical module is used to respectively count the proportions of the security scores of all devices before and after the external operation is provided in different predetermined intervals, and obtain the first recognition result distribution of the device set before and after the external operation is provided.

3. The system according to claim 2, characterized in that The first judgment module includes: A comparison module, used to compare whether the difference in the proportion of the security scores of all devices before and after providing the external operation in different predetermined intervals is within a threshold; The sub-determination module is used to provide a consistent distribution of the first recognition results of the device set before and after the external operation if the distribution ratio difference is less than or equal to a threshold; if the distribution ratio difference is greater than the threshold, then the first recognition result distribution of the device set before and after the external operation is inconsistent.

4. The system according to claim 2, characterized in that The system further comprises: The identification module is used to identify the safety of the device based on the initial prediction recognition model if the first recognition result distribution of the device set before and after the external operation is provided is consistent; if the second recognition result distribution of the device set before and after the external operation is provided is consistent, identify the safety of the device based on the trained prediction recognition model.

5. A model training method for removing endogenous features, characterized in that: The method comprises: Provide external operations to each device in the device set, and collect device characteristics of each device before and after providing the external operations; Determine the first recognition result distribution of the device set before and after providing the external operation according to the device characteristics of each device before and after providing the external operation; Determining whether the distribution of the first recognition results of the device set is consistent before and after providing the external operation; If the distribution of the first recognition results of the device set before and after the external operation is provided is inconsistent, after the device features related to the external operation in the device features are cleared, the second recognition result distribution of the device set before and after the external operation is provided is determined according to the device features of each device before and after the external operation is provided; Determining whether the distribution of the second recognition results of the device set before and after providing the external operation is consistent; If the distribution of the second recognition results of the device set before and after the external operation is provided is consistent, the endogenous features are removed from the device features, and a prediction recognition model is trained based on the device features with the endogenous features removed.

6. The method according to claim 5, characterized in that The determining of the first recognition result distribution of the device set before and after providing the external operation according to the device characteristics of each device before and after providing the external operation comprises: Input the device characteristics of each device before and after the external operation into the initial prediction model, and output the safety score of each device before and after the external operation; The proportions of the security scores of all devices in different predetermined intervals before and after the external operation is provided are respectively counted to obtain the first recognition result distribution of the device set before and after the external operation is provided.

7. The method according to claim 6, characterized in that The determining whether the distribution of the first recognition results of the device set before and after providing the external operation is consistent includes: Compare the differences in the proportions of the security scores of all devices before and after providing the external operation in different predetermined intervals to see whether they are within the threshold; If the distribution ratio difference is less than or equal to the threshold, the distribution of the first recognition results of the device set before and after the external operation is provided is consistent; If the distribution ratio difference is greater than a threshold, the distribution of the first recognition results of the device set before and after the external operation is provided is inconsistent.

8. The method according to claim 5, characterized in that The method further comprises: If the distribution of the first recognition results of the device set before and after the external operation is provided is consistent, identifying the device safety based on the initial prediction recognition model; If the distribution of the second identification results of the device set before and after the external operation is provided is consistent, the device is identified to be safe based on the trained predictive identification model.

9. An electronic device, comprising: processor; as well as A memory storing computer executable instructions which, when executed, cause the processor to perform a method according to any one of claims 5 to 8.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 5 to 8 is implemented.