Model training method and device, electronic equipment and storage medium
By screening and training a model that recognizes backdoor samples in a federated learning environment, the problem of low backdoor attack defense efficiency is solved, efficient backdoor sample detection of edge devices is achieved, and the central computing resource requirements are reduced.
Patent Information
- Application Number
- CN202510330271.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-06-27
AI Technical Summary
In a federated learning environment, backdoor attacks have low defense efficiency, high false positive rates, and poor adaptability to new attacks, resulting in edge devices being unable to meet high computing resource requirements.
By obtaining the loss value of the sample to be tested, the target loss value greater than the threshold is selected as the backdoor sample, and the model to be selected is trained to identify the backdoor sample, thereby reducing the demand for central computing resources and improving the detection efficiency of the backdoor sample.
It realizes that the edge device itself can accurately identify backdoor samples, reduces the demand for central computing resources, and improves the detection efficiency of backdoor samples.
Smart Images

Figure CN120216993A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular, to a model training method, apparatus, electronic device, and storage medium. Background Art
[0002] In the context of the rapid development of current digital technologies, federated learning technology has emerged. In this technology, multiple edge devices are allowed to collaborate in training a shared machine learning model without exchanging the data they hold, which greatly enhances data privacy protection. However, this distributed and decentralized training method introduces new security adjustments, especially the risk of backdoor attacks.
[0003] Currently, some defense strategies against backdoor attacks are also provided, but these strategies are for data detection and model detection, which requires consuming a large amount of computing resources, and edge devices cannot meet these computing resource requirements, resulting in low operating efficiency of the strategies. Summary of the Invention
[0004] This application provides a model training method, apparatus, electronic device, and storage medium, which reduces the demand for central computing resources and improves the detection efficiency of backdoor samples.
[0005] In a first aspect, an embodiment of this application provides a model training method, and the method includes:
[0006] Obtain N samples to be tested, and calculate the loss value of each sample to be tested, where N is an integer greater than or equal to 1;
[0007] Screen out target loss values greater than a threshold from all the loss values, and use the samples to be tested corresponding to the target loss values as backdoor samples;
[0008] Use all the screened backdoor samples as a training set to train a candidate model to obtain a target model.
[0009] In this way, a model that can accurately identify backdoor samples can be trained, so that the edge device itself can detect backdoor samples through this target model, which not only reduces the demand for central computing resources, but also improves the detection efficiency of backdoor samples.
[0010] In an optional embodiment, the obtaining N samples to be tested and calculating the loss value of each sample to be tested includes:
[0011] Perform the following operations for each of the N samples to be tested:
[0012] Obtain the sample data, label, and model parameters of the sample to be tested, where the label is used to identify the sample to be tested;
[0013] Import the sample data, the labels, and the model parameters into the first loss function to obtain the loss value corresponding to the sample to be tested.
[0014] Through the above method, the loss value of each sample to be tested can be accurately calculated.
[0015] In an alternative embodiment, screening out the target loss values greater than the threshold among all the loss values includes:
[0016] Based on the loss value of each sample to be tested, divide the N samples to be tested into a normal sample set and a backdoor sample set;
[0017] Obtain the first expected loss of the normal sample set and the second expected loss of the backdoor sample set;
[0018] Input the loss value of the sample to be tested, the first expected loss, and the second expected loss into the second loss function to obtain a new loss value;
[0019] Screen out the target loss values greater than the threshold among all the new loss values.
[0020] Through the above method, the accuracy of the loss values of each sample to be tested can be further improved.
[0021] In an alternative embodiment, training the candidate model with all the screened backdoor samples as the training set includes:
[0022] Obtain the first feature parameter and the second feature parameter in the initial model, where the first feature parameter and the second feature parameter are the features of two consecutive layers in the initial model;
[0023] Input the first feature parameter, the second feature parameter, and the loss term weight into the model evaluation function to obtain a model evaluation result;
[0024] Adjust the loss term weight according to the model evaluation result to obtain the candidate model;
[0025] Train the candidate model with all the screened backdoor samples as the training set.
[0026] In an alternative embodiment, after training the candidate model with all the screened backdoor samples as the training set to obtain the target model, the method further includes:
[0027] Obtain the global update vector sent by the server;
[0028] Calculate the cosine similarity value between the local update vector and the global update vector;
[0029] If the cosine similarity value is less than the threshold, discard the global update vector;
[0030] If the cosine similarity value is greater than the threshold, update the model parameters in the target model according to the global update vector.
[0031] In a second aspect, an embodiment of the present application provides a model training device, the device includes:
[0032] An acquisition module, configured to acquire N samples to be tested, and calculate the loss value of each sample to be tested, where N is an integer greater than or equal to 1;
[0033] A processing module, configured to screen out target loss values greater than the threshold from all loss values, and use the samples to be tested corresponding to the target loss values as backdoor samples; train a candidate model with all the screened backdoor samples as a training set to obtain a target model.
[0034] In an optional embodiment, the acquisition module is specifically configured to acquire the sample data, labels, and model parameters of the samples to be tested, where the labels are used to identify the samples to be tested;
[0035] Import the sample data, the labels, and the model parameters into a first loss function to obtain the loss value corresponding to the sample to be tested.
[0036] In an optional embodiment, the processing module is specifically configured to divide the N samples to be tested into a normal sample set and a backdoor sample set based on the loss value of each sample to be tested;
[0037] Obtain a first expected loss of the normal sample set and a second expected loss of the backdoor sample set;
[0038] Input the loss value of the sample to be tested, the first expected loss, and the second expected loss into a second loss function to obtain a new loss value;
[0039] Screen out target loss values greater than the threshold from all the new loss values.
[0040] In a third aspect, an embodiment of the present application provides an electronic device, including:
[0041] A memory, configured to store a computer program;
[0042] A processor, configured to implement the method steps of the above model training method when executing the computer program stored on the memory.
[0043] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the method steps of the above model training method are implemented.
[0044] For the various aspects in the above second to fourth aspects and the possible technical effects that each aspect may achieve, please refer to the technical effects that can be achieved for the first aspect or various possible solutions in the first aspect described above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0045] Figure 1 is a flowchart of a model training method provided by the present application;
[0046] Figure 2 is a schematic structural diagram of an application system provided by the present application;
[0047] Figure 3 is a flowchart of calculating the loss value of each sample to be measured provided by the present application;
[0048] Figure 4 is a schematic structural diagram of a model training device provided by the present application;
[0049] Figure 5 is a schematic structural diagram of an electronic device provided by the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0050] In order to make the objectives, technical solutions, and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings. The specific operation methods in the method embodiments can also be applied to the device embodiments or system embodiments. It should be noted that in the description of the present application, "a plurality" is understood as "at least two". "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone. The connection between A and B may represent: A is directly connected to B and A is connected to B through C. In addition, in the description of the present application, terms such as "first" and "second" are only used for the purpose of distinguishing descriptions, and cannot be understood as indicating or implying relative importance, nor can they be understood as indicating or implying order.
[0051] The embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0052] In the context of the rapid development of current digital technologies, federated learning technology has emerged. In this technology, multiple edge devices are allowed to collaborate in training a shared machine learning model without exchanging the data they hold, which greatly enhances data privacy protection. However, this distributed and decentralized training method introduces new security challenges, especially the risk of backdoor attacks.
[0053] Currently, some defense strategies against backdoor attacks are also provided, but these strategies are for data detection and model detection, which require a large amount of computing resources, and edge devices cannot meet these computing resource requirements, resulting in low operating efficiency of the strategies.
[0054] To solve the above technical problems, the embodiments of the present application provide a model training method. In this method, first, N samples to be tested are obtained, and then the loss value of each sample to be tested is calculated. Among all the calculated loss values, the target loss values greater than the threshold are selected, and the samples to be tested corresponding to the target loss values are used as backdoor samples. All the selected backdoor samples are used as a training set to train the candidate model, thereby obtaining the target model. In this way, a model that can accurately identify backdoor samples can be trained, so that the edge device itself can detect backdoor samples through this target model, which not only reduces the demand for central computing resources but also improves the detection efficiency of backdoor samples.
[0055] Refer to Figure 1 The following is a flowchart of a model training method provided by the embodiments of the present application. First, this method is applied to Figure 2 the system shown in Figure 2 In this system, it includes a cloud server and multiple edge devices. Each edge device is connected to the cloud server, and the cloud server can directly or indirectly transmit data to and from the edge devices. This method is specifically applied to the edge devices in this system. Through this method, the problems of low defense efficiency, high false alarm rate, and poor adaptability to new attacks in the current federated learning environment can be solved. The method includes:
[0056] S1, Obtain N samples to be tested and calculate the loss value of each sample to be tested;
[0057] Specifically, if a specific trigger is implanted in a sample, when using the sample implanted with the trigger for training, these samples will exhibit learning characteristics different from normal samples, especially in terms of the performance of the loss value. Therefore, after obtaining the samples to be tested, the loss values of these samples to be tested are first calculated. Refer to Figure 3 As shown in the embodiments of the present application, the loss value of each of the N samples to be tested is calculated according to the following method:
[0058] S31. Obtain the sample data, label, and model parameters of the sample to be tested;
[0059] Specifically, the sample data of the sample to be tested is information such as attribute information and attribute values in the sample to be tested. Of course, in addition to this information, other information may also be included in the sample data. It is not limited in the embodiments of the present application.
[0060] In addition to obtaining the above sample data, it is also necessary to obtain the label of the sample to be tested. The label is the unique identifier of the sample to be tested, and the sample to be tested can be directly determined through the label.
[0061] Then further obtain the model parameters. The model parameters are the training parameters of the initial model when training the sample to be tested. That is to say, each sample to be tested corresponds to a model parameter when being trained in the initial model. The model parameters corresponding to different samples to be tested can be the same or different.
[0062] S32. Import the sample data, label, and model parameters into the first loss function to obtain the loss value corresponding to the sample to be tested;
[0063] In step S31, the respective parameter values of the sample to be tested can be accurately obtained, and then the parameter values are brought into the following loss function for calculation:
[0064] L(x, y; θ) = -log(p(y|x; θ))
[0065] In this loss function, L(x, y; θ) represents the loss value, x is the sample data, y is the label, θ is the model parameter, and p(y|x; θ) is the probability that the model predicts the label y given the input x.
[0066] The loss value corresponding to the sample to be tested can be calculated through the above formula.
[0067] The loss value corresponding to each of the N samples to be tested can be calculated through the above method. Due to the differences in the samples to be tested, the loss values are also different.
[0068] S2. Screen out the target loss values greater than the threshold from all the loss values, and use the samples to be tested corresponding to the target loss values as backdoor samples;
[0069] Since there are significant differences in the loss values between normal samples and backdoor samples, after calculating the loss value of each sample to be tested, the loss value is compared with the threshold. If the loss value is greater than the threshold, the sample to be tested is used as a backdoor sample. Of course, if the loss value is less than the threshold, the sample is used as a normal sample. Normal samples are classified into the normal sample set, and backdoor samples are classified into the backdoor sample set.
[0070] In the embodiments of the present application, in order to more accurately identify normal samples and backdoor samples, the loss value of each sample to be tested can be further calculated.
[0071] First, obtain the first expected loss of the normal sample set and the second expected loss of the backdoor sample set. The first expected loss can be calculated based on the loss values of each normal sample in the normal sample set, and the second expected loss can be calculated based on the loss values of each backdoor sample in the backdoor sample set.
[0072] After obtaining the first expected loss and the second expected loss, input the loss value of the sample to be tested, the first expected loss, and the second expected loss into the second loss function to obtain a new loss value. In the embodiments of the present application, the new loss value can be calculated by the following formula:
[0073]
[0074] where represents the expected loss calculated on the clean data set, and represents the expected loss calculated on the backdoor data set.
[0075] Through the above method, the loss values corresponding to normal samples and backdoor samples can be calculated more accurately, so that the difference in loss values between normal samples and backdoor samples is greater.
[0076] After calculating the new loss value, screen out the target loss values greater than the threshold among all the new loss values. In this way, the backdoor samples can be more accurately determined among all the samples to be tested.
[0077] S3. Use all the screened backdoor samples as the training set to train the candidate model to obtain the target model.
[0078] In step S2, all backdoor samples are accurately screened out. At this time, all backdoor samples can be formed into a backdoor sample set, and this backdoor sample set is used as the training set. Then, use this training set to train the candidate model, so that a target model that can accurately identify backdoor samples can be selected.
[0079] In the embodiments of the present application, in order to enable the model to more accurately identify backdoor samples, the parameters of the initial model can also be adjusted first, so as to obtain the candidate model.
[0080] Specifically, in the embodiments of the present application, the first feature parameter and the second feature parameter of the initial model are obtained. The first feature parameter and the second feature parameter are the features of two consecutive layers in the initial model. That is to say, the initial model is a model composed of multiple layers of networks. Therefore, the feature parameters of two consecutive layers can be obtained, and then the first feature parameter, the second feature parameter, and the loss term weight are input into the model evaluation function to obtain the model evaluation result. Then, the loss term weight is adjusted according to the model evaluation result to obtain the candidate model.
[0081] In the embodiments of the present application, the loss values of two consecutive layers can be calculated first through the following loss function:
[0082]
[0083] where, Ψ(A m ) and Ψ(A m+1 ) are the feature representations obtained after processing two consecutive layers A m and A m+1 respectively.
[0084] After obtaining the loss values of the above two consecutive layers, the model evaluation result is further calculated. The model evaluation result can be calculated through the following formula:
[0085]
[0086] where, is the standard cross-entropy loss, which is used to evaluate the classification performance of the model. is the binary cross-entropy loss, which evaluates the prediction accuracy of the model for the existence of categories. β and δ are hyperparameters for adjusting the weights of each loss term.
[0087] It should be noted here that β is the existence loss weight, and this parameter determines the influence degree of the category existence judgment on the model training. δ is the distillation loss weight, and this parameter is used to control the contribution ratio of the distillation mechanism in the total loss.
[0088] In the embodiments of the present application, the parameter adjustment of the model is specifically as follows:
[0089] 1. Priority is given to the accuracy of the main task
[0090] Under this strategy, β is increased and δ is decreased. Through this strategy, the existence judgment ability of the main task can be ensured, and the accuracy of the classification result can be enhanced; and the interference of the distillation process on the optimization of the main task of the model can be reduced.
[0091] 2. Priority is given to security
[0092] Under this strategy, δ is increased and β is decreased. Through this strategy, the model pays more attention to the ability to resist backdoor attacks; and the influence of the category existence on the overall loss is reduced.
[0093] Of course, in addition to the above strategies in the embodiments of the present application, it can also be adjusted to other strategies, which can be adjusted according to the actual application scenario and are not limited here.
[0094] After the model parameters of the initial model are adjusted through the above method, the above-mentioned candidate model is obtained. Then, the candidate model is trained with the selected backdoor sample set to obtain the final target model. After obtaining the target model, the edge device can identify the sample to be tested through the target model, so as to accurately determine whether the sample to be tested is a backdoor sample, so that the edge device itself can detect the backdoor sample through the target model, which not only reduces the demand for central computing resources, but also improves the detection efficiency of the backdoor sample.
[0095] Furthermore, in the embodiments of the present application, after the edge device obtains the target model, the edge device will report the model parameters of the target model to the cloud server. The cloud server will collect the model parameters reported by each edge device, and then the cloud server will aggregate the model parameters uploaded by each edge device by applying the federated averaging algorithm. This algorithm calculates the weighted average of all the uploaded model parameters to obtain the global model parameters. The specific calculation formula is as follows:
[0096]
[0097] Where, W t represents the weight of the current global model, is the model parameter of the i-th edge device in the t+1 round, η is the learning rate, and N is the total number of edge devices participating in the update.
[0098] After calculating the global model parameters, the cloud server will send the global model parameters to each edge device, and each edge device will update its own target model according to the global model parameters. Through this method, the global model parameters can be calculated based on the target models of each edge device, thus ensuring the consistency and accuracy of the target models in the edge devices.
[0099] In the embodiments of the present application, in order to ensure the accuracy of the model parameter update, each edge device will calculate the cosine similarity value between the update vector and the global update vector (i.e., the global model parameters) after obtaining the global update vector sent by the cloud server. In the embodiments of the present application, the cosine similarity value can be calculated through the following formula:
[0100]
[0101] Where, u and v represent the local update vector and the global update vector respectively.
[0102] If the cosine similarity value is less than the threshold, it indicates that there is a large difference between the global update vector and the local update vector. The global update vector is an abnormal update deviating from the normal range, so the global update vector is directly discarded.
[0103] If the cosine similarity value is greater than the threshold, the model parameters in its own target model are updated according to the global update vector.
[0104] Through the above method, the accuracy of the global model parameters sent by the cloud server can be detected, thus ensuring the accuracy of the model parameter update of the edge device.
[0105] Furthermore, in terms of robustness, in the case of no defense, the robustness of the target model of the edge device is relatively low, only 4.5, which indicates that the target model is extremely vulnerable to damage when facing attacks.
[0106] In the case of edge defense, by implementing defense measures on the edge device, the robustness of the target model of the edge device is increased to 0.65, which shows that edge defense can enhance the anti - attack ability of the model to a certain extent.
[0107] In the case of hierarchical defense, after adopting the hierarchical defense strategy, the robustness of the target model of the edge device is further increased to 0.85, showing the best defense effect. This strategy significantly enhances the security and stability of the model through multiple protection measures.
[0108] Through the above - mentioned hierarchical defense framework, efficient and robust backdoor defense is achieved, thus significantly improving the accuracy and efficiency of defense and enhancing the system adaptability.
[0109] Based on the same inventive concept, an embodiment of the present application also provides a model training device. Refer to Figure 4 The following is a schematic structural diagram of a model training device provided by an embodiment of the present application. The device includes:
[0110] An acquisition module 401, configured to acquire N samples to be tested and calculate the loss value of each sample to be tested, where N is an integer greater than or equal to 1;
[0111] A processing module 402, configured to screen out target loss values greater than the threshold from all loss values, and use the samples to be tested corresponding to the target loss values as backdoor samples; train a candidate model with all the screened - out backdoor samples as a training set to obtain a target model.
[0112] In an optional embodiment, the acquisition module 401 is specifically configured to acquire the sample data, label, and model parameters of the sample to be tested, where the label is used to identify the sample to be tested;
[0113] Import the sample data, the labels, and the model parameters into the first loss function to obtain the loss value corresponding to the sample to be tested.
[0114] In an alternative embodiment, the processing module 402 is specifically configured to divide the N samples to be tested into a normal sample set and a backdoor sample set based on the loss value of each sample to be tested;
[0115] Obtain the first expected loss of the normal sample set and the second expected loss of the backdoor sample set;
[0116] Input the loss value of the sample to be tested, the first expected loss, and the second expected loss into the second loss function to obtain a new loss value;
[0117] Select the target loss values greater than the threshold from all the new loss values.
[0118] Based on the same inventive concept, an electronic device is further provided in an embodiment of the present application. The electronic device can implement the functions of the foregoing model training device. Refer to Figure 5 , the electronic device includes:
[0119] At least one processor 501 and a memory 502 connected to the at least one processor 501. In the embodiment of the present application, the specific connection medium between the processor 501 and the memory 502 is not limited. Figure 5 In Figure 5 it is taken as an example that the processor 501 and the memory 502 are connected through a bus 500. The bus 500 is represented by a thick line in Figure 5 For the connection manners between other components, only schematic illustrations are provided and are not to be taken as limitations. The bus 500 can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation,
[0120] In the embodiment of the present application, the memory 502 stores instructions executable by the at least one processor 501. By executing the instructions stored in the memory 502, the at least one processor 501 can execute a model training method described above. The processor 501 can implement Figure 4 the functions of each module in the device shown in
[0121] Among them, the processor 501 is the control center of the device, and can connect various parts of the entire control device through various interfaces and lines. By running or executing the instructions stored in the memory 502 and calling the data stored in the memory 502, various functions of the device and process data, so as to monitor the device as a whole.
[0122] In a possible design, the processor 501 may include one or more processing units. The processor 501 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communications. It can be understood that the above-mentioned modem processor may not be integrated into the processor 501. In some embodiments, the processor 501 and the memory 502 may be implemented on the same chip, and in some embodiments, they may also be separately implemented on independent chips.
[0123] The processor 501 may be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application-specific integrated circuit, a field-programmable gate array, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, and can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of a model training method disclosed in combination with the embodiments of the present application may be directly embodied as being executed by a hardware processor, or executed by a combination of hardware and software modules in the processor.
[0124] As a non-volatile computer-readable storage medium, the memory 502 can be used to store non-volatile software programs, non-volatile computer-executable programs, and modules. The memory 502 may include at least one type of storage medium. For example, it may include flash memory, hard disk, multimedia card, card-type memory, random access memory (RAM), static random access memory (SRAM), programmable read-only memory (PROM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), magnetic memory, magnetic disk, optical disc, etc. The memory 502 is any other medium that can be used to carry or store desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory 502 in the embodiments of the present application may also be a circuit or any other device capable of implementing a storage function, for storing program instructions and / or data.
[0125] By programming the design of the processor 501, the code corresponding to the model training method introduced in the foregoing embodiments can be solidified into the chip, so that the chip can execute the steps of the model training method of the embodiment shown in FIG. 1 when running. How to program the design of the processor 501 is a well-known technology to those skilled in the art and will not be elaborated here.
[0126] Based on the same inventive concept, an embodiment of the present application further provides a storage medium storing computer instructions, which when run on a computer, cause the computer to execute a model training method described above.
[0127] In some possible implementation manners, each aspect of the model training method provided by the present application can also be implemented in the form of a program product, which includes program code. When the program product runs on a device, the program code is used to cause the control device to execute the steps in the model training method according to various exemplary embodiments of the present application described above in this specification.
[0128] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0129] The present application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in Figure 1 one or more flows and / or blocks Figure 1 one or more blocks.
[0130] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device realizes the functions specified in Figure 1 one or more flows and / or blocks Figure 1The functions specified in one or more boxes.
[0131] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable device provide for implementing in the process Figure 1 One process or more processes and / or boxes Figure 1 The steps of the functions specified in one box or more boxes.
[0132] Obviously, those skilled in the art can make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalent technologies, this application is also intended to include these changes and modifications.
Claims
1. A model training method, characterized in that: The method comprises: Obtain N samples to be tested, and calculate the loss value of each of the samples to be tested, where N is an integer greater than or equal to 1; Filter out the target loss value greater than the threshold from all loss values, and use the sample to be tested corresponding to the target loss value as the backdoor sample; All the backdoor samples that have been screened out are used as training sets to train the candidate model and obtain the target model.
2. The method according to claim 1, characterized in that The step of obtaining N samples to be tested and calculating the loss value of each sample to be tested includes: For each of the N samples to be tested, perform the following operations: Obtaining sample data, labels, and model parameters of the sample to be tested, wherein the label is used to identify the sample to be tested; The sample data, the label and the model parameters are introduced into a first loss function to obtain a loss value corresponding to the sample to be tested.
3. The method according to claim 2, characterized in that Filter out target loss values greater than the threshold from all loss values, including: Based on the loss value of each of the samples to be tested, the N samples to be tested are divided into a normal sample set and a backdoor sample set; Obtaining a first expected loss of the normal sample set and a second expected loss of the backdoor sample set; Inputting the loss value of the sample to be tested, the first expected loss, and the second expected loss into a second loss function to obtain a new loss value; Filter out target loss values greater than the threshold among all new loss values.
4. The method according to claim 1, characterized in that All the backdoor samples that have been screened out are used as training sets to train the candidate model, including: Acquire a first characteristic parameter and a second characteristic parameter in the initial model, wherein the first characteristic parameter and the second characteristic parameter are characteristics of two consecutive layers in the initial model; Inputting the first feature parameter, the second feature parameter, and the loss term weight into a model evaluation function to obtain a model evaluation result; Adjust the weight of the loss term according to the model evaluation result to obtain the candidate model; All the backdoor samples screened out are used as training sets to train the candidate model.
5. The method according to claim 1, characterized in that After the candidate model is trained by using all the screened backdoor samples as a training set to obtain a target model, the method further includes: Get the global update vector sent by the server; Calculate the cosine similarity value between the current update vector and the global update vector; If the cosine similarity value is less than a threshold, discarding the global update vector; If the cosine similarity value is greater than a threshold, the model parameters in the target model are updated according to the global update vector.
6. A model training device, characterized in that: The device comprises: An acquisition module, used to acquire N samples to be tested and calculate the loss value of each sample to be tested, where N is an integer greater than or equal to 1; The processing module is used to screen out the target loss value greater than the threshold from all loss values, and use the sample to be tested corresponding to the target loss value as the backdoor sample; train the candidate model by using all the screened backdoor samples as the training set to obtain the target model.
7. The device according to claim 6, characterized in that The acquisition module is specifically used to acquire sample data, labels and model parameters of the sample to be tested, wherein the label is used to identify the sample to be tested; The sample data, the label and the model parameters are introduced into a first loss function to obtain a loss value corresponding to the sample to be tested.
8. The device according to claim 6, characterized in that The processing module is specifically used to divide the N samples to be tested into a normal sample set and a backdoor sample set based on the loss value of each sample to be tested; Obtaining a first expected loss of the normal sample set and a second expected loss of the backdoor sample set; Inputting the loss value of the sample to be tested, the first expected loss, and the second expected loss into a second loss function to obtain a new loss value; Filter out target loss values greater than the threshold among all new loss values.
9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to implement the method steps of any one of claims 1 to 5 when executing the computer program stored in the memory.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps described in any one of claims 1 to 5 are implemented.