XGBoost model backdoor detection method and system based on local model and ensemble learning
By adopting local model and integrated learning methods in the XGBoost model, the problem of poor backdoor detection in the existing technology is solved, and more efficient and reliable backdoor attack detection is achieved, improving the security and stability of the model.
Patent Information
- Application Number
- CN202510205219.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-06-27
AI Technical Summary
The existing XGBoost model backdoor detection method is not effective in the face of complex attack strategies, and is prone to false positives or missed reports in high-dimensional data and complex models.
Using a local model and ensemble learning method, multiple independent XGBoost models are trained by preprocessing and clustering the original data, each model focusing on a subset of data. Then, anomaly detection algorithm is used to identify the abnormal pattern, and the prediction results of each local model are integrated through an integrated learning method to generate backdoor detection results.
The XGBoost model detects backdoor attacks is improved, the robustness and reliability of detection is enhanced, false alarms and missed alarms are reduced, and the security and stability of the model in practical applications is improved.
Smart Images

Figure CN120217359A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of machine learning security, and specifically relates to an XGBoost model backdoor detection method and system based on local models and ensemble learning. Background Art
[0002] With the rapid development of machine learning and artificial intelligence technologies, the application of these technologies in various key fields such as finance, healthcare, and autonomous driving has become increasingly in-depth. Therefore, the security and robustness of models have become the focus of common concern in academia and industry. The reliability of models is directly related to economic security, personal health, and life safety, posing higher requirements for the security of models in these fields. As an efficient and powerful gradient boosting tree (GBT) algorithm, XGBoost (eXtreme Gradient Boosting) has been widely used in fields such as financial risk control, credit scoring, and predictive maintenance due to its excellent prediction performance, ability to handle missing values, and support for parallel computing. [1] In the field of financial risk control, the XGBoost model can accurately identify potential default customers, helping financial institutions reduce credit risks; in a credit scoring system, it provides reliable credit scores by analyzing customers' historical data to support credit decisions; in the field of predictive maintenance, it can predict equipment failures to avoid production interruptions and equipment damage. [2] However, with the widespread application of the XGBoost model, its potential security risks have gradually emerged, especially the backdoor attack problem, which has attracted extensive attention from researchers and industry experts.
[0003] Backdoor attack is a concealed and dangerous attack method. Attackers implant backdoors during the model training process, causing the model to exhibit abnormal behaviors under specific conditions, thereby achieving control over the model. This kind of attack not only destroys the prediction accuracy of the model but may also lead to the leakage of sensitive information, and even cause serious consequences in security-sensitive fields such as autonomous driving. Therefore, the research on backdoor attack detection and defense technologies for the XGBoost model is of great significance for ensuring model security, safeguarding user interests, and social stability. [3]
[0004] Currently, the backdoor detection methods for the XGBoost model mainly focus on four aspects: model review and verification, input data detection, behavior analysis, and model output consistency check. Model review and verification aim to identify abnormal weight distributions or unreasonable decision paths by deeply analyzing the structure and parameters of the model. For example, Shafahi et al. proposed a method for detecting backdoors by examining the model weights and structure. [4] Input data detection focuses on analyzing the feature patterns in the input data to identify specific situations that may trigger backdoor behaviors. Wang et al. developed a method for detecting backdoors by analyzing the patterns of input features [5] Behavior analysis discovers abnormal reactions by monitoring the output behaviors of the model under different input conditions. Huang et al. proposed a backdoor detection technique based on the analysis of model output behaviors [6] Finally, model output consistency checking detects whether there are inconsistent output differences by comparing the model's performance on different datasets. Liu et al. used this method to identify backdoors in the model [7] Chen et al. further developed this field and proposed a comprehensive backdoor detection strategy that combines multiple output analysis techniques to enhance the comprehensiveness and accuracy of detection [8] .
[0005] Although existing detection methods can reveal backdoors in the model to a certain extent, they still expose some limitations when dealing with complex attack strategies. These methods often rely on the detection of known attack patterns, so their effectiveness may be greatly reduced when facing unknown or novel attack methods. At the same time, there is still room for improvement in the detection accuracy of existing technologies, especially when dealing with high-dimensional data and complex models, false positives or false negatives are likely to occur. For example, Tran et al. [9] pointed out that traditional detection methods often struggle to maintain high accuracy in high-dimensional data scenarios. In addition, some detection methods require a large amount of computing resources, which will lead to a significant increase in detection costs when dealing with large-scale datasets and complex models (Chen et al.
[10] ) discussed the impact of computing resource limitations on backdoor detection performance and proposed improvement schemes.
[0006] With the development of technology, backdoor detection methods have been continuously improved. For example, detection methods based on deep learning have improved detection accuracy and efficiency by learning the internal representations and behavior patterns of the model. Carlini and Wagner
[11] demonstrated how to effectively improve the detection ability for complex attacks using deep learning methods. Comprehensive detection techniques that combine multiple detection methods improve the robustness and reliability of detection through multi-angle analysis. In the future, with the increase in model complexity and the continuous evolution of attack methods, backdoor detection technologies will face more challenges. Through interdisciplinary research, such as combining emerging technologies like graph neural networks, adversarial learning, and reinforcement learning, it is expected to further improve the effectiveness and efficiency of backdoor detection and ensure the security and reliability of machine learning models.
[0007] In the prior art, although the XGBoost model performs excellently in various prediction tasks, its ability to detect complex backdoor attacks still has limitations, and these limitations may cause the model to be manipulated under specific conditions, thereby affecting the accuracy and security of decision-making.
[0008] [1] CHEN T, GUESTRIN C. Xgboost: A scalable tree boosting system;proceedings of the Proceedings of the 22nd acm sigkdd internationalconference on knowledge discovery and data mining, F, 2016[C].
[0009] [2] NATEKIN A, KNOLL A. Gradient boosting machines, a tutorial[J]. Frontiers in neurorobotics, 2013, 7:21.
[0010] [3] GAO Y, XU C, WANG D, et al. Strip: A defence against trojan attacks ondeep neural networks;proceedings of the Proceedings of the 35th annualcomputer security applications conference, F, 2019[C].
[0011] [4] SHAFAHI A H, W.;NAJIBI, M.;CAMBRIA, E.;DAVIS, L.S. Detecting Backdoorsin Deep Neural Networks[J]. arXiv preprint arXiv:180505801, 2018.
[0012] [5]WANG B, YAO Y, SHAN S, et al. Neural cleanse: Identifying and mitigating backdoor attacks in neural networks; proceedings of the 2019 IEEE symposium on security and privacy (SP), F, 2019[C]. IEEE.
[0013] [6]LI Y, JIANG Y, LI Z, et al. Backdoor learning: A survey[J]. IEEE Transactions on Neural Networks and Learning Systems, 2022, 35(1): 5 - 22.
[0014] [7]LIU Y, MA S, AAFER Y, et al. Trojaning attack on neural networks[J]. 2017.
[0015] [8]CHEN P - Y, ZHANG H, SHARMA Y, et al. Zoo: Zeroth order optimization - based black - box attacks to deep neural networks without training substitute models; proceedings of the Proceedings of the 10th ACM workshop on artificial intelligence and security, F, 2017[C].
[0016] [9]TRAN B, LI J, MADRY A. Spectral signatures in backdoor attacks[J]. Advances in neural information processing systems, 2018, 31.
[0017]
[10] CHEN J,WU X,RASTOGI V,et al.Towards understanding limitations ofpixel discretization against adversarial attacks;proceedings of the 2019IEEEEuropean Symposium on Security and Privacy(EuroS&P),F,2019[C].IEEE.
[0018]
[11] CARLINI N,WAGNER D.Towards evaluating the robustness of neuralnetworks;proceedings of the 2017ieee symposium on security and privacy(sp),F,2017[C].Ieee. Summary of the Invention
[0019] The present invention is made to solve the above problems, and aims to provide an XGBoost model backdoor detection method and system based on local models and ensemble learning.
[0020] The present invention provides an XGBoost model backdoor detection method based on local models and ensemble learning, which has the following characteristics and is applied to machine learning models that require high robustness and security, including the following steps: S10, preprocessing and clustering the original data in a given original dataset to obtain several subsets S i ; S20, training independent XGBoost models on each subset S i to obtain corresponding local models M i ; S30, using the local models M i to predict their corresponding subsets S i to obtain several prediction results P i ; S40, applying an anomaly detection algorithm to each prediction result P i to identify the corresponding anomaly patterns AP i ; S50, using an ensemble learning method to construct a meta-model M meta , integrating the prediction results P i of each local model M i to generate a backdoor detection result P meta ; S60, comparing the backdoor detection result P meta with the anomaly patterns AP iPerform analysis and comparison to ensure the existence of backdoors in the subset; S70, the abnormal pattern AP i After summarizing the comparative analysis results of i , generate a backdoor detection report, thereby finally realizing backdoor detection.
[0021] In the XGBoost model backdoor detection method based on local models and ensemble learning provided by the present invention, it may also have the following features: Among them, in step S10, the preprocessing includes removing outliers, filling in missing values, and data standardization, and the clustering method includes using the K-means clustering algorithm.
[0022] In the XGBoost model backdoor detection method based on local models and ensemble learning provided by the present invention, it may also have the following features: Among them, in step S20, during the training process of the XGBoost model corresponding to each local model M i Cross-validation is used to optimize the model parameters. During the training of the XGBoost model corresponding to each local model M i The objective function for training the corresponding XGBoost model is: And L is the loss function, l is the loss term, y i is the true label value, is the predicted label value, i is the sample index, n epsilon is the number of training samples after partitioning the subset S i Ω is the regularization term, θ is the model parameter, the regularization term Ω is used to control the complexity of the model and prevent overfitting, T is the number of decision trees in the XGBoost model, γ is the tree complexity weight, λ is the regularization parameter, is the leaf node weight of the tree, and j represents the jth decision tree.
[0023] In the XGBoost model backdoor detection method based on local models and ensemble learning provided by the present invention, it may also have the following features: Among them, by minimizing the objective function L(θ), the XGBoost model obtains the best fit on the training data, and the complexity of the XGBoost model is controlled by the regularization term Ω to improve its generalization ability on new data.
[0024] In the XGBoost model backdoor detection method based on local models and ensemble learning provided by the present invention, it may also have the following features: Among them, in step S40, the anomaly detection algorithm includes the Isolation Forest algorithm.
[0025] In the XGBoost model backdoor detection method based on local models and ensemble learning provided by the present invention, it may also have the following features: Among them, in step S50, the ensemble learning method includes the voting mechanism method, the weighted average method, or the stacking method.
[0026] In the XGBoost model backdoor detection method based on local models and ensemble learning provided by the present invention, it may further have the following features: Among them, step S50 includes the following sub-steps: S51, using the ensemble learning method to comprehensively analyze the prediction results P i to generate a comprehensive model; S52, using the prediction results P i as the input of the comprehensive model to generate a training dataset T meta ; S53, using the training dataset T meta to train the comprehensive model, and denoting the trained model as the meta-model M meta ; S54, using the meta-model M meta to analyze the prediction results P i to generate a backdoor detection result P meta .
[0027] In the XGBoost model backdoor detection method based on local models and ensemble learning provided by the present invention, it may further have the following features: Among them, the machine learning models that require high robustness and security are machine learning models applicable to fields including finance or healthcare.
[0028] The present invention also provides an XGBoost model backdoor detection system based on local models and ensemble learning, which has the following features. It uses the XGBoost model backdoor detection method of any one of the foregoing, and includes: a model training unit, which is used to preprocess and cluster the original data in a given original dataset, and then train a number of independent XGBoost models to obtain corresponding local models M i ; a prediction unit, connected to the model training unit, which is used to use the local models M i to predict its corresponding subset S i to obtain a number of prediction results P i ; a first detection unit, connected to the prediction unit, which is used to apply an anomaly detection algorithm to each prediction result P i to identify the corresponding anomaly pattern AP i ; a second detection unit, connected to the prediction unit, which is used to construct a meta-model M meta using the ensemble learning method, and integrate the prediction results P i of each local model M i to generate a backdoor detection result P meta ; and an anomaly result comparison and report generation unit, connected to the first detection unit and the second detection unit, which is used to analyze and compare the backdoor detection result P meta with the anomaly pattern AP i to ensure that there is a backdoor in the subset, and then the anomaly pattern AP iThe comparative analysis results are summarized to generate a backdoor detection report, thereby ultimately achieving backdoor detection.
[0029] Functions and Effects of the Invention
[0030] According to a method and system for detecting backdoors of an XGBoost model based on a local model and integrated learning provided by the present invention, the detection method comprises the following steps: first, preprocessing and cleaning the original data, and then using a clustering algorithm (such as K-means) to divide the data into multiple subsets. Train an independent XGBoost model on each data subset to generate a local model. Each local model predicts its corresponding data subset and generates a prediction result. Next, apply an anomaly detection algorithm (such as Isolation Forest) to the prediction result of each local model to identify abnormal patterns. Then, use an integrated learning method (such as voting mechanism, weighted average, stacking, etc.) to comprehensively analyze the abnormal patterns of each local model and generate a comprehensive model. The prediction results of each local model are compared and analyzed by the comprehensive model to confirm the final abnormal output. Finally, the comparative analysis results of all abnormal patterns are summarized to generate a final backdoor detection report. The report contains detailed analysis results of each abnormal pattern, potential backdoor attacks and recommended defense measures.
[0031] Therefore, the XGBoost model backdoor detection method and system based on local model and ensemble learning of the present invention have the following beneficial effects:
[0032] (1) The present invention trains multiple local XGBoost models on the original data to target different data subsets to enhance the model's ability to identify abnormal behaviors. Each local model focuses on a specific slice of the data, enabling it to learn and identify potential abnormal patterns in that subset more deeply, thereby effectively improving the overall model's detection efficiency and accuracy for backdoor attacks.
[0033] (2) The present invention uses the output of local models for ensemble learning, and identifies abnormal model outputs by comparing the prediction results of different local models. This approach can further enhance the reliability of detection. Through this local model integration strategy, the present invention can generate identically distributed data sets with original data features under arbitrary feature conditions. These data sets can be used to further train and strengthen the main XGBoost model, overcoming the training difficulties caused by too few data samples and unavailable sensitive data.
[0034] (3) The present invention can effectively improve the security and stability of the XGBoost model in practical applications, especially in areas with high data sensitivity or security requirements, such as financial services and personal privacy protection, and provides a new solution for the secure training and application of machine learning models. Description of the Drawings
[0035] Figure 1 is a flowchart of a method for detecting backdoors in an XGBoost model based on local models and ensemble learning in an embodiment of the present invention;
[0036] Figure 2 is an architecture diagram of a method for detecting backdoors in an XGBoost model based on local models and ensemble learning in an embodiment of the present invention. Detailed Embodiments
[0037] In order to make the technical means, creative features, achieved purposes, and effects of the present invention easy to understand, the following embodiments will specifically elaborate on a method and system for detecting backdoors in an XGBoost model based on local models and ensemble learning of the present invention in conjunction with the accompanying drawings.
[0038] <Embodiment>
[0039] Figure 1 is a flowchart of a method for detecting backdoors in an XGBoost model based on local models and ensemble learning in an embodiment of the present invention; Figure 2 is an architecture diagram of a method for detecting backdoors in an XGBoost model based on local models and ensemble learning in an embodiment of the present invention.
[0040] As Figure 1 and Figure 2 shown, this embodiment provides a method for detecting backdoors in an XGBoost model based on local models and ensemble learning, which is applied to machine learning models (including the financial or medical fields) that require high robustness and security, and includes the following steps:
[0041] S10. After preprocessing and clustering the original data in the given original dataset, several subsets S i are obtained, including the following sub-steps S11 to S15:
[0042] S11. Given a dataset consisting of n data with m features.
[0043] S12. Use a statistics-based method to remove outliers. In this embodiment, the standard deviation method is specifically used, and the data outside a certain range (such as the mean plus or minus three standard deviations) is regarded as an outlier and removed:
[0044] x i ∈[μ - 3σ, μ + 3σ]
[0045] where x i represents the i-th sample of the data, μ is the mean of the data, and σ is the standard deviation of the data.
[0046] S13. Fill in the missing values using the mean imputation method or the interpolation method.
[0047] Among them, the mean imputation method replaces the missing value with the mean of this feature, while the interpolation method fills in the missing value according to the trend of adjacent data.
[0048] S14. Transform the data of different features to the same dimension to achieve data standardization. In this embodiment, the Z-score standardization is specifically adopted:
[0049]
[0050] Among them, is the standardized data, x i is the original data, μ is the mean, and σ is the standard deviation.
[0051] Through the preprocessing of the above steps S12 to S14, the quality and consistency of the data are ensured. The main goal of the preprocessing is to make the data more suitable for the subsequent machine learning model training and improve the performance and stability of the model.
[0052] S15. Cluster the data preprocessed in steps S12 to S14. In this embodiment, the K-means clustering algorithm is used to divide the preprocessed data set into k subsets S i , which specifically includes the following sub-steps S15-1 to S15-4:
[0053] S15-1. Randomly select k initial cluster centers.
[0054] S15-2. Calculate the distance from each data point to each cluster center and assign the data point to the nearest cluster.
[0055] S15-3. Update the center of each cluster to the mean of all data points within the cluster.
[0056] S15-4. Repeat steps S15-2 and S15-3 until the cluster centers no longer change or reach the maximum number of iterations.
[0057] Through steps S15-1 to S15-4, k subsets S i are obtained, and each subset S i contains a certain number of data samples for subsequent local model training:
[0058] S i ={x∣x∈data,cluster(x)=i},i = 1,2,…,k
[0059] Among them, cluster(x) represents the clustering assignment of the data sample x. Each subset S iContains data samples belonging to the $i$-th cluster.
[0060] S20. For each subset $S$ i Train an independent XGBoost model to obtain a corresponding number of local models $M$ i :
[0061] $M$ i = XGBoost($S$ i ), $i = 1, 2, \ldots, k$
[0062] The XGBoost model is a decision-tree-based gradient boosting algorithm, which is efficient, accurate, and robust, and is suitable for processing large-scale datasets and complex feature engineering. During the training process, cross-validation is used to optimize the model parameters to improve the prediction performance of the model. Cross-validation is a commonly used model validation method that divides the dataset into multiple subsets, trains and validates on different subsets, thereby evaluating the performance of the model and selecting the best parameters.
[0063] During the cross-validation process, the dataset $S$ i is divided into a training set and a validation set. By training the model on the training set and evaluating the performance of the model on the validation set, the parameter combination that can minimize the prediction error on the validation set is selected. The specific steps are as follows:
[0064] S20-1. Divide the dataset $S$ i into $k$ subsets.
[0065] S20-2. Successively use each subset as the validation set and the other subsets as the training set for model training and validation.
[0066] S20-3. Calculate the prediction error for each validation and take the average as the performance metric of the model.
[0067] S20-4. Select the parameter combination that minimizes the average prediction error.
[0068] The objective function for model training is:
[0069]
[0070] where $L$ is the loss function, $l$ is the loss term, $y$ i is the true label value, is the predicted label value, $i$ is the sample index, $n$ epsilon is the subset $S$ iThe number of training samples after partitioning, Ω is the regularization term, θ is the model parameter, and the regularization term Ω is used to control the complexity of the model and prevent overfitting. By minimizing the objective function L(θ), the XGBoost model can obtain the best fit on the training data.
[0071] T is the number of decision trees in the XGBoost model, γ is the complexity weight of the tree, λ is the regularization parameter, is the leaf node weight of the tree, j represents the j-th decision tree, and the complexity of the XGBoost model is controlled by the regularization term Ω to improve its generalization ability on new data.
[0072] By training the local model M through the above step S20 i , independent XGBoost models can be trained on each data subset S i to generate local models M with high prediction performance i , providing a basis for subsequent local model prediction and abnormal pattern recognition.
[0073] S30. Use the local model M i to predict its corresponding subset S i to obtain a number of prediction results P i .
[0074] After the XGBoost model is trained, it can predict the input data to generate predicted values, and these predicted values represent the prediction results of the model for the input data.
[0075] The prediction process is as follows: For each data sample x in each data subset S i , use the corresponding local model M i to make a prediction to obtain the prediction result P i :
[0076] P i = M i (S i ), i = 1, 2, …, k
[0077] where the prediction result P i contains the predicted values of each data sample.
[0078] S40. Apply an anomaly detection algorithm to each prediction result P i to identify the corresponding abnormal pattern AP i .
[0079] Specifically, in this step, the Isolation Forest algorithm is used as the anomaly detection algorithm to identify abnormal patterns in the data, that is, those data points that are significantly different from the normal pattern:
[0080] AP i = IsolationForest(P i ), i = 1, 2, …, k
[0081] The Isolation Forest algorithm is a tree - based anomaly detection algorithm that identifies anomaly points in data by constructing multiple random trees. The basic idea of the Isolation Forest algorithm is that anomaly points are more likely to be isolated, that is, in the tree structure, the path length of anomaly points is shorter. The basic steps of the Isolation Forest algorithm are as follows:
[0082] S40 - 1, Construct the tree structure: Randomly select features and split points from the dataset to construct the tree structure.
[0083] S40 - 2, Calculate the path length: For each data point, calculate its path length in the tree structure.
[0084] S40 - 3, Anomaly score calculation: Calculate the anomaly score according to the path length. The shorter the path length, the higher the anomaly score.
[0085] The specific formula is as follows:
[0086]
[0087] Among them, Score(x, n epsilon is the anomaly score of data point x, E(h(x)) is the average path length of the data point in all trees, c(n epsilon ) is an adjustment constant related to the dataset size n epsilon .
[0088] S50, Use the ensemble learning method to construct the meta - model M meta , and integrate the prediction results P i of each local model M i to generate the backdoor detection result P meta , including the following sub - steps S51~S54:
[0089] S51, Use the ensemble learning method to comprehensively analyze the prediction results P i to generate a comprehensive model.
[0090] Among them, the ensemble learning method includes the voting mechanism method, the weighted average method, or the stacking method. In this embodiment, the stacking method is specifically selected.
[0091] S52, Use the prediction results P i as the input of the comprehensive model to generate the training dataset T meta :
[0092]
[0093] Among them, P i,j is the prediction result of the i-th local model for the j-th sample, y i,j is the corresponding true label, and q is the number of abnormal samples in the data subset.
[0094] S53, using the training data set T meta Train the comprehensive model and record the trained model as meta-model M meta , the training formula is as follows:
[0095] M meta =Train(T meta )
[0096] S54, using metamodel M meta The prediction result P i Analyze and generate backdoor detection results P meta :
[0097] P meta =M meta (P1,P2,…,P k )
[0098] Through the above steps S51 to S54, the prediction results of multiple models are combined through ensemble learning to improve the overall prediction accuracy and robustness.
[0099] S60, the backdoor detection result P meta AP with abnormal mode i An analysis comparison is performed to ensure that the backdoor exists in the subset.
[0100] The purpose of this step is to ensure that the abnormal mode AP i Accuracy:
[0101] Compare(P meta ,AP i ), i=1,2,…,k
[0102] The purpose of the above abnormal output comparison is to further confirm and identify potential backdoor attack patterns through the analysis results of the comprehensive model.
[0103] S70, the abnormal mode AP i The comparative analysis results are summarized to generate a backdoor detection report R final , thus ultimately achieving backdoor detection.
[0104] R final =Report(P meta )
[0105] This embodiment also provides an XGBoost model backdoor detection system based on local models and ensemble learning, which uses the XGBoost model backdoor detection method based on local models and ensemble learning in this embodiment, and includes a model training unit, a prediction unit, a first detection unit, a second detection unit, and an abnormal result comparison and report generation unit.
[0106] The model training unit is used to preprocess and cluster the original data in the given original dataset, and then train a number of independent XGBoost models to obtain a corresponding number of local models M i 。
[0107] The prediction unit is connected to the model training unit and is used to use the local model M i to predict its corresponding subset S i and obtain a number of prediction results P i 。
[0108] The first detection unit is connected to the prediction unit and is used to apply an anomaly detection algorithm to each prediction result P i to identify the corresponding abnormal pattern AP i 。
[0109] The second detection unit is connected to the prediction unit and is used to construct a meta-model M using an ensemble learning method meta to integrate the prediction results P i of each local model M i so as to generate a backdoor detection result P meta 。
[0110] The abnormal result comparison and report generation unit is connected to the first detection unit and the second detection unit, and is used to analyze and compare the backdoor detection result P meta with the abnormal pattern AP i to ensure that there is a backdoor in the subset, and then summarize the comparative analysis results of the abnormal pattern AP i to generate a backdoor detection report R final so as to finally achieve backdoor detection.
[0111] <Test case>
[0112] This test case uses an XGBoost model backdoor detection method and system based on local models and ensemble learning provided by the embodiment for testing.
[0113] This test case uses 2 datasets for testing respectively:
[0114] (1) Financial dataset: Use the publicly available financial dataset, the "Give Me Some Credit" dataset on Kaggle, which contains a total of 10,000 records.
[0115] (2) Medical dataset: Using the publicly available medical dataset, the "Heart Disease" dataset from UCI, which contains a total of 5000 records.
[0116] The evaluation metrics of this test case include detection accuracy, detection success rate, false alarm rate, miss rate, and calculation time.
[0117] The experimental method of this test case is as follows: The dataset is divided into a training set and a test set, accounting for 70% and 30% of the total dataset respectively. Use the traditional global single model detection method and an XGBoost model backdoor detection method and system based on local models and ensemble learning in the embodiment to perform backdoor detection respectively, and compare the results of each index.
[0118] Test results: An XGBoost model backdoor detection method and system based on local models and ensemble learning provided by the embodiment are significantly better than the traditional method in all indexes. Specifically, the detection accuracy of the method provided by the embodiment on the financial dataset reaches 98%, the false alarm rate is 4%, and the miss rate is 2%. While on the medical dataset, the detection accuracy reaches 95%, the false alarm rate is 3%, and the miss rate is 1%. In contrast, the detection accuracy of the traditional global single model detection method on the same dataset is 83% and 80% respectively.
[0119] Functions and effects of the embodiment
[0120] This embodiment proposes an XGBoost model backdoor detection method and system based on local models and ensemble learning. Compared with the prior art, this embodiment has the following remarkable beneficial effects:
[0121] (1) Improve detection accuracy: By dividing the data into multiple subsets and training independent XGBoost models on each subset, it is possible to learn and identify abnormal patterns in specific subsets more deeply, thereby improving the overall model's detection accuracy for backdoor attacks. The results of the test case show that the method of this embodiment improves the detection accuracy by about 15% compared with the traditional method (such as the global single model detection method).
[0122] (2) Enhance robustness and reliability: Using the ensemble learning method (stacking) to comprehensively analyze the prediction results of local models can effectively identify abnormal outputs and further enhance the robustness and reliability of detection. The results of the test case show that when facing complex backdoor attacks, the detection success rate of the method of this embodiment is as high as 92%, which is significantly better than the existing methods.
[0123] (3)Effectively reducing false positives and false negatives: Through multi-level anomaly detection and integrated learning strategies, the method of this embodiment can effectively reduce the situations of false positives and false negatives when dealing with high-dimensional data and complex models, ensuring the accuracy of the detection results. The results of the test cases show that the false positive rate of the method of this embodiment is lower than 5%, and the false negative rate is lower than 3%.
[0124] (4)Wide applicability: The method of this embodiment is not only applicable to fields with high security requirements such as finance and healthcare, but can also be extended and applied to other machine learning models that require high robustness and security, having broad application prospects. Through experimental verification on financial and healthcare data sets, this method performs excellently in different application scenarios.
[0125] (6) Those skilled in the art of this industry should understand that the present invention is not limited by the above embodiments. What is described in the above embodiments and the specification only illustrates the principle of the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and all these changes and improvements fall within the scope of the present invention claimed. The scope of the present invention claimed is defined by the appended claims and their equivalents.
Claims
1. A backdoor detection method for XGBoost model based on local model and ensemble learning, characterized in that: Applied to machine learning models that require high robustness and security, including the following steps: S10, after preprocessing and clustering the original data in the given original data set, several subsets S are obtained i ; S20, in each of the subsets S i Train independent XGBoost models on the , and get the corresponding local models M i ; S30, using the local model M i The corresponding subset S i Make predictions and get some prediction results P i ; S40, for each prediction result P i Apply anomaly detection algorithms to identify the corresponding abnormal pattern APs i ; S50, constructing meta-model M using ensemble learning method meta , integrating each local model M i The prediction result P i Thus generating the backdoor detection result P meta ; S60, the backdoor detection result P meta With the abnormal mode AP i Performing analysis and comparison to ensure the presence of a backdoor in the subset; S70, the abnormal mode AP i The comparative analysis results are summarized to generate a backdoor detection report, thereby ultimately achieving backdoor detection.
2. The XGBoost model backdoor detection method based on local model and ensemble learning according to claim 1 is characterized in that: in, In step S10, preprocessing includes removing outliers, filling missing values, and data standardization. The clustering method includes using K-means clustering algorithm.
3. The XGBoost model backdoor detection method based on local model and ensemble learning according to claim 1, characterized in that: in, In step S20, each of the local models M i During the training of the corresponding XGBoost model, cross-validation is used to optimize the model parameters. Each of the local models M i The corresponding objective function of XGBoost model training is: and L is the loss function, l is the loss term, y i is the true label value, is the predicted label value, i is the sample index, n epsilon It is a subset S i The number of training samples after division, Ω is the regularization term, θ is the model parameter, the regularization term Ω is used to control the complexity of the model to prevent overfitting, T is the number of decision trees in the XGBoost model, γ is the complexity weight of the tree, and λ is the regularization parameter. is the leaf node weight of the tree, and j indicates that the decision tree is the jth one.
4. The XGBoost model backdoor detection method based on local model and ensemble learning according to claim 3 is characterized in that: in, By minimizing the objective function L(θ), the XGBoost model obtains the best fit on the training data. The complexity of the XGBoost model is controlled by the regularization term Ω to improve its generalization ability on new data.
5. The XGBoost model backdoor detection method based on local model and ensemble learning according to claim 1, characterized in that: in, In step S40, the anomaly detection algorithm includes an Isolation Forest algorithm.
6. The XGBoost model backdoor detection method based on local model and ensemble learning according to claim 1, characterized in that: in, In step S50, the ensemble learning method includes a voting mechanism method, a weighted average method or a stacking method.
7. The XGBoost model backdoor detection method based on local model and ensemble learning according to claim 1, Features: Wherein, step S50 includes the following sub-steps: S51, using an ensemble learning method to transform the prediction result P i Conduct comprehensive analysis to generate a comprehensive model; S52, the prediction result P i As the input of the comprehensive model, the training data set T is generated meta ; S53, using the training data set T meta The comprehensive model is trained and the trained model is recorded as the meta-model M meta ; S54, using the metamodel M meta The prediction result P i Analyze and generate backdoor detection results P meta .
8. The XGBoost model backdoor detection method based on local model and ensemble learning according to any one of claims 1 to 7, characterized in that: in, The machine learning model that requires high robustness and security is a machine learning model suitable for fields including finance or medicine.
9. An XGBoost model backdoor detection system based on local model and ensemble learning, characterized in that: The XGBoost model backdoor detection method based on local model and ensemble learning as described in any one of claims 1 to 8 comprises: The model training part is used to preprocess and cluster the raw data in a given raw data set, train several independent XGBoost models, and obtain the corresponding local models M i ; A prediction unit connected to the model training unit is used to use the local model M i The corresponding subset S i Make predictions and get some prediction results P i ; The first detection unit is connected to the prediction unit and is used to detect each prediction result P i Apply anomaly detection algorithm to identify the corresponding abnormal pattern AP i ; The second detection unit is connected to the prediction unit and is used to construct the meta-model M using an integrated learning method. meta , integrating each local model M i The prediction result P i Thus generating the backdoor detection result P meta ;as well as The abnormal result comparison and report generation unit is connected to the first detection unit and the second detection unit, and is used to compare the backdoor detection result P meta With the abnormal mode AP i After analyzing and comparing to ensure that the backdoor exists in the subset, the abnormal pattern AP i The comparative analysis results are summarized to generate a backdoor detection report, thereby ultimately achieving backdoor detection.