Safety monitoring method and system based on embedded large model in intelligent screen

By evaluating the data domain differences of the large model by generating adversarial networks, combining watermark embedding and weight obfuscation technology, the balance problem between large model security and performance is solved, and the security monitoring and performance maintenance of large models in smart screens is realized.

CN120296749AActive Publication Date: 2025-07-11HUNAN ZHENTONG ZHIYONG ARTIFICIAL INTELLIGENCE TECHNOLOGY CO LTD
View PDF 9 Cites 0 Cited by

Patent Information

Application Number
CN202510765888.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-10
Publication Date
2025-07-11
Estimated Expiration
2045-06-10

AI Technical Summary

Technical Problem

The prior art can easily lead to significant decline in model performance when enhancing the security of large models, and even lead to failure of equipment to work properly, ignoring the dynamic balance between security and performance.

Method used

By collecting multimodal input data of the large model, using the generative adversarial network to generate a comparison data domain, evaluate the degree of difference of the data domain, determine whether the input task data domain is an authorized task data domain, and conduct security monitoring and adjustment of the embedding process of the large model in real time, including watermark embedding, weight obfuscation and reinforcement learning control.

Benefits of technology

It realizes accurate identification of cross-domain risks, prevent task abuse, resist hardware cracking and software reverse engineering, and ensure model integrity and security while maintaining stable model performance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296749A_ABST
    Figure CN120296749A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of electric digital data processing, and particularly discloses a safety monitoring method and system based on an embedded large model in an intelligent screen, and the method comprises the steps: firstly collecting the multi-modal input data of the large model, forming an input task data field, and generating a comparison data field through a generative adversarial network; secondly, comparing the two data fields, and extracting related information to evaluate a difference degree value of the data fields; then, the value is compared with a preset threshold interval, and whether the input task data field is an authorized task data field or not is judged; if the data field is an authorized task data field, the large model carries out reasoning, real-time safety monitoring is carried out in the reasoning process, and once abnormity is found, corresponding safety adjustment is carried out on the reasoning process according to specific conditions, so that the operation safety of the large model is guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of electronic digital data processing, and in particular to a safety monitoring method and system based on a large model embedded in a smart screen. Background Art

[0002] With its powerful learning and processing capabilities, big models have achieved remarkable results in natural language processing, computer vision and other fields. In smart screens, big models enable devices to have intelligent functions such as voice interaction and image recognition, greatly enriching the user experience. From home entertainment to commercial display, the application scenarios of smart screens are constantly expanding. With the popularization of smart screen devices, the security and privacy protection of big models are becoming more and more concerned. How to protect the security and privacy of big models in smart hardware has become a key issue that smart device manufacturers and developers must solve.

[0003] For example, the invention patent with publication number CN119167358A discloses an effective network security incident monitoring method and system based on a big data model, including: automatically collecting data activity records from multiple data sources in the enterprise network; cleaning and formatting the data activity records; extracting leakage features related to data leakage behavior in the data activity records, building a data leakage incident monitoring model based on the leakage features, and monitoring data leakage incidents in real time; setting monitoring thresholds according to historical data leakage situations, and triggering an early warning mechanism when the monitoring results exceed the threshold; tracking and tracing data leakage incidents to find the source of data leakage.

[0004] For example, the invention patent with publication number CN118981789A discloses a system for protecting sensitive information of large models, which includes the following steps: S1, user identity registration and authorization management; S2, formulation of access control strategy; S3, construction of sensitive information database; S4, sensitive information inspection of input and generated content; S5, user behavior monitoring and risk assessment; S6, log recording and security auditing; through various measures such as authorization management, access control, sensitive information inspection, behavior monitoring and security auditing of user use, security management and control of large model applications are achieved.

[0005] Combining the above technical solutions, it is found that the existing large model security monitoring technical solutions ignore the dynamic balance between the security and performance of large models when protecting large models in different scenarios, which can easily lead to a significant decrease in model performance while enhancing the security of large models, and even make the equipment unable to work normally. Summary of the invention

[0006] In view of the deficiencies in the prior art, the present invention provides a security monitoring method and system based on a large model embedded in a smart screen, which can effectively solve the problems involved in the above-mentioned background technology.

[0007] To achieve the above objectives, the present invention is realized through the following technical solutions: In the first aspect of the present invention, a security monitoring method based on an embedded large model in an intelligent screen is provided, including: collecting multi-modal input data of the current large model to form an input task data domain of the large model, and generating an input task comparison data domain of the large model based on a generative adversarial network; comparing the input task data domain of the large model with the input task comparison data domain of the large model, extracting data domain comparison information, and evaluating the data domain difference degree value of the large model; comparing the data domain difference degree value of the large model with each predefined preset data domain difference threshold interval to determine whether the input task data domain of the large model is an authorized task data domain of the large model; the large model performs reasoning on the authorized task data domain, monitors the security of the embedding process of the large model in real time, and finally makes security adjustments to the reasoning process of the large model.

[0008] As a further method, to evaluate the data domain difference degree value of the large model, the specific evaluation process is as follows: The data domain comparison information includes the mean difference of each feature dimension of the large model data domain and the relative entropy of the large model data domain; collecting the generation information of the input task comparison data domain of the large model, including the discriminator loss value of the large model and the generator loss value of the large model; multiplying the discriminator loss value of the large model and the generator loss value of the large model by the corresponding weight parameters respectively and adding them to obtain the influence degree value of the large model's generation device, matching it with the difference degree influence factor corresponding to each predefined influence degree value interval of the generation device to obtain the difference degree influence factor of the large model; performing unitless normalization processing on the mean difference of each feature dimension of the large model data domain and the relative entropy of the large model data domain respectively, and performing data aggregation processing with the difference degree influence factor of the large model to obtain the data domain difference degree value of the large model.

[0009] As a further method, to determine whether the input task data domain of the large model is an authorized task data domain of the large model, specifically, the data domain difference degree value of the large model is compared with each preset data domain difference threshold interval to obtain a difference degree comparison result, and based on the difference degree comparison result, it is determined whether the input task data domain of the large model is an authorized task data domain of the large model; if the data domain difference degree value of the large model belongs to the first difference threshold interval, it is determined that the input task data domain is a normal input, and the input task data domain of the large model is recorded as the authorized task data domain of the large model; if the data domain difference degree value of the large model belongs to the second difference threshold interval, weight verification is triggered; if the data domain difference degree value of the large model belongs to the third difference threshold interval, it is determined that the current input task data domain is an abnormal input and a warning is triggered.

[0010] As a further method, weight verification is carried out. The specific analysis process is as follows: The reinforcement learning controller filters out the filters that affect the functionality of the large model, which are denoted as key filters, and extracts the original weight parameters corresponding to the key filters; The original weight parameters are compared with the predefined weight parameter confusion interval, and the original weight parameters belonging to the weight parameter confusion interval are denoted as the key weights of the large model. The reinforcement learning controller generates a key weight mask for the key weights; The key weights of the large model are compared with the key weight mask to evaluate the weight confusion variation degree of the large model, and continue to determine whether the input task data domain of the large model is the authorized task data domain of the large model.

[0011] As a further method, continue to determine whether the input task data domain of the large model is the authorized task data domain of the large model. The specific determination process is as follows: The weight confusion variation degree of the large model is compared with the preset weight variation threshold intervals. If the weight confusion variation degree of the large model belongs to the first variation threshold interval, it is determined that the weight verification of the large model is normal, and the input task data domain of the large model is denoted as the authorized task data domain of the large model; If the weight confusion variation degree of the large model belongs to the second variation threshold interval, the mask parameter index and the allowed variation amplitude interval in the authorized key stored in the current large model are extracted, and compared with the position index and the variation amplitude of the actual variation parameter between the input task data domain of the large model and the comparison data domain of the input task of the large model. If the position index and the variation amplitude of the actual variation parameter both belong to the mask parameter index and the allowed variation amplitude interval in the authorized key, it is determined that the actual variation parameter is a reasonable difference within the authorized range, update the local authorization status to temporary trust, and denote the input task data domain of the large model as the authorized task data domain of the large model, otherwise it is determined that the actual variation parameter is an unreasonable variation, and an emergency response is triggered; If the weight confusion variation degree of the large model belongs to the third variation threshold interval, the input task data domain of the large model is the unauthorized task data domain of the large model, it is determined that the large model has abnormal use, and an emergency response is triggered.

[0012] As a further method, the embedding process of the large model is monitored for security in real time. The specific analysis process is as follows: The watermark embedding operation is performed on the authorized task data domain of the large model to generate a watermark model; The embedding process of the large model is monitored for security in real time. Periodically, the watermark information is extracted from the secondary bits of the authorized task data domain of the large model to reconstruct the watermark model. The watermark model is compared with the reconstructed watermark model. If the watermark model is the same as the reconstructed watermark model, the security monitoring continues. If the watermark model is different from the reconstructed watermark model, the execution feature information of the large model is collected, the feature integrity index of the large model is determined, and the inference process of the large model is adjusted for security.

[0013] In the second aspect of the present invention, a security monitoring system based on a large model embedded in an intelligent screen is provided, including: a comparison data domain generation module, configured to collect multi-modal input data of the current large model, form an input task data domain of the large model, and generate a comparison data domain of the input task of the large model based on a generative adversarial network; a data domain difference evaluation module, configured to compare the input task data domain of the large model with the comparison data domain of the input task of the large model, extract data domain comparison information, and evaluate the data domain difference degree value of the large model; an authorized data domain determination module, configured to compare the data domain difference degree value of the large model with each predefined preset data domain difference threshold interval, and determine whether the input task data domain of the large model is an authorized task data domain of the large model; a large model security monitoring module, configured to perform inference on the authorized task data domain by the large model, perform real-time security monitoring on the embedding process of the large model, and finally perform security adjustment on the inference process of the large model.

[0014] Compared with the prior art, the embodiments of the present invention have at least the following advantages or beneficial effects:

[0015] (1) By providing a security monitoring method and system based on a large model embedded in an intelligent screen, the present invention first collects multi-modal input data of the large model, forms an input task data domain, and uses a generative adversarial network to generate a comparison data domain. Then, the two data domains are compared, and relevant information is extracted to evaluate the data domain difference degree value. Next, this value is compared with the preset threshold interval to determine whether the input task data domain is an authorized task data domain. If it is an authorized task data domain, the large model performs inference, and real-time security monitoring is carried out during the inference process. Once an anomaly is found, corresponding security adjustments are made to the inference process according to the specific situation, so as to ensure the safe operation of the large model.

[0016] (2) By extracting data domain comparison information, comparing the input task data domain with the generated comparison data domain, and evaluating the data domain difference degree value of the large model, the present invention can accurately determine whether the current input data belongs to the task scope authorized by the model, identify cross-domain risks, and prevent task abuse. At the same time, due to the complex distribution of multi-modal input data of the intelligent screen, the data domain difference evaluation processes the feature differences of different modalities through normalization and weighted aggregation, which can ensure that the model maintains stable performance for diverse data within the authorized domain, enables the large model to dynamically adapt to multi-modal input, and improves its robustness.

[0017] (3) By collecting the key weight comparison information of the large model, the present invention determines the weight confusion mutation degree of the large model, and monitors in real time whether the core parameters of the model are illegally modified. Even if the model is illegally copied, the confused weights obtained by unauthorized users will cause a significant decrease in the inference accuracy, effectively preventing the theft of the model's core parameters through hardware cracking or software reverse engineering, thereby resisting parameter tampering attacks and ensuring the integrity of the model. The weight confusion mutation degree combines the mask parameter index and the allowable mutation interval in the authorization key to distinguish legal changes from illegal tampering, realizing refined authorization management and preventing out-of-bounds use. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] The present invention will be further described with reference to the accompanying drawings. However, the embodiments in the drawings do not constitute any limitation to the present invention. For those of ordinary skill in the art, other drawings can be obtained based on the following drawings without creative efforts.

[0019] Figure 1 It is a schematic flow chart of the method steps of the present invention.

[0020] Figure 2 It is a schematic diagram of the connection of system modules of the present invention.

[0021] Figure 3 It is a schematic diagram of the process structure of the present invention.

[0022] Figure 4 It is a detailed flow chart of the steps of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0023] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0024] Referring to Figure 1 As shown, the first aspect of the present invention provides a security monitoring method based on an embedded large model in an intelligent screen, including: collecting multi-modal input data of the current large model to form an input task data domain of the large model, and generating an input task comparison data domain of the large model based on a generative adversarial network.

[0025] GAN (Generative Adversarial Network) refers to the GAN architecture with enhanced authorization domain, which includes a generator G and a discriminator D. The generator takes random noise and a one-hot encoding as inputs and generates training samples. The discriminator is used to determine whether the input data samples are real or generated and give their corresponding labels. During the training process, the generator tries to generate realistic samples to deceive the discriminator, while the discriminator tries to distinguish the authenticity of the data, thus forming an adversarial relationship between the two. Among them, the discriminator includes a feature extraction module and two classifiers. The feature extractor is used to extract the features of the input samples. The first classifier is used to determine whether the input is a real sample or a generated sample, and the second classifier is used to discriminate the class label of the extracted features. During the training process, the mean squared error (MSE) loss is used to help the discriminator distinguish real and generated samples. In the joint optimization of generation and discrimination, the KL divergence is used to limit the label distribution of the generated data to be close to the target label, so as to ensure that the generated samples are not only realistic but also conform to specific labels. The above-mentioned KL (Kullback-Leibler) divergence is an asymmetric measure of the difference between two probability distributions. It quantifies the "distance" between one probability distribution and another probability distribution.

[0026] The input task data domain of the above-mentioned large model refers to the multi-modal input data set corresponding to the specific task currently processed by the large model, which includes various data features and their distributions in the task scenario and is the direct data input source for the model to perform inference. Its core is a data set strongly related to the current task and with a specific distribution, such as the user interaction data of the smart screen in different functional scenarios. For example, in the voice control task of a smart TV, the data types can include voice data, touch data, environmental data, etc. The data domain features are that when instruction words such as "open" and "play" frequently appear in the voice text, the touch coordinates are concentrated in the function button area at the bottom of the screen, and the image contains the preset application icon layout.

[0027] In this embodiment, a task-specific model generation framework based on domain locking is designed, as Figure 3 shown in the domain locking model generation Figure 3 which is the schematic flow structure diagram of the present invention. By using the generative adversarial network (GAN) to construct contrast domain data with different distributions from the authorized data domain and optimizing through the KL divergence loss and the maximum mean discrepancy (MMD) loss, the model has excellent performance in the authorized domain while its performance significantly degrades in other domains. This framework realizes the refined adaptation of the task scenario, introduces the inter-domain contrast mechanism into representation learning for the first time, and proposes a new authorization mode that takes into account both performance and applicability.

[0028] Compare the input task data domain of the large model with the input task contrast data domain of the large model, extract the data domain comparison information, and evaluate the data domain difference degree value of the large model.

[0029] Specifically, to evaluate the data domain difference degree value of the large model, the specific evaluation process is as follows:

[0030] The above data domain comparison information includes the mean difference of each feature dimension of the large model data domain and the relative entropy of the large model data domain, and the data domain comparison information can be extracted from the data domain comparison log of the large model.

[0031] The mean difference of each feature dimension of the above large model data domain is specifically obtained by collecting the mean of each feature dimension of the input task data domain of the large model and the mean of each feature dimension of the input task comparison data domain of the large model, and performing a difference process to obtain the mean difference of each feature dimension of the large model data domain. Assume that the input task data domain is , and the input task comparison data domain is . For the i-th feature dimension, their means are and respectively, then the mean difference can be expressed as:

[0032] Collect the generation information of the input task comparison data domain of the large model, including the discriminator loss value of the large model and the generator loss value of the large model, where the discriminator loss value can be calculated by the discriminator loss function, and the generator loss can be calculated by the generator loss function.

[0033] Multiply the discriminator loss value of the large model and the generator loss value of the large model by the corresponding weight parameters respectively and add them to obtain the influence degree value of the generation device of the large model, and match it with the difference degree influence factor corresponding to each predefined influence degree value interval of the generation device to obtain the difference degree influence factor of the large model.

[0034] The above influence degree value of the generation device of the large model is specifically obtained by multiplying the discriminator loss value of the large model by the weight parameter corresponding to the predefined discriminator loss value in the model monitoring information library to obtain the first influence degree value of the generation device; multiplying the generator loss value of the large model by the weight parameter corresponding to the predefined generator loss value in the model monitoring information library to obtain the second influence degree value of the generation device, and adding the first influence degree value of the generation device and the second influence degree value of the generation device to obtain the influence degree value of the generation device of the large model.

[0035] The weight parameters corresponding to the discriminator loss value and the weight parameters corresponding to the generator loss value are both extracted from the model monitoring information library, and the mapping relationship therein can be one-to-one or many-to-one. For example, the discriminator loss value and the generator loss value respectively form a mapping set with the weight parameters corresponding to the discriminator loss value and the weight parameters corresponding to the generator loss value preset in the model monitoring information library, and the real-time discriminator loss value and generator loss value are brought into the mapping set to obtain the weight parameters corresponding to the discriminator loss value and the weight parameters corresponding to the generator loss value.

[0036] Normalize the mean difference of each feature dimension in the large model data domain and the relative entropy in the large model data domain by removing the unit respectively, and perform data aggregation processing with the difference degree influence factor of the large model to obtain the difference degree value of the large model data domain. The specific analysis method is as follows:

[0037] In the formula, is the difference degree value of the large model data domain, is the mean difference of the i-th feature dimension in the large model data domain, where i is the number of each feature dimension, , and N is the total number of feature dimensions, is the relative entropy of the large model data domain, is the weight parameter corresponding to the mean difference of the feature dimension predefined in the model monitoring information library, is the weight parameter corresponding to the relative entropy predefined in the model monitoring information library, is the difference degree influence factor of the large model.

[0038] The weight parameter corresponding to the mean difference of the feature dimension and the weight parameter corresponding to the relative entropy are both extracted from the model monitoring information library, and the mapping relationship therein can be one-to-one or many-to-one. For example, the mean difference of the feature dimension and the relative entropy respectively form a mapping set with the weight parameter corresponding to the mean difference of the feature dimension and the weight parameter corresponding to the relative entropy preset in the model monitoring information library, and the real-time mean difference of the feature dimension and the relative entropy are brought into the mapping set to obtain the weight parameter corresponding to the mean difference of the feature dimension and the weight parameter corresponding to the relative entropy.

[0039] In this embodiment, through multivariate analysis of the mean difference of each feature dimension, relative entropy, and the difference degree influence factor, specifically, the correlation between these parameters is considered. The mean difference of each feature dimension and relative entropy complement each other. The mean difference starts from the specific feature dimension, and relative entropy considers the overall distribution, jointly depicting the difference characteristics of the data domain. If the mean difference of each feature dimension is large, it often means that the distribution of data on each feature is significantly different, which may lead to an increase in relative entropy because the overall probability distribution difference increases with the increase in the feature distribution difference, bringing a negative impact on the data domain difference degree of the large model; conversely, if the relative entropy is large, it may also imply a large mean difference of feature dimensions, also bringing a negative impact on the data domain difference degree of the large model. At the same time, when the mean difference of each feature dimension is large, it indicates that there is a significant difference between the input task data domain and the comparison data domain, which may make it more difficult for the GAN to generate comparison data, resulting in changes in the discriminator loss value and the generator loss value, and then affecting the difference degree influence factor, thereby affecting the data domain difference degree of the large model.

[0040] Compare the data domain difference degree value of the large model with each predefined preset data domain difference threshold interval to determine whether the input task data domain of the large model is the authorized task data domain of the large model.

[0041] Furthermore, to determine whether the input task data domain of the large model is the authorized task data domain of the large model, specifically, the data domain difference degree value of the large model is verified with each preset data domain difference threshold interval to obtain a verification result, and based on the verification result, it is determined whether the input task data domain of the large model is the authorized task data domain of the large model.

[0042] If the data domain difference degree value of the large model belongs to the first difference threshold interval, it is determined that the input task data domain is a normal input, and the input task data domain of the large model is recorded as the authorized task data domain of the large model.

[0043] If the data domain difference degree value of the large model belongs to the second difference threshold interval, weight verification is triggered;

[0044] If the data domain difference degree value of the large model belongs to the third difference threshold interval, it is determined that the current input task data domain is an abnormal input, and a warning is triggered.

[0045] The above warning is specifically to restrict the output of the large model, block sensitive function buttons, record abnormal interaction logs, and report risk events to the cloud management platform.

[0046] Specifically, for weight verification, the specific analysis process is as follows:

[0047] Use a reinforcement learning controller to screen the filters that affect the functionality of the large model, denoted as key filters, and extract the original weight parameters corresponding to the key filters.

[0048] By introducing a mask M to identify the weights that need to be obfuscated, the number of weights to be obfuscated is minimized as much as possible, thereby reducing the security risks associated with storing and transmitting the obfuscated weights as keys. The definition of the mask M is as follows:

[0049] where is the original weight parameter, and are adjustable hyperparameters. Through this mask, the weights falling within the range - , + can be selectively obfuscated, while the weights outside this interval remain unchanged. Through the mask, we can optimize the weight changes , generating new weight changes . Among them, the symbol represents the multiplication operation of the corresponding elements in the matrix. By selecting the constant , the influence of weight obfuscation can be distributed to different layers of the model. After that, norm regularization is applied to the adjusted weight changes to encourage sparsity of the weight changes, that is, to reduce the number of non-zero elements, only store the changes of important weights, reduce the security risks associated with transmitting them as keys, compress the storage requirements, and combine the distributed design of the mask M with norm regularization to reduce the dependence on storage resources while performing weight obfuscation.

[0050] The above-mentioned reinforcement learning controller is mainly composed of three parts: a state encoder, a policy network, and an output decoder. For each layer a filter index k is selected, where , and represents the total number of filters (or output channels) in the th layer. Since is determined by the architecture of the target large model M, the environment of the agent is static. If n filters need to be selected for each layer, the agent performs a total of actions (L is the number of layers), and these actions are represented by . All agents share a controller with weight parameter , and its optimization goal is to maximize the expected reward : where represents the policy distribution of performing given the controller parameters ; The reward signal for guiding the controller, where E is the expectation function. Reward Encourages the controller to select those filters that will significantly reduce the model accuracy after obfuscation, and its definition is as follows: where represents the large model data validation set prediction accuracy on.

[0051] Compare the original weight parameters with the predefined weight parameter obfuscation interval, and mark the original weight parameters belonging to the weight parameter obfuscation interval as the key weights of the large model. The reinforcement learning controller generates a key weight mask for the key weights, where the original weight parameters belonging to the weight parameter obfuscation interval are represented as the weight parameters to be obfuscated and are marked through the mask.

[0052] Compare the key weights of the large model with the key weight mask, evaluate the weight obfuscation variability of the large model, and continue to determine whether the input task data domain of the large model is the authorized task data domain of the large model.

[0053] It should be noted that in this embodiment, weight verification can determine whether the input task data domain is the authorized task data domain. Its core logic is to achieve authorization control of the model function through the legality verification of the key weights, that is, by comparing the actual weights with the legal weight templates in the authorization key, to determine whether the current weights are within the authorized allowable variation range. The key filters selected by the reinforcement learning controller correspond to the weight parameters that have the greatest impact on the core functions (such as speech recognition, image classification) in the model. These weights directly determine the performance of the model on the authorized tasks (for example, the voice interaction function of the smart screen depends on specific filters to extract semantic features). The key weight mask generated by reinforcement learning only discloses the real weight index and the allowable variation range (stored in the authorization key) to authorized users. Unauthorized users cannot unlock the key weights even if they obtain the model, and can only use the obfuscated invalid weights (resulting in a significant decrease in inference accuracy). Weight verification is a progressive supplement to the data domain difference evaluation, and the two together constitute a double verification of "input legality → model function legality".

[0054] In this embodiment, such as Figure 3 the reinforcement learning-driven weight obfuscation shown Figure 3This is a schematic diagram of the process structure of the present invention. Based on the weight confusion and key protection mechanism driven by reinforcement learning, the degree of confusion of model parameters is dynamically adjusted by generating a weight mask, realizing the double-layer authorization protection of the model. This mechanism ensures that the model is only valid for users holding the authorization key. Even if the model is obtained by unauthorized users, its core functions cannot be unlocked. Compared with the traditional authorization mechanism, this method improves the flexibility and security of usage authorization without significantly affecting the model performance.

[0055] Furthermore, the weight confusion variability of the large model is evaluated. The specific evaluation process is as follows:

[0056] Collect the key weight comparison information of the large model, including the cosine similarity of each key weight of the large model, the relative difference ratio value of each key weight of the large model, and the proportion of key weight confusion of the large model. The key weight comparison information is specifically extracted from the weight comparison log of the large model.

[0057] Collect the algorithm iteration times of the reinforcement learning controller. The algorithm iteration times can be extracted from the execution report of the reinforcement learning controller and matched with the weight confusion impact element corresponding to each predefined algorithm iteration time interval to obtain the weight confusion impact element of the large model.

[0058] The relative difference ratio value of each key weight of the large model is specifically the ratio of the absolute value of the difference between the key weight and the corresponding element of the key weight mask to the absolute value of the corresponding element of the key weight. The proportion of key weight confusion of the large model is specifically the ratio of the number of elements in the key weight that are in the predefined weight parameter confusion interval to the total number of key weight elements.

[0059] Perform unitless normalization processing on the cosine similarity of each key weight of the large model, the relative difference ratio value of each key weight of the large model, and the proportion of key weight confusion of the large model, and perform data aggregation processing with the weight confusion impact element of the large model to obtain the weight confusion variability of the large model. The specific analysis method is as follows:

[0060] In the formula, is the weight confusion variability of the large model, is the cosine similarity of the j-th key weight of the large model, j is the number of each key weight, j = 1, 2, 3,..., M, and M is the total amount of key weights, is the relative difference ratio value of the j-th key weight of the large model, is the proportion of key weight confusion of the large model, is the weight confusion impact element of the large model, is the weight parameter corresponding to the cosine similarity of the key weight predefined in the model monitoring information library, is the weight parameter corresponding to the predefined key weight relative difference ratio value in the model monitoring information database, is the weight parameter corresponding to the predefined key weight confusion ratio in the model monitoring information database.

[0061] It should be noted that the cosine similarity of each key weight of the above large model refers to the cosine similarity between each key weight of the large model and the corresponding key weight mask.

[0062] Among them, the weight parameter corresponding to the key weight cosine similarity, the weight parameter corresponding to the key weight relative difference ratio value, and the weight parameter corresponding to the key weight confusion ratio are all extracted from the model monitoring information database, and the mapping relationship therein can be one-to-one or many-to-one. For example, the key weight cosine similarity, the key weight relative difference ratio value, and the key weight confusion ratio respectively form a mapping set with the weight parameter corresponding to the predefined key weight cosine similarity, the weight parameter corresponding to the key weight relative difference ratio value, and the weight parameter corresponding to the key weight confusion ratio in the model monitoring information database. Substituting the real-time key weight cosine similarity, the key weight relative difference ratio value, and the key weight confusion ratio into the mapping set to obtain the weight parameter corresponding to the key weight cosine similarity, the weight parameter corresponding to the key weight relative difference ratio value, and the weight parameter corresponding to the key weight confusion ratio.

[0063] In this embodiment, through the key weight cosine similarity, the key weight relative difference ratio value, the key weight confusion ratio and the weight confusion influence element of the large model for multivariate analysis, specifically considering the correlation between these parameters. The key weight cosine similarity and the key weight relative difference ratio value of the large model reflect the weight change from different angles. When the cosine similarity is high, the relative difference ratio value is often low, and the weight confusion variability of the large model is lower; conversely, when the cosine similarity is low, the relative difference ratio value may be high, and the weight confusion variability of the large model increases. When the key weight confusion ratio increases, it means that more key weights are in the confusion interval, which may lead to a decrease in the cosine similarity of each key weight and an increase in the relative difference ratio value of each key weight, also increasing the weight confusion variability of the large model. The weight confusion influence element plays a regulatory role. When the weight confusion influence element is large, it will amplify the influence of other parameters on the weight confusion variability. In the reinforcement learning process, if the number of algorithm iterations is large, resulting in an increase in the weight confusion influence element, even if the original changes in the cosine similarity of each key weight, the relative difference ratio value of each key weight, and the key weight confusion ratio are small, the finally obtained weight confusion variability may also increase significantly.

[0064] Specifically, continue to determine whether the input task data domain of the large model is the authorized task data domain of the large model. The specific determination process is as follows:

[0065] Compare the weight confusion variability of the large model with the preset weight variability threshold intervals. If the weight confusion variability of the large model belongs to the first variability threshold interval, it is determined that the weight verification of the large model is normal, and the input task data domain of the large model is recorded as the authorized task data domain of the large model.

[0066] If the weight confusion variability of the large model belongs to the second variability threshold interval, extract the mask parameter index and the allowable variability interval in the authorized key stored in the current large model, and compare them with the position index and the variability amplitude of the actual variability parameter between the input task data domain of the large model and the input task comparison data domain of the large model. If both the position index and the variability amplitude of the actual variability parameter belong to the mask parameter index and the allowable variability interval in the authorized key, it is determined that the actual variability parameter is a reasonable difference within the authorized range, then update the local authorization status to temporary trust, and record the input task data domain of the large model as the authorized task data domain of the large model; otherwise, it is determined that the actual variability parameter is an unreasonable variability, and an emergency response is triggered.

[0067] If the weight confusion variability of the large model belongs to the third variability threshold interval, the input task data domain of the large model is the unauthorized task data domain of the large model, it is determined that the large model is used abnormally, and an emergency response is triggered. The above-mentioned emergency response is specifically to immediately freeze the inference function of the large model, automatically roll back to the weight parameters of the most recent authorized state, and at the same time send a real-time alert to the device administrator.

[0068] The large model performs inference on the authorized task data domain, monitors the security of the embedding process of the large model in real time, and finally makes security adjustments to the inference process of the large model.

[0069] Furthermore, monitor the security of the embedding process of the large model in real time. The specific analysis process is as follows:

[0070] Perform a watermark embedding operation on the authorized task data domain of the large model to generate a watermark model. The above-mentioned watermark embedding operation is specifically based on the IEEE754 floating-point standard, and embeds the watermark information into the least significant bits (minor bits) of the large model parameters to generate a watermark model.

[0071] Collect all the sign bits and exponent bits of the large model parameters, that is, the most significant bits, and record them as . Then, obtain the recovery bit R through matrix multiplication operation, . Specifically, the recovery bit is calculated by the following formula: where, is a pseudo-random binary matrix generated by the authorized key, with a size of .

[0072] The model parameters and recovery bits are divided into groups of u elements each, and evenly divided into g groups. For each group, the primary bits C and recovery bits R are input into a hash function to generate h hash bits. After generating the hash bits for each group, all the recovery bits and hash bits are combined to form a watermark. Finally, the model watermark is embedded into the secondary bits of the model by means of secondary bit replacement to generate a watermarked model 。

[0073] Monitor the embedding process of the large model in real time. Periodically extract the watermark information from the secondary bits of the authorized task data domain of the large model, reconstruct the watermarked model, and compare the watermarked model with the reconstructed watermarked model. If the watermarked model is the same as the reconstructed watermarked model, continue the security monitoring. If the watermarked model is different from the reconstructed watermarked model, collect the execution feature information of the large model, determine the feature integrity index of the large model, and perform security adjustment on the inference process of the large model

[0074] In this embodiment, as Figure 3 shown in the watermark embedding and recovery Figure 3 is the schematic flow structure diagram of the present invention. Innovatively, the watermark is embedded into the secondary bits of the model parameters and combined with the hash algorithm to generate a unique identifier for verifying the integrity and ownership of the model. When the model is attacked or tampered with, the damaged parameters can be located through hash comparison, and the weights can be restored to the original state using the model key. This mechanism not only expands the application scope of watermark technology, but also provides a refined tampering detection and repair function for the model, significantly enhancing the integrity and reliability of model protection

[0075] Specifically, the security adjustment of the inference process of the large model is as follows:

[0076] Compare the feature integrity index of the large model with each predefined feature integrity index interval. If the feature integrity index of the large model belongs to the first integrity index interval, record the watermark different state to the cloud management platform last time, and execute the preset security enhancement measures

[0077] If the feature integrity index of the large model belongs to the second integrity index interval, temporarily disable the function of the large model with specific labels, only retain the interactive function of non-specific labels, and shorten the watermark detection period to the preset length for continuously tracking the change trend of the feature integrity index

[0078] If the feature integrity index of the large model belongs to the third integrity index interval, it is determined that there is unauthorized tampering behavior during the execution of the large model. Locate the position of the tampered parameters through hash comparison, and restore the parameters using the original weight index stored by the key

[0079] Watermark recovery specifically extracts the watermark information from the least significant bits of the model. These least significant bits contain recovery bits and hash bits. The watermark and the most significant bits are evenly divided into g groups. For each group, the corresponding hash bits are extracted and compared with the recomputed hash bits to distinguish the tampered recovery bits and the most significant bits. If the extracted hash bits of this group are exactly equal to the recomputed hash bits, this group is marked as a complete group; otherwise, it is marked as a tampered group. Suppose the total number of recovered bits in the initially extracted complete groups is , then the recovery bit formula can be rewritten as:

[0080] where and are matrices composed of rows selected from K and respectively (generated by the authorized key), and these rows correspond to the complete recovery bits, represents the index of the complete recovery bits. At this time, the further extracted most significant bits are further divided into complete most significant bits and tampered most significant bits . Therefore, this formula can be further refined as:

[0081] where and are matrices composed of columns corresponding to the most significant bits in and . In this formula, all other terms except are correct terms, and is the most significant bit that needs to be recovered. The problem of recovering the tampered most significant bit can be transformed into the problem of solving the matrix . As long as this formula has a unique solution, the tampered most significant bit can be completely recovered.

[0082] Furthermore, the determination of the feature integrity index of the large model is as follows: The specific determination process is:

[0083] The above-mentioned execution feature information of the large model includes the watermark matching degree of the large model and the proportion of the watermark tampering position in the large model. Among them, the execution feature information can be specifically extracted from the execution report of the large model.

[0084] Extract the performance information of the large model. The performance information can be extracted from the execution report of the large model, including the CPU utilization rate of the large model and the inference duration of the large model. Multiply the CPU utilization rate of the large model and the inference duration of the large model by the corresponding weight factors respectively and then add them together, and record the result as the performance impact degree value of the large model.

[0085] The watermark matching degree of the above large model is specifically the matching degree between the reconstructed watermark model and the original watermark information, that is, the watermark matching degree. The proportion of watermark tampering positions in the large model is specifically the proportion of the number of tampered positions in the watermark to the total number of watermark positions.

[0086] Multiplying the CPU utilization rate of the large model and the inference duration of the large model by their corresponding weight factors respectively and then adding them together specifically means multiplying the CPU utilization rate of the large model by the weight factor corresponding to the predefined CPU utilization rate in the model monitoring information library to obtain the first performance impact degree value; multiplying the inference duration of the large model by the weight factor corresponding to the predefined inference duration in the model monitoring information library to obtain the second performance impact degree value, and adding the first performance impact degree value and the second performance impact degree value to obtain the performance impact degree value of the large model.

[0087] The weight factor corresponding to the CPU utilization rate and the weight factor corresponding to the inference duration are both obtained by extracting from the model monitoring information library, and the mapping relationship therein can be a one-to-one or many-to-one relationship. For example, the CPU utilization rate and the inference duration respectively form a mapping set with the weight factors corresponding to the predefined CPU utilization rate and the weight factors corresponding to the inference duration in the model monitoring information library, and the real-time CPU utilization rate and inference duration are brought into the mapping set to obtain the weight factor corresponding to the CPU utilization rate and the weight factor corresponding to the inference duration.

[0088] Perform unitless normalization processing on the watermark matching degree of the large model, the proportion of watermark tampering positions in the large model, and the performance impact degree value of the large model respectively, and then perform weighted aggregation processing in sequence to obtain the feature integrity index of the large model. The specific analysis method is as follows:

[0089] In the formula, is the feature integrity index of the large model, is the watermark matching degree of the large model, is the proportion of watermark tampering positions in the large model, is the performance impact degree value of the large model, is the weight parameter corresponding to the predefined watermark matching degree in the model monitoring information library, is the weight parameter corresponding to the predefined proportion of watermark tampering positions in the model monitoring information library, is the weight parameter corresponding to the predefined performance impact degree value in the model monitoring information library.

[0090] The weight parameters corresponding to the watermark matching degree, the weight parameters corresponding to the proportion of the watermark tampering position, and the weight parameters corresponding to the performance impact degree value are all extracted from the model monitoring information library. The mapping relationship therein can be one-to-one or many-to-one. For example, the watermark matching degree, the proportion of the watermark tampering position, and the performance impact degree value respectively form a mapping set with the weight parameters corresponding to the watermark matching degree, the weight parameters corresponding to the proportion of the watermark tampering position, and the weight parameters corresponding to the performance impact degree value preset in the model monitoring information library. The real-time watermark matching degree, the proportion of the watermark tampering position, and the performance impact degree value are brought into the mapping set to obtain the weight parameters corresponding to the watermark matching degree, the weight parameters corresponding to the proportion of the watermark tampering position, and the weight parameters corresponding to the performance impact degree value.

[0091] In this embodiment, through the multivariate analysis of the watermark matching degree, the proportion of the watermark tampering position, and the performance impact degree value, specifically, the correlation between these variables is considered. There is a negative correlation between the watermark matching degree and the proportion of the watermark tampering position. The higher the watermark matching degree, the more similar the reconstructed watermark is to the original watermark. Then, the proportion of the watermark tampering position is often lower, which means that the possibility of the model being tampered with is smaller and the feature integrity of the large model is greater. On the contrary, the lower the watermark matching degree, the higher the proportion of the watermark tampering position, indicating that the model may have suffered more tampering and the feature integrity of the large model is smaller. At the same time, when the watermark matching degree is high, it indicates that the model performance is relatively stable at this time, and the performance impact degree value may be lower, increasing the feature integrity of the model. If the watermark matching degree is low, it may mean that the model has been tampered with, which will cause the model to run abnormally, increase the CPU utilization rate and the inference duration, and then increase the performance impact degree value, bringing a negative impact to the feature integrity of the large model.

[0092] In this embodiment, the specific process of the security monitoring of the large model is as Figure 4 shown Figure 4 This is the detailed flow chart of the steps of the present invention, which is used to express the detailed process of the embodiments of the present invention. First, the input data of the large model is collected, and then the comparison data is generated and the difference value between the two is calculated. The branch is made by judging whether the difference value is normal: if it is normal, the large model inference is entered, and then the watermark verification is carried out. If the verification passes, it is executed normally; if it does not pass, it enters the security processing. If the difference value is abnormal, the security verification is entered and the weight verification is carried out. If the verification passes, it is executed normally; if it does not pass, it also enters the security processing. Finally, the security processing points to the function restriction or the emergency response, forming a complete processing logic.

[0093] Refer to Figure 2As shown in the figure, the second aspect of the present invention provides a security monitoring system based on a large model embedded in an intelligent screen, including: a comparison data domain generation module, a data domain difference evaluation module, an authorized data domain determination module, a large model security monitoring module, and a model monitoring information library. Among them, the model monitoring information library is used to store preset values of various factors.

[0094] The comparison data domain generation module is connected to the data domain difference evaluation module, the data domain difference evaluation module is connected to the authorized data domain determination module, the authorized data domain determination module is connected to the large model security monitoring module, and the data domain difference evaluation module, the authorized data domain determination module, and the large model security monitoring module are all connected to the model monitoring information library.

[0095] The comparison data domain generation module is used to collect multi-modal input data of the current large model, form the input task data domain of the large model, and generate the input task comparison data domain of the large model based on the generative adversarial network.

[0096] The data domain difference evaluation module is used to compare the input task data domain of the large model with the input task comparison data domain of the large model, extract the data domain comparison information, and evaluate the data domain difference degree value of the large model.

[0097] The authorized data domain determination module is used to compare the data domain difference degree value of the large model with each predefined preset data domain difference threshold interval, and determine whether the input task data domain of the large model is the authorized task data domain of the large model.

[0098] The large model security monitoring module is used to make the large model reason about the authorized task data domain, monitor the security of the embedding process of the large model in real time, and finally make security adjustments to the reasoning process of the large model.

[0099] The above content is only an example and explanation of the structure of the present invention. Those skilled in the art of this technology can make various modifications or supplements to the described specific embodiments or use similar methods to replace them. As long as they do not deviate from the structure of the invention or exceed the scope defined by the present invention, they should all belong to the protection scope of the present invention.

Claims

1. A security monitoring method based on a large model embedded in an intelligent screen, characterized in that, Including: Collect the multi-modal input data of the current large model to form the input task data domain of the large model, and based on the generative adversarial network, generate the input task comparison data domain of the large model; Compare the input task data domain of the large model with the input task comparison data domain of the large model, extract the data domain comparison information, and evaluate the data domain difference degree value of the large model; Compare the data domain difference degree value of the large model with each predefined preset data domain difference threshold interval to determine whether the input task data domain of the large model is the authorized task data domain of the large model; The large model performs reasoning on the authorized task data domain, monitors the security of the embedding process of the large model in real time, and finally makes security adjustments to the reasoning process of the large model.

2. The security monitoring method based on the large model embedded in the intelligent screen according to claim 1, characterized in that: The specific evaluation process of the data domain difference degree value of the large model is as follows: The data domain comparison information includes the mean difference of each feature dimension of the large model data domain and the relative entropy of the large model data domain; Collect the generation information of the input task comparison data domain of the large model, including the discriminator loss value of the large model and the generator loss value of the large model; Multiply the discriminator loss value of the large model and the generator loss value of the large model by the corresponding weight parameters respectively and add them to obtain the influence degree value of the large model's generation device, and match it with the difference degree influence factor corresponding to each predefined generation device influence degree value interval to obtain the difference degree influence factor of the large model; Perform unitless normalization processing on the mean difference of each feature dimension of the large model data domain and the relative entropy of the large model data domain respectively, and perform data aggregation processing with the difference degree influence factor of the large model to obtain the data domain difference degree value of the large model.

3. The security monitoring method based on the large model embedded in the intelligent screen according to claim 2, wherein: The specific method for determining whether the input task data domain of the large model is the authorized task data domain of the large model is to compare the data domain difference degree value of the large model with each preset data domain difference threshold interval to obtain the difference degree comparison result, and based on the difference degree comparison result, determine whether the input task data domain of the large model is the authorized task data domain of the large model; If the data domain difference degree value of the large model belongs to the first difference threshold interval, it is determined that the input task data domain is a normal input, and the input task data domain of the large model is recorded as the authorized task data domain of the large model; If the data domain difference degree value of the large model belongs to the second difference threshold interval, weight verification is triggered; If the data domain difference degree value of the large model belongs to the third difference threshold interval, it is determined that the current input task data domain is an abnormal input and a warning is triggered.

4. The security monitoring method based on the large model embedded in the intelligent screen according to claim 3, wherein: The specific analysis process of the weight verification is as follows: Use the reinforcement learning controller to screen the filters that affect the functionality of the large model, denoted as key filters, and extract the original weight parameters corresponding to the key filters; Compare the original weight parameters with the predefined weight parameter confusion interval, and record the original weight parameters belonging to the weight parameter confusion interval as the key weights of the large model. The reinforcement learning controller generates a key weight mask for the key weights; Compare the key weights of the large model with the key weight mask, evaluate the weight confusion variation degree of the large model, and continue to determine whether the input task data domain of the large model is the authorized task data domain of the large model.

5. The security monitoring method based on the large model embedded in the intelligent screen according to claim 4, wherein: The process of evaluating the weight confusion variability of the large model is as follows: Collect the key weight comparison information of the large model, including the cosine similarity of each key weight of the large model, the relative difference ratio value of each key weight of the large model, and the proportion of key weight confusion of the large model; Collect the number of algorithm iterations of the reinforcement learning controller, match the weight confusion impact elements corresponding to each pre-defined algorithm iteration number interval to obtain the weight confusion impact elements of the large model; Perform unitless normalization processing on the cosine similarity of each key weight of the large model, the relative difference ratio value of each key weight of the large model, and the proportion of key weight confusion of the large model, and perform data aggregation processing with the weight confusion impact elements of the large model to obtain the weight confusion variability of the large model.

6. The security monitoring method based on the large model embedded in the intelligent screen according to claim 4, wherein: The process of continuing to determine whether the input task data domain of the large model is the authorized task data domain of the large model is as follows: Compare the weight confusion variability of the large model with each pre-set weight variability threshold interval. If the weight confusion variability of the large model belongs to the first variability threshold interval, it is determined that the weight verification of the large model is normal, and the input task data domain of the large model is recorded as the authorized task data domain of the large model; If the weight confusion variability of the large model belongs to the second variability threshold interval, extract the mask parameter index and the allowable variability range in the authorized key stored in the current large model, and compare them with the position index and variability range of the actual variability parameter between the input task data domain of the large model and the input task comparison data domain of the large model. If both the position index and variability range of the actual variability parameter belong to the mask parameter index and the allowable variability range in the authorized key, it is determined that the actual variability parameter is a reasonable difference within the authorized range, update the local authorization status to temporary trust, and record the input task data domain of the large model as the authorized task data domain of the large model. Otherwise, it is determined that the actual variability parameter is an unreasonable variability, and an emergency response is triggered; If the weight confusion variability of the large model belongs to the third variability threshold interval, the input task data domain of the large model is the unauthorized task data domain of the large model, and it is determined that the large model is used abnormally, triggering an emergency response.

7. The security monitoring method based on the large model embedded in the intelligent screen according to claim 1, wherein: The process of performing real-time security monitoring on the embedding process of the large model is as follows: Perform a watermark embedding operation on the authorized task data domain of the large model to generate a watermark model; Perform real-time security monitoring on the embedding process of the large model. Periodically extract the watermark information from the secondary bits of the authorized task data domain of the large model, reconstruct the watermark model, and compare the watermark model with the reconstructed watermark model. If the watermark model is the same as the reconstructed watermark model, continue the security monitoring. If the watermark model is different from the reconstructed watermark model, collect the execution feature information of the large model, determine the feature integrity index of the large model, and perform security adjustment on the inference process of the large model.

8. The security monitoring method based on the large model embedded in the intelligent screen according to claim 7, wherein: The process of performing security adjustment on the inference process of the large model is as follows: Compare the feature integrity index of the large model with each predefined feature integrity index interval. If the feature integrity index of the large model belongs to the first integrity index interval, record the state of the different watermarks to the cloud management platform last time, and execute the preset security enhancement measures; If the feature integrity index of the large model belongs to the second integrity index interval, temporarily disable the function of the large model with specific labels, only retain the interaction function of non-specific labels, and shorten the watermark detection period to the preset length for continuously tracking the change trend of the feature integrity index; If the feature integrity index of the large model belongs to the third integrity index interval, it is determined that there is unauthorized tampering behavior during the execution of the large model. Locate the position of the tampered parameter through hash comparison, and restore the parameter using the original weight index stored by the key.

9. The security monitoring method based on the large model embedded in the intelligent screen according to claim 8, wherein: The specific determination process of the feature integrity index of the large model is as follows: The execution feature information of the large model includes the watermark matching degree of the large model and the proportion of the watermark tampering position of the large model; Extract the performance information of the large model, including the CPU utilization rate of the large model and the inference duration of the large model; Multiply and add the CPU utilization rate of the large model and the inference duration of the large model with the corresponding weight factors respectively, and obtain and record it as the performance impact degree value of the large model; Perform unitless normalization processing on the watermark matching degree of the large model, the proportion of the watermark tampering position of the large model, and the performance impact degree value of the large model respectively, and perform weighted aggregation processing in sequence to obtain the feature integrity index of the large model.

10. A system applying the security monitoring method based on the large model embedded in the intelligent screen as described in any one of claims 1-9, characterized in that: Including: A comparison data domain generation module for collecting multi-modal input data of the current large model to form an input task data domain of the large model, and generating an input task comparison data domain of the large model based on a generative adversarial network; A data domain difference evaluation module for comparing the input task data domain of the large model with the input task comparison data domain of the large model, extracting data domain comparison information, and evaluating the data domain difference degree value of the large model; An authorized data domain determination module for comparing the data domain difference degree value of the large model with each predefined preset data domain difference threshold interval to determine whether the input task data domain of the large model is the authorized task data domain of the large model; A large model security monitoring module for the large model to perform inference on the authorized task data domain, perform real-time security monitoring on the embedding process of the large model, and finally perform security adjustment on the inference process of the large model.

Citation Information

Patent Citations

  • Abnormal data detection method and device, electronic equipment and storage medium

    CN115563568A

  • Container running state monitoring method, intelligent computing cloud operating system and computing platform

    CN118012719A

  • Wheel set anomaly detection method and system based on generative adversarial network

    CN119290434A

  • Network security dynamic early warning method and system based on multi-source data fusion

    CN119402253A

  • Industrial scene safety assessment method and system based on generative adversarial network

    CN119940930A