Encrypted traffic intrusion detection method and system based on personalized federal learning
By adopting a personalized federated learning method in encrypted traffic scenarios, using dynamic regularization terms and feature vector distribution similarity optimization model, combined with CKKS homomorphic encryption, the detection accuracy and privacy issues in encrypted traffic detection are solved, and efficient and secure intrusion detection is achieved.
Patent Information
- Application Number
- CN202510542983.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-28
- Publication Date
- 2025-07-11
AI Technical Summary
In encrypted traffic scenarios, traditional intrusion detection technology faces zero-day attack powerlessness and high false positive rate. Deep learning models have the risk of user privacy leakage in centralized learning mode, and data heterogeneity leads to a decrease in detection accuracy.
Using a method based on personalized federated learning, dynamic regularization terms are added in the local training stage of the client, dynamic weighting is performed when inheriting the global model, collaborative training is performed by calculating the distribution similarity of feature vectors, and model transmission is used using CKKS homomorphic encryption algorithm to ensure data privacy.
It improves detection accuracy and adaptability in encrypted traffic scenarios, reduces false alarms and missed alarms, guarantees data privacy, and improves model training efficiency and detection performance.
Smart Images

Figure CN120301671A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer network security, and particularly to an encrypted traffic intrusion detection method and system based on personalized federated learning. Background Art
[0002] With the rapid development of the Internet, network security issues have become increasingly severe, especially the intrusion detection in the encrypted traffic scenario faces many challenges. On the one hand, traditional signature-based intrusion detection technologies are powerless against zero-day attacks. Although anomaly detection-based methods are gradually emerging, they have a high false positive rate when dealing with a large amount of dynamic data. On the other hand, deep learning models applied to intrusion detection are becoming increasingly complex, and there is a serious risk of user privacy leakage in the data collection stage under the centralized learning mode. At the same time, network data in different regions has a high degree of heterogeneity. Factors such as different devices, user habits, and traffic peak periods lead to non-independent and identically distributed data, making it difficult for traditional global models to accurately fit all data.
[0003] In such a background, federated learning emerged as a distributed machine learning paradigm. It allows participants to jointly model without sharing data. The central server does not need to collect the original traffic data. Each client trains the model based on the local dataset and only transmits the model parameters or gradients to the server, which ensures data privacy to a certain extent. However, in the application of federated learning to intrusion detection in the encrypted traffic scenario, there are still problems such as large communication overhead and a decrease in detection accuracy due to data heterogeneity. Summary of the Invention
[0004] In order to overcome the deficiencies of the prior art, the purpose of the present invention is to provide an encrypted traffic intrusion detection method and system based on personalized federated learning.
[0005] To achieve the above purpose, the present invention provides the following solutions:
[0006] An encrypted traffic intrusion detection method based on personalized federated learning, comprising:
[0007] S1. In the local training stage of the client, add a dynamic regularization term to the initial local model for model training to obtain a locally enhanced model with enhanced feature extraction;
[0008] S2. In the stage of inheriting the global model, the client inherits the locally enhanced model based on the local dataset to obtain an inherited local model;
[0009] S3. In the collaborative training stage, calculate the similarity of the feature vector distributions between clients and optimize the corresponding local model in the target client with uneven data distribution based on the similarity of the feature vector distributions to obtain an optimized local model;
[0010] S4. In the homomorphic encryption transmission stage, each client encrypts the final local model and uploads it to the server.
[0011] Preferably, in S1, a dynamic regularization term is added to the loss function of the local model for model training to obtain a local model with enhanced feature extraction; wherein, the formula of the dynamic regularization term is:
[0012]
[0013] where θ i represents the parameters of the feature extractor of client i, c is the global feature centroid, is the global feature centroid corresponding to class y l , λ is the dynamic hyperparameter weight, n i represents the number of training data samples owned by client i, l is the index of the training data samples of client i, and the value range is from 1 to n i , represents the feature vector extracted from the input sample x i by the feature extractor based on the parameter θ l , is the square of the L2 norm, calculates the difference degree between the feature vector output by the feature extractor and the global feature centroid of the corresponding class.
[0014] Preferably, in S2, the shallow layer of the local model with enhanced feature extraction inherits the global model, and the deep layer performs dynamic weighted inheritance according to the situation of the global model and the local model on the local dataset of the client.
[0015] Preferably, in S2, the deep layer of the local model with enhanced feature extraction performs dynamic weighted inheritance according to the evaluation metric values of the global model and the local model on the local dataset of the client; wherein, the calculation method of the inheritance weight is:
[0016]
[0017] where w1 represents the inheritance weight of the global model, w2 represents the inheritance weight of the local model, A represents the evaluation metric value of the global model on the local dataset, and B represents the evaluation metric value of the local model on the local dataset.
[0018] Preferably, in S3, each client uses the KL divergence to measure the distribution similarity of the feature vectors and uploads the KL divergence to the central server; wherein, the KL divergence calculation formula is:
[0019]
[0020] Among them, P i represents the feature vector distribution of client i, and P j represents the feature vector distribution of client j. D KL (P i ||P j ) represents the KL divergence between client i and client j.
[0021] Preferably, in S3, after the central server receives the KL divergences of each client, by comparing the KL divergence values between clients with the threshold T, the clients with KL divergence values greater than the threshold T are selected as clients with uneven data distribution, and the clients with KL divergence values less than or equal to the threshold T are regarded as similar clients; the deep models obtained by training the similar clients are acquired, and these models are sent to the target clients with uneven data distribution to optimize the target clients.
[0022] Preferably, in S4, the client encrypts the gradient or parameter update of the local model using the CKKS homomorphic encryption algorithm and uploads it to the server. The encrypted data undergoes aggregation calculation within the ciphertext space through the CKKS homomorphic encryption algorithm to generate the final global model.
[0023] Preferably, in S4, the gradient or parameter update g of the client's local model i is mapped to the polynomial ring R through a complex vector and controlled by applying a scaling factor Δ, and finally an integer polynomial is generated and encrypted into the ciphertext ct i ; where the form of the ciphertext is:
[0024]
[0025] where v i is a random ternary polynomial, e i0 , e i1 is the error term, m i is the plaintext gradient, Δ is the scaling factor, a and b are public keys, and q represents the modulus of the current homomorphic level;
[0026] After the server receives the encrypted models uploaded by all clients, a weighted aggregation operation is performed to obtain the aggregated global ciphertext model; where the aggregated ciphertext ct agg is:
[0027]
[0028] where K is the number of clients, w i is the weight of client i, and it satisfies
[0029] The client decrypts the aggregated global encrypted model using the private key to obtain the aggregation result.
[0030] The present invention also provides an encrypted traffic intrusion detection system based on personalized federated learning, including:
[0031] A training module, used in the local training stage of the client, to add a dynamic regularization term to the initial local model for model training to obtain a locally enhanced model with enhanced feature extraction.
[0032] An inheritance module, used in the global model inheritance stage, where the client inherits the locally enhanced model based on the local dataset to obtain an inherited local model.
[0033] A collaborative training module, used in the collaborative training stage, to calculate the similarity of the feature vector distributions between clients and optimize the corresponding local model in the target client with uneven data distribution based on the similarity of the feature vector distributions to obtain an optimized local model.
[0034] An encrypted transmission module, used in the homomorphic encryption transmission stage, where each client encrypts the final local model and uploads it to the server.
[0035] The present invention also provides a computer-readable storage medium, on which a computer program is stored. The computer program, when executed by a processor, implements the steps in the above-mentioned encrypted traffic intrusion detection method based on personalized federated learning.
[0036] The beneficial effects of the encrypted traffic intrusion detection method based on personalized federated learning provided by the present invention are as follows: Compared with the prior art, by adding a dynamic regularization term in the local training stage of the client, considering the uniqueness of the client data, the model can better adapt to the differences in the data distributions of different clients, and improve the detection accuracy in the encrypted traffic scenario with high data heterogeneity. At the same time, when the client inherits the global model, the shallow layer inherits the global model to obtain general features, and the deep layer determines the personalized inheritance method according to the local data, and inherits the global model and the local model through dynamic weighting, so that the model can not only learn the global commonality but also highlight the local characteristics, improving the adaptability and detection ability of the model to the local encrypted traffic data. And each client uses the same pre-trained feature extractor, calculates the similarity of the feature vector distribution and uploads it. The central server filters relevant clients based on this and transmits the deep model. The target client receives and processes these models. This collaborative training method not only improves the model training efficiency but also further improves the overall detection performance by sharing relevant model information. Finally, the present invention adopts the CKKS homomorphic encryption algorithm to ensure the security of the client model parameters during the upload and aggregation processes in the federated learning framework. At the same time, through weighted aggregation and hierarchical homomorphic design, the model training efficiency and detection accuracy in the encrypted traffic scenario are effectively improved. In addition, the rescaling mechanism controls the noise accumulation in multiple rounds of training, ensuring that the model can maintain high accuracy and reliability in an environment with high data heterogeneity while ensuring privacy. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0038] Figure 1 is the flowchart of the encrypted traffic intrusion detection method based on personalized federated learning provided by the present invention;
[0039] Figure 2 is the internal flowchart of the local training stage of the client provided by the present invention;
[0040] Figure 3 is the internal flowchart of the stage of inheriting the global model provided by the present invention;
[0041] Figure 4 is the internal flowchart of the collaborative training stage of the client provided by the present invention;
[0042] Figure 5 is the internal flowchart of the homomorphic encryption transmission stage provided by the present invention. Detailed implementation manners
[0043] The technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0044] The mention of "embodiment" in this article means that the specific features, structures or characteristics described in connection with the embodiment may be included in at least one embodiment of the present application. The phrase appears in various positions in the specification and does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.
[0045] The terms "first", "second", "third", "fourth", etc. in the specification and claims of the present application and the accompanying drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a series of steps, processes, methods, etc. included do not limit to the listed steps, but optionally further include steps not listed, or optionally further include other step elements inherent to these processes, methods, products or devices.
[0046] To make the above objects, features and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific implementation manners.
[0047] Please refer to Figures 1-5 , an encrypted traffic intrusion detection method based on personalized federated learning, including:
[0048] S1. In the local training stage of the client, add a dynamic regularization term to the initial local model for model training to obtain a local model with enhanced feature extraction.
[0049] Specifically, a dynamic regularization term is added during the local training phase of the client, aiming to enable the model to balance global information and personalized needs during training; during the global model inheritance phase, the client determines the personalized and shared parts of the model inheritance based on local data, enabling the model to better adapt to the characteristics of local data; during the collaborative training phase, each client achieves cross-client information sharing and collaboration by using the same pre-trained feature extractor, calculating the similarity of feature vector distributions, etc., improving the overall performance of the model. The overall process combines personalized learning and collaborative training, leveraging both the uniqueness of local data and sharing information through the method of federated learning, improving the accuracy and adaptability of the model in intrusion detection in the encrypted traffic scenario, while protecting local data privacy and avoiding risks brought by the transmission of raw data in the network.
[0050] The formula for the dynamic regularization term is as follows:
[0051]
[0052] Where, θ i represents the parameters of the feature extractor of client i, c is the global feature centroid, is the global feature centroid corresponding to class y l , λ is the dynamic hyperparameter weight, n i represents the number of training data samples owned by client i, l is the index of the training data samples of client i, and the value range is from 1 to n i , represents the feature vector extracted from the input sample x i by the feature extractor based on the parameter θ l , is the square of the L2 norm, also known as the square of the Euclidean distance, calculates the difference degree between the feature vector output by the feature extractor and the corresponding class global feature centroid . Summing up this difference degree for all samples and multiplying by yields the regularization term
[0053] Specifically, the dynamic regularization term formula constrains the model training by calculating the difference between the feature vectors output by the feature extractor and the global feature centroids of the corresponding categories, summing up this difference for all samples, and then multiplying by a specific coefficient. Among them, the client feature extractor parameters determine the way to extract features from the input data; the global feature centroids represent the feature centers of the same type of data of all clients; the dynamic hyperparameter weights are used to balance the supervised learning loss and the regularization loss; the number of client training data samples and the sample indices are used to traverse and calculate the differences of all samples. Adding the dynamic regularization term helps the model focus on learning basic features in the initial stage of training, pay attention to personalized features as the training progresses, enhances the adaptability of the model to different client data, improves the generalization ability of the model, thus improving the accuracy of intrusion detection and reducing false alarms and missed detections.
[0054] It should be noted that the feature extractor is placed in the shallow layer of the deep neural network, and low-dimensional feature embeddings are extracted from the input encrypted traffic data by using the characteristics of the shallow network. The shallow network can usually capture the basic and general features of the data, providing key basic information for subsequent model training and classification. This design enables the model to quickly extract the key basic features of the encrypted traffic data, improves the efficiency and accuracy of feature extraction, provides a good feature basis for the subsequent intrusion detection classification task, and helps to improve the overall detection performance of the model.
[0055] S2. In the stage of inheriting the global model, the client inherits the locally enhanced model of the feature extraction according to the local dataset to obtain the inherited local model;
[0056] In step S2, the shallow layer of the model inherits the global model, and the deep layer determines the personalized inheritance method according to the local data.
[0057] Specifically, when inheriting the global model, the shallow layer of the model inherits the global model because the shallow layer model mainly learns general features, and the shallow layer of the global model can provide widely applicable feature representations; the deep layer determines the personalized inheritance method according to the local data. The deep layer model focuses more on the specific processing of the task and the learning of the unique features of the local data. Adjusting according to the local data can better adapt to the characteristics of the local encrypted traffic data. This inheritance method takes into account the generality and personalization of the model, enabling the model to obtain general intrusion detection features from the global model and optimize for the local data, improving the detection accuracy of the model for the local encrypted traffic data and reducing the detection errors caused by data differences.
[0058] In step S2, after a certain number of iterations, according to the situation of the global model and the local model on the local dataset of the client, the deep model dynamically weights and inherits the global model and the local model. Let the evaluation index value of the global model on the local dataset be A, and the evaluation index value of the local model on the local dataset be B. The calculation methods of the inheritance weight w1 of the global model and the inheritance weight w2 of the local model in the deep model are as follows:
[0059]
[0060] Specifically, after a certain number of iterations, according to the evaluation index values (such as accuracy, recall, etc.) of the global model and the local model on the local dataset of the client, the deep model dynamically weights and inherits. By calculating the evaluation index values of the global model and the local model on the local dataset, the inheritance weight of the global model and the inheritance weight of the local model are determined, so that the model can dynamically adjust the proportion of the two according to the actual effect during inheritance. The dynamic weighted inheritance method enables the model to flexibly adjust the dependence on the global model and the local model according to the training effect in different stages, further optimizing the adaptability of the model to local data and improving the performance of the model on the local dataset, so as to more accurately detect intrusion behaviors in local encrypted traffic.
[0061] S3. In the collaborative training stage, calculate the similarity of the feature vector distributions between clients and optimize the corresponding local model in the target client with uneven data distribution based on the similarity of the feature vector distributions to obtain an optimized local model;
[0062] In step S3, each client uses the KL divergence to measure the similarity of the feature vector distributions. For the feature vector distribution P of client i i and the feature vector distribution P of client j j , the KL divergence calculation formula is:
[0063]
[0064] And upload the KL divergence to the central server.
[0065] Specifically, each client uses the KL divergence to measure the similarity of the feature vector distributions. The KL divergence can quantify the difference between two probability distributions. By calculating the difference in the feature vector distributions between clients, the similarity degree of the client data is judged, and the calculation result is uploaded to the central server to provide a basis for the central server to screen similar clients in the future. Using the KL divergence to measure similarity can accurately find clients with similar data distributions, providing an effective data matching basis for collaborative training, helping to achieve cross-client knowledge sharing and model optimization without sharing the original data, and improving the adaptability of the overall model to different data distributions and intrusion detection capabilities.
[0066] Furthermore, when uploading the KL divergence to the central server, encryption processing is performed. A specific encryption algorithm is used to encrypt the data to prevent it from being stolen or tampered with during data transmission, ensuring the security and privacy of the data. The encryption processing guarantees the security of data transmission, avoids privacy issues caused by the leakage of KL divergence data, enables the client not to worry about data security risks when participating in collaborative training, enhances the reliability and stability of the system, and promotes the application of federated learning in encrypted traffic scenarios.
[0067] In step S3, after the central server receives the similarity metrics of each client, it filters out the similar clients of the clients with severely uneven data distributions, obtains the deep models trained by the similar clients, and sends these models to the target clients with uneven data distributions. When filtering out the similar clients, a similarity threshold is set to T. If the KL divergence value D KL (P i ||P j ) ≤ T between client i and client j, then client j is determined to be a similar client of client i. Then, the deep models trained by the similar clients are obtained and sent to the target clients with uneven data distributions to help the target clients optimize their own models. This filtering and model transmission mechanism can utilize the model information of similar clients to supplement the model training of the target clients, alleviate the impact of uneven data distribution on model performance, improve the intrusion detection ability of the model in complex data distribution situations, and enhance the robustness of the model.
[0068] In step S3, the target client processes the models received from other clients by means of weighted merging. The weighted merging method refers to the weighted merging method of the deep models in the step of inheriting the global model. Assume that the target client receives models from m similar clients, and the merging weight of the k-th similar client model in the target client is w k , and Then, the calculation formula for the model parameters θ merge of the target client after merging is:
[0069]
[0070] where θ k is the parameter of the k-th similar client model.
[0071] Furthermore, the target client processes the models of other clients it receives through weighted merging, and the weighted merging method refers to the weighted merging method of the deep model in the step of inheriting the global model. According to the situation of each similar client model, a merging weight is assigned to it, and the sum of the merging weights of all similar client models is 1. Finally, the merged model parameters are calculated through weighted summation. The weighted merging method can integrate the model advantages of multiple similar clients, further optimize the model of the target client, improve the performance and generalization ability of the model, enable it to more accurately identify the attack categories in encrypted traffic in the intrusion detection task, and enhance the overall detection effect.
[0072] Specifically, the dynamic hyperparameter weight λ takes a small value at the beginning of training and increases as training progresses, enabling the model to focus on learning global general features in the early stage of training and gradually pay attention to local personalized features in the later stage, realizing the dynamic optimization of the model learning process, improving the generalization ability of the model and its adaptability to the encrypted traffic scenario.
[0073] S4. In the homomorphic encryption transmission stage, each client encrypts its final local model and uploads it to the server.
[0074] In step S4, the client uses the CKKS homomorphic encryption algorithm to encrypt the model gradients or parameter updates trained locally and uploads them to the server. The encrypted model performs aggregation calculations in the ciphertext space through CKKS homomorphic encryption operations to generate a global model.
[0075] Specifically, the gradient or parameter update g of the client's local model i is mapped to the polynomial ring R through a complex vector and the scaling factor Δ is applied for precision control, and finally an integer polynomial is generated and encrypted into a ciphertext ct i . Among them, the form of the ciphertext is:
[0076]
[0077] Among them, v i is a random ternary polynomial, e i0 , e i1 is an error term, m i is the plaintext gradient, Δ is the scaling factor, and a, b are public keys.
[0078] After the server receives the encrypted models uploaded by all clients, it performs a weighted aggregation operation to calculate the encrypted global model. Let the weight of each client be w i , then the aggregated ciphertext ct agg is:
[0079]
[0080] where K is the number of clients, and w i is the weight of client i, and satisfies Since CKKS supports additive homomorphicity between ciphertexts, the aggregation operation can be completed without decryption.
[0081] To ensure the accuracy of the encrypted transmission process, the hierarchical homomorphic design and rescaling mechanism of CKKS ensure that the noise level remains within a controllable range after each multiplication by setting the modulus chain Q = q0·q1·····q L , ensuring that the noise level remains within a controllable range after each multiplication. After each multiplication operation, a rescaling step is performed to eliminate the additional noise introduced by the multiplication and reduce the noise level to a manageable range. The specific rescaling operation is as follows:
[0082]
[0083] where q′ = q / q l is the new modulus after modulus reduction.
[0084] In addition, the CKKS algorithm ensures that the noise growth is effectively controlled during multiple rounds of training and avoids affecting the accuracy of the decryption result due to excessive noise by presetting the calculation depth L and the length of the modulus chain. In each round of training, the following noise upper bound condition needs to be satisfied:
[0085] q l ≥4·(2N) (L+1) ·B (L+1)
[0086] where B is the upper bound of the noise for a single operation, N is the polynomial degree, and L is the calculation depth. This condition ensures that the accuracy of the decryption result is not affected by noise during decryption and guarantees the accuracy of the model.
[0087] Finally, the client uses the private key to decrypt the aggregated global ciphertext model ct global to obtain the approximate aggregated result g global , and restores it to a floating-point parameter vector. Due to the approximate calculation characteristics of CKKS, the error between the decryption result and the plaintext aggregation is limited to ∈≤Δ -1 ·B, which is within the tolerance range of floating-point operations in federated learning and will not significantly affect the convergence of the model. Through this homomorphic encryption transmission mechanism, it is ensured that when the client performs model aggregation and transmission, data privacy is effectively protected, and at the same time, cross-client collaborative training and model optimization in the encrypted traffic detection scenario are realized, improving the adaptability of the model to data distribution differences and the overall detection ability.
[0088] The present invention also provides an encrypted traffic intrusion detection system based on personalized federated learning, including:
[0089] A training module, which is used to add a dynamic regularization term to an initial local model during the local training phase of a client to perform model training and obtain a locally enhanced model with enhanced feature extraction;
[0090] An inheritance module, which is used to inherit the locally enhanced model with enhanced feature extraction according to a local dataset by the client during the global model inheritance phase to obtain an inherited local model;
[0091] A collaborative training module, which is used to calculate the similarity of feature vector distributions among clients and optimize the corresponding local model in a target client with uneven data distribution based on the similarity of feature vector distributions to obtain an optimized local model during the collaborative training phase;
[0092] An encrypted transmission module, which is used to encrypt the final local models of each client and upload them to a server during the homomorphic encryption transmission phase.
[0093] Compared with the prior art, the beneficial effects of an encrypted traffic intrusion detection system based on personalized federated learning provided by the present invention are the same as those of the encrypted traffic intrusion detection method based on personalized federated learning described in the above technical solution, and will not be elaborated here.
[0094] The present invention also provides an electronic device, including a bus, a transceiver, a memory, a processor, and a computer program stored on the memory and executable on the processor. The transceiver, the memory, and the processor are connected through the bus. When the computer program is executed by the processor, it implements the steps in the above-mentioned encrypted traffic intrusion detection method based on personalized federated learning. Compared with the prior art, the beneficial effects of an electronic device provided by the present invention are the same as those of the encrypted traffic intrusion detection method based on personalized federated learning described in the above technical solution, and will not be elaborated here.
[0095] The present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the steps in the above-mentioned encrypted traffic intrusion detection method based on personalized federated learning. Compared with the prior art, the beneficial effects of a computer-readable storage medium provided by the present invention are the same as those of the encrypted traffic intrusion detection method based on personalized federated learning described in the above technical solution, and will not be elaborated here.
[0096] In the present specification, each embodiment is described in a progressive manner. The key points of each embodiment are the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For the methods disclosed in the embodiments, since they correspond to the devices disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the device part.
[0097] In this article, specific examples are used to elaborate on the principles and implementation modes of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation modes and application scopes. To sum up, the content of this specification should not be construed as a limitation on the present invention.
Claims
1. An encrypted traffic intrusion detection method based on personalized federated learning, characterized in that Including: S1. In the local training stage of the client, a dynamic regularization term is added to the initial local model for model training to obtain a locally enhanced model with enhanced feature extraction; S2. In the stage of inheriting the global model, the client inherits the locally enhanced model with enhanced feature extraction according to the local dataset to obtain an inherited local model; S3. In the collaborative training stage, the similarity of the feature vector distribution among clients is calculated, and the local model corresponding to the target client with uneven data distribution is optimized based on the similarity of the feature vector distribution to obtain an optimized local model; S4. In the homomorphic encryption transmission stage, each client encrypts the final local model and uploads it to the server.
2. The encrypted traffic intrusion detection method based on personalized federated learning according to claim 1, wherein In S1, a dynamic regularization term is added to the loss function of the local model for model training to obtain a locally enhanced model with enhanced feature extraction; wherein, the formula of the dynamic regularization term is: Among them, θ i represents the parameters of the feature extractor of client i, c is the global feature centroid, is the global feature centroid corresponding to class y l , λ is the dynamic hyperparameter weight, n i represents the number of training data samples owned by client i, l is the index of the training data samples of client i, and the value range is from 1 to n i , represents the feature vector extracted from the input sample x i by the feature extractor based on the parameter θ l , is the square of the L2 norm, calculates the degree of difference between the feature vector output by the feature extractor and the global feature centroid of the corresponding class.
3. The encrypted traffic intrusion detection method based on personalized federated learning according to claim 2, wherein, In S2, the shallow layer of the locally enhanced model with enhanced feature extraction inherits the global model, and the deep layer performs dynamic weighted inheritance according to the situation of the global model and the local model on the local dataset of the client.
4. The encrypted traffic intrusion detection method based on personalized federated learning according to claim 3, wherein, In S2, the deep layer of the locally enhanced model with enhanced feature extraction performs dynamic weighted inheritance according to the evaluation index values of the global model and the local model on the local dataset of the client; wherein, the calculation method of the inheritance weight is: wherein, w1 represents the inheritance weight of the global model, w2 represents the inheritance weight of the local model, A represents the evaluation index value of the global model on the local dataset, and B represents the evaluation index value of the local model on the local dataset.
5. The encrypted traffic intrusion detection method based on personalized federated learning according to claim 4, characterized in that, In S3, each client uses the KL divergence to measure the similarity of the feature vector distribution and uploads the KL divergence to the central server; wherein, the calculation formula of the KL divergence is: Among them, P i represents the feature vector distribution of client i, and P j represents the feature vector distribution of client j. D KL (P i ||P j ) represents the KL divergence between client i and client j.
6. The encrypted traffic intrusion detection method based on personalized federated learning according to claim 5, wherein, In S3, after the central server receives the KL divergences of each client, by comparing the magnitudes of the KL divergence values among clients with the threshold T, the clients with KL divergence values greater than the threshold T are selected as clients with uneven data distribution, and the clients with KL divergence values less than or equal to the threshold T are used as similar clients; Obtain the deep models trained by the similar clients and send these models to the target client with uneven data distribution to optimize the target client.
7. The encrypted traffic intrusion detection method based on personalized federated learning according to claim 6, characterized in that, In S4, the client encrypts the gradients or parameter updates of the local model using the CKKS homomorphic encryption algorithm and uploads them to the server. The encrypted data undergoes aggregation calculation in the ciphertext space through the CKKS homomorphic encryption algorithm to generate the final global model.
8. The method for detecting encrypted traffic intrusion based on personalized federated learning according to claim 7, wherein In S4, the gradient or parameter update g of the local model of the client i is mapped to the polynomial ring R through a complex vector and controlled by applying a scaling factor Δ, and finally an integer polynomial is generated and encrypted into a ciphertext ct i ; where the form of the ciphertext is: Among them, v i is a random ternary polynomial, e i0 , e i1 is an error term, m i is the plaintext gradient, Δ is a scaling factor, a and b are public keys, and q represents the modulus of the current homomorphic level; After receiving all the encrypted models uploaded by the clients on the server side, perform a weighted aggregation operation to obtain the aggregated global ciphertext model; among them, the aggregated ciphertext ct agg is as follows: Among them, K is the number of clients, and w i is the weight of client i, and it satisfies The client decrypts the aggregated global ciphertext model using the private key to obtain the aggregation result.
9. An encrypted traffic intrusion detection system based on personalized federated learning, characterized in that, Including: A training module, used for adding a dynamic regularization term to the initial local model in the local training stage of the client for model training to obtain a locally enhanced model with enhanced feature extraction; An inheritance module, used for the client to inherit the locally enhanced model with enhanced feature extraction according to the local dataset in the stage of inheriting the global model to obtain an inherited local model; A collaborative training module, which is used in the collaborative training stage to calculate the similarity of feature vector distributions among clients and optimize the corresponding local model in the target client with uneven data distribution based on the similarity of feature vector distributions to obtain an optimized local model; An encrypted transmission module, which is used in the homomorphic encryption transmission stage for each client to encrypt the final local model and upload it to the server.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps in the encrypted traffic intrusion detection method based on personalized federated learning according to any one of claims 1-8.