Neural network model encryption method and system for hierarchical encryption

Through the neural network model encryption method of hierarchical encryption and multi-dimensional integrity verification, the security threats of the model in the development, transmission, storage and use process are solved, and the precise protection of key hierarchies and core parameters is achieved, the security and reliability of the model are improved, and the stable security guarantee is ensured to adapt to different application environments.

CN120337266APending Publication Date: 2025-07-18JIANGSU DAOYUNYIN TECH CO LTD
View PDF 0 Cites 5 Cited by

Patent Information

Application Number
CN202510516716.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-23
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

In the development, transmission, storage and use of neural network models, neural network models face security threats such as code plagiarism, cyber attacks and data leakage, resulting in the model being copied, tampered with, and sensitive information leaked, seriously affecting innovation enthusiasm and corporate reputation.

Method used

The neural network model encryption method of hierarchical encryption is adopted to build a model hierarchical key spectrum by constructing a model hierarchical sensitivity map and parameter importance network, selectively encrypting the key hierarchy and core parameters, and combining multi-dimensional integrity checks and perform state security monitoring, a dynamic evolutionary protection mechanism is established.

Benefits of technology

It realizes accurate protection of neural network models, improves security and reliability, prevents the model from being stolen and tampered, reduces the impact of performance, and can continuously deal with new attacks and maintain long-term effectiveness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337266A_ABST
    Figure CN120337266A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of neural network model security, and discloses a hierarchical encryption neural network model encryption method and system, and the method comprises the steps: obtaining model architecture data, hierarchical topology data and weight parameter data; constructing a model hierarchy sensitivity map for vulnerability analysis to obtain a key horizon map; constructing a parameter importance network for sensitivity analysis to obtain a core parameter set; constructing a model protection strategy knowledge base; performing equipment fingerprint analysis to obtain equipment unique identification data; performing matrix transformation detection to obtain a hierarchical transformation function family; generating a hierarchical key pedigree; performing hierarchical encryption analysis to obtain a hierarchical encryption matrix; performing hierarchical protection conversion by using the hierarchical encryption matrix to obtain a model protection version; performing multi-dimensional integrity verification to obtain a target encryption model; monitoring the operation safety state of the model in real time, and optimizing a hierarchical encryption matrix; and the safety of the model is greatly improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of neural network model security. More specifically, the present invention relates to an encryption method and system for a neural network model with hierarchical encryption. Background Art

[0002] With the rapid development of artificial intelligence and big data technologies, various models are widely used in fields such as medical care, finance, and industrial production, playing an irreplaceable and important role. However, during the development stage, model code and training data are core assets. The complex open-source environment has led to frequent code plagiarism. Competitors may obtain the undisclosed model code and training data through improper means, such as infiltrating the team or maliciously purchasing information. Once the core code is leaked, opponents can quickly replicate the model functions, seize the market share, render the efforts of the development team in vain, seriously dampen the enthusiasm for innovation, and hinder the innovative development of the industry. When the model is transmitted, network attackers can easily intercept the model data transmitted between different servers and devices by taking advantage of network protocol vulnerabilities and sniffing technologies. They can not only tamper with the data, causing misdiagnosis in medical diagnoses and endangering the lives of patients, and triggering incorrect investment decisions in financial risk assessments, resulting in huge losses. They can also steal the data for illegal business activities, infringing on intellectual property rights and economic interests. There are also hidden dangers in the storage link. Hackers launch attacks by taking advantage of vulnerabilities in server operating systems and application programs. Once the server is breached, the stored model data is at risk of leakage. Sensitive information such as patient privacy information in medical models and customer financial data in financial models is leaked, which not only triggers a trust crisis but also exposes enterprises to legal lawsuits and huge compensation, seriously damaging the reputation and operation of enterprises. In the model usage link, malicious users input special data to spy on the internal information of the model. If the core secrets are cracked, the security and reliability of the model will be completely lost, possibly triggering serious security incidents.

[0003] In view of this, the present invention proposes an encryption method and system for a neural network model with hierarchical encryption to solve the above problems. Summary of the Invention

[0004] To overcome the above-mentioned defects of the prior art and to achieve the above object, the present invention provides the following technical solution: An encryption method for a neural network model with hierarchical encryption, comprising:

[0005] Step S1: Obtain model architecture data, hierarchical topology data, and weight parameter data; construct a model layer sensitivity map based on the model architecture data, perform vulnerability analysis on the model layer sensitivity map to obtain a key layer map; construct a parameter importance network based on the hierarchical topology data and the weight parameter data, perform sensitivity analysis on the parameter importance network to obtain a core parameter set; construct a model protection strategy knowledge base according to the key layer map and the core parameter set;

[0006] Step S2: Perform device fingerprint analysis based on the model protection policy knowledge base to obtain device unique identification data; perform matrix transformation detection on the key layers in the model protection policy knowledge base to obtain a family of hierarchical transformation functions; perform key generation based on the device unique identification data and the family of hierarchical transformation functions, identify the optimal protection algorithm combination, and obtain a hierarchical key pedigree;

[0007] Step S3: Perform hierarchical encryption analysis according to the hierarchical key pedigree to obtain a hierarchical encryption matrix; apply the hierarchical encryption matrix to the model key layer parameters for hierarchical protection conversion to obtain a model protection version; perform model multi-dimensional integrity verification based on the model protection version to obtain a target encrypted model;

[0008] Step S4: Perform real-time monitoring on the security status of the target encrypted model during use to obtain execution state security data; optimize the hierarchical encryption matrix based on the execution state security data to achieve dynamic evolution of the encrypted model protection mechanism.

[0009] This application provides a neural network model encryption system with hierarchical encryption for performing the neural network model encryption method with hierarchical encryption as described above, including:

[0010] Data analysis module: Obtain model architecture data, hierarchical topology data, and weight parameter data; construct a model layer sensitivity map based on the model architecture data, perform vulnerability analysis on the model layer sensitivity map to obtain a key layer map; construct a parameter importance network based on the hierarchical topology data and the weight parameter data, perform sensitivity analysis on the parameter importance network to obtain a core parameter set; construct a model protection policy knowledge base according to the key layer map and the core parameter set;

[0011] Key construction module: Perform device fingerprint analysis based on the model protection policy knowledge base to obtain device unique identification data; perform matrix transformation detection on the key layers in the model protection policy knowledge base to obtain a family of hierarchical transformation functions; perform key generation based on the device unique identification data and the family of hierarchical transformation functions, identify the optimal protection algorithm combination, and obtain a hierarchical key pedigree;

[0012] Hierarchical encryption module: Perform hierarchical encryption analysis according to the hierarchical key pedigree to obtain a hierarchical encryption matrix; apply the hierarchical encryption matrix to the model key layer parameters for hierarchical protection conversion to obtain a model protection version; perform model multi-dimensional integrity verification based on the model protection version to obtain a target encrypted model;

[0013] Monitoring and Optimization Module: Monitors the security status of the target encryption model in real time during use to obtain execution-state security data; optimizes the hierarchical encryption matrix based on the execution-state security data to achieve the dynamic evolution of the encrypted model protection mechanism.

[0014] Technical Effects and Advantages of the Encryption Method and System for a Hierarchically Encrypted Neural Network Model of the Present Invention:

[0015] Through the comprehensive analysis of model architecture data, hierarchical topology data, and weight parameter data, the present invention realizes the accurate identification and protection of key layers and core parameters of the neural network model, making the security protection of the model more targeted and effective. By constructing a model hierarchical sensitivity map and a parameter importance network, the system can scientifically evaluate the importance of different layers and parameters, thereby reasonably allocating computing resources during the encryption process and avoiding the performance overhead problem caused by full-model encryption. By constructing an inter-layer key isolation mechanism, the independence and security of keys are ensured. This key generation mechanism based on device characteristics binds the model to a specific device, significantly increasing the difficulty of the model being used by unauthorized devices and effectively preventing the model from being stolen and illegally copied. The design of hierarchical keys enables other layers to remain secure even if the keys of some layers are cracked, greatly enhancing the overall protection ability of the model. Through the protection transformation of the key parameters of the model's critical layers by the hierarchical encryption matrix, this method realizes selective encryption, minimizing the impact on the model's inference performance while ensuring security. The multi-dimensional integrity verification mechanism combines multiple dimensions such as structural integrity, parameter integrity, call integrity, and execution integrity to comprehensively ensure the authenticity and reliability of the model, and can effectively identify and resist model tampering attacks. Through the real-time monitoring and analysis of execution-state security data, a dynamically evolving protection mechanism is established, which can adaptively optimize the encryption strategy according to the actual usage scenario and security threats. This self-evolving ability enables the model protection mechanism to continuously cope with new attack methods and maintain long-term effectiveness. At the same time, the execution-state security monitoring can also evaluate the adaptability of the protection strategy in scenarios such as inference acceleration, distributed deployment, and quantization to ensure stable and reliable security protection in different application environments. Description of the Drawings

[0016] Figure 1 Schematic diagram of an encryption method for a hierarchically encrypted neural network model of the present invention;

[0017] Figure 2 Schematic diagram of an encryption system for a hierarchically encrypted neural network model of the present invention. Detailed Embodiments

[0018] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0019] Embodiment 1;

[0020] Please refer to Figure 1 As shown, a method for encrypting a hierarchical encryption neural network model in this embodiment includes: Step S1: Obtain model architecture data, hierarchical topology data, and weight parameter data; construct a model layer sensitivity map based on the model architecture data, perform vulnerability analysis on the model layer sensitivity map to obtain a key layer map; construct a parameter importance network based on the hierarchical topology data and the weight parameter data, perform sensitivity analysis on the parameter importance network to obtain a core parameter set; construct a model protection strategy knowledge base according to the key layer map and the core parameter set;

[0021] Step S2: Perform device fingerprint analysis based on the model protection strategy knowledge base to obtain device unique identifier data; perform matrix transformation detection on the key layers in the model protection strategy knowledge base to obtain a family of hierarchical transformation functions; perform key generation based on the device unique identifier data and the family of hierarchical transformation functions, identify the optimal protection algorithm combination, and obtain a hierarchical key pedigree;

[0022] Step S3: Perform hierarchical encryption analysis according to the hierarchical key pedigree to obtain a hierarchical encryption matrix; apply the hierarchical encryption matrix to the model key layer parameters for hierarchical protection conversion to obtain a model protection version; perform model multi-dimensional integrity verification based on the model protection version to obtain a target encrypted model;

[0023] Step S4: Real-time monitor the security status of the target encrypted model during use to obtain execution state security data; optimize the hierarchical encryption matrix based on the execution state security data to realize the dynamic evolution of the encrypted model protection mechanism.

[0024] Preferably, step S1 includes:

[0025] Collect model structure description data, inter-layer connection data, and computational graph data to form model architecture data; collect hierarchical type data, parameter scale data, activation function data, and gradient flow data to form hierarchical topology data; obtain weight matrix data, bias vector data, and quantization parameter data to form weight parameter data;

[0026] Perform a structural sensitivity analysis on the model architecture data to obtain a hierarchical influence spectrum diagram; perform an importance ranking on the hierarchical influence spectrum diagram to obtain a hierarchical importance sequence; construct a model hierarchical sensitivity map based on the hierarchical importance sequence;

[0027] Perform a parameter dependence analysis on the hierarchical topology data to obtain an initial parameter association network; perform a sparsity analysis and sensitivity extraction on the weight parameter data to obtain parameter sensitivity data; construct a parameter importance network based on the initial parameter association network and the parameter sensitivity data;

[0028] Use the influence propagation algorithm to identify key nodes in the model hierarchical sensitivity map to obtain a key layer map;

[0029] Use the spectral clustering algorithm to perform a parameter group analysis on the parameter importance network to obtain a parameter importance cluster; perform a threshold screening based on the parameter importance cluster to obtain a core parameter set;

[0030] Construct a protection strategy ontology framework, and map the key layer map and the core parameter set to the protection strategy ontology framework to form an initial protection strategy library;

[0031] Use the security level encoding technology to add risk attributes to the initial protection strategy library to obtain a risk - graded protection strategy library; perform a strategy reasoning and extension on the risk - graded protection strategy library to obtain a model protection strategy knowledge base.

[0032] Specifically, neural network model data collection is first carried out, including three types of key data: model architecture data, hierarchical topology data, and weight parameter data. Model architecture data describes the overall structure of the neural network and the inter-layer connection relationships, which are obtained by parsing the model definition file or calling the model introspection API (a programming interface that provides users with methods to access the internal attributes and states of the model). For example, for a typical convolutional neural network (CNN), the sequential arrangement of convolutional layers, pooling layers, and fully connected layers and their interconnection methods can be obtained to form a complete computational graph. Among them, the model structure description data includes basic information such as the type and number of layers, network depth and width; the inter-layer connection data describes the connection methods between layers, including sequential connections, skip connections, and residual connections, etc.; the computational graph data represents the model as a directed acyclic graph (DAG), facilitating the analysis of data flow and gradient flow. Hierarchical topology data focuses on the specific characteristics of each layer in the network, including: hierarchical type data (such as convolutional layer, fully connected layer, attention layer, etc.), parameter scale data (such as the number of parameters, tensor dimensions, etc.), activation function data (such as ReLU, Sigmoid, GELU, etc.), and gradient flow data (describing the flow path and intensity of gradients during backpropagation). For example, for the attention layer, the number of heads of multi-head attention, hidden layer dimension, attention score calculation method, etc. need to be recorded. Weight parameter data contains the actual parameter values of the model, including weight matrix data, bias vector data, and quantization parameter data. For a trained model, these data constitute the core intellectual property of the model and are the key objects of protection. For example, in the convolutional layer, the weight matrix data is represented as a four-dimensional tensor, including four dimensions: the number of output channels, the number of input channels, the height of the convolutional kernel, and the width; the bias vector data is a one-dimensional tensor with a length equal to the number of output channels; the quantization parameter data includes the quantization ratio and zero-point offset of weights and activation values, which are used to support low-precision inference.

[0033] Conduct a structural sensitivity analysis on the model architecture data to identify the key structures that have a greater impact on the model performance. The structural sensitivity analysis adopts a multi-perspective computational graph analysis method, and evaluates the model from three perspectives: forward propagation, backward propagation, and gradient transmission. For the forward propagation perspective, analyze the direct contribution of each layer to the output; for the backward propagation perspective, analyze the impact of each layer on the gradient update; for the gradient transmission perspective, analyze the flow and attenuation of the gradient in the network. Through the comprehensive analysis of these three perspectives, a hierarchical influence spectrum diagram is generated, which quantifies the degree of influence of each network layer on the overall model performance. Specifically, for the computational graph G=(V,E) under each perspective, where V represents the node set (network layer) and E represents the edge set (inter-layer connection), calculate various centrality indicators of the nodes, including degree centrality (DC) and betweenness centrality (BC). Among them: Degree centrality reflects the number of direct connections of the node: DC(v)=|N(v)|, where N(v) is the set of nodes directly connected to node v; betweenness centrality reflects the importance of the node as an information transmission "bridge": where Set{s,t} is the number of shortest paths from node s to node t, and Set{s,t}(v) is the number of shortest paths from node s to node t passing through node v. Standardize the above centrality indicators to obtain the standardized centrality indicators. Subsequently, through weighted average and variance analysis, comprehensively evaluate and analyze the variability of the centrality indicators from the three perspectives to obtain a set of stability evaluation indicators. For example, the weighted average M_i and standard deviation S_i of the centrality indicators of each layer under different perspectives can be calculated to evaluate the overall importance and stability of this layer. Based on the standardized centrality indicators and the set of stability evaluation indicators, construct a hierarchical influence spectrum diagram. Sort the importance of the hierarchical influence spectrum diagram to obtain a hierarchical importance sequence. The importance ranking is based on the comprehensive influence score Among them, α and β are weight coefficients, satisfying that the sum of weights is 1, and respectively controlling the contributions of average importance and stability to the final ranking. The hierarchical importance sequence is arranged in descending order. The layers at the front of the sequence have the greatest impact on the model performance and become the primary protection targets. A model hierarchical sensitivity map is constructed based on the hierarchical importance sequence. This map is a weighted directed graph G'=(V',E',W), where V' represents each layer in the model, E' represents the inter-layer dependency relationship, and W represents the weight of the edge (dependency strength). By analyzing the mutual influence and dependency relationship between each layer in the hierarchical importance sequence, a more refined sensitivity map is constructed. This map not only contains the importance information of each layer but also reflects the mutual influence between layers. Perform parameter dependency analysis on the hierarchical topology data to obtain the initial network of parameter associations. Parameter dependency analysis aims to identify the dependency relationships between different layers and different parameter groups in the network. By constructing a parameter association graph G_p=(V_p,E_p), where V_p represents the parameter group (such as the weight matrix of a certain layer), and E_p represents the dependency relationship between parameter groups, quantified as the correlation coefficient or mutual information. For example, the mutual information between two groups of parameters X and Y where p(x,y) is the joint probability distribution of parameters x and y, p(x) is the marginal probability distribution of parameter x, and p(y) is the marginal probability distribution of parameter y. Perform sparsity analysis and sensitivity extraction on the weight parameter data to obtain parameter sensitivity data. Sparsity analysis evaluates the distribution characteristics of parameters, including indicators such as the L0 norm (number of non-zero elements), L1 norm (sum of absolute values), and L2 norm (Euclidean norm). Sensitivity extraction evaluates the impact of parameter changes on the model output through perturbation analysis. Specifically, perform a small perturbation δ on the parameter θ_i and calculate the output change rate where \(e_i\) is a unit vector and \(f(\theta)\) is the model output. The parameter sensitivity data combines the above sparsity index and sensitivity index (output change rate) through weighted combination to generate the overall sensitivity score of the parameter. Based on the parameter correlation initial network and the parameter sensitivity data, a parameter importance network is constructed. The parameter importance network is a weighted graph \(G_w=(V_w, E_w, W_w)\), where \(V_w\) represents the parameter group, \(E_w\) represents the correlation relationship between parameter groups, and \(W_w\) represents the weight of the edge, comprehensively considering the sensitivity and correlation strength of the parameters. Through this network, the mutual influence and overall importance structure between parameters can be intuitively represented. The influence propagation algorithm is used to identify key nodes in the model hierarchical sensitivity map to obtain the key layer map. The influence propagation algorithm identifies the set of key nodes that can maximize the influence by simulating the propagation process of information in the network. Commonly used influence propagation algorithms include the independent cascade model (IC) and the linear threshold model (LT). Taking the independent cascade model as an example, given an initial set of activated nodes \(STA\), at each step \(Step\), each newly activated node \(Node\) independently tries to activate its unactivated neighbor nodes \(UN\) with probability \(p_{uv}\). Through multiple simulations, the initial node set that can activate the most nodes is selected as the key node. The key layer map is a subgraph, and the nodes in the key layer map represent the identified key layer nodes, and the edges represent the connection relationships between the nodes. The spectral clustering algorithm is used to perform parameter group analysis on the parameter importance network to obtain the parameter importance clusters. The spectral clustering algorithm clusters the nodes in the graph into tightly connected subgroups based on the eigenvectors of the Laplacian matrix of the graph. The specific steps include: constructing the Laplacian matrix of the parameter importance network; calculating the eigenvalues and eigenvectors of the Laplacian matrix; selecting the eigenvectors corresponding to the \(k\) smallest non-zero eigenvalues to form the eigenmatrix; performing \(k\)-means clustering on the row vectors of the eigenmatrix to obtain the parameter importance clusters. Based on the parameter importance clusters, threshold screening is performed to obtain the core parameter set. Threshold screening sets the screening threshold according to the importance score and cluster characteristics of the parameters, and selects the parameters with importance greater than the screening threshold as the core parameters. The screening threshold can be determined by analyzing the distribution characteristics of the importance scores, such as using the percentile method based on the cumulative distribution function. The core parameter set constitutes the most critical subset of parameters in the model and is the key object of protection. A protection strategy ontology framework is constructed, and the key layer map and the core parameter set are mapped to the protection strategy ontology framework to form an initial protection strategy library. The protection strategy ontology framework is a structured knowledge representation system, including a concept layer, a relationship layer, and an instance layer. The concept layer defines concepts such as protection objects, protection methods, and risk types; the relationship layer defines the relationships between concepts, such as "application", "resistance", etc.; the instance layer contains specific protection strategy instances.By mapping the key layer diagrams and the core parameter sets to the ontology framework, an initial protection policy library is generated. Each policy record in this library contains information such as the protected object, the applicable protection method, and the expected effect. The risk attributes are added to the initial protection policy library using the security level coding technology to obtain a risk - graded protection policy library. The security level coding is based on standards such as the Common Vulnerability Scoring System, and quantitatively evaluates the risks faced by each protected object, including dimensions such as the risk impact scope, attack complexity, and exploitation difficulty. The risk - graded protection policy library adds a risk level attribute to each protection policy, facilitating the adjustment of the protection intensity according to the risk level. The policy inference and extension are performed on the risk - graded protection policy library to obtain a model protection policy knowledge base. The policy inference and extension are based on description logic and rule - based reasoning technologies, and new protection policies are generated through the existing policies. For example, if policy A1 is applicable to protected object X1, and object Y1 has similar risk characteristics to X1, then it can be inferred that policy A1 is also applicable to object Y1. The model protection policy knowledge base is a complete knowledge system, containing multi - aspect information such as protected objects, protection methods, risk assessment, and policy selection, providing decision - making support for subsequent model protection.

[0034] Preferably, step S2 includes:

[0035] Obtain the hardware fingerprint data, operation environment feature data, and runtime identification data from the target device, and construct a device identification feature vector;

[0036] Based on the device identification feature vector and the built - in security seed, construct a hybrid identity authentication model, and perform identity construction based on the hybrid identity authentication model to obtain the device unique identification data;

[0037] Extract the key layer sequence from the model protection policy knowledge base, construct a hierarchical protection mapping diagram, and perform priority analysis on the hierarchical protection mapping diagram to obtain a hierarchical protection priority sequence;

[0038] Match the hierarchical protection priority sequence with the matrix transformation algorithm, identify the optimal transformation function, and obtain a family of hierarchical transformation functions;

[0039] Perform parameter mapping on the device unique identification data and the family of hierarchical transformation functions to obtain the initial key material;

[0040] Based on the initial key material, construct a key derivation function, identify the best key generation strategy, and obtain a hierarchical key sequence;

[0041] Perform collision - resistant strengthening and entropy enhancement processing on the hierarchical key sequence, construct an inter - layer key isolation mechanism, and obtain a hierarchical key pedigree.

[0042] Specifically, first, device fingerprint analysis is carried out. By collecting the hardware information, software environment characteristics, and runtime status of the target device (the device where the model is deployed), a unique device identifier is constructed. The hardware fingerprint data includes hardware unique identifiers such as CPUID, MAC address, and device serial number; the operation environment characteristic data includes the type and version of the operating system, the version of the system library, driver information, etc.; the runtime identifier data includes dynamic information such as system startup time, running process list, and memory layout characteristics. For example, on a mobile device, the SIM card ID, IMEI code, sensor calibration parameters, etc. can be obtained as hardware fingerprints; in a server environment, the motherboard serial number, disk ID, network card MAC address, etc. can be obtained. These raw data are processed through feature extraction and dimensionality reduction to construct a device identifier feature vector. To enhance security, the feature vector can be hashed and obfuscated to reduce reversibility. Based on the device identifier feature vector and the built-in security seed, a hybrid identity authentication model is constructed. The built-in security seed is a random byte sequence pre-embedded in the model or application program, serving as an additional security factor for device authentication. The hybrid identity authentication model combines static features and dynamic features to improve the security and reliability of identity authentication. The construction of the hybrid identity authentication model is based on multi-factor fusion technology and can be expressed as a function: Hde = Freg(V_device, S_seed, T), where V_device is the device feature vector, S_seed is the security seed, and T is the time factor. The authentication model is usually implemented using cryptographic hash functions, HMAC, or authentication algorithms based on elliptic curves. For example, the HMAC-SHA256 algorithm can be used, with the security seed as the key and the device feature vector as the message, to generate a device authentication identifier. Based on the hybrid identity authentication model, identity construction is carried out to obtain device unique identifier data. The device unique identifier data is a byte sequence of a fixed length, with uniqueness, unpredictability, and anti-tampering properties, and is used for subsequent key generation and device binding. In practical applications, the device unique identifier may need to be updated regularly to cope with changes in the device environment, so metadata such as version number and timestamp can be introduced. Extract the key layer sequence from the model protection policy knowledge base to construct a hierarchical protection mapping graph. The key layer sequence is a list of model layers sorted by importance. The hierarchical protection mapping graph is a bipartite graph:

[0043] G_map = (V_layer, V_protection, E_map), where V_layer represents the set of model layer nodes, V_protection represents the set of protection method nodes, and E_map represents the mapping relationship between the layer and the protection method. For example, for the convolutional layer, it may be mapped to the "weight matrix decomposition" protection method; for the fully connected layer, it may be mapped to the "parameter permutation" protection method. Perform a priority analysis on the hierarchical protection mapping graph to obtain the hierarchical protection priority sequence. The priority analysis assigns a protection priority score to each layer based on factors such as the importance of the layer, the risk level, and the effectiveness of the protection method. The hierarchical protection priority sequence is a list of layers arranged in descending order of the priority score, ensuring that the most important layer receives the highest level of protection. Perform a matrix transformation algorithm matching on the hierarchical protection priority sequence to identify the optimal transformation function and obtain the family of hierarchical transformation functions. The matrix transformation algorithm matching process selects the most suitable algorithm from a predefined transformation algorithm library according to the characteristics of each layer (such as parameter shape, sparsity, numerical distribution, etc.) and security requirements. The transformation algorithm library contains various matrix transformation methods, such as SVD decomposition, orthogonal transformation, permutation transformation, affine transformation, etc. For example, for the weight matrix Wei, the reverse difficulty can be increased through SVD decomposition; for the convolutional kernel, the channel order can be changed through permutation transformation while maintaining functional equivalence. The family of hierarchical transformation functions is a set of mathematical transformation functions, each function corresponding to a matrix transformation method and parameter-optimized for a specific layer type. For example, the transformation function can be in the form of:

[0044] The affine transformation of \(T_i(Wei)=MTA\times Wei\times MTB + MTC\), where \(MTA\) and \(MTB\) are invertible matrices, and \(MTC\) is an offset matrix. These transformation functions must satisfy invertibility to ensure that the model functions are not affected. Map the device unique identifier data to the parameters of the hierarchical transformation function family to obtain the initial key material. The parameter mapping process decomposes and expands the device unique identifier data to generate the parameter values required by the transformation function. For example, for the affine transformation, specific numerical values need to be generated for the invertible matrix and the offset matrix. Parameter mapping can be achieved through cryptographic hash functions and pseudo-random number generators to ensure the unpredictability and device binding of the parameter values. The initial key material is a set of original key data, containing the parameter values and control information required by each layer of transformation functions. Based on the initial key material, construct a key derivation function, identify the optimal key generation strategy, and obtain the hierarchical key sequence. A key derivation function (KDF) is an algorithm that generates keys for specific purposes from the initial key material, such as HKDF or PBKDF2. The key generation strategy includes configurations such as key length, update frequency, and derivation method. The hierarchical key sequence is a set of ordered keys corresponding to the encryption keys of different critical layers. Each key may contain multiple sub-keys for different encryption operations. Perform collision resistance strengthening and entropy enhancement processing on the hierarchical key sequence, construct an inter-layer key isolation mechanism, and obtain the hierarchical key pedigree. Collision resistance strengthening aims to ensure sufficient differences between keys of different layers to prevent the derivation of other keys due to the leakage of one key. Entropy enhancement processing improves the cryptographic strength by increasing the randomness and unpredictability of the keys. Perform a hash expansion transformation on the hierarchical key sequence to increase the key entropy value and obtain a high-entropy key set. The hash expansion transformation transforms the original key through multiple rounds of hash functions to generate a longer and higher-entropy key. For example, the SHAKE-256 expandable output function can be used: \(K'_i = SHAKE-256(K_i, L)\); where \(K_i\) is the original key, \(L\) is the target output length, and \(K'_i\) is the output key. By adjusting the output length \(L\), the key length requirements of different encryption algorithms can be met. Perform key isolation analysis based on the high-entropy key set to ensure that the minimum Hamming distance between keys of different levels exceeds the security threshold and obtain the key interval data. The Hamming distance is an indicator that measures the number of different characters at corresponding positions in two equal-length strings. For any two keys \(K'_i\) and \(K'_j\) at different levels, calculate their Hamming distance, and the Hamming distance is greater than the preset security threshold. The key interval data is a matrix, and the elements in the matrix represent the Hamming distance between key pairs. Based on the composite hash chain technology, construct a forward security mechanism for the high-entropy key set to obtain a time-sequential security key chain. The composite hash chain is a one-way function chain structure, where the \((m + 1)\)-th element is obtained by calculating the \(m\)-th element through a hash function. This structure ensures forward security, that is, even if subsequent keys are leaked, the previously used keys cannot be derived.The time-sequential security key chain adds security protection in the time dimension and supports dynamic update and version control of keys. Based on the time-sequential security key chain and key interval data for correlation analysis, the correlation metric factors between different keys are calculated, including mutual information, correlation coefficient, and collision probability, to obtain the key independence quantization index. The mutual information measures the degree of information sharing between two keys; the correlation coefficient quantifies the linear correlation between keys; the collision probability represents the probability that two keys generate the same value. These indicators together constitute a comprehensive evaluation of key independence. Based on the key independence quantization index, a hierarchical dependency graph is constructed to form a hierarchical key pedigree. The hierarchical dependency graph is a directed graph G_key = (V_key, E_key), where V_key represents the key nodes at each layer and E_key represents the dependency relationship between keys. The dependency relationship is based on the key generation mechanism and usage scenario to ensure that the hierarchical structure of the keys is consistent with the hierarchical structure of the model. The hierarchical key pedigree is a complete key management system that contains the full life cycle information of key generation, storage, usage, and update, providing a cryptographic basis for the hierarchical encryption of the model.

[0045] Preferably, step S3 includes:

[0046] Based on the hierarchical key pedigree, construct a family of parameter transformation algorithms, design a transformation strategy specialized for each layer, and obtain a set of hierarchical encryption schemes;

[0047] Use matrix decomposition technology to construct a model protection transformation framework, and integrate the set of hierarchical encryption schemes into a hierarchical encryption matrix based on the model protection transformation framework;

[0048] Extract model parameter data from the model protection strategy knowledge base, and selectively encrypt the model parameter data using the hierarchical encryption matrix to obtain a set of protected parameters;

[0049] Fuse the set of protected parameters with the non-critical parameters in the original model to construct a model protection version;

[0050] Combine cryptographic checksum and watermarking technology to perform integrity verification on the model protection version to obtain an integrity verification mark;

[0051] Based on the integrity verification mark, construct a multi-level anti-tampering mechanism to ensure the security boundary of the model and obtain the target encrypted model.

[0052] Specifically, based on the hierarchical key pedigree, construct a family of parameter transformation algorithms and design specialized transformation strategies for different types of network layers. The family of parameter transformation algorithms is a set of mathematical transformation algorithms, and each algorithm transforms the parameters of a specific type of network layer. For example, for the convolutional layer, a transformation algorithm based on channel permutation and kernel decomposition can be designed; for the fully connected layer, a transformation algorithm based on matrix factorization and random projection can be designed; for the attention layer, a transformation algorithm based on multi-head recombination and position encoding obfuscation can be designed. Design layer-specific transformation strategies to optimize the parameters and behaviors of the transformation algorithms according to the characteristics and security requirements of each layer. For example, for the shallow convolutional layer, focus on hiding the kernel weights while retaining visual features; for the deep fully connected layer, focus on scrambling the weight distribution while maintaining the inference performance. The set of hierarchical encryption schemes is a set of encryption schemes, and each set of encryption schemes corresponds to the corresponding key layer in the model and contains information such as transformation algorithms, key application methods, and decryption mechanisms. Use matrix factorization technology to construct a model protection transformation framework. Matrix factorization technology decomposes the original parameter matrix into the product of multiple sub-matrices, and protects the original parameters by encrypting these sub-matrices. The model protection transformation framework defines the configuration such as the method of matrix factorization, parameter selection, and decomposition ratio, providing a unified framework for the protection of different layers. For example, the non-negative matrix factorization method. Integrate the set of hierarchical encryption schemes into a hierarchical encryption matrix based on the model protection transformation framework. The hierarchical encryption matrix M_enc is a structured encryption configuration that contains the encryption parameters, transformation functions, and key application strategies of each layer. For example, for a model with n key layers, the hierarchical encryption matrix can be represented as an n×n matrix, where M_enc[i,j] describes the influence or dependency of the encryption scheme of the i-th layer on the j-th layer. In this way, the unified management and coordinated optimization of the encryption of each layer of the model are achieved. Extract the model parameter data from the model protection strategy knowledge base to obtain the original parameter values to be protected. Apply the hierarchical encryption matrix to selectively encrypt the model parameter data to obtain a set of protected parameters. The selective encryption strategy applies different strengths of encryption methods to different parameters according to the importance and sensitivity of the parameters. For example, for core parameters, strong encryption methods may be used; for secondary parameters, lightweight obfuscation may be used. The set of protected parameters P_protected = {p′_1, p′_2,..., p′_m} is the set of encrypted parameters, where p′_m = Enc(p_m, K_m), and p′_m is the result of encrypting the original parameter p_m using the key K_m. Integrate the set of protected parameters with the non-critical parameters in the original model to construct a protected version of the model. The protected version of the model retains the inference function of the original model, but the key parameters have been encrypted and protected, increasing the difficulty of unauthorized access and reverse analysis.For example, for a neural network model {L_1, L_2, ..., L_r}, where L_r represents the r-th layer, a protected version {L′_1, L′_2, ..., L′_r} is constructed, where L′_r may be the original layer or the encrypted and protected layer. Combining cryptographic checksums and watermarking techniques, the integrity of the protected version of the model is verified to obtain an integrity verification tag. The cryptographic checksum calculates the digest value of the model through a secure hash function, which is used to detect unauthorized modifications. For example, the SHA-256 algorithm is used to calculate the hash value of the model as the digital fingerprint of the model. The watermarking technique embeds specific tags or patterns in the model for model traceability and ownership authentication. The watermark can be embedded in the model structure or parameters, such as embedding a specific bit pattern in the weight matrix or adding a specific trigger pattern to the model inference result. The integrity verification tag is a set of data that includes the hash value of the model, watermark information, and verification rules, etc., which are used for subsequent integrity verification. Based on the integrity verification tag, a multi-level anti-tampering mechanism is constructed to ensure the security boundary of the model, and the target encrypted model is obtained. The multi-level anti-tampering mechanism uses various technical means to prevent the model from being modified or misused without authorization. A multi-dimensional integrity verification framework is constructed, covering the dimensions of structural integrity, parameter integrity, call integrity, and execution integrity. The structural integrity dimension checks whether the architecture of the model has been modified; the parameter integrity dimension verifies whether the model parameters have been tampered with; the call integrity dimension monitors the call method and context of the model; the execution integrity dimension ensures that the execution environment and process of the model meet the expectations. Multiple hashing is performed on the integrity verification tag to obtain multiple hashing features. Multiple hashing uses different hash algorithms (such as SHA-256, SHA-3, BLAKE2, etc.) to calculate multiple hash values, increasing the robustness of the anti-tampering mechanism. The multiple hashing features are mapped to the multi-dimensional integrity verification framework to obtain a multi-dimensional integrity proof set. The multi-dimensional integrity proof set is a set of proof data used to verify the integrity of the model in each dimension. For example, the structural integrity proof may include the hash value of the model hierarchy; the parameter integrity proof may include the checksum of the key parameters; the call integrity proof may include the signature of the API call sequence; the execution integrity proof may include the verification result of the runtime environment. Threshold cryptography techniques are used to determine the verification weights of each dimension and each proof, and a hierarchical verification model is constructed. Threshold cryptography techniques are a method of distributing cryptographic operations to multiple participants, and the cryptographic operation can only be completed when a sufficient number of participants collaborate. In model verification, a (t1, n1) threshold mechanism can be set, requiring at least t1 out of n1 dimensions to pass the verification before the model integrity is considered guaranteed. The hierarchical verification model assigns different weights and verification strategies to different integrity dimensions according to security requirements and application scenarios. Policy analysis is performed based on the hierarchical verification model to obtain a hierarchical verification strategy.The hierarchical verification strategy is a set of verification rules and processes that adopt different verification methods and intensities for different usage scenarios and risk levels. For example, for low-risk scenarios, only the basic structural integrity may be verified; for high-risk scenarios, comprehensive multi-dimensional verification may be required. Applying the zero-knowledge proof mechanism to transform the hierarchical verification strategy generates the definition of the model security boundary. Zero-knowledge proof is a cryptographic technique that allows one party (the prover) to prove to another party (the verifier) that a certain statement is true without revealing any information other than the fact that the statement is true. Through zero-knowledge proof, the integrity and legality of the model can be proven without disclosing the sensitive information of the model. The model security boundary definition is a set of security policies and constraint conditions that clearly define requirements such as the usage scope of the model, access control, and security checks. The target encryption model is a fully protected neural network model with multiple security mechanisms such as hierarchical encryption protection, integrity verification, and security boundary control.

[0053] Preferably, step S4 includes:

[0054] Collect the behavioral characteristics and security event data during the use of the target encryption model by the user to form an execution-state security database;

[0055] Conduct security risk analysis based on the execution-state security database, identify the optimization direction of the protection mechanism, and obtain the protection enhancement parameters;

[0056] Apply the protection enhancement parameters to optimize the hierarchical encryption matrix to achieve the dynamic evolution of the model protection mechanism.

[0057] Specifically, design an execution - state security monitoring framework to comprehensively monitor the security status of the target encryption model during its use. The execution - state security monitoring framework consists of three main components: call compliance detection, parameter access pattern detection, and decryption request legitimacy detection. Call compliance detection monitors the call method and context of the model to determine whether it conforms to predefined compliance rules. For example, check the identity of the caller, call time, call frequency, etc.; Parameter access pattern detection analyzes the access behavior to model parameters and identifies abnormal access patterns. For example, detecting high - frequency access to specific parameters within a short period may imply a reverse - engineering attack; Decryption request legitimacy detection verifies the source and legitimacy of decryption requests to prevent unauthorized decryption operations. For example, verify the digital signature and timestamp of decryption requests. Through these detection components, collect the behavioral characteristics and security event data of users during the use of the target encryption model. Behavioral characteristics include information such as call patterns, access frequencies, usage scenarios, etc.; Security event data includes security - related events such as abnormal access, decryption failure, and integrity verification failure. These data are cleaned, standardized, and feature - extracted to form an execution - state security database. Trace the correlation between decryption operations and performance performance during the execution of the target encryption model to obtain performance impact assessment data. Decryption operations are a key step in the use of encryption models, and their performance directly affects the overall performance of the model. By measuring performance metrics (such as latency, throughput, memory occupancy, etc.) under different decryption strategies, evaluate the impact of decryption operations on the model execution efficiency. Performance impact assessment data contains multiple sets of performance test results, recording the performance performance under different protection strategies and decryption methods. Collect the application - scenario data of the model protection mechanism, analyze the adaptability of protection strategies in inference acceleration, distributed deployment, and quantization scenarios to obtain scenario adaptability assessment data. The inference acceleration scenario focuses on the performance performance of the model on hardware accelerators (such as GPUs, TPUs, NPUs, etc.); The distributed - deployment scenario focuses on the collaborative inference and secure communication of the model in a multi - node environment; The quantization scenario focuses on the protection effect of the model under low - precision representation. Scenario adaptability assessment data records the adaptability and effectiveness of the model protection mechanism in various application scenarios. Integrate performance impact assessment data and scenario adaptability assessment data to construct a comprehensive protection - effectiveness index and form an execution - state security database. The comprehensive protection - effectiveness index is a set of quantitative indicators that comprehensively evaluate the security, performance impact, and scenario adaptability of the model protection mechanism. The execution - state security database is a structured data warehouse that stores the behavioral characteristics, security events, and performance assessment data during the use of the model, providing data support for subsequent security risk analysis. Conduct security risk analysis based on the execution - state security database to identify potential vulnerabilities and improvement spaces in the protection mechanism. Security risk analysis uses multiple methods, such as statistical analysis, anomaly detection, pattern recognition, etc., to extract security risk information from the execution - state data.For example, potential attack patterns are identified through clustering analysis; attack trends and regularities are detected through time series analysis; and the associations between security events and usage behaviors are discovered through correlation analysis. The optimization directions of the protection mechanism are identified, and the protection areas that need to be strengthened and the encryption policies that need to be adjusted are determined. The optimization directions may include: enhancing the encryption intensity of specific layers, adjusting the key update frequency, optimizing the decryption process, adding anti-tampering detection points, etc. The protection enhancement parameters are a set of configuration parameters used to guide the optimization and adjustment of the protection mechanism. For example, the parameters may include: encryption intensity coefficient, key length, decryption trigger condition, integrity check frequency, etc. The hierarchical encryption matrix is optimized by applying the protection enhancement parameters, and the encryption schemes and parameter settings of each layer are adjusted. For example, for the layers that are frequently attacked, their encryption intensity and decryption complexity can be increased; for the layers sensitive to performance, their decryption algorithms can be optimized to reduce the performance impact. The optimization of the hierarchical encryption matrix is an iterative process, and through multiple adjustments and tests, the optimal balance between security and performance is found.

[0058] In this embodiment, through the comprehensive analysis of the model architecture data, hierarchical topology data, and weight parameter data, the accurate identification and protection of the key layers and core parameters of the neural network model are realized, making the security protection of the model more targeted and effective. By constructing the model layer sensitivity map and parameter importance network, the system can scientifically evaluate the importance of different layers and parameters, so as to reasonably allocate computing resources during the encryption process, avoiding the performance overhead problem caused by full-model encryption. By constructing an inter-layer key isolation mechanism, the independence and security of keys are ensured. This device-feature-based key generation mechanism binds the model to a specific device, significantly increasing the difficulty of the model being used by unauthorized devices and effectively preventing the model from being stolen and illegally copied. The design of hierarchical keys enables other layers to remain secure even if the keys of some layers are cracked, greatly enhancing the overall protection ability of the model. By protecting and transforming the key parameters of the model's key layers through the hierarchical encryption matrix, this method realizes selective encryption, minimizing the impact on the model's inference performance while ensuring security. The multi-dimensional integrity verification mechanism combines multiple dimensions such as structural integrity, parameter integrity, call integrity, and execution integrity, comprehensively ensuring the authenticity and reliability of the model, and can effectively identify and resist model tampering attacks. By monitoring and analyzing the execution-state security data in real time, a dynamically evolving protection mechanism is established, which can adaptively optimize the encryption policy according to the actual usage scenario and security threats. This self-evolving ability enables the model protection mechanism to continuously cope with new attack methods and maintain long-term effectiveness. At the same time, the execution-state security monitoring can also evaluate the adaptability of the protection strategy in scenarios such as inference acceleration, distributed deployment, and quantization, ensuring stable and reliable security protection in different application environments.

[0059] Embodiment 2;

[0060] Please refer toFigure 2 As shown in the figure, for the parts not described in detail in this embodiment, refer to the description of Embodiment 1. A neural network model encryption system with hierarchical encryption is provided, including:

[0061] Data analysis module: Obtain model architecture data, hierarchical topology data, and weight parameter data; construct a model layer sensitivity map based on the model architecture data, perform vulnerability analysis on the model layer sensitivity map to obtain a key layer map; construct a parameter importance network based on the hierarchical topology data and the weight parameter data, perform sensitivity analysis on the parameter importance network to obtain a core parameter set; construct a model protection strategy knowledge base according to the key layer map and the core parameter set;

[0062] Key construction module: Perform device fingerprint analysis based on the model protection strategy knowledge base to obtain device unique identifier data; perform matrix transformation detection on the key layers in the model protection strategy knowledge base to obtain a family of hierarchical transformation functions; generate keys based on the device unique identifier data and the family of hierarchical transformation functions, identify the optimal protection algorithm combination, and obtain a hierarchical key pedigree;

[0063] Hierarchical encryption module: Perform hierarchical encryption analysis according to the hierarchical key pedigree to obtain a hierarchical encryption matrix; apply the hierarchical encryption matrix to the key layer parameters of the model for hierarchical protection conversion to obtain a protected version of the model; perform multi-dimensional integrity verification on the protected version of the model to obtain a target encrypted model;

[0064] Monitoring and optimization module: Monitor the security status of the target encrypted model during use in real time to obtain execution state security data; optimize the hierarchical encryption matrix based on the execution state security data to achieve the dynamic evolution of the encrypted model protection mechanism. Each module is connected by wired and / or wireless means to achieve data transmission between modules.

[0065] The above are only the preferred embodiments of the present invention and are not used to limit the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing embodiments or perform equivalent replacements for some of the technical features. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

[0066] It should be noted that in this text, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including one..." does not exclude the presence of additional identical elements in the process, method, article or device including said element.

[0067] In the description of the present invention, it should be understood that the terms "first", "second", etc. are only used for distinguishing descriptions and cannot be construed as indicating or implying relative importance.

[0068] In the description of the present invention, unless otherwise specified, the meaning of "a plurality of" is two or more.

[0069] In the description of the present invention, the meaning of "several" is one or more, and the meaning of "a large number of" is two or more.

[0070] In the description of this specification, the descriptions referring to terms such as "an embodiment", "some embodiments", "example", "specific example" or "some examples", etc. mean that the specific features, structures, materials or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in a suitable manner in any one or more embodiments or examples.

[0071] For the formulas in this specification, the dimensional quantities are removed and only the numerical values are calculated. The formula is obtained by collecting a large amount of data and performing software simulation to get a formula closest to the actual situation. The preset parameters and threshold values in the formula are set by those skilled in the art according to the actual situation.

[0072] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the claims and their equivalents.

Claims

1. A method for encrypting a hierarchical encrypted neural network model, characterized in that, Including: Step S1: Obtain model architecture data, hierarchical topology data, and weight parameter data; Based on the model architecture data, construct a model layer sensitivity map, perform vulnerability analysis on the model layer sensitivity map, and obtain a critical layer map; Based on the hierarchical topology data and the weight parameter data, construct a parameter importance network, perform sensitivity analysis on the parameter importance network, and obtain a core parameter set; construct a model protection strategy knowledge base according to the critical layer map and the core parameter set; Step S2: Based on the model protection strategy knowledge base, perform device fingerprint analysis to obtain device unique identifier data; perform matrix transformation detection on the critical layers in the model protection strategy knowledge base to obtain a family of hierarchical transformation functions; based on the device unique identifier data and the family of hierarchical transformation functions, generate keys, identify the optimal protection algorithm combination, and obtain a hierarchical key pedigree; Step S3: Perform hierarchical encryption analysis according to the hierarchical key pedigree to obtain a hierarchical encryption matrix; apply the hierarchical encryption matrix to the model critical layer parameters for hierarchical protection conversion to obtain a model protection version; perform model multi-dimensional integrity verification based on the model protection version to obtain a target encrypted model; Step S4: Monitor the security status of the target encrypted model during use in real time to obtain execution state security data; Optimize the hierarchical encryption matrix based on the execution state security data to realize the dynamic evolution of the encrypted model protection mechanism.

2. The method for protecting a hierarchical encryption neural network model according to claim 1, wherein Step S1 includes: Collect model structure description data, inter-layer connection data, and computational graph data to form model architecture data; collect hierarchical type data, parameter scale data, activation function data, and gradient flow data to form hierarchical topology data; obtain weight matrix data, bias vector data, and quantization parameter data to form weight parameter data; Perform structural sensitivity analysis on the model architecture data to obtain a layer influence spectrum; perform importance ranking on the layer influence spectrum to obtain a layer importance sequence; construct a model layer sensitivity map based on the layer importance sequence; Perform parameter dependence analysis on the hierarchical topology data to obtain an initial parameter association network; perform sparsity analysis and sensitivity extraction on the weight parameter data to obtain parameter sensitivity data; construct a parameter importance network based on the initial parameter association network and the parameter sensitivity data; Use the influence propagation algorithm to identify critical nodes in the model layer sensitivity map to obtain a critical layer map; Use the spectral clustering algorithm to perform parameter group analysis on the parameter importance network to obtain a parameter importance cluster; perform threshold screening based on the parameter importance cluster to obtain a core parameter set; Construct a protection strategy ontology framework, map the critical layer map and the core parameter set to the protection strategy ontology framework to form an initial protection strategy library; Use security level encoding technology to add risk attributes to the initial protection strategy library to obtain a risk-graded protection strategy library; perform policy inference and extension on the risk-graded protection strategy library to obtain a model protection strategy knowledge base.

3. The method for protecting a hierarchical encryption neural network model according to claim 2, wherein Performing structural sensitivity analysis on the model architecture data to obtain a hierarchical influence spectrum diagram, including: Performing computational graph analysis on the model architecture data from three perspectives of forward propagation, backward propagation, and gradient transmission to obtain a multi-perspective computational graph set; Performing centrality metric calculation on the nodes in the multi-perspective computational graph set to obtain a standardized centrality index; Performing weight synthesis and variance analysis on the standardized centrality index to obtain a stability evaluation index set; Organizing the standardized centrality index and the stability evaluation index set by level to form a hierarchical influence spectrum diagram.

4. The method for protecting a hierarchical encryption neural network model according to claim 1, wherein Step S2 includes: Obtaining hardware fingerprint data, operating environment characteristic data, and runtime identification data from the target device, and constructing a device identification feature vector; Constructing a hybrid identity authentication model based on the device identification feature vector and the built-in security seed, and performing identity construction based on the hybrid identity authentication model to obtain device unique identification data; Extracting key layer sequences from the model protection policy knowledge base, constructing a hierarchical protection mapping diagram, and performing priority analysis on the hierarchical protection mapping diagram to obtain a hierarchical protection priority sequence; Performing matrix transformation algorithm matching on the hierarchical protection priority sequence to identify the optimal transformation function and obtain a hierarchical transformation function family; Performing parameter mapping on the device unique identification data and the hierarchical transformation function family to obtain initial key materials; Constructing a key derivation function based on the initial key materials, identifying the best key generation strategy, and obtaining a hierarchical key sequence; Performing anti-collision strengthening and entropy enhancement processing on the hierarchical key sequence, constructing an inter-layer key isolation mechanism, and obtaining a hierarchical key pedigree.

5. The method for protecting a hierarchical encryption neural network model according to claim 4, wherein The anti-collision strengthening and entropy enhancement processing of the hierarchical key sequence, constructing an inter-layer key isolation mechanism, and obtaining a hierarchical key pedigree include: Performing hash extension transformation on the hierarchical key sequence to increase the key entropy value and obtain a high-entropy key set; Performing key isolation analysis based on the high-entropy key set to ensure that the minimum Hamming distance between different hierarchical keys exceeds the security threshold and obtain key interval data; Constructing a forward security mechanism for the high-entropy key set based on the composite hash chain technology to obtain a time-sequential security key chain; Performing correlation analysis based on the time-sequential security key chain and the key interval data, and calculating the correlation metric factors between different keys, including mutual information, correlation coefficient, and collision probability, to obtain a key independence quantization index; Constructing a hierarchical dependence map based on the key independence quantization index to form a hierarchical key pedigree.

6. The method for protecting a hierarchical encrypted neural network model according to claim 1, characterized in that, Step S3 includes: Constructing a parameter transformation algorithm family based on the hierarchical key pedigree, designing a level-specific transformation strategy, and obtaining a hierarchical encryption scheme set; Using matrix decomposition technology to construct a model protection transformation framework, and integrating the hierarchical encryption scheme set into a hierarchical encryption matrix based on the model protection transformation framework; Extracting model parameter data from the model protection policy knowledge base, and selectively encrypting the model parameter data using the hierarchical encryption matrix to obtain a protected parameter set; Fusing the protected parameter set with non-critical parameters in the original model to construct a model protection version. Integrate cryptographic school verification sum with watermark technology to perform integrity verification on the protected version of the model, and obtain an integrity verification mark; Based on the integrity verification mark, construct a multi-level anti-tampering mechanism to ensure the security boundary of the model, and obtain a target encrypted model.

7. The method for protecting a hierarchical encryption neural network model according to claim 6, characterized in that, The constructing a multi-level anti-tampering mechanism based on the integrity verification mark to ensure the security boundary of the model includes: Construct a multi-dimensional integrity verification framework covering the dimensions of structural integrity, parameter integrity, call integrity, and execution integrity; Perform multiple hashing operations on the integrity verification mark to obtain multiple hashing features, and map the multiple hashing features to the multi-dimensional integrity verification framework to obtain a multi-dimensional integrity proof set; Use threshold cryptography technology to determine the verification weights of each dimension and each proof, construct a hierarchical verification model, and perform policy analysis based on the hierarchical verification model to obtain a hierarchical verification policy; Apply the zero-knowledge proof mechanism to perform verification conversion on the hierarchical verification policy to generate a definition of the model security boundary.

8. The method for protecting a hierarchical encryption neural network model according to claim 1, wherein Step S4 includes: Collect the behavioral characteristics and security event data during the use of the target encrypted model by users to form an execution-state security database; Based on the execution-state security database, perform security risk analysis, identify the optimization direction of the protection mechanism, and obtain protection enhancement parameters; Apply the protection enhancement parameters to optimize the hierarchical encryption matrix to achieve the dynamic evolution of the model protection mechanism.

9. The method for protecting a hierarchical encryption neural network model according to claim 8, characterized in that, The collecting the behavioral characteristics and security event data during the use of the model by users to form an execution-state security database includes: Design an execution-state security monitoring framework including call compliance detection, parameter access pattern detection, and decryption request legality detection; Track the correlation between the decryption operation and the performance during the execution of the target encrypted model to obtain performance impact evaluation data; Collect the application scenario data of the model protection mechanism, analyze the adaptability of the protection strategy in scenarios such as inference acceleration, distributed deployment, and quantization, and obtain scenario adaptability evaluation data; Integrate the performance impact evaluation data and the scenario adaptability evaluation data, construct a comprehensive index of protection effectiveness, and form an execution-state security database.

10. A hierarchical encryption neural network model encryption system, which is used to implement the hierarchical encryption neural network model protection method described in any one of claims 1-9, and is characterized in that, Include: Data analysis module: Obtain model architecture data, hierarchical topology data, and weight parameter data; Based on the model architecture data, construct a model layer sensitivity map, perform vulnerability analysis on the model layer sensitivity map, and obtain a key layer map; Based on the hierarchical topology data and the weight parameter data, construct a parameter importance network, perform sensitivity analysis on the parameter importance network, and obtain a core parameter set; construct a model protection strategy knowledge base according to the key layer map and the core parameter set; Key construction module: Based on the model protection strategy knowledge base, perform device fingerprint analysis to obtain device unique identification data; perform matrix transformation detection on the key layers in the model protection strategy knowledge base to obtain a family of hierarchical transformation functions; perform key generation based on the device unique identification data and the family of hierarchical transformation functions, identify the optimal protection algorithm combination, and obtain a hierarchical key pedigree; Hierarchical Encryption Module: Perform hierarchical encryption analysis according to the hierarchical key pedigree to obtain a hierarchical encryption matrix; apply the hierarchical encryption matrix to the key layer parameters of the model for hierarchical protection conversion to obtain a protected version of the model; perform multi-dimensional integrity verification on the protected version of the model to obtain a target encrypted model; Monitoring and Optimization Module: Monitor the security status of the target encrypted model during use in real time to obtain execution-state security data; Optimize the hierarchical encryption matrix based on the execution-state security data to achieve dynamic evolution of the encrypted model protection mechanism.

Citation Information

Cited By

  • Encryption system and method of trusted chip and storage medium

    CN120934747A

  • Model weight parameter protection method, terminal equipment and storage medium

    CN121212349A

  • Asset digital twin management platform data encryption method based on knowledge graph

    CN121351114A

  • Network model parameter protection method based on multilayer key

    CN121508859A

  • Method for protecting parameters of a network model based on multiple keys

    CN121508859B