Data security protection method based on trusted encryption mechanism and anomaly detection

Through the method of abnormal detection based on data distribution characteristics, homomorphic encryption, differential privacy combined with federated learning, the limitations of the existing technology in data security protection are solved, and the security and privacy protection of the entire cycle of data is realized, and the complex and changeable distributed environment is adapted to.

CN120378204APending Publication Date: 2025-07-25XI AN JIAOTONG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510721204.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

The existing data security protection technology has limitations when facing new attacks, and it is difficult to achieve fine-grained protection in distributed environments such as cloud computing and edge computing. The trust mechanism in cross-domain data sharing scenarios is missing. The existing solutions lack real-time response capabilities in collaborative optimization of encryption and detection components and dynamic environments.

Method used

The trusted encryption mechanism based on data distribution characteristics is adopted, and combined with federated learning, through multi-level abnormal detection and malicious score calculation, the data is protected throughout the whole cycle, including exception filtering before data use, privacy protection during use and malicious data filtering after use.

Benefits of technology

It realizes the completion of multiple data operations and training without transmitting data and parameters themselves, comprehensively guarantees data security and privacy, improves the security and stability of data sharing, and adapts to complex and changeable practical scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378204A_ABST
    Figure CN120378204A_ABST
Patent Text Reader

Abstract

The invention discloses a data security protection method based on a trusted encryption mechanism and anomaly detection, which is divided into four steps for data security protection: firstly, using data anomaly detection based on data distribution characteristics to preliminarily screen abnormal data; then, an original data credible encryption mechanism based on homomorphic encryption and differential privacy guarantees data security and privacy; sharing data through a federated learning model of parameter encryption and credible aggregation; and finally, rejecting malicious parameter updating through a federated learning backdoor detection algorithm based on malicious scores. Through the above steps, security and privacy protection of the data can be realized, and efficient sharing of the user data is effectively guaranteed at the same time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data security protection, and in particular to a trusted data protection framework based on differential privacy, homomorphic encryption and federated learning. Background Art

[0002] With the rapid development of information technology, data has become one of the most core assets in the digital economy era. However, the large-scale circulation and sharing of data also brings severe security challenges, including risks such as data leakage, tampering, and illegal access. In recent years, frequent data security incidents around the world (such as ransomware attacks, supply chain attacks, insider leaks, etc.) have not only caused huge economic losses, but also seriously threatened personal privacy, corporate reputation and even national security. In this context, how to build an efficient and reliable data security protection system has become a key issue that needs to be urgently solved in academia and industry.

[0003] Traditional data security protection technologies mainly rely on border defense (such as firewalls, intrusion detection systems) and basic encryption methods (such as symmetric encryption, asymmetric encryption). However, these methods have obvious limitations when dealing with new attacks: on the one hand, border defense is difficult to prevent internal threats and advanced persistent threats (APT), and attackers can penetrate horizontally once they break through the outer defense line; on the other hand, although conventional encryption mechanisms (such as AES, RSA) can ensure the security of static data storage and transmission, they lack the ability to provide fine-grained protection for data during dynamic use, especially in distributed environments such as cloud computing and edge computing, key management, access control and other issues are becoming increasingly prominent.

[0004] To make up for the above shortcomings, the fusion protection technology based on trusted encryption mechanism and anomaly detection has gradually become a research hotspot in recent years. At the encryption technology level, new encryption schemes such as trusted execution environment (TEE) and homomorphic encryption (HE) achieve "available but invisible" data through hardware isolation or mathematical algorithms. For example, Intel SGX protects key computing processes through the enclave mechanism, while Paillier homomorphic encryption supports direct calculations in the ciphertext state. In addition, technologies such as attribute-based encryption (ABE) and proxy re-encryption (PRE) achieve fine-grained access control through dynamic policies. However, a single encryption technology often has performance bottlenecks (such as the computational overhead of homomorphic encryption) or relies on specific hardware (such as TEE), making it difficult to adapt to complex and changing actual scenarios.

[0005] Anomaly detection technology provides another layer of protection for data security from the perspective of behavioral analysis. Machine learning-driven detection models (such as LSTM and Isolation Forest) can identify potential threats by analyzing log information such as user behavior and data access patterns. Compared with traditional rule-based detection methods (such as Snort), this type of technology can discover unknown attack patterns, but it relies on high-quality training data and has problems such as high false positive rate and vulnerability to adversarial samples. In recent years, federated learning and differential privacy have been introduced to improve the privacy protection capabilities of detection models, but how to balance detection accuracy and privacy still needs further exploration.

[0006] Current research trends show that deeply integrating trusted encryption mechanisms with anomaly detection technologies and building a multi-level, adaptive protection framework is an effective way to improve data security. For example, protecting the training and reasoning process of the detection model through TEE, or using lightweight encryption to implement privacy protection analysis of log data. However, existing solutions still face the following challenges: (1) The problem of coordinated optimization of encryption and detection components, which requires a balance between security strength and system performance; (2) Insufficient real-time response capabilities in dynamic environments; (3) Lack of trust mechanisms in cross-domain data sharing scenarios. Solving these problems requires innovations at multiple levels, including algorithm design, system architecture, and standardized protocols. Summary of the invention

[0007] The content of the present invention is to propose a data security protection method based on a trusted encryption mechanism and anomaly detection, and to study data security protection technology based on a trusted encryption mechanism and anomaly detection: using federated learning to protect data privacy and security, establishing a shared target model, extracting data features and model behaviors, coordinating anomaly detection technology, building a detection model, and realizing illegal data detection. This framework is divided into four steps to perform anomaly detection and security protection on data. First, data anomaly detection based on data distribution characteristics is used to preliminarily screen abnormal data; then, a trusted encryption mechanism for original data based on homomorphic encryption and differential privacy is used to ensure data security and privacy; then, data is shared through a federated learning model with parameter encryption and trusted aggregation; finally, malicious parameter updates are eliminated through a federated learning backdoor detection algorithm based on malicious scores. Through the above steps, data security and privacy protection can be achieved, while effectively ensuring efficient sharing of user data.

[0008] In order to achieve the above object, the present invention adopts the following technical solutions: 1) Data anomaly detection based on data distribution characteristics Step S101: Input user local data and perform multi-dimensional statistical feature extraction Step S102: Based on the multi-dimensional statistical features obtained in step S101, the sample anomaly score is calculated based on the local outlier factor to determine whether the data sample is abnormal. 2) Trusted Encryption Mechanism for Original Data Based on Homomorphic Encryption and Differential Privacy Step S103: Input the data after anomaly detection obtained in Step S102, and apply differential privacy noise to the data Step S104: Input the perturbed data obtained in Step S103, and perform homomorphic encryption 3) Security Protection Mechanism for Federated Learning Model Based on Parameter Encryption and Trusted Aggregation Step S105: According to the data in Step S104, the user trains the model locally to obtain the trained parameters, encrypts the model parameters, and uploads the encrypted model Step S106: According to the encrypted models uploaded by each user obtained in Step S105, the server calculates the aggregated ciphertext, performs model aggregation operations, and finally transmits the aggregated model back to each user 4) Backdoor Detection for Federated Learning Model Based on Malicious Score Step S107: Calculate the malicious score of the federated learning model according to the trained federated learning model Step S108: Adaptively update the federated learning model according to the malicious score obtained in Step S107 Furthermore, the specific content of Step S101 is as follows: Step S201: Calculate the mean, covariance matrix, skewness and kurtosis of the data, and output the final feature vector Step S202: Set a judgment threshold, and preliminarily screen and filter the user data in the covariance matrix that is greater than the threshold for preliminary data anomaly detection Furthermore, it is characterized in that in Step S102, the anomaly score of the sample is calculated based on the local outlier factor to determine whether there is an anomaly in the data sample. Specifically: Step S301: Define the distance neighborhood

[0009] Step S302: According to the definition in Step S301 Calculate the local reachability density LRD. The formula for calculating LRD is as follows:

[0010] Wherein, is the data sample, is the distance neighborhood

[0011] Step S303: Calculate the local outlier factor score LOF according to the local reachability density defined in Step S303. The formula for calculating LOF is as follows:

[0012] Among them, is a data sample, is the distance domain, denoted as the local reachability density of the sample Step S304: According to the LOF score obtained in step S303, if the LOF is greater than 1, the data sample is abnormal; otherwise, the data sample is normal. Furthermore, in step S103, differential privacy noise is applied to the data. Specifically: Step S401: Input the original data , define the privacy budget

[0013] Step S402: According to the privacy budget defined in step S401, calculate -sensitivity

[0014]

[0015] Among them, is the data after applying differential privacy perturbation.

[0016] Step S403: According to the sensitivity obtained in step S402, generate noise, and this noise samples noise from the Laplace distribution, that is, the noise obeys the following distribution:

[0017] where is is -sensitivity, is the privacy budget.

[0018] Step S404: Add the noise obtained in step S403 to the original data to obtain the perturbed data that satisfies differential privacy

[0019] Furthermore, step S104 performs homomorphic encryption on the perturbed data. Specifically: Step S501: According to the perturbed data obtained in step S404, first generate a key, the key includes a public key and a private key, and encrypt the data with the public key Step S502: Use the private key obtained in step S501 to decrypt the encrypted data Furthermore, step 106 performs secure aggregation on the ciphertext parameters uploaded by each user. Specifically: Step S601: Each user i generates a random mask (Meet ), and share it with other users through a multi-party secure computing protocol Step S602: According to the encryption method in Step 501, the user encrypts the masked parameters and uploads them to the server Step S603: The server calculates the aggregated ciphertext based on the encrypted parameters uploaded by the user and distributes it to each user Step S604: The user decrypts according to the decryption method in Step 502 to obtain the parameter model Further, in Step 107, malicious scores are calculated for each user model, specifically: Step S701: Calculate the robust distance according to each user model. This metric inputs adversarial samples to the deep learning model and records the output differences between the model on the adversarial samples and the original dataset samples, and uses this as an attribute layer metric Step S702: Calculate neuron metrics according to each user model, including neuron output distance and neuron activation distance. The former calculates the output layer neuron numerical output distance of two models under the condition of a given same test set, and the latter calculates the difference in their activation values (which can only be 0 or 1) Step S703: According to each user model, introduce LOD, LAD, and JSD as network layer metrics. The first metric LOD represents the L2 norm of the distances between the output values of a certain layer among models under a given input set. Similar to NOD and NAD, LAD is the L2 norm of the activation value distances. And JSD represents the distance between the probability distributions of the output values of a certain layer of two neural networks. JSD uses JS divergence to measure the distance between the two probability distributions Further, Step 108 adaptively updates the federated learning model using the malicious scores of the user models, specifically: Step S801: Concatenate the attribute layer metrics, neuron metrics, and network layer metrics obtained in Step 701, Step 702, and Step 703 to obtain a high-dimensional vector Step S802: For the high-dimensional vector concatenated in Step S801, calculate the covariance matrix, and assign corresponding adaptive weights to each model according to the variance sum of the vector on each type of metric (that is, the larger the variance, the more likely it is a malicious model, and the smaller the weight during update) A further improvement of the present invention is that: Step S102 detects data sample anomalies based on the local outlier factor, fully considering that backdoor data or abnormal data may not be obvious in the global distribution, but the local features are abnormal. By defining the k-distance neighborhood, calculating the local reachability density of each sample, and then obtaining the local outlier factor score, it is judged whether the data sample is abnormal according to the score threshold.

[0020] A further improvement of the present invention lies in that: the step S104 processes data samples based on the original data trusted encryption mechanism of homomorphic encryption and differential privacy, which can not only protect data privacy but also effectively ensure data security.

[0021] A further improvement of the present invention lies in that: in the step S107, the malicious score of the user model is calculated through three types of indicators of the attribute layer, neuron layer and network layer, and whether there are malicious behaviors or backdoors in the user model is evaluated from multiple perspectives, and the model is adaptively updated according to the malicious score, ensuring the safe and stable operation of federated learning.

[0022] Compared with the prior art, the present invention has the following advantages: 1) The method of the present invention aims at data security protection technology and conducts security protection throughout the entire life cycle of data use. That is, before data use, anomaly detection based on statistical distribution and local outlier factor is performed to preliminarily filter out abnormal data; during data use, differential privacy, homomorphic encryption and federated learning are adopted to ensure data security and privacy. After data use, malicious score calculation is performed to filter out malicious data use results. 2) Based on homomorphic encryption and differential privacy technologies, the present invention can complete various data operations and training without transmitting the data and parameters themselves. 3) The present invention uses multi-level indicators to evaluate the malicious score of the user model, which can comprehensively evaluate the malicious degree of the user model, including whether there are adversarial behaviors, backdoor behaviors, etc., and comprehensively ensures the security of each user's data use. BRIEF DESCRIPTION OF THE DRAWINGS Figure 1 It is the overall flowchart of the data security protection technology based on the trusted encryption mechanism and anomaly detection of the present invention; Figure 2 It is the flowchart of the data anomaly detection method based on the data distribution characteristics of the present invention; Figure 3 It is the flowchart of the method for calculating the anomaly score of samples based on the local outlier factor of the present invention; Figure 4 It is the flowchart of the original data trusted encryption mechanism method based on homomorphic encryption and differential privacy of the present invention; Figure 5 It is the flowchart of the federated learning algorithm based on homomorphic encryption of the present invention Figure 6 It is the flowchart of the backdoor detection algorithm for the federated learning model based on the malicious score of the present invention DETAILED DESCRIPTION OF THE EMBODIMENTS The following will describe in detail a data security protection method based on a trusted encryption mechanism and anomaly detection proposed by the present invention with reference to the accompanying drawings.

[0023] Refer to Figure 1As shown in the figure, the present invention discloses a data security protection technology based on a trusted encryption mechanism and anomaly detection, including the following steps: 1) Data anomaly detection based on data distribution characteristics Step S101: Input the user's local data and perform multi-dimensional statistical feature extraction. For image data, it includes the data mean, variance, standard deviation, etc. of each channel; for tabular data, for numerical tabular data, the mean and variance are mainly calculated. For text tabular data, due to its structured characteristics, it needs to be converted into a semantic embedding vector using a word embedding model, and the mean and variance are calculated based on the cosine distance; for graph data, mainly by calculating the number of nodes in the graph and the in-degree and out-degree of the edges. If there is vector information on the nodes or edges, calculate the variance and mean of these vector information Step S102: Based on the multi-dimensional statistical features obtained in step S101, calculate the anomaly score of the sample based on the local outlier factor, and determine whether there is an anomaly in the data sample 2) Trusted encryption mechanism for original data based on homomorphic encryption and differential privacy Step S103: Input the data that has completed anomaly detection obtained in step S102, and apply differential privacy noise to the data. For image data, differential privacy noise can be applied to the three channels, including R, G, and B. For tabular data, for numerical tabular data, directly add the corresponding perturbation value. For text tabular data, due to its unstructured characteristics, it is converted into a semantic embedding vector using a word embedding model, and then differential noise perturbation is applied; for graph data, if there is vector information on the nodes or edges, directly apply the perturbation, otherwise do not perform any perturbation Step S104: Input the perturbed data obtained in step S103 and perform homomorphic encryption 3) Security protection mechanism for federated learning models based on parameter encryption and trusted aggregation Step S105: According to the data in step S104, the user trains the model locally to obtain the trained parameters, encrypts the model parameters, and uploads the encrypted model. The federated learning model selects different models according to the data type, selects a convolutional neural network for image data, selects a decision tree-like model for tabular data, and selects a graph neural network for graph data.

[0024] Step S106: According to the encrypted models uploaded by each user obtained in step S105, the server calculates the aggregated ciphertext and performs model aggregation operations, and finally transmits the aggregated model back to each user 4) Backdoor detection for federated learning models based on malicious scores Step S107: Calculate the malicious score of the federated learning model according to the trained federated learning model Step S108: Adaptively update the federated learning model according to the malicious score obtained in Step S107 Refer to Figure 2 as shown, specifically: Step S201: Calculate the mean, covariance matrix, skewness, and kurtosis of the data, and output the final feature vector Step S202: Set a judgment threshold, and preliminarily screen and filter the user data in the covariance matrix that is greater than the threshold for preliminary data anomaly detection Refer to Figure 3 as shown, specifically: Step S301: Define distance neighborhood

[0025] Step S302: According to the defined in Step S301, calculate the local reachability density LRD. The formula for calculating LRD is as follows:

[0026] where is the data sample, is distance neighborhood.

[0027] Step S303: According to the local reachability density defined in Step S303, calculate the local outlier factor score LOF. The formula for calculating LOF is as follows:

[0028] where is the data sample, is distance neighborhood, represents the local reachability density of the sample Step S304: According to the LOF score obtained in Step S303, if LOF is greater than 1, the data sample is abnormal; otherwise, the data sample is normal Refer to Figure 4 as shown, specifically, it can be divided into the following steps: Step S401: Input the original data , define the privacy budget

[0029] Step S402: According to the privacy budget defined in Step S401, calculate -sensitivity

[0030]

[0031] where Data after applying differential privacy perturbation Step S403: Generate noise according to the sensitivity obtained in step S402. The noise is sampled from the Laplace distribution, that is, the noise obeys the following distribution:

[0032] where is is - sensitivity, is the privacy budget.

[0033] Step S404: Add the noise obtained in step S403 to the original data to obtain perturbed data that satisfies differential privacy

[0034] Step S501: According to the perturbed data obtained in step S404, first generate a key, which includes a public key and a private key, and encrypt the data with the public key Step S502: Decrypt the encrypted data using the private key obtained in step S501 Refer to Figure 5 shown. Specifically, it can be divided into the following steps: Step S601: Each user i generates a random mask (satisfying ), and shares it with other users through a multi-party secure computing protocol Step S602: According to the encryption method in step 501, the user encrypts the masked parameters and uploads them to the server Step S603: The server calculates the aggregated ciphertext based on the encrypted parameters uploaded by the users and distributes it to each user Step S604: The user decrypts to obtain the parameter model according to the decryption method in step 502 Refer to Figure 6 shown. Specifically, it can be divided into the following steps: Step S701: Calculate the robust distance according to each user model. This metric generates adversarial samples and inputs them into the deep learning model, and records the output differences between the model's outputs for the adversarial samples and the original dataset samples, and uses this as an attribute layer metric Step S702: Calculate the neuron metrics according to each user model, including the neuron output distance and the neuron activation distance. The former calculates the numerical output distance of the output layer neurons of two models under the condition of a given same test set, and the latter calculates the difference in their activation values (which can only be 0 or 1) Step S703: According to each user model, introduce LOD, LAD, and JSD as network layer metrics. The first metric LOD represents the L2 norm of the distance between the output values of a certain layer among models under a given input set. Similar to NOD and NAD, LAD is the L2 norm of the distance of activation values. And JSD represents the distance of the probability distributions of the output values of a certain layer of two neural networks. JSD uses the JS divergence to measure the distance between the two probability distributions. Step S801: Concatenate the attribute layer metrics, neuron metrics, and network layer metrics obtained in Step 701, Step 702, and Step 703 to obtain a high-dimensional vector. Step S802: For the high-dimensional vector concatenated in Step S801, calculate the covariance matrix, and assign corresponding adaptive weights to each model according to the sum of variances of the vector on each type of metric (that is, the larger the variance, the more likely it is a malicious model, and the smaller the weight during update).

Claims

1. A data security protection method based on a trusted encryption mechanism and anomaly detection, characterized in that It includes the following steps: 1) Data anomaly detection based on data distribution characteristics; Step S101: Input the user's local data and perform multi-dimensional statistical feature extraction; Step S102: Based on the multi-dimensional statistical features obtained in Step S101, calculate the anomaly score of the sample based on the local outlier factor, and determine whether there is an anomaly in the data sample; 2) A trusted encryption mechanism for original data based on homomorphic encryption and differential privacy; Step S103: Input the data after anomaly detection obtained in Step S102, and apply differential privacy noise to the data; Step S104: Input the perturbed data obtained in Step S103 and perform homomorphic encryption; 3) A security protection mechanism for the federated learning model based on parameter encryption and trusted aggregation; Step S105: According to the data in Step S104, the user trains the model locally to obtain the trained parameters, encrypts the model parameters, and uploads the encrypted model; Step S106: According to the encrypted models uploaded by each user obtained in Step S105, the server calculates the aggregated ciphertext and performs model aggregation operations, and finally sends the aggregated model back to each user; 4) Backdoor detection of the federated learning model based on the malicious score; Step S107: Calculate the malicious score of the model according to the trained federated learning model; Step S108: Adaptively update the federated learning model according to the malicious score obtained in Step S107.

2. The method according to claim 1, characterized in that, In the above Step S101 for multi-dimensional statistical feature extraction, specifically: Step S201: Calculate the mean, covariance matrix, skewness, and kurtosis of the data, and output the final feature vector; Step S202: Set a judgment threshold, and preliminarily screen and filter the user data in the covariance matrix that is greater than the threshold for preliminary data anomaly detection.

3. The method according to claim 1, characterized in that, In the above Step S102, calculating the anomaly score of the sample based on the local outlier factor and determining whether there is an anomaly in the data sample, specifically: Step S301: Define, according to the preliminarily screened data samples obtained in step S202, distance domain ; Step S302: According to what is defined in Step S301 calculate the local reachability density LRD; Step S303: Calculate the local outlier factor score LOF according to the local reachability density defined in Step S302; Step S304: According to the LOF score obtained in Step S303, if LOF is greater than 1, the data sample is abnormal, otherwise the data sample is normal.

4. The method according to claim 3, wherein The formula for calculating LRD in Step S302 is as follows: Among them, is a data sample, is the distance domain.

5. The method according to claim 3, wherein In Step S303, the formula for calculating LOF is as follows: Among them, is a data sample, is the distance domain, denoted as the local reachability density of the sample.

6. The method according to claim 1, wherein In the above Step S103, applying differential privacy noise to the data, specifically: Step S401: Input the original data , define the privacy budget ; Step S402: Calculate according to the privacy budget defined in step S401 - Sensitivity Among them, is the data after adding differential privacy perturbation Step S403: Generate noise according to the sensitivity obtained in step S402. This noise samples noise from a Laplace distribution, that is, the noise obeys the following distribution: Among them, is - sensitivity, is the privacy budget, Step S404: Add the noise obtained in step S403 to the original data to obtain perturbed data that satisfies differential privacy .

7. The method according to claim 1 or 6, characterized in that In the above Step S104, performing homomorphic encryption on the perturbed data, specifically: Step S501: According to the perturbed data obtained in Step S404, first generate a key, the key includes a public key and a private key, and encrypt the data with the public key; Step S502: Use the private key obtained in Step S501 to decrypt the encrypted data.

8. The method according to claim 1 or 7, characterized in that, In the above Step 106, performing secure aggregation on the encrypted parameters uploaded by each user, specifically: Step S601: Each user i generates a random mask (satisfying ), and shares it with other users through a multi-party secure computation protocol; Step S602: According to the encryption method in Step 501, the user encrypts the masked parameters and uploads them to the server; Step S603: The server calculates the aggregated ciphertext according to the encrypted parameters uploaded by the user and distributes it to each user; Step S604: The user decrypts to obtain the parameter model according to the decryption method in step 502.

9. The method according to claim 1, characterized in that, In step 107, the malicious scores are calculated for each user model, specifically: Step S701: Calculate the robustness distance according to each user model. This metric inputs adversarial samples into the deep learning model, records the output differences between the model for the adversarial samples and the original dataset samples, and uses this as an attribute layer metric. Step S702: Calculate the neuron metrics according to each user model, including the neuron output distance and the neuron activation distance. The former calculates the output layer neuron numerical output distance between two models given the same test set, and the latter calculates the difference in their activation values, which can only be 0 or 1. Step S703: According to each user model, introduce LOD, LAD, and JSD as network layer metrics. The first metric LOD represents the L2 norm of the distance between the output values of a certain layer between models given an input set, similar to NOD and NAD. LAD is the L2 norm of the activation value distance, and JSD represents the distance between the probability distributions of the output values of a certain layer of two neural networks. JSD uses the JS divergence to measure the distance between the two probability distributions.

10. The method according to claim 1 or 9, characterized in that In step 108, the federated learning model is adaptively updated using the malicious scores of the user models, specifically: Step S801: Concatenate the attribute layer metrics, neuron metrics, and network layer metrics obtained in step 701, step 702, and step 703 to obtain a high-dimensional vector. Step S802: For the high-dimensional vector concatenated in step S801, calculate the covariance matrix, and assign corresponding adaptive weights to each model according to the variance sum of the vector on each type of metric, that is, the larger the variance, the more likely it is a malicious model, and the smaller the weight during update.