Graph convolutional network topology correction method and device for model reverse engineering

By obtaining the binary file of the target model, using deep learning model and graph convolution network to correct operator information and connection relationships, the problem of inaccurate topology structure in the existing technology is solved, and efficient and reliable model reverse engineering is achieved.

CN120387490APending Publication Date: 2025-07-29Chinese People's Liberation Army Cyberspace Force Information Engineering University
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510580548.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-07
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

In the reverse engineering of existing models, operator prediction errors lead to node type errors and connection order deviations in dynamic analysis, affecting the accuracy and robustness of the topological structure.

Method used

By obtaining the binary file of the target model, using the trained deep learning model to recover operator information, combining dynamic analysis tools to establish the initial network topology, and using graph convolutional network to correct the calculation graph to correct the wrong nodes and connection order.

Benefits of technology

It significantly improves the completeness and accuracy of topological recovery, and enhances the reverse restoration capability of deep learning models in embedded scenarios such as smart home devices and mobile terminals.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120387490A_ABST
    Figure CN120387490A_ABST
Patent Text Reader

Abstract

The invention provides a model reverse engineering-oriented graph convolutional network topology correction method and device. The method comprises the steps of obtaining a binary file corresponding to a target model; recovering operator information of the target model according to the binary file by using a trained deep learning model; performing dynamic analysis on the binary file to obtain a calling relationship among all operators, and establishing connection among the operators with the calling relationship so as to generate an initial network topology corresponding to the target model; operators are used as nodes, connection relations among the operators are used as edges, and a computational graph is constructed according to the initial network topology; and correcting the calculation graph by using a preset graph convolutional network to obtain a final network topology corresponding to the target model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of model reverse engineering, and in particular to a graph convolutional network topology correction method and device for model reverse engineering. Background Art

[0002] Deep learning models are widely used in edge devices (such as smartphones and autonomous driving systems) due to their excellent reasoning ability. In the previous research "Research on Key Techniques for Reverse Engineering of DeepLearning Models for x86 Executable Files", a process for reverse recovering the model framework from dynamic library files was proposed. Through disassembly, operator prediction, and dynamic analysis, the operators, topology, and hyperparameters of the model were successfully restored, and the inference accuracy of the reconstructed model was close to that of the original model (for example, ResNet18 reached 93.64%). However, this process faces two major challenges in the topology recovery stage: firstly, operator prediction errors (such as the confusion rate between Add and BiasAdd being as high as 15%) lead to incorrect node types; secondly, missing execution paths in dynamic analysis cause connection order deviations. Such errors may cause tensor shape conflicts and even interrupt model inference (such as when Add is misjudged as BiasAdd, input parameters are missing). Therefore, there is an urgent need for an automated correction method to improve the accuracy and robustness of the topology. Summary of the Invention

[0003] In view of the fact that most existing model framework reverse methods are based on framework structure comparison and side-channel listening techniques, the research on binary-based model framework reverse methods is not sufficient, and issues such as the accuracy of topology recovery and the manual time cost are not considered, the present invention provides a graph convolutional network topology correction method and device for model reverse engineering.

[0004] In a first aspect, the present invention provides a graph convolutional network topology correction method for model reverse engineering, including:

[0005] Obtaining a binary file corresponding to a target model;

[0006] Using a trained deep learning model to recover the operator information of the target model according to the binary file;

[0007] Performing dynamic analysis on the binary file to obtain the call relationship between all operators, and establishing connections between the operators with call relationships to generate an initial network topology corresponding to the target model;

[0008] Taking the operators as nodes and the connection relationships between the operators as edges, thereby constructing a computational graph according to the initial network topology;

[0009] Use a preset graph convolutional network to correct the computational graph, so as to obtain the final network topology corresponding to the target model.

[0010] Furthermore, perform dynamic analysis on the binary file to obtain the call relationships between all operators, specifically including:

[0011] Use a dynamic instrumentation tool to mark the entry points of the functions where the operators are located in the binary file;

[0012] Run the binary file, monitor the execution of each instruction during the running process, and when it is found that an instruction calls the marked entry point, record the relevant information of the instruction;

[0013] After the binary file finishes running, judge whether the exit point of one operator is the entry point of another operator according to the recorded information. If so, there is a call relationship between the two operators.

[0014] Furthermore, use a preset graph convolutional network to correct the computational graph, so as to obtain the final network topology corresponding to the target model, specifically including:

[0015] Add self-loops to each node in the computational graph and establish the adjacency matrix of the computational graph after adding self-loops, and normalize the adjacency matrix;

[0016] Perform a linear transformation on the feature vector of each node, then use the normalized adjacency matrix to aggregate the feature vectors of the nodes, and use residual connections to retain the original feature vectors of each node. Finally, introduce a non-linear activation function to obtain an updated adjacency matrix, and restore a new computational graph according to the updated adjacency matrix, which is the final network topology corresponding to the target model.

[0017] In a second aspect, the present invention provides a graph convolutional network topology correction device for model reverse engineering, including:

[0018] An acquisition module, configured to acquire a binary file corresponding to a target model;

[0019] An operator mapping module, configured to use a trained deep learning model to restore the operator information of the target model according to the binary file;

[0020] A dynamic analysis module, configured to perform dynamic analysis on the binary file to obtain the call relationships between all operators, establish connections between the operators with call relationships, so as to generate an initial network topology corresponding to the target model;

[0021] A computation graph construction module, configured to use operators as nodes and the connection relationships between operators as edges, thereby constructing a computation graph according to the initial network topology;

[0022] A correction module, configured to correct the computation graph by using a preset graph convolutional network, thereby obtaining the final network topology corresponding to the target model.

[0023] Further, the dynamic analysis module includes an instrumentation unit, an instruction tracing unit, and a judgment unit;

[0024] The instrumentation unit is configured to use a dynamic instrumentation tool to mark the entry point of the function where the operator is located in the binary file;

[0025] The instruction tracing unit is configured to run the binary file, monitor the execution of each instruction during the running process, and record the relevant information of the instruction when it is found that an instruction calls the marked entry point;

[0026] The judgment unit is configured to, after the binary file finishes running, judge whether the exit point of an operator is the entry point of another operator according to the recorded information. If so, there is a call relationship between the two operators.

[0027] Further, the correction module includes a preprocessing unit and an updating unit;

[0028] The preprocessing unit is configured to add self-loops to each node in the computation graph, establish an adjacency matrix of the computation graph after adding self-loops, and normalize the adjacency matrix;

[0029] The updating unit is configured to perform a linear transformation on the feature vector of each node, then aggregate the feature vectors of the nodes by using the normalized adjacency matrix, retain the original feature vector of each node by using a residual connection, finally introduce a non-linear activation function to obtain an updated adjacency matrix, and restore a new computation graph according to the updated adjacency matrix, which is the final network topology corresponding to the target model.

[0030] In a third aspect, the present invention provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, the method described in the first aspect is implemented.

[0031] In a fourth aspect, the present invention provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method described in the first aspect is implemented.

[0032] The beneficial effects of the present invention are as follows:

[0033] The present invention first obtains the operator information of the target model through a trained deep learning model, then uses a dynamic analysis tool to perform memory tracing on the operator instructions and save the read and write records, and connects two adjacent operators according to the generated read and write record files, and so on, to complete the connection between all operators and restore the network topology of the target model; then, for the accuracy of topology restoration, error detection is performed on the restored topology structure to find the nodes with errors and the deviations in the connection order. The specific implementation is to utilize the sensitivity and excellent processing ability of the graph convolutional network for graph structure data, and then combine the prior knowledge of the target model to train a graph neural network that can correct the model topology nodes to achieve topology correction.

[0034] The present invention overcomes the defects of low efficiency and dependence on manual work of the traditional exhaustive method, and provides an efficient and reliable post-processing solution for model reverse engineering. It can make the reconstructed alternative neural network closer to the target model, significantly enhance the reverse reduction ability of deep learning models in embedded scenarios such as smart home devices and mobile terminals, and provide a new technical path for the security analysis of Internet of Things device models.

[0035] The experimental results show that the solution of the present invention can accurately and effectively connect operators to form a topology structure, can effectively solve the problems of insufficient accuracy of operator nodes and large differences in topology structures, and after topology correction, the integrity of topology restoration has a significant improvement. The three models with the best performance are googlneet, efficientnet, and regnet, and the integrity has increased by 3.62%, 2.79%, and 2.96% respectively compared with the initial topology structure, which proves the feasibility of the GCN correction method provided by the present invention and also has good performance. Description of the Drawings

[0036] Figure 1 It is one of the flow diagrams of the graph convolutional network topology correction method for model reverse engineering provided by the embodiment of the present invention;

[0037] Figure 2 It is the second flow diagram of the graph convolutional network topology correction method for model reverse engineering provided by the embodiment of the present invention;

[0038] Figure 3 It is the structural diagram of the graph convolutional network topology correction device for model reverse engineering provided by the embodiment of the present invention;

[0039] Figure 4 It is the structural block diagram of an electronic device provided by the embodiment of the present invention. Detailed Embodiments

[0040] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will clearly describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.

[0041] The following provides relevant introductions to the terms related to the technical solutions of the present invention.

[0042] (1) Computational graph

[0043] A computational graph is a graphical representation method used to describe the computational process, usually composed of nodes and directed edges. Nodes represent computational operations or variables, while edges represent data or dependencies. Through the computational graph, the input, output, and intermediate operations in the computational process can be clearly shown, facilitating the analysis and optimization of the computational process. It is widely used in deep learning and numerical calculations and can help understand the operation logic of complex models.

[0044] Computational graphs are usually divided into two types: static computational graphs and dynamic computational graphs. Static computational graphs need to fully define the structure of the graph before computation and are suitable for scenarios requiring high performance and optimization, such as the early versions of TensorFlow. Dynamic computational graphs are constructed dynamically during runtime, offering higher flexibility for debugging and modification. PyTorch is a typical dynamic computational graph framework. Whether it is a static computational graph or a dynamic computational graph, they both provide an efficient way to describe and execute complex mathematical operations. Especially in deep learning, computational graphs have become the core tools for model training and inference.

[0045] (2) Graph neural network

[0046] A graph neural network (GNN) is a deep learning model specifically designed to process graph-structured data. It learns the feature representations of nodes or graphs by aggregating the information of nodes and their neighbors in the graph. The core idea of GNN is to iteratively update the embedding vectors of nodes so that they can capture the structural information of the graph and the relationships between nodes. This model is suitable for non-Euclidean data such as social networks and molecular structures and can effectively solve the problems of graph data that are difficult to handle by traditional neural networks.

[0047] The basic framework of GNN usually includes three steps: aggregation, update, and readout. In the aggregation stage, each node collects the feature information of its neighbor nodes; in the update stage, the node updates its own feature representation based on the aggregated information; finally, in the readout stage, the representation of the entire graph is generated through pooling or global aggregation operations. This mechanism enables GNN to effectively learn complex patterns in the graph structure and is applicable to various tasks such as node classification, graph classification, and link prediction.

[0048] In recent years, significant progress has been made in the research of GNNs, giving rise to various variant models, such as Graph Convolutional Network (GCN), Graph Attention Network (GAT), and Graph Autoencoder (GAE). By introducing different aggregation and update mechanisms, these models further enhance the performance and applicability of GNNs. For example, GCN generalizes convolutional operations to graph data through spectral graph theory, while GAT uses the attention mechanism to assign different weights to different neighbor nodes, thus better capturing the key information in the graph structure.

[0049] (3) DNN Reverse Attack

[0050] Model function reverse attack: It refers to training a substitute model with a function similar to the given target deep learning model for a given target deep learning model. The cloned substitute model only has a similar function to the target model, but the model framework and parameters in the model are not the same as those of the target model. Its main process can be divided into two steps: (1) constructing the training dataset of the substitute model by querying the target model; (2) designing a reasonable learning algorithm based on the constructed training dataset to train the substitute model. ActiveThief, INVERSENET, GAMIN, etc. all construct substitute databases based on public datasets. MAZE uses knowledge distillation and zero-order gradient estimation methods to achieve the inversion goal of accurately cloning the model function without the original training data. Kahla M et al. proposed the Boundary Rejection Model Inversion (BREP-MI) algorithm in 2022 to invert private training data using only the prediction labels of the target model.

[0051] Model extraction reverse attack: It refers to opening the original black-box model to obtain the internal information of the model. By obtaining the internal framework and parameter information of the model to reconstruct the model, the reconstructed model generally has similarities with the framework or parameters of the original target model, not only in terms of function similarity but also in terms of structural similarity. Yuankun Zhu et al. first proposed using the unencrypted PCIe bus to invert DNN models, which is the first work to fully invert the structural information of DNN models. DND combines symbolic execution with dedicated loop analysis to recover the framework and parameter information of the model. Vasisht Duddu et al. demonstrated that attackers can use the property that the execution time of a neural network increases with the increase in the depth of the neural network to infer the total number of layers (depth) of the neural network.

[0052] (4) Binary Reverse Analysis

[0053] Binary reverse analysis is a technique for understanding software behavior and internal structure by analyzing binary code. It is a complex and highly technical task that uses various professional tools to understand and infer the behavior and logic of binary code. This technique has important applications in fields such as security research, vulnerability mining, and malware analysis. The present invention uses a compiled binary file and, through the disassembly technique of static analysis, obtains important information in the internal structure of the model.

[0054] The present invention can be applied to the topology recovery process of the target model, aiming to automatically detect and correct the error nodes in the initially recovered network topology diagram, improve the accuracy of the reverse model, make the reconstructed alternative neural network closer to the target model, and achieve the reverse of intelligent agent devices in daily life.

[0055] As Figure 1 shown, an embodiment of the present invention provides a graph convolutional network topology correction method for model reverse engineering, including the following steps:

[0056] S101: Obtain the binary file corresponding to the target model;

[0057] S102: Use the trained deep learning model to recover the operator information of the target model according to the binary file;

[0058] Specifically, the deep learning model can be the Deep Operator Network (DeepONet) or the Graph Neural Network (GNN). If the Deep Operator Network (DeepONet) is selected, its training process is as follows: The binary instruction sequence can be used as the input, and the operator information as the output, and the model is trained through supervised learning. If the Graph Neural Network (GNN) is selected, the binary file needs to be represented as a graph structure (such as a control flow graph or a data dependence graph), and the GNN is used to model these graph structures to recover the operator information.

[0059] S103: Perform dynamic analysis on the binary file to obtain the call relationships between all operators, establish connections between the operators with call relationships, and thus generate the initial network topology corresponding to the target model;

[0060] S104: Use the operator as a node and the connection relationship between the operators as an edge, and thus construct a computational graph according to the initial network topology;

[0061] S105: Use a preset graph convolutional network to correct the computational graph, aiming to modify the error nodes in the graph and the deviation of the connection order between the nodes, so that the modified topological structure is closer to the true network topology of the target model, and thus obtain the final network topology corresponding to the target model.

[0062] The present invention overcomes the defects of low efficiency and dependence on manual work of the traditional exhaustive method, and provides an efficient and reliable post-processing solution for model reverse engineering. It can make the reconstructed alternative neural network closer to the target model, significantly enhancing the reverse reduction ability of deep learning models in embedded scenarios such as smart home devices and mobile terminals, and providing a new technical path for the security analysis of Internet of Things device models.

[0063] In one embodiment, as Figure 2 shown, the embodiment of the present invention provides a dynamic analysis method to obtain the call relationship of operator nodes, mainly including the following steps:

[0064] S201: Use a dynamic instrumentation tool (such as IntelPin) to mark the entry point of the function where the operator is located in the binary file;

[0065] S202: Run the binary file, monitor the execution of each instruction during the running process, and when it is found that an instruction calls the marked entry point, record the relevant information of the instruction;

[0066] S203: After the binary file runs to completion, determine whether the exit point of one operator is the entry point of another operator according to the recorded information. If so, there is a call relationship between the two operators.

[0067] Specifically, this embodiment also provides the pseudo-code of the dynamic analysis method, as shown in Algorithm 1.

[0068]

[0069] In this embodiment, it is assumed that the binary file corresponding to the target model contains a total of n function files. First, put the starting addresses of all assembly functions containing operators into addr_list to form an addrs_list file that records the entry points of all operators; then execute the instruction tracing algorithm, and pass the target model address (prog_path), the input required for the target model to run (in_data), the file recording the operator entry points (addr_list), and the log file for saving the generated results (log_path) to the tracing function, and run the target model file; initialize the instruction tracing module Pintools, then open the log_path file to save the results of the instruction tracing, and then start the instruction tracing, trace the addresses in addr_list, check whether the instruction address is in addr_list, if not, skip it, if it is in addr_list, traverse each memory operand in the instruction, find the effective address according to the memory operand, save the content in the effective address in log_path, register Fini so that it can be called when the application exits, and return the effective address of the memory operand.

[0070] In this way, it is possible to record whether the monitored instruction addresses have calls and are called. When an operator calls the entry point of another operator at the exit point, the two operators can be connected. The previous operator is the predecessor node of the latter operator, and the latter operator is the successor node of the previous operator. By analogy, all operators are connected to form the initial network topology of the target model, and the operator node edge information of the computational graph is also obtained.

[0071] The operator information of the target model is restored by training the prediction model, and then the dynamic detection tool is used to monitor specific instruction addresses to establish the connection between operators, so that the operators are connected to each other to form the initial network topology of the target model, and the connection between the operators of the target model is deeply restored. However, it is not an easy task to ensure that each operator and the connection between operators are completely correct, just like the network topology of the target model. Because unexpected effects will occur both in model prediction and in the process of establishing the connection between operators, and the desired results cannot be fully achieved. Therefore, certain improvements are needed to reduce the possible error probability.

[0072] In one embodiment, the initial network topology of the target model is corrected by using a GCN network with residual connections. It can be understood that after obtaining the initial network topology of the target model, it cannot be guaranteed that each connection is correct, and there may be nodes with incorrect connections. Therefore, it is necessary to correct it to make the recovery degree and accuracy of the network topology of the target model higher. In this embodiment, the graph convolutional network GCN is used to correct the operator nodes in the model network topology, modify the incorrect nodes, and finally realize the update and modification of the network topology of the target model, so that the network topology of the target model is restored to a better effect.

[0073] The purpose of this embodiment is to correct the errors existing in the model network topology through the correction of the computational graph. In view of the fact that the graph convolutional network (GCN) can effectively capture structural information and perform excellently in various graph-related tasks, GCN is used to correct the errors in the computational graph, and finally achieve the effect of optimizing the topology structure.

[0074] According to the initial network topology of the target model and the data restored during the restoration of the computational graph, the information required to construct the computational graph can be obtained. Next, construct the computational graph G = <V, E>, and the set of computational graphs is {G1, G2, G3,..., G n}, where V is the set of nodes, E is the set of directed edges, and the attribute information of the nodes. Each node has a feature vector, which is used to describe the characteristic attributes corresponding to the node, and constitutes the preprocessing information.

[0075] The information obtained through preprocessing is fed into a GCN network with residual connections. During the convolution operation, first, the adjacency matrix of the graph is established, and a self-loop is added to the adjacency matrix so that each node can retain its own information when aggregating neighbor information. Second, each row and each column of the adjacency matrix are normalized to balance the contributions of nodes with different degrees to information aggregation. Then, a linear transformation is performed on the feature vector of each node, and all trainable parameters in the graph convolution process are in the linear layer of the linear transformation. Then, the adjacency matrix is used for feature aggregation to conduct the feature information in adjacent nodes to this node. Finally, a non-linear activation function is introduced to enhance the expression ability of the model. To alleviate the gradient disappearance and over-smoothing problems in deep networks, residual connections are added, and the feature vector of each node has a "memory" function.

[0076] In this embodiment, through the adjustment of the GCN, a more accurate computational graph is finally obtained, and then the topological structure of the model is updated to make it more complete and accurate.

[0077] Based on the same inventive concept, as Figure 3 shown, the embodiment of the present invention also provides a graph convolution network topology correction device for model reverse engineering, including an acquisition module, an operator mapping module, a dynamic analysis module, a computational graph construction module, and a correction module.

[0078] The acquisition module is used to acquire the binary file corresponding to the target model; the operator mapping module is used to use the trained deep learning model to restore the operator information of the target model according to the binary file; the dynamic analysis module is used to perform dynamic analysis on the binary file to obtain the call relationship between all operators, and establish a connection between the operators with a call relationship, so as to generate the initial network topology corresponding to the target model; the computational graph construction module is used to use the operator as a node and the connection relationship between operators as an edge, so as to construct a computational graph according to the initial network topology; the correction module is used to use a preset graph convolution network to correct the computational graph, so as to obtain the final network topology corresponding to the target model.

[0079] It should be noted that the network topology correction device provided in the embodiment of the present invention is to implement the above method, and its functions can be specifically referred to the above method embodiments, which will not be elaborated here.

[0080] Figure 4 Illustrates a schematic physical structure diagram of an electronic device, as Figure 4As shown in the figure, the electronic device may include: a processor 401, a communications interface 402, a memory 403, and a communication bus 404. Among them, the processor 401, the communications interface 402, and the memory 403 complete communication with each other through the communication bus 404. The processor 401 may call the logical instructions in the memory 403 to execute a graph convolutional network topology correction method for model reverse engineering. The method includes: obtaining a binary file corresponding to a target model; using a trained deep learning model to restore the operator information of the target model according to the binary file; performing dynamic analysis on the binary file to obtain the call relationship between all operators, and establishing connections between the operators with a call relationship, thereby generating an initial network topology corresponding to the target model; taking the operators as nodes and the connection relationship between the operators as edges, thereby constructing a computational graph according to the initial network topology; using a preset graph convolutional network to correct the computational graph, thereby obtaining a final network topology corresponding to the target model.

[0081] In addition, when the logical instructions in the above-mentioned memory 403 are implemented in the form of software functional units and sold or used as independent products, they may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, may be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk, or an optical disc that can store program codes.

[0082] The embodiments of the present invention further provide a computer program product. The computer program product includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the graph convolutional network topology correction method for model reverse engineering provided by the above-mentioned method embodiments.

[0083] The embodiments of the present invention further provide a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the graph convolutional network topology correction method for model reverse engineering provided by the above-mentioned method embodiments.

[0084] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0085] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for graph convolutional network topology correction for model reverse engineering, characterized in that including: Obtain the binary file corresponding to the target model; Use the trained deep learning model to restore the operator information of the target model according to the binary file; Perform dynamic analysis on the binary file to obtain the call relationship between all operators, and establish connections between the operators with call relationships, thereby generating the initial network topology corresponding to the target model; Use the operator as a node and the connection relationship between operators as an edge, thereby constructing a computational graph according to the initial network topology; Use a preset graph convolutional network to correct the computational graph, thereby obtaining the final network topology corresponding to the target model.

2. The method for correcting the topology of a graph convolutional network for model reverse engineering according to claim 1, wherein Performing dynamic analysis on the binary file to obtain the call relationship between all operators specifically includes: Use a dynamic instrumentation tool to mark the entry point of the function where the operator is located in the binary file; Run the binary file, monitor the execution of each instruction during the running process, and record the relevant information of the instruction when it is found that an instruction calls the marked entry point; After the binary file finishes running, judge whether the exit point of one operator is the entry point of another operator according to the recorded information. If so, there is a call relationship between the two operators.

3. The method for correcting the topology of a graph convolutional network for model-oriented reverse engineering according to claim 1, characterized in that, Using a preset graph convolutional network to correct the computational graph, thereby obtaining the final network topology corresponding to the target model, specifically including: Add self-loops to each node in the computational graph and establish the adjacency matrix of the computational graph after adding self-loops, and normalize the adjacency matrix; Perform a linear transformation on the feature vector of each node, then use the normalized adjacency matrix to aggregate the feature vectors of the nodes, and use residual connections to retain the original feature vectors of each node. Finally, introduce a non-linear activation function to obtain an updated adjacency matrix, and restore a new computational graph according to the updated adjacency matrix, which is the final network topology corresponding to the target model.

4. A graph convolutional network topology correction device for model reverse engineering, characterized in that including: An acquisition module for obtaining the binary file corresponding to the target model; An operator mapping module for using the trained deep learning model to restore the operator information of the target model according to the binary file; A dynamic analysis module for performing dynamic analysis on the binary file to obtain the call relationship between all operators, and establishing connections between the operators with call relationships, thereby generating the initial network topology corresponding to the target model; A computational graph construction module for using the operator as a node and the connection relationship between operators as an edge, thereby constructing a computational graph according to the initial network topology; A correction module for using a preset graph convolutional network to correct the computational graph, thereby obtaining the final network topology corresponding to the target model.

5. The graph convolutional network topology correction device for model-oriented reverse engineering according to claim 4, wherein The dynamic analysis module includes an instrumentation unit, an instruction tracking unit, and a judgment unit; The instrumentation unit is used to mark the entry point of the function where the operator is located in the binary file by using a dynamic instrumentation tool; The instruction tracking unit is used to run the binary file, monitor the execution of each instruction during the running process, and record the relevant information of the instruction when it is found that an instruction calls the marked entry point; The determination unit is configured to determine, after the binary file runs to completion, whether an exit point of one operator is an entry point of another operator according to the recorded information. If so, there is a call relationship between the two operators.

6. The graph convolutional network topology correction device for model-oriented reverse engineering according to claim 4, wherein The correction module includes a preprocessing unit and an updating unit; The preprocessing unit is configured to add self-loops to each node in the computational graph and establish an adjacency matrix of the computational graph after adding the self-loops, and normalize the adjacency matrix; The updating unit is configured to perform a linear transformation on the eigenvector of each node, then aggregate the eigenvector of the node using the normalized adjacency matrix, and use residual connection to retain the original eigenvector of each node. Finally, a non-linear activation function is introduced to obtain an updated adjacency matrix, and a new computational graph is restored according to the updated adjacency matrix, which is the final network topology corresponding to the target model.

7. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, the method according to any one of claims 1 to 3 is implemented.

8. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the method according to any one of claims 1 to 3 is implemented.