Federal learning method and device of intrusion detection model, node and medium

Through the federated learning method, the coordinated work of central nodes and computing nodes is used to achieve timely detection of network attacks and data security protection, solving the problem of IDS detection of unknown attacks and data privacy leakage, and improving network security and privacy protection.

CN120433949APending Publication Date: 2025-08-05DATANG MOBILE COMM EQUIP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410151803.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-02-02
Publication Date
2025-08-05

AI Technical Summary

Technical Problem

Existing intrusion detection systems (IDS) are difficult to effectively detect emerging unknown types of attacks, and centralized machine learning training methods have problems with training data security and privacy leakage.

Method used

The federated learning method is adopted to send initial model parameters to the computing node through the central node. The computing node uses local training data to update and encrypt the model parameters. The aggregation node performs aggregation, and the central node decrypts and calculates and processes it. Finally, the target model parameters of the intrusion detection model are obtained to ensure the security and privacy of the training data.

Benefits of technology

It realizes timely detection of complex and unknown network attacks, protects the security and privacy of local training data of each computing node, ensures the confidentiality and integrity of model parameters, and enhances the security of sensitive data within the network domain.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120433949A_ABST
    Figure CN120433949A_ABST
Patent Text Reader

Abstract

The invention discloses a federated learning method and device of an intrusion detection model, a node and a medium, and relates to the field of wireless communication. The specific implementation scheme is as follows: sending initial model parameters of an intrusion detection model to each computing node; receiving a first aggregation parameter sent by the aggregation node; wherein the first aggregation parameter is obtained by aggregating received first encryption model parameters sent by each computing node by the aggregation node; the first encryption model parameter is obtained by updating the initial model parameter by the computing node by using local training data to obtain an updated model parameter and encrypting the updated model parameter; and performing decryption and calculation processing on the first aggregation parameter to obtain a target model parameter of the intrusion detection model. Therefore, the security and privacy of the training data can be protected, the confidentiality and integrity of the model parameters can be ensured, and the security and privacy of sensitive data in each network domain are ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of wireless communication technology, and in particular to a federated learning method, device, node, and medium for an intrusion detection model. Background Art

[0002] Currently, network traffic data can be monitored based on a set of predefined rules or attack signatures that can identify known malicious behavior. An IDS (Intrusion Detection System) matches network traffic data with known attack patterns to identify or detect network attacks (such as DDoS (Distributed Denial of Service) attacks) and security threats. However, this approach requires the IDS to constantly update its rule base to effectively detect new network attacks and security threats, which is a relatively ongoing process.

[0003] To solve this problem, network traffic data can be detected based on machine learning algorithms in the field of AI (Artificial Intelligence) to improve the detection capabilities of complex network attacks and new security threats.

[0004] However, the above-mentioned machine learning algorithms adopt a centralized training method, which lacks protection for the security and privacy of training data and poses the problem of privacy data leakage. Summary of the Invention

[0005] The present application provides a federated learning method, device, node, and medium for an intrusion detection model.

[0006] According to one aspect of the present application, a federated learning method for an intrusion detection model is provided, which is applied to a central node and includes: sending initial model parameters of the intrusion detection model to at least one computing node; wherein the intrusion detection model is used to detect whether there is a network attack in network traffic data, and when the network attack exists, detect the attack type to which the network attack belongs; receiving a first aggregation parameter sent by an aggregation node; wherein the first aggregation parameter is obtained by the aggregation node aggregating the first encrypted model parameters sent by each of the computing nodes; the first encrypted model parameter is obtained by the computing node updating the initial model parameter using local training data to obtain an updated model parameter, and encrypting the updated model parameter; decrypting and calculating the first aggregation parameter to obtain the target model parameter of the intrusion detection model.

[0007] According to another aspect of the present application, there is provided another federated learning method for an intrusion detection model, which is applied to an aggregation node, and includes: receiving a first encrypted model parameter sent by at least one computing node; wherein the first encrypted model parameter is obtained by the computing node updating the initial model parameter of the intrusion detection model sent by the central node using local training data, and encrypting the updated model parameter; aggregating each of the first encrypted model parameters to obtain a first aggregate parameter; and sending the first aggregate parameter to the central node; wherein the first aggregate parameter is used for decryption and calculation processing by the central node to obtain a target model parameter of the intrusion detection model; wherein the intrusion detection model is used to detect whether there is a network attack in network traffic data, and when the network attack exists, detect the attack type to which the network attack belongs.

[0008] According to another aspect of the present application, there is provided another federated learning method for an intrusion detection model, which is applied to a computing node, and includes: receiving initial model parameters of the intrusion detection model sent by a central node; wherein the intrusion detection model is used to detect whether there is a network attack in network traffic data, and when there is the network attack, detect the attack type to which the network attack belongs; using local training data to update the initial model parameters to obtain updated model parameters; encrypting the updated model parameters to obtain first encrypted model parameters; sending the first encrypted model parameters to an aggregation node; wherein the first encrypted model parameters are used for aggregation processing at the aggregation node to obtain first aggregation parameters, and sending the first aggregation parameters to the central node; the first aggregation parameters are used for decryption and calculation processing at the central node to obtain target model parameters of the intrusion detection model.

[0009] According to another aspect of the present application, a central node is provided, including:

[0010] Memory, transceiver, processor:

[0011] A memory for storing computer programs; a transceiver for sending and receiving data under the control of a processor; a processor for reading the computer program in the memory and performing the following operations: sending initial model parameters of the intrusion detection model to at least one computing node; wherein the intrusion detection model is used to detect whether there is a network attack in network traffic data, and when the network attack exists, detecting the attack type to which the network attack belongs; receiving a first aggregation parameter sent by an aggregation node; wherein the first aggregation parameter is obtained by the aggregation node aggregating the first encrypted model parameters sent by each of the computing nodes; the first encrypted model parameter is obtained by the computing node updating the initial model parameter using local training data to obtain an updated model parameter, and encrypting the updated model parameter; decrypting and calculating the first aggregation parameter to obtain the target model parameter of the intrusion detection model.

[0012] According to another aspect of the present application, there is provided an aggregation node, comprising:

[0013] Memory, transceiver, processor:

[0014] A memory for storing computer programs; a transceiver for sending and receiving data under the control of a processor; a processor for reading the computer program in the memory and performing the following operations: receiving first encrypted model parameters sent by at least one computing node; wherein the first encrypted model parameters are obtained by the computing node using local training data to update the initial model parameters of the intrusion detection model sent by the central node, and encrypting the updated model parameters; aggregating each of the first encrypted model parameters to obtain a first aggregated parameter; sending the first aggregated parameter to the central node; wherein the first aggregated parameter is used for decryption and calculation processing by the central node to obtain the target model parameter of the intrusion detection model; wherein the intrusion detection model is used to detect whether there is a network attack in network traffic data, and when the network attack exists, detect the attack type to which the network attack belongs.

[0015] According to another aspect of the present application, a computing node is provided, including:

[0016] Memory, transceiver, processor:

[0017] A memory for storing computer programs; a transceiver for sending and receiving data under the control of a processor; a processor for reading the computer program in the memory and performing the following operations: receiving initial model parameters of the intrusion detection model sent by a central node; wherein the intrusion detection model is used to detect whether there is a network attack in network traffic data, and when the network attack exists, detecting the attack type to which the network attack belongs; updating the initial model parameters using local training data to obtain updated model parameters; encrypting the updated model parameters to obtain first encrypted model parameters; sending the first encrypted model parameters to an aggregation node; wherein the first encrypted model parameters are used for aggregation processing at the aggregation node to obtain first aggregation parameters, and sending the first aggregation parameters to the central node; the first aggregation parameters are used for decryption and calculation processing at the central node to obtain target model parameters of the intrusion detection model.

[0018] According to another aspect of the present application, a federated learning device for an intrusion detection model is provided, which is applied to a central node and includes:

[0019] A sending unit, configured to send initial model parameters of the intrusion detection model to at least one computing node; wherein the intrusion detection model is configured to detect whether network traffic data contains a network attack, and if so, to detect the attack type to which the network attack belongs;

[0020] a receiving unit, configured to receive a first aggregation parameter sent by an aggregation node; wherein the first aggregation parameter is obtained by the aggregation node aggregating the first encrypted model parameters sent by each of the computing nodes; and the first encrypted model parameter is obtained by the computing node updating the initial model parameter using local training data to obtain an updated model parameter, and encrypting the updated model parameter;

[0021] A processing unit is used to decrypt and calculate the first aggregation parameters to obtain target model parameters of the intrusion detection model.

[0022] According to another aspect of the present application, another federated learning device for an intrusion detection model is provided, which is applied to an aggregation node and includes:

[0023] A receiving unit, configured to receive a first encrypted model parameter sent by at least one computing node; wherein the first encrypted model parameter is an updated model parameter obtained by the computing node updating the initial model parameter of the intrusion detection model sent by the central node using local training data, and encrypting the updated model parameter;

[0024] an aggregation unit, configured to aggregate the first encryption model parameters to obtain a first aggregate parameter;

[0025] a sending unit, configured to send the first aggregation parameter to the central node; wherein the first aggregation parameter is used by the central node to perform decryption and calculation processing to obtain the target model parameter of the intrusion detection model;

[0026] The intrusion detection model is used to detect whether there is a network attack in the network traffic data, and if there is a network attack, detect the attack type of the network attack.

[0027] According to another aspect of the present application, another federated learning device for an intrusion detection model is provided, which is applied to a computing node and includes:

[0028] A receiving unit, configured to receive initial model parameters of the intrusion detection model sent by the central node; wherein the intrusion detection model is configured to detect whether network traffic data contains a network attack, and if so, to detect the attack type to which the network attack belongs;

[0029] An updating unit, configured to update the initial model parameters using local training data to obtain updated model parameters;

[0030] an encryption unit, configured to encrypt the updated model parameters to obtain first encrypted model parameters;

[0031] A sending unit is used to send the first encryption model parameter to the aggregation node; wherein the first encryption model parameter is used by the aggregation node to perform aggregation processing to obtain the first aggregation parameter, and the first aggregation parameter is sent to the central node; the first aggregation parameter is used by the central node to perform decryption and calculation processing to obtain the target model parameter of the intrusion detection model.

[0032] According to another aspect of the present application, a processor-readable storage medium is provided, characterized in that the processor-readable storage medium stores a computer program, and the computer program is used to enable the processor to execute the federated learning method of the intrusion detection model shown in any of the above embodiments.

[0033] According to another aspect of the present application, a computer program product is provided, including a computer program, which, when executed by a processor, implements the federated learning method of the intrusion detection model shown in any of the above embodiments of the present application.

[0034] The federated learning method, device, node and medium of the intrusion detection model provided in the embodiments of the present application can realize intrusion detection based on federated learning in a communication network by introducing various computing nodes. Intrusion detection based on federated learning can better and promptly respond to complex network attacks and unknown attacks. In addition, federated learning realizes distributed machine learning, ensuring that the local training data of each computing node does not leave its own node, thereby protecting the security and privacy of the training data. In addition, the model parameters updated by the computing node are encrypted, which can ensure the confidentiality and integrity of the model parameters, further ensuring the security and privacy of sensitive data in each network domain.

[0035] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present application, nor is it intended to limit the scope of the present application. Other features of the present application will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] The accompanying drawings are provided to facilitate a better understanding of the present invention and do not constitute a limitation of the present application.

[0037] Figure 1 A flowchart of a federated learning method for an intrusion detection model provided in an embodiment of the present application;

[0038] Figure 2 A flowchart of another federated learning method for an intrusion detection model provided in an embodiment of the present application;

[0039] Figure 3 A flowchart of another federated learning method for an intrusion detection model provided in an embodiment of the present application;

[0040] Figure 4 A flowchart of another federated learning method for an intrusion detection model provided in an embodiment of the present application;

[0041] Figure 5 A flowchart of another federated learning method for an intrusion detection model provided in an embodiment of the present application;

[0042] Figure 6 A flowchart of another federated learning method for an intrusion detection model provided in an embodiment of the present application;

[0043] Figure 7 A schematic diagram of the architecture of the intrusion detection system provided in an embodiment of the present application;

[0044] Figure 8 This is a schematic diagram of the implementation principle of the embodiment of this application Figure 1 ;

[0045] Figure 9This is a schematic diagram of the implementation principle of the embodiment of this application Figure 2 ;

[0046] Figure 10 A schematic diagram of the structure of a central node provided in an embodiment of the present application;

[0047] Figure 11 A schematic diagram of the structure of an aggregation node provided in an embodiment of the present application;

[0048] Figure 12 A schematic diagram of the structure of a computing node provided in an embodiment of the present application;

[0049] Figure 13 A schematic diagram of the structure of a federated learning device for an intrusion detection model provided in an embodiment of the present application;

[0050] Figure 14 A schematic diagram of the structure of a federated learning device for another intrusion detection model provided in an embodiment of the present application;

[0051] Figure 15 A schematic diagram of the structure of a federated learning device for another intrusion detection model provided in an embodiment of the present application. DETAILED DESCRIPTION

[0052] In the embodiments of this application, the term "and / or" describes the association relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent three situations: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally indicates that the associated objects are in an "or" relationship.

[0053] In the embodiments of the present application, the term "plurality" refers to two or more than two, and other quantifiers are similar.

[0054] The following will be combined with the drawings in the embodiments of this application to clearly and completely describe the technical solutions in the embodiments of this application. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0055] Traditional intrusion detection systems monitor network traffic data based on a set of predefined rules or attack signatures that can identify known malicious behavior. IDS identifies potential security threats by matching network traffic data with known attack patterns. To effectively detect new network attacks (such as DDoS attacks) and security threats, IDSs must constantly update their rule base, a relatively ongoing process.

[0056] With the continuous development of AI / ML (Machine Learning) technology, many AI / ML-based intrusion detection solutions have been proposed. These solutions often use machine learning algorithms to identify network traffic data to improve the detection capabilities of complex network attacks and new security threats. For example, some have enhanced the efficiency and accuracy of IDS intrusion detection by training machine learning models such as random forests, SVMs (Support Vector Machines), DAEs (Deep Autoencoders), and recurrent neural networks (RNNs).

[0057] However, the above intrusion detection methods have at least the following problems:

[0058] 1. IDS can only effectively detect known attack types, but has poor detection effects on emerging and unknown attack types;

[0059] 2. While existing AI / ML technologies have achieved improvements in improving detection rates and responding to complex attacks, they face challenges such as high computational overhead, imbalanced or easily outdated training data, and difficulty obtaining new training data sets to timely train machine learning models and update model parameters in the face of emerging and unknown attack types.

[0060] 3. Existing AI / ML technologies use centralized training methods, which lack protection for the security and privacy of training data and are prone to data leakage.

[0061] 4. Existing federated learning-based IDSs are not specifically designed for communication networks.

[0062] Therefore, in order to solve at least one of the above-mentioned problems, the embodiments of the present application provide a federated learning method, device, node and medium for an intrusion detection model, wherein the method and device are based on the same application concept. Since the principles of solving problems by the method and device are similar, the implementation of the device and method can refer to each other, and the repeated parts will not be repeated.

[0063] The following describes the federated learning method, device, node, and medium of the intrusion detection model provided by the present application with reference to the accompanying drawings. Before describing the embodiments of the present application in detail, for ease of understanding, the following common technical terms are first introduced:

[0064] Software Defined Security (SDS) is a security model that decouples security functions from hardware systems and implements them through software. This involves software controlling and managing information security, and is typically implemented in an SDN (Software Defined Network) environment. It can be considered an SDN-based security model. SDS centralizes security management, with these security measures implemented and controlled through software. Similar to SDN, SDS offers the flexibility to adjust security measures based on evolving security threats.

[0065] Figure 1 A flowchart of a federated learning method for an intrusion detection model provided in an embodiment of the present application.

[0066] The federated learning method of the intrusion detection model in the embodiment of the present application can be executed by a central node, wherein the central node can be deployed in a core network device.

[0067] like Figure 1 As shown, the federated learning method of the intrusion detection model may include the following steps:

[0068] Step S101: sending initial model parameters of an intrusion detection model to at least one computing node.

[0069] The intrusion detection model is used to detect whether network traffic data contains a network attack and, if so, to determine the attack type. For example, network traffic data can be input into an intrusion detection model for intrusion detection. The output of the intrusion detection model can be used to indicate whether the network traffic data contains a network attack. If so, the output can further indicate the attack type of the network attack.

[0070] Computing nodes can be deployed on edge nodes or access network devices. Edge nodes can be MEC (Multi-access Edge Computing) devices, application (App) servers, etc. close to the wireless access network side.

[0071] Here, the access network device is used as an example. A base station can include multiple cells that provide services to terminal devices. Depending on the specific application scenario, a base station can also be called an access point, or it can be a device in the access network that communicates with wireless terminal devices over the air interface through one or more sectors, or other names. The base station can be used to convert received air frames into Internet Protocol (IP) packets and serve as a router between the wireless terminal device and the rest of the access network, where the rest of the access network may include an Internet Protocol (IP) communication network. The base station can also coordinate the attribute management of the air interface. For example, the base station involved in the embodiments of the present application can be a base station (Base Transceiver Station, BTS) in the Global System for Mobile communications (GSM) or Code Division Multiple Access (CDMA), a base station (NodeB) in Wide-band Code Division Multiple Access (WCDMA), an evolutionary Node B (eNB or e-NodeB) in the long term evolution (LTE) system, a 5G base station (gNB) in the 5G network architecture (next generation system), a home evolved Node B (HeNB), a relay node, a femto, a pico, etc., and is not limited in the embodiments of the present application. In some network structures, the base station may include a centralized unit (CU) node and a distributed unit (DU) node, and the centralized unit and the distributed unit may also be geographically separated.

[0072] The terminal device may be a device that provides voice and / or data connectivity to a user, a handheld device with wireless connection capabilities, or other processing devices connected to a wireless modem. The names of terminal devices may vary in different systems. For example, in a 5G system, a terminal device may be referred to as a user equipment (UE). A wireless terminal device may communicate with one or more core networks (CNs) via a radio access network (RAN). A wireless terminal device may be a mobile terminal device, such as a mobile phone (or "cellular" phone) and a computer with a mobile terminal device. For example, a portable, pocket-sized, handheld, computer-built-in, or vehicle-mounted mobile device may exchange voice and / or data with a radio access network. Examples include personal communication service (PCS) phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, and personal digital assistants (PDAs). The wireless terminal device may also be referred to as a system, a subscriber unit, a subscriber station, a mobile station, a mobile station, a remote station, an access point, a remote terminal device, an access terminal device, a user terminal device, a user agent, or a user device, but is not limited in the embodiments of the present application.

[0073] In an embodiment of the present application, the central node may initialize the intrusion detection model, obtain initialized model parameters (referred to as initial model parameters in this application), and send the initial model parameters to at least one computing node.

[0074] In any embodiment of the present application, the initial model parameters may be sent in a manner such as: the central node may send or broadcast the initial model parameters to each computing node in a broadcast manner.

[0075] In any embodiment of the present application, the initial model parameters may be transmitted by, for example, a central node encrypting the initial model parameters using an encryption algorithm and transmitting the encrypted initial model parameters to each computing node. Accordingly, upon receiving the encrypted initial model parameters, the computing node may decrypt the encrypted initial model parameters to obtain the initial model parameters.

[0076] As an example, the central node may use its own private key to encrypt the initial model parameters to obtain the encrypted initial model parameters, and then send the encrypted initial model parameters to each computing node.

[0077] For example, the central node can use the elliptic private key used in the elliptic curve encryption algorithm to encrypt the initial model parameters to obtain the encrypted initial model parameters. Among them, the private key and public key used in the elliptic curve encryption algorithm have high security and relatively short key length.

[0078] In any embodiment of the present application, the initial model parameters may be sent in a manner such that the central node may send the initial model parameters to each computing node based on a secure communication channel between the central node and each computing node.

[0079] The secure communication channel between the central node and any computing node can be established in the following way:

[0080] 1. The central node sends an authentication request to the computing node, where the authentication request carries the central node's security certificate.

[0081] 2. After receiving the authentication request, the computing node can authenticate the security certificate in the authentication request, and if the security certificate passes the authentication, generate an authentication pass response and send the authentication pass response to the central node.

[0082] 3. When the central node receives the authentication success response sent by the computing node, it can establish a secure communication channel between the central node and the computing node.

[0083] Therefore, it is possible to send initial model parameters to computing nodes based on different methods, which can improve the flexibility and applicability of the method.

[0084] Step S102, receiving the first aggregation parameter sent by the aggregation node; wherein the first aggregation parameter is obtained by the aggregation node aggregating the first encrypted model parameters sent by each computing node; the first encrypted model parameter is obtained by the computing node updating the initial model parameter using local training data to obtain the updated model parameter, and encrypting the updated model parameter.

[0085] The local training data of a computing node can be network traffic data collected or collected locally by the computing node. The network traffic data may include data received and / or sent by the computing node, such as voice, text messages, and data. For example, if the computing node is deployed on an access network device, the local training data may include various message data sent by the terminal, signaling and protocol data related to the terminal, and so on.

[0086] It should be noted that the computing nodes can be deployed on edge nodes or access network devices. The local training data of the computing nodes can include the latest network traffic data collected by the computing nodes. The intrusion detection model can be trained based on the latest collected network traffic data, which can ensure that the model is updated and adapted to changes in network traffic in a timely manner, thereby improving the real-time detection capability of the model and more comprehensively covering various attack types, thereby improving the accuracy and robustness of model detection.

[0087] The aggregation node may also be deployed on a core network device, and the aggregation node and the central node may be deployed on different core network devices.

[0088] In an embodiment of the present application, after receiving the initial model parameters, each computing node can use multiple batches of local training data to train the intrusion detection model to update the initial model parameters and obtain updated model parameters. When the training of multiple batches of local training data is completed, the computing node can encrypt the updated model parameters to obtain the encrypted updated model parameters (referred to as the first encrypted model parameters in this application), and send the first encrypted model parameters to the aggregation node.

[0089] After receiving the first encryption model parameters sent by the computing node, the aggregation node can aggregate (such as packaging) the first encryption model parameters sent by each computing node to obtain an aggregation parameter (referred to as the first aggregation parameter in this application). Afterwards, the aggregation node can send the first aggregation parameter to the central node, and accordingly, the central node can receive the first aggregation parameter sent by the aggregation node.

[0090] It should be noted that when the aggregation node receives the encrypted model parameters sent by the computing node, it can increase the training round by one, that is, the training round refers to the number of times the aggregation node receives the encrypted model parameters sent by the same computing node.

[0091] Step S103: decrypt and calculate the first aggregated parameters to obtain target model parameters of the intrusion detection model.

[0092] The calculation processing includes but is not limited to: federal averaging, weighted summing, median taking and other processing.

[0093] In an embodiment of the present application, after receiving the first aggregation parameter, the central node may decrypt the first aggregation parameter and perform calculation processing on the decrypted model parameters to obtain target model parameters of the intrusion detection model.

[0094] As an example, after the central node decrypts the first aggregation parameter and obtains the decrypted model parameter, it can determine the various parameter values belonging to the same model parameter from the decrypted model parameter, and perform calculations on the various parameter values belonging to the same model parameter, such as federal averaging, weighted summation, etc., to obtain the final parameter value corresponding to the same model parameter, which is recorded as the target model parameter in this application.

[0095] In any embodiment of the present application, after the intrusion detection model is trained, the central node can perform intrusion detection on the real-time network traffic data based on the target model parameters in the intrusion detection model to determine whether there is a network attack in the real-time network traffic data.

[0096] The federated learning method of the intrusion detection model in the embodiment of the present application can realize intrusion detection based on federated learning in a communication network by introducing various computing nodes. Intrusion detection based on federated learning can better and timely respond to complex network attacks and unknown attacks. In addition, federated learning realizes distributed machine learning, ensuring that the local training data of each computing node does not leave its own node, thereby protecting the security and privacy of the training data. In addition, the model parameters updated by the computing node are encrypted, which can ensure the confidentiality and integrity of the model parameters, further ensuring the security and privacy of sensitive data in each network domain.

[0097] In order to clearly illustrate the above embodiments, the present application also proposes a federated learning method for an intrusion detection model.

[0098] Figure 2 A flowchart of another federated learning method for an intrusion detection model provided in an embodiment of the present application.

[0099] like Figure 2 As shown in Figure 2, the federated learning method of the intrusion detection model can be applied to the central node, including the following steps:

[0100] Step S201: sending initial model parameters of an intrusion detection model to at least one computing node.

[0101] Among them, the intrusion detection model is used to detect whether there is a network attack in the network traffic data, and if there is a network attack, detect the attack type to which the network attack belongs.

[0102] For the explanation of step S201, please refer to the relevant description in any embodiment of the present application and will not be repeated here.

[0103] In any embodiment of the present application, the computing node may be an SDS node, which can enhance the abstraction capability of security functions while utilizing the software-defined architecture, and further ensure the security and privacy of sensitive data within each network domain.

[0104] Step S202, receiving the first aggregation parameter sent by the aggregation node; wherein the first aggregation parameter is obtained by the aggregation node aggregating the first encrypted model parameters sent by each computing node; the first encrypted model parameter is obtained by the computing node updating the initial model parameter using local training data to obtain the updated model parameter, and using the public key of the central node to encrypt the updated model parameter.

[0105] In an embodiment of the present application, after receiving the initial model parameters, each computing node can use multiple batches of local training data to train the intrusion detection model to update the initial model parameters and obtain updated model parameters. When the training of multiple batches of local training data is completed, the computing node can use the public key of the central node to encrypt the updated model parameters to obtain first encrypted model parameters, and send the first encrypted model parameters to the aggregation node.

[0106] As an example, the computing node may encrypt the updated model parameters using an elliptic public key used in an elliptic curve encryption algorithm to obtain the first encrypted model parameters. The public key used in the elliptic curve encryption algorithm has high security and a relatively short key length.

[0107] In an embodiment of the present application, after receiving the first encryption model parameters sent by each computing node, the aggregation node can aggregate (such as packaging) the first encryption model parameters sent by each computing node to obtain a first aggregation parameter. Afterwards, the aggregation node can send the first aggregation parameter to the central node, and accordingly, the central node can receive the first aggregation parameter sent by the aggregation node.

[0108] Step S203: Decrypt the first aggregation parameter based on the private key of the central node.

[0109] In an embodiment of the present application, after receiving the first aggregation parameter, the central node can decrypt the first aggregation parameter based on its own private key to obtain the decrypted model parameter.

[0110] As an example, the central node may use the elliptic private key used in the elliptic curve encryption algorithm to decrypt the first aggregation parameter to obtain the decrypted model parameter.

[0111] Step S204: performing calculation processing on the model parameters obtained by decryption to obtain target model parameters of the intrusion detection model.

[0112] In an embodiment of the present application, the computing node may perform computational processing (such as federated averaging, weighted summing, etc.) on the model parameters obtained by decryption to obtain target model parameters of the intrusion detection model.

[0113] The federated learning method of the intrusion detection model in the embodiment of the present application performs asymmetric encryption on the updated model parameters, which can ensure that the communication link between the computing node and the central node is not obtained by the aggregation node and other attackers in the intermediate path, further ensuring the security and privacy of sensitive data in each network domain.

[0114] In order to clearly illustrate how the first aggregation parameter is decrypted and calculated in any embodiment of the present application to obtain the target model parameters of the intrusion detection model, the present application also proposes a federated learning method for the intrusion detection model.

[0115] Figure 3 A flowchart of another federated learning method for an intrusion detection model provided in an embodiment of the present application.

[0116] like Figure 3 As shown in Figure 2, the federated learning method of the intrusion detection model can be applied to the central node, including the following steps:

[0117] Step S301: Send initial model parameters of an intrusion detection model to at least one computing node.

[0118] Among them, the intrusion detection model is used to detect whether there is a network attack in the network traffic data, and if there is a network attack, detect the attack type to which the network attack belongs.

[0119] Step S302: Receive a first aggregation parameter sent by an aggregation node.

[0120] Among them, the first aggregation parameter is obtained by the aggregation node aggregating the first encrypted model parameters sent by each computing node; the first encrypted model parameter is obtained by the computing node updating the initial model parameter using local training data to obtain the updated model parameter, and encrypting the updated model parameter.

[0121] The explanation of steps S301 to S302 can be found in the relevant description in any embodiment of the present application and will not be repeated here.

[0122] Step S303: decrypt and calculate the first aggregation parameters to obtain global model parameters.

[0123] In an embodiment of the present application, the central node can decrypt the first aggregation parameter to obtain the decrypted model parameter, and perform calculation processing (such as federal averaging, weighted summation, etc.) on the decrypted model parameter to obtain the global model parameter.

[0124] Step S304, determining whether the termination condition of the intrusion detection model training is met, if so, executing step S305, if not, executing step S306.

[0125] The termination training condition is a pre-set termination condition for model training. For example, the termination training condition may include but is not limited to at least one of the following conditions:

[0126] First, the training time of the intrusion detection model reaches a set time; wherein the set time is a pre-set time threshold.

[0127] The second item is that the training rounds of the intrusion detection model reach the set rounds, or the number of training rounds of the intrusion detection model reaches the set number of rounds; wherein the set rounds are a preset number threshold, the set number of rounds are a preset number threshold, and the set rounds or the set number of rounds are positive integers.

[0128] The third item is that the first KPI (Key Performance Indicators) of the intrusion detection model on the validation set is higher than the corresponding first threshold.

[0129] Among them, the first threshold corresponding to the first KPI indicator is a pre-set threshold, and the first thresholds corresponding to different first KPI indicators can be different, or all the same, or partially the same, partially different, etc., and the embodiment of the present application does not limit this.

[0130] Among them, the first KPI indicator includes but is not limited to the following indicators: accuracy, precision, recall rate, F1 value, R2 value (R2 value is used to evaluate the degree of explanation of the intrusion detection model for the test data in the test set), AUC-ROC (Area Under the Receiver Operating Characteristic Curve), AUC-PR (Area Under the Precision-Recall Curve), etc.

[0131] Among them, accuracy refers to the proportion of test data predicted correctly by the intrusion detection model to the total test data in the test set; precision refers to the proportion of test data that are actually positive among the test data predicted by the intrusion detection model as positive examples; recall refers to the proportion of test data predicted as positive by the intrusion detection model among all the test data in the test set that are positive examples; F1 value is the harmonic mean of precision and recall, which is used to evaluate the performance of the intrusion detection model; R2 value is used to evaluate the degree to which the intrusion detection model explains the test data, indicating the goodness of fit of the intrusion detection model; AUC-ROC is the area under the ROC curve, which is used to evaluate the performance of the intrusion detection model at different thresholds; AUC-PR is the area under the Precision-Recall curve, which is used to evaluate the accuracy performance of the intrusion detection model at different recall rates.

[0132] Fourth, the second KPI indicator of the intrusion detection model on the validation set is lower than the corresponding second threshold.

[0133] Among them, the second threshold corresponding to the second KPI indicator is a pre-set threshold, and the second thresholds corresponding to different second KPI indicators can be different, or all the same, or partially the same, partially different, etc., and the embodiment of the present application does not limit this.

[0134] The second KPI indicator includes but is not limited to the following indicators: MSE (Mean Squared Error), MAE (Mean Absolute Error), RMSE (Root Mean Squared Error), etc.

[0135] It should be noted that the above-mentioned training termination conditions are only exemplary, but the present application is not limited thereto. In actual application, other training termination conditions can also be set.

[0136] In an embodiment of the present application, the central node may determine whether the termination training condition of the intrusion detection model is currently met. If so, step S305 may be executed; if not, step S306 may be executed.

[0137] It should be noted that step S305 and step S306 are two parallel implementation methods. In actual application, only one needs to be executed.

[0138] Step S305: Using the global model parameters as target model parameters of the intrusion detection model.

[0139] In an embodiment of the present application, when the termination training conditions of the intrusion detection model are currently met, model training can be stopped. At this time, the central node can directly use the global model parameters as the final parameters of the intrusion detection model (referred to as target model parameters in this application).

[0140] Step S306: performing at least one round of iteration according to the global model parameters to obtain target model parameters of the intrusion detection model.

[0141] In an embodiment of the present application, when the termination training conditions of the intrusion detection model are not currently met, the intrusion detection model can be further trained. For example, the central node can perform at least one round of iterative process based on the global model parameters to obtain the target model parameters of the intrusion detection model.

[0142] In any embodiment of the present application, the central node performs a first round (i.e., the first round) of iteration, which may be:

[0143] 1. The central node may use the global model parameters as the intermediate model parameters of the first round of iteration process, and send the intermediate model parameters of the first round of iteration process to at least one computing node.

[0144] The method of sending the intermediate model parameters is similar to the method of sending the initial model parameters, and will not be described in detail here.

[0145] 2. The central node may receive the second aggregation parameter of the first round of iteration process sent by the aggregation node.

[0146] Among them, the second aggregation parameter of the first round of iteration process is obtained by the aggregation node aggregating the second encryption model parameters of the first round of iteration process sent by each computing node; the second encryption model parameter of the first round of iteration process is obtained by the computing node updating and encrypting the intermediate model parameters of the first round of iteration process using local training data.

[0147] That is, in this application, after receiving the intermediate model parameters of the first round of iteration, the computing node can use local training data to update the intermediate model parameters of the first round of iteration to obtain updated intermediate model parameters, and encrypt the updated intermediate model parameters to obtain second encrypted model parameters of the first round of iteration. The encryption method of the updated intermediate model parameters is similar to the encryption method of the updated model parameters and is not further described here.

[0148] Afterwards, the computing node can send the second encryption model parameters of the first round of iterative process to the aggregation node. The aggregation node can aggregate the second encryption model parameters of the first round of iterative process sent by each computing node, obtain the second aggregation parameters of the first round of iterative process, and send the second aggregation parameters of the first round of iterative process to the central node.

[0149] 3. The central node can determine whether the termination training condition of the intrusion detection model is currently met. If so, step 4 is executed; if not, step 5 is executed.

[0150] 4. When the termination training condition of the intrusion detection model is currently met, the central node can stop the iteration and decrypt and calculate the second aggregation parameters of the first round of iteration process to obtain the target model parameters of the intrusion detection model.

[0151] 5. When the termination training condition of the intrusion detection model is not currently met, the central node can continue to iterate. For example, the central node can decrypt and calculate the second aggregation parameter of the first round of iteration process to obtain the intermediate model parameters of the second round of iteration process.

[0152] In any embodiment of the present application, the central node performs a non-first round of iteration (such as the i-th round of iteration, where i is a positive integer greater than 1), for example, the following steps may be performed:

[0153] A. The central node can send the intermediate model parameters of the i-th round of iteration process to at least one computing node.

[0154] B. The central node may receive the second aggregation parameter of the i-th round of iteration sent by the aggregation node.

[0155] Among them, the second aggregation parameter of the i-th round of iteration process is obtained by the aggregation node aggregating the second encryption model parameters of the i-th round of iteration process sent by each computing node; the second encryption model parameter of the i-th round of iteration process is obtained by the computing node updating and encrypting the intermediate model parameters of the i-th round of iteration process using local training data.

[0156] That is, in this application, after receiving the intermediate model parameters of the i-th iteration process, the computing node can use local training data to update the intermediate model parameters of the i-th iteration process to obtain updated intermediate model parameters, and encrypt the updated intermediate model parameters to obtain second encrypted model parameters of the i-th iteration process. The encryption method of the updated intermediate model parameters is similar to the encryption method of the updated model parameters and is not further described here.

[0157] Afterwards, the computing node can send the second encryption model parameters of the i-th round of iteration process to the aggregation node. The aggregation node can aggregate the second encryption model parameters of the i-th round of iteration process sent by each computing node, obtain the second aggregation parameters of the i-th round of iteration process, and send the second aggregation parameters of the i-th round of iteration process to the central node.

[0158] C. The central node can determine whether the termination training condition of the intrusion detection model is currently met. If so, step D is executed; if not, step E is executed.

[0159] D. When the termination training condition of the intrusion detection model is currently met, the central node can stop the iteration and decrypt and calculate the second aggregation parameter of the i-th round of iteration process to obtain the target model parameters of the intrusion detection model.

[0160] E. When the termination training condition of the intrusion detection model is not currently met, the central node can continue to iterate. For example, the central node can decrypt and calculate the second aggregation parameter of the i-th round of iteration process to obtain the intermediate model parameters of the i+1-th round of iteration process.

[0161] The federated learning method of the intrusion detection model in the embodiment of the present application can effectively update the global model parameters of the intrusion detection model based on each round of iteration process to improve the prediction accuracy of the intrusion detection model.

[0162] In order to clearly illustrate any of the above embodiments, the present application also proposes a federated learning method for an intrusion detection model.

[0163] Figure 4 A flowchart of another federated learning method for an intrusion detection model provided in an embodiment of the present application.

[0164] like Figure 4 As shown in Figure 2, the federated learning method of the intrusion detection model can be applied to the central node, including the following steps:

[0165] Step S401: Sending initial model parameters of an intrusion detection model to at least one computing node.

[0166] Among them, the intrusion detection model is used to detect whether there is a network attack in the network traffic data, and if there is a network attack, detect the attack type to which the network attack belongs.

[0167] For the explanation of step S401, please refer to the relevant description in any embodiment of the present application and will not be repeated here.

[0168] Step S402: Receive a first aggregation parameter sent by an aggregation node; wherein the first aggregation parameter is obtained by aggregating the first encryption model parameters sent by each computing node when an aggregation opportunity is met.

[0169] In the embodiment of the present application, the aggregation opportunity refers to the aggregation opportunity of the encryption model parameters, and the encryption model parameters may include the first encryption model parameters or the second encryption model parameters, wherein the aggregation opportunity may include at least one of the following:

[0170] First, the encrypted model parameters received by the aggregation node include the updated model parameters for setting the training rounds.

[0171] For example, the aggregation node may aggregate the encrypted model parameters sent by each computing node every 10 training rounds.

[0172] Second, the aggregation node receives the model parameter aggregation instruction sent by the central node.

[0173] The model parameter aggregation instruction is used to instruct the aggregation node to aggregate the received encryption model parameters.

[0174] The third item is reaching the target time, where the target time is determined by the aggregation node based on the predicted training end time of each computing node.

[0175] Among them, the aggregation node can use relevant algorithms (such as AI algorithms) to predict the training end time of each computing node, and determine the target time based on the training end time of each computing node. For example, the maximum value of the training end time can be used as the target time.

[0176] The fourth item is to confirm that each computing node has completed the update of the model parameters, that is, each computing node has been trained.

[0177] In an embodiment of the present application, the aggregation node may aggregate the first encrypted model parameters received from the respective computing nodes when an aggregation opportunity is met to obtain first aggregated parameters. The first encrypted model parameters are obtained by the computing node updating the initial model parameters using local training data to obtain updated model parameters, and then encrypting the updated model parameters.

[0178] As an example, take the aggregation timing as the first item above, and the number of computing nodes is 3, namely computing node 1, computing node 2, and computing node 3. First, computing node 1 can use local training data to independently train the intrusion detection model and obtain the updated model parameter W r 1 (referred to as updated model parameters in this application), similarly, computing node 2 can use local training data to independently train the intrusion detection model to obtain the updated model parameters W r 2 (referred to as updated model parameters in this application), computing node 3 can use local training data to independently train the intrusion detection model to obtain the updated model parameters W r 3(denoted as updating model parameters in this application), where r represents the training round of the computing node. Moreover, each computing node can encrypt and update the model parameters using the public key PKc of the central node after each round of model training.

[0179] For example, the encryption process can be as follows:

[0180] Compute node 1: E(W r 1 )←encrypt{PKc*W r 1};

[0181] Compute node 2: E(W r 2 )←encrypt{PKc*W r 2};

[0182] Compute Node 3: E(W r 3 )←encrypt{PKc*W r 3};

[0183] Afterwards, computing node 1, computing node 2, and computing node 3 can send E(W r 1 )、E(W r 2 )、E(W r 3 ) to a secure aggregation node.

[0184] Afterwards, when the aggregation timing is determined to be met, the aggregation node may aggregate (eg, collect and package) the received encryption model parameters. For example, the aggregation process may be:

[0185] 1. The aggregation node collects the encryption model parameters E(W1)←∑(W r 1 )、E(W2)←∑(W r 2 )、E(W3)←∑(W r 3 ); where ∑ refers to packaging, i.e., packaging the encrypted model parameters of each training round sent by the same computing node;

[0186] 2. The aggregation node collects model parameters according to the set training rounds (or called the prescribed training rounds): E(ΔW)←Agg(E(W1)+E(W2)+E(W3)); where Agg refers to aggregation (such as packaging);

[0187] 3. The aggregation node packages E(ΔW) and sends it to the central node.

[0188] Step S403: decrypt and calculate the first aggregated parameter to obtain target model parameters of the intrusion detection model.

[0189] For the explanation of step S403, please refer to the relevant description in any embodiment of the present application and will not be repeated here.

[0190] In any embodiment of the present application, when the aggregation timing is when a model parameter aggregation instruction is received from the central node, the central node may also send a broadcast message to each computing node, wherein the broadcast message is used to reset the training round to avoid aggregating duplicate model parameters.

[0191] The federated learning method of the intrusion detection model in the embodiment of the present application can configure the aggregation timing on the aggregation node side based on actual application needs to meet personalized training needs in different scenarios.

[0192] The above are various method embodiments executed by the central node. This application also proposes a federated learning method of an intrusion detection model executed by an aggregation node.

[0193] Figure 5 A flowchart of another federated learning method for an intrusion detection model provided in an embodiment of the present application.

[0194] like Figure 5 As shown in Figure 2, the federated learning method of the intrusion detection model can be applied to the aggregation node, including the following steps:

[0195] Step S501, receiving a first encrypted model parameter sent by at least one computing node; wherein the first encrypted model parameter is obtained by the computing node updating the initial model parameter of the intrusion detection model sent by the central node using local training data, and encrypting the updated model parameter.

[0196] Among them, the intrusion detection model is used to detect whether there is a network attack in the network traffic data, and if there is a network attack, detect the attack type to which the network attack belongs.

[0197] Step S502: Aggregate the first encryption model parameters to obtain a first aggregate parameter.

[0198] Step S503: Send the first aggregation parameter to the central node; wherein the first aggregation parameter is used by the central node to perform decryption and calculation processing to obtain the target model parameter of the intrusion detection model.

[0199] In any embodiment of the present application, the aggregation node may aggregate the first encryption model parameters to obtain the first aggregation parameter when an aggregation opportunity is met; wherein the aggregation opportunity includes at least one of the following:

[0200] First, the received encrypted model parameters include the updated model parameters for setting the training rounds;

[0201] The second item is receiving the model parameter aggregation instruction sent by the central node;

[0202] The third item is the target time. The target time is determined by the aggregation node based on the predicted training end time of each computing node.

[0203] The fourth item is to ensure that all computing nodes have completed the update of model parameters.

[0204] In any embodiment of the present application, when the aggregation timing is to reach the target moment, the aggregation node can send an indication message to each computing node; wherein the indication message is used to instruct the computing node to stop updating the model parameters, that is, the indication message is used to instruct each computing node to stop training the intrusion detection model to reduce resource consumption.

[0205] In any embodiment of the present application, the computing node may be an SDS node.

[0206] It should be noted that the aforementioned Figures 1 to 4 The explanations of the various method embodiments executed by the central node in the embodiments are also applicable to this embodiment. The implementation principles are similar and will not be described in detail here.

[0207] The federated learning method of the intrusion detection model in the embodiment of the present application can realize intrusion detection based on federated learning in a communication network by introducing various computing nodes. Intrusion detection based on federated learning can better and timely respond to complex network attacks and unknown attacks. In addition, federated learning realizes distributed machine learning, ensuring that the local training data of each computing node does not leave its own node, thereby protecting the security and privacy of the training data. In addition, the model parameters updated by the computing node are encrypted, which can ensure the confidentiality and integrity of the model parameters, further ensuring the security and privacy of sensitive data in each network domain.

[0208] The above are various method embodiments executed by a central node or an aggregation node. The present application also proposes a federated learning method of an intrusion detection model executed by a computing node.

[0209] Figure 6 A flowchart of another federated learning method for an intrusion detection model provided in an embodiment of the present application.

[0210] like Figure 6 As shown, the federated learning method of the intrusion detection model can be applied to computing nodes, including the following steps:

[0211] Step S601: receiving initial model parameters of an intrusion detection model sent by a central node.

[0212] Among them, the intrusion detection model is used to detect whether there is a network attack in the network traffic data, and if there is a network attack, detect the attack type to which the network attack belongs.

[0213] Step S602: Update the initial model parameters using local training data to obtain updated model parameters.

[0214] Step S603: encrypt the updated model parameters to obtain first encrypted model parameters.

[0215] Step S604, sending the first encrypted model parameter to the aggregation node; wherein the first encrypted model parameter is used for the aggregation node to perform aggregation processing, obtain the first aggregation parameter, and send the first aggregation parameter to the central node; the first aggregation parameter is used for the central node to perform decryption and calculation processing to obtain the target model parameter of the intrusion detection model.

[0216] In any embodiment of the present application, the computing node may be an SDS node.

[0217] In any embodiment of the present application, the computing node can use the public key of the central node to encrypt the updated model parameters to obtain the first encrypted model parameters; correspondingly, the first aggregation parameters are used by the central node to decrypt the first aggregation parameters using the private key of the central node, and calculate the decrypted model parameters to obtain the target model parameters of the intrusion detection model.

[0218] It should be noted that the aforementioned Figures 1 to 4 The explanations of the various methods implemented by the central node in the embodiments are also applicable to this embodiment, and the aforementioned Figure 5 The explanation of the embodiment of the method executed by the aggregation node in the embodiment is also applicable to this embodiment. The implementation principle is similar and will not be described in detail here.

[0219] The federated learning method of the intrusion detection model in the embodiment of the present application can realize intrusion detection based on federated learning in a communication network by introducing various computing nodes. Intrusion detection based on federated learning can better and timely respond to complex network attacks and unknown attacks. In addition, federated learning realizes distributed machine learning, ensuring that the local training data of each computing node does not leave its own node, thereby protecting the security and privacy of the training data. In addition, the model parameters updated by the computing node are encrypted, which can ensure the confidentiality and integrity of the model parameters, further ensuring the security and privacy of sensitive data in each network domain.

[0220] Traditionally, data collected or collected by terminals needs to be uploaded and processed centrally in cloud-based data centers. With the rapid growth of data sources, distributed machine learning is seen as one of the methods to solve the problem of large-scale data processing. Distributed machine learning mainly relies on the computing and storage capabilities of terminals and edge servers. However, data calculation, offloading, and processing in edge servers still involve the transmission of sensitive data, especially security network traffic data used to detect network attacks (such as DDoS attacks). This may cause users to worry about privacy and even violate privacy laws.

[0221] Federated learning aims to address this issue by building machine learning models based on distributed datasets across multiple devices while preventing privacy data leakage. This application provides a collaborative federated learning architecture solution that enables multiple network domains to collaborate on intrusion detection operations, mitigating the impact of network attacks on communication systems while ensuring the security and privacy of sensitive data within each network domain. In this framework, each data partition corresponds to a subset of data samples collected from one or more users. Devices or nodes participating in federated learning do not need to send the original training data they collected; they only need to send updated model parameters for aggregation.

[0222] As an example, taking the computing nodes as SDS nodes, the architecture of the intrusion detection system (or intrusion detection network system) can be as follows: Figure 7 As shown, the intrusion detection system includes a central node, an aggregation node and at least one SDS node ( Figure 7 Only three SDS nodes are used as an example.)

[0223] Among them, the central node is responsible for initializing the collaborative federated learning process and distributing and initializing the global model parameters.

[0224] Aggregation node (or security aggregation node): used to aggregate the updated model parameters (referred to as updated parameters) of federated learning training of SDS nodes and transmit the aggregated updated parameters to the central node.

[0225] SDS node: As a local node for federated learning, it performs local model training based on its local training data and sends the updated parameters after training to the aggregation node.

[0226] The intrusion detection system provided in this application can be a federated learning intrusion detection network system based on software-defined security, which is used to solve the problem of rapid response in the face of emerging and unknown attack threats in 6G ubiquitous networks while protecting the security and privacy of training data in model training scenarios. Among them, by introducing SDS nodes, while utilizing the software-defined architecture, the security function abstraction capability is enhanced, and the SDS nodes are used as local training nodes for the federated learning intrusion detection model. The implementation principle mainly includes the following parts:

[0227] 1. Training model initialization: The central node initializes the global intrusion detection model and the parameters required for federated learning, and sends the initialized model parameters (referred to as initial model parameters in this application) to each SDS node through a secure communication channel.

[0228] 2. Local model training: Each SDS node uses local training data to independently train the intrusion detection model. After each round of model training, it uses the central node's public key (such as the elliptic curve public key, that is, the public key used in the elliptic curve encryption algorithm, which has high security and a relatively short key length) PKc to encrypt the updated model parameters (referred to as updated model parameters in this application), obtain the encrypted model parameters, and send the encrypted model parameters to the aggregation node.

[0229] 3. Aggregation node collection and packaging: The aggregation node collects the encryption model parameters sent by each SDS node. After collecting the encryption model parameters sent by each SDS according to established rules, these encryption model parameters are aggregated (such as packaging) and sent to the central node.

[0230] Among them, the established rules can be to stipulate or set training rounds, or the central node can actively request the aggregation node to aggregate (such as packaging), or the aggregation node can determine that each SDS node has completed the collection of model parameters (such as each SDS node has been trained).

[0231] 4. The central node decrypts the aggregated parameters with its private key PRc and calculates the new global model parameters. After that, the global model parameters can be distributed to each federated learning SDS node.

[0232] 5. Repeat the above steps until the termination conditions are met (such as reaching the predetermined number of training rounds, reaching the predetermined training duration, or other stopping conditions).

[0233] The implementation principle of this application is described in detail below in combination with Example A and Example B.

[0234] Example A: Aggregation nodes aggregate encryption model parameters according to the specified time, such as Figure 8 As shown in Figure 2, the federated learning process mainly includes the following steps:

[0235] A.1. Training model initialization: The central node initializes the global intrusion detection model and the model parameters W0 required for federated learning, and sends the initialized model parameters (referred to as initial model parameters in this application) to each SDS node through a secure communication channel.

[0236] A.2. Local model training: Taking the number of SDS nodes as 3, namely SDS node 1, SDS node 2, and SDS node 3, SDS node 1, SDS node 2, and SDS node 3 can use local training data to independently train the intrusion detection model and obtain the updated model parameters W. r 1 、W r 2 、W r 3 (denoted as updating model parameters in this application), where r represents the training round of the SDS node. Moreover, each SDS node can encrypt and update the model parameters using the central node's public key PKc after each round of model training.

[0237] For example, the encryption process can be as follows:

[0238] SDS node 1: E(W r 1 )←encrypt{PKc*W r 1};

[0239] SDS node 2: E(W r 2 )←encrypt{PKc*W r 2};

[0240] SDS node 3: E(W r 3 )←encrypt{PKc*W r 3};

[0241] A.3, SDS node 1, SDS node 2, and SDS node 3 send E(W r 1 )、E(W r 2 )、E(W r 3) to a secure aggregation node.

[0242] A.4. Aggregation node collects and packages the received encryption model parameters: Aggregation node collects the encryption model parameters E(W1)←∑(W r 1 )、E(W2)←∑(W r 2 )、E(W3)←∑(W r 3 ), where ∑ refers to packaging, i.e., packaging the encryption model parameters of each training round received from the same SDS node; after the collection is completed according to the established training rounds (e.g., each SDS node undergoes 10 rounds of training): E(ΔW)←Agg(E(W1)+E(W2)+E(W3)), where Agg refers to aggregation (e.g., packaging).

[0243] A.5. The aggregation node packages E(ΔW) and sends it to the central node.

[0244] A.6. The central node uses its private key PRc to decrypt the aggregated parameters, obtaining the decrypted model parameters ΔW←decrypt{PRc*E(ΔW)}. Furthermore, the central node can also perform calculations on ΔW to obtain new global model parameters.

[0245] A.7. The central node distributes the new global model parameters to each federated learning SDS node.

[0246] Repeat the above steps until the training termination condition is met (such as reaching a predetermined number of training rounds, reaching a predetermined training time, or other stopping conditions).

[0247] Example B: The central node triggers the aggregation node to aggregate model parameters, such as Figure 9 As shown in Figure 2, the federated learning process mainly includes the following steps:

[0248] B.1. Training model initialization: The central node initializes the global intrusion detection model and the model parameters W0 required for federated learning, and sends the initialized model parameters (referred to as initial model parameters in this application) to each SDS node through a secure communication channel.

[0249] B.2. Local model training: Take the number of SDS nodes as 3, namely SDS node 1, SDS node 2, and SDS node 3 as an example. SDS node 1, SDS node 2, and SDS node 3 can use local training data to independently train the intrusion detection model and obtain the updated model parameters W. r 1 、W r 2 、Wr 3 (denoted as updating model parameters in this application), where r represents the training round of the SDS node. Moreover, each SDS node can encrypt and update the model parameters using the central node's public key PKc after each round of model training.

[0250] Each SDS node can train the intrusion detection model using multiple batches of training data to update the initial model parameters and obtain updated model parameters. When the training of multiple batches of training data is completed, the SDS node can encrypt the updated model parameters to obtain encrypted model parameters and send the encrypted model parameters to the aggregation node.

[0251] When the aggregation node receives the encrypted model parameters sent by the SDS node, the training round may be increased by one, that is, the training round refers to the number of times the aggregation node receives the encrypted model parameters sent by the same SDS node.

[0252] For example, the encryption process can be as follows:

[0253] SDS node 1: E(W r 1 )←encrypt{PKc*W r 1};

[0254] SDS node 2: E(W r 2 )←encrypt{PKc*W r 2};

[0255] SDS node 3: E(W r 3 )←encrypt{PKc*W r 3};

[0256] B.3. The central node sends a model parameter aggregation instruction (or model parameter collection instruction) to the aggregation node.

[0257] B.4. The aggregation node collects the existing encryption model parameters, E(W1)←∑(W r 1 )、E(W2)←∑(W r 2 )、E(W3)←∑(W r 3 ), where r is the number of training rounds from the SDS nodes that the aggregation node has collected when receiving the model parameter aggregation instruction sent by the central node.

[0258] B.5. Encryption model parameters collected by aggregation nodes: E(ΔW)←Agg(E(W1)+E(W2)+E(W3).

[0259] B.6. The aggregation node packages E(ΔW) and sends it to the central node.

[0260] B.7. The central node decrypts the aggregated parameters using its private key PRc, obtaining the decrypted model parameters ΔW←decrypt{PRc*E(ΔW)}. Furthermore, the central node can also perform calculations on ΔW to obtain new global model parameters.

[0261] B.8. The central node distributes the new global model parameters to each federated learning SDS node.

[0262] B.9. The central node sends a broadcast message to each SDS node. The broadcast message is used to reset the training round.

[0263] Repeat the above steps until the training termination condition is met (such as reaching a predetermined number of training rounds, reaching a predetermined training time, or other stopping conditions).

[0264] In summary, this application provides an intrusion detection solution based on a federated learning collaborative architecture, through which multiple network domains can cooperate to perform intrusion detection operations, thereby reducing the impact of network attacks on communication systems and ensuring the security and privacy of sensitive data within each network domain. Among them, by introducing SDS nodes, while utilizing the software-defined architecture, the abstraction capability of security functions is enhanced, and the SDS nodes are used as local training nodes for intrusion detection models. Moreover, after the SDS nodes train the local intrusion detection models, they perform asymmetric encryption on the updated model parameters, which can ensure that the updated model parameters are not obtained by the aggregation nodes and other attackers in the intermediate paths during the communication link between the local SDS nodes and the central node.

[0265] Compared with the existing technology, the present application has at least the following advantages: by introducing SDS nodes, federated learning-based intrusion detection can be realized in the communication network. Federated learning-based intrusion detection can better and timely respond to complex network attacks and unknown attacks. In addition, federated learning realizes distributed machine learning, ensuring that the local training data of each SDS node does not leave its own node, thereby protecting the security and privacy of the training data. In addition, after using asymmetric encryption for the updated model parameters of the local SDS node, the confidentiality and integrity of the model parameters can be guaranteed.

[0266] The technical solution provided in the embodiment of the present application can be applicable to a variety of systems, especially 5G systems. For example, applicable systems may be Global System of Mobile communication (GSM) systems, Code Division Multiple Access (CDMA) systems, Wideband Code Division Multiple Access (WCDMA) systems, General Packet Radio Service (GPRS) systems, Long Term Evolution (LTE) systems, LTE Frequency Division Duplex (FDD) systems, LTE Time Division Duplex (TDD) systems, Long Term Evolution Advanced (LTE-A) systems, Universal Mobile Telecommunication System (UMTS) systems, Worldwide interoperability for Microwave Access (WiMAX) systems, 5G New Radio (NR) systems, etc. These various systems include terminals and network equipment. The system may also include core network parts, such as the Evolved Packet System (EPS) and the 5G System (5GS).

[0267] In order to implement the above embodiment, the present application also proposes a central node.

[0268] Figure 10 A schematic diagram of the structure of a central node provided in an embodiment of the present application.

[0269] like Figure 10 As shown, the central node may include: a transceiver 1000 , a processor 1010 , and a memory 1020 .

[0270] Among them, the memory 1020 is used to store computer programs; the transceiver 1000 is used to send and receive data under the control of the processor 1010; the processor 1010 is used to read the computer program in the memory 1020 and perform the following operations: sending initial model parameters of the intrusion detection model to at least one computing node; wherein the intrusion detection model is used to detect whether there is a network attack in the network traffic data, and when there is a network attack, detect the attack type to which the network attack belongs; receiving the first aggregation parameter sent by the aggregation node; wherein the first aggregation parameter is obtained by the aggregation node aggregating the first encrypted model parameters sent by each computing node; the first encrypted model parameter is obtained by the computing node updating the initial model parameter using local training data to obtain the updated model parameter, and encrypting the updated model parameter; the first aggregation parameter is decrypted and calculated to obtain the target model parameter of the intrusion detection model.

[0271] The transceiver 1000 is configured to receive and send data under the control of the processor 1010 .

[0272] Among them, Figure 10 In the embodiment, the bus architecture may include any number of interconnected buses and bridges, specifically linking together various circuits of one or more processors represented by processor 1010 and memory represented by memory 1020. The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are all well known in the art and, therefore, will not be described further herein. The bus interface provides an interface. The transceiver 1000 may be a plurality of components, namely, a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium, such as a wireless channel, a wired channel, an optical cable, and the like. The processor 1010 is responsible for managing the bus architecture and general processing, and the memory 1020 may store data used by the processor 1010 when performing operations.

[0273] The processor 1010 may be a CPU, an ASIC, an FPGA, or a CPLD, and the processor 1010 may also adopt a multi-core architecture.

[0274] As a possible implementation method, the computing node is a software-defined security (SDS) node.

[0275] As a possible implementation manner, the central node and the aggregation node are deployed in different core network devices, and at least one computing node is deployed in different edge nodes or access network devices.

[0276] As a possible implementation method, the first encrypted model parameter is obtained by the computing node using the public key of the central node to encrypt the updated model parameter; accordingly, the processor 1010 performs decryption and calculation processing on the first aggregation parameter, specifically: based on the private key of the central node, the first aggregation parameter is decrypted; the decrypted model parameter is calculated to obtain the target model parameter of the intrusion detection model.

[0277] As a possible implementation method, the processor 1010 performs decryption and calculation processing on the first aggregation parameters to obtain the target model parameters of the intrusion detection model, specifically: decrypting and calculating the first aggregation parameters to obtain global model parameters; judging whether the termination training conditions of the intrusion detection model are met; if so, using the global model parameters as the target model parameters of the intrusion detection model; if not, performing at least one round of iterative process according to the global model parameters to obtain the target model parameters of the intrusion detection model.

[0278] As a possible implementation method, the processor 1010 executes the first round of iteration process, specifically: using the global model parameters as the intermediate model parameters of the first round of iteration process, and sending the intermediate model parameters of the first round of iteration process to at least one computing node; receiving the second aggregation parameters of the first round of iteration process sent by the aggregation node; wherein, the second aggregation parameters of the first round of iteration process are obtained by the aggregation node aggregating the second encrypted model parameters of the first round of iteration process sent by each computing node; the second encrypted model parameters of the first round of iteration process are obtained by the computing node updating and encrypting the intermediate model parameters of the first round of iteration process using local training data; judging whether the termination training condition is met; if so, stopping the iteration, and decrypting and calculating the second aggregation parameters of the first round of iteration process to obtain the target model parameters of the intrusion detection model; if not, decrypting and calculating the second aggregation parameters of the first round of iteration process to obtain the intermediate model parameters of the second round of iteration process.

[0279] As a possible implementation method, the processor 1010 executes a non-first round of iteration, specifically: sending the intermediate model parameters of this round of iteration to at least one computing node; receiving the second aggregation parameters of this round of iteration sent by the aggregation node; wherein the second aggregation parameters of this round of iteration are obtained by the aggregation node aggregating the second encrypted model parameters of this round of iteration sent by each computing node; the second encrypted model parameters of this round of iteration are obtained by the computing node updating and encrypting the intermediate model parameters of this round of iteration using local training data; judging whether the termination training condition is met; if so, stopping the iteration, and decrypting and calculating the second aggregation parameters of this round of iteration to obtain the target model parameters of the intrusion detection model; if not, decrypting and calculating the second aggregation parameters of this round of iteration to obtain the intermediate model parameters of the next round of iteration.

[0280] As a possible implementation method, the training termination conditions include at least one of the following: the training time of the intrusion detection model reaches the set time; the training rounds of the intrusion detection model reach the set rounds; the first KPI indicator of the intrusion detection model on the validation set is higher than the corresponding first threshold; the second KPI indicator of the intrusion detection model on the validation set is lower than the corresponding second threshold; wherein, the first KPI indicator includes at least one of the following: accuracy; precision; recall rate; F1 value; R2 value; AUC-ROC; AUC-PR; wherein, the second KPI indicator includes at least one of the following: MSE; MAE; RMSE.

[0281] As a possible implementation, the aggregation timing of the encryption model parameters includes at least one of the following:

[0282] The received encryption model parameters include updated model parameters for setting training rounds; wherein the encryption model parameters include first encryption model parameters or second encryption model parameters;

[0283] Receive the model parameter aggregation instruction sent by the central node;

[0284] Arrival at the target time; where the target time is determined by the aggregation node based on the predicted training end time of each computing node;

[0285] Make sure that all computing nodes have completed the update of model parameters.

[0286] As a possible implementation, when the aggregation opportunity is receiving a model parameter aggregation instruction sent by the central node, the processor 1010 is further used to perform the following operations: sending a broadcast message to each computing node, wherein the broadcast message is used to reset the training round.

[0287] As a possible implementation method, the processor 1010 executes sending the initial model parameters of the intrusion detection model to at least one computing node, specifically: broadcasting the initial model parameters to each computing node; or, encrypting the initial model parameters based on the private key of the central node, and sending the encrypted initial model parameters to each computing node; or, sending the initial model parameters to each computing node based on a secure communication channel between the central node and each computing node; wherein the secure communication channel is established when the central node sends an authentication request to the computing node and receives an authentication success response sent by the computing node; wherein the authentication request carries the security certificate of the central node, and the authentication success response is generated when the computing node authenticates the security certificate and passes the authentication.

[0288] It should be noted that the central node provided in the embodiment of the present application can achieve the above Figures 1 to 4 All the method steps implemented in the method embodiment can achieve the same technical effects, and the parts and beneficial effects of this embodiment that are the same as those in the method embodiment will not be described in detail here.

[0289] In order to implement the above embodiment, the present application also proposes an aggregation node.

[0290] Figure 11 A schematic diagram of the structure of an aggregation node provided in an embodiment of the present application.

[0291] like Figure 11 As shown, the aggregation node may include: a transceiver 1100 , a processor 1110 , and a memory 1120 .

[0292] Among them, the memory 1120 is used to store computer programs; the transceiver 1100 is used to send and receive data under the control of the processor 1110; the processor 1110 is used to read the computer program in the memory 1120 and perform the following operations: receiving a first encryption model parameter sent by at least one computing node; wherein the first encryption model parameter is obtained by the computing node updating the initial model parameters of the intrusion detection model sent by the central node using local training data, and encrypting the updated model parameter; aggregating each first encryption model parameter to obtain a first aggregation parameter; sending the first aggregation parameter to the central node; wherein the first aggregation parameter is used for decryption and calculation processing by the central node to obtain the target model parameter of the intrusion detection model; wherein the intrusion detection model is used to detect whether there is a network attack in the network traffic data, and when there is a network attack, detect the attack type to which the network attack belongs.

[0293] The transceiver 1100 is configured to receive and send data under the control of the processor 1110 .

[0294] Among them, Figure 11 In the embodiment, the bus architecture may include any number of interconnected buses and bridges, specifically various circuits linked together by one or more processors represented by processor 1110 and memory represented by memory 1120. The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are all well known in the art and, therefore, will not be described further herein. The bus interface provides an interface. The transceiver 1100 may be a plurality of components, i.e., a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium, such as a wireless channel, a wired channel, an optical cable, and the like. The processor 1110 is responsible for managing the bus architecture and general processing, and the memory 1120 may store data used by the processor 1110 when performing operations.

[0295] The processor 1110 may be a CPU, an ASIC, an FPGA, or a CPLD, and the processor 1110 may also adopt a multi-core architecture.

[0296] As a possible implementation, the processor 1110 aggregates the first encryption model parameters to obtain the first aggregate parameter, specifically: when an aggregation opportunity is met, aggregates the first encryption model parameters to obtain the first aggregate parameter;

[0297] The aggregation opportunity includes at least one of the following:

[0298] The received encrypted model parameters include updated model parameters for setting training rounds;

[0299] Receive the model parameter aggregation instruction sent by the central node;

[0300] Arrival at the target time; where the target time is determined by the aggregation node based on the predicted training end time of each computing node;

[0301] Make sure that all computing nodes have completed the update of model parameters.

[0302] As a possible implementation, when the aggregation timing is the target arrival time, the processor 1110 is further configured to perform the following operations: sending an indication message to each computing node; wherein the indication message is configured to instruct the computing node to stop updating the model parameters.

[0303] As a possible implementation method, the computing node is a software-defined security (SDS) node.

[0304] It should be noted that the aggregation node provided in the embodiment of the present application can achieve the above Figure 5All the method steps implemented in the method embodiment can achieve the same technical effects, and the parts and beneficial effects of this embodiment that are the same as those in the method embodiment will not be described in detail here.

[0305] In order to implement the above embodiment, the present application also proposes a computing node.

[0306] Figure 12 A schematic diagram of the structure of a computing node provided in an embodiment of the present application.

[0307] like Figure 12 As shown, the computing node may include: a transceiver 1200 , a processor 1210 , and a memory 1220 .

[0308] Among them, the memory 1220 is used to store computer programs; the transceiver 1200 is used to send and receive data under the control of the processor 1210; the processor 1210 is used to read the computer program in the memory 1220 and perform the following operations: receive the initial model parameters of the intrusion detection model sent by the central node; wherein, the intrusion detection model is used to detect whether there is a network attack in the network traffic data, and when there is a network attack, detect the attack type to which the network attack belongs; use local training data to update the initial model parameters to obtain updated model parameters; encrypt the updated model parameters to obtain first encrypted model parameters; send the first encrypted model parameters to the aggregation node; wherein the first encrypted model parameters are used for aggregation processing at the aggregation node to obtain first aggregation parameters, and send the first aggregation parameters to the central node; the first aggregation parameters are used for decryption and calculation processing at the central node to obtain target model parameters of the intrusion detection model.

[0309] The transceiver 1200 is configured to receive and send data under the control of the processor 1210 .

[0310] Among them, Figure 12 In the embodiment, the bus architecture may include any number of interconnected buses and bridges, specifically various circuits linked together by one or more processors represented by processor 1210 and memory represented by memory 1220. The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are all well known in the art and, therefore, will not be described further herein. The bus interface provides an interface. The transceiver 1200 may be a plurality of components, i.e., a transmitter and a receiver, providing a unit for communicating with various other devices on a transmission medium, such as a wireless channel, a wired channel, an optical cable, and the like. The processor 1210 is responsible for managing the bus architecture and general processing, and the memory 1220 may store data used by the processor 1210 when performing operations.

[0311] The processor 1210 may be a CPU, an ASIC, an FPGA, or a CPLD, and the processor 1210 may also adopt a multi-core architecture.

[0312] As a possible implementation method, the computing node is a software-defined security (SDS) node.

[0313] As a possible implementation, the processor 1210 encrypts the updated model parameter to obtain the first encrypted model parameter, specifically by: using the public key of the central node to encrypt the updated model parameter to obtain the first encrypted model parameter;

[0314] Correspondingly, the first aggregation parameter is used to decrypt the first aggregation parameter using the private key of the central node, and to calculate the model parameters obtained by decryption to obtain the target model parameters of the intrusion detection model.

[0315] It should be noted that the computing nodes provided in the embodiment of the present application can achieve the above Figure 6 All the method steps implemented in the method embodiment can achieve the same technical effects, and the parts and beneficial effects of this embodiment that are the same as those in the method embodiment will not be described in detail here.

[0316] With the above Figures 1 to 4 Corresponding to the federated learning method of the intrusion detection model provided in the embodiment, the present application also provides a federated learning device for the intrusion detection model. Figures 1 to 4 The federated learning method of the intrusion detection model provided in the embodiment corresponds to the embodiment, so the implementation method of the federated learning method of the intrusion detection model is also applicable to the federated learning device of the intrusion detection model provided in the embodiment of the present application, and will not be described in detail in the embodiment of the present application.

[0317] Figure 13 A schematic diagram of the structure of a federated learning device for an intrusion detection model provided in an embodiment of the present application.

[0318] like Figure 13 As shown, the federated learning device 1300 of the intrusion detection model can be applied to a central node, including: a sending unit 1310, a receiving unit 1320 and a processing unit 1330.

[0319] The sending unit 1310 is used to send initial model parameters of the intrusion detection model to at least one computing node; wherein the intrusion detection model is used to detect whether there is a network attack in the network traffic data, and when there is a network attack, detect the attack type to which the network attack belongs.

[0320] The receiving unit 1320 is used to receive the first aggregation parameter sent by the aggregation node; wherein the first aggregation parameter is obtained by the aggregation node aggregating the first encrypted model parameters sent by each computing node; the first encrypted model parameter is obtained by the computing node updating the initial model parameter using local training data to obtain the updated model parameter, and encrypting the updated model parameter.

[0321] The processing unit 1330 is configured to decrypt and perform calculation processing on the first aggregation parameter to obtain target model parameters of the intrusion detection model.

[0322] As a possible implementation method, the computing node is a software-defined security (SDS) node.

[0323] As a possible implementation manner, the central node and the aggregation node are deployed in different core network devices, and at least one computing node is deployed in different edge nodes or access network devices.

[0324] As a possible implementation, the first encrypted model parameter is obtained by the computing node encrypting the updated model parameter using the public key of the central node;

[0325] Accordingly, the processing unit 1330 is specifically configured to: decrypt the first aggregation parameter based on the private key of the central node; and perform calculation processing on the model parameters obtained by decryption to obtain target model parameters of the intrusion detection model.

[0326] As a possible implementation method, the processing unit 1330 is specifically used to: decrypt and calculate the first aggregation parameters to obtain global model parameters; determine whether the termination training conditions of the intrusion detection model are met; if so, use the global model parameters as the target model parameters of the intrusion detection model; if not, perform at least one round of iterative process according to the global model parameters to obtain the target model parameters of the intrusion detection model.

[0327] As a possible implementation method, the first round of iterative process includes: using the global model parameters as the intermediate model parameters of the first round of iterative process, and sending the intermediate model parameters of the first round of iterative process to at least one computing node; receiving the second aggregated parameters of the first round of iterative process sent by the aggregation node; wherein the second aggregated parameters of the first round of iterative process are obtained by the aggregation node aggregating the second encrypted model parameters of the first round of iterative process sent by each computing node; the second encrypted model parameters of the first round of iterative process are obtained by the computing node updating and encrypting the intermediate model parameters of the first round of iterative process using local training data; judging whether the termination training condition is met; if so, stopping the iteration, and decrypting and calculating the second aggregated parameters of the first round of iterative process to obtain the target model parameters of the intrusion detection model; if not, decrypting and calculating the second aggregated parameters of the first round of iterative process to obtain the intermediate model parameters of the second round of iterative process.

[0328] As a possible implementation method, the non-first round of iteration process includes: sending the intermediate model parameters of this round of iteration process to at least one computing node; receiving the second aggregation parameters of this round of iteration process sent by the aggregation node; wherein the second aggregation parameters of this round of iteration process are obtained by the aggregation node aggregating the second encrypted model parameters of this round of iteration process sent by each computing node; the second encrypted model parameters of this round of iteration process are obtained by the computing node updating and encrypting the intermediate model parameters of this round of iteration process using local training data; judging whether the termination training condition is met; if so, stopping the iteration, and decrypting and calculating the second aggregation parameters of this round of iteration process to obtain the target model parameters of the intrusion detection model; if not, decrypting and calculating the second aggregation parameters of this round of iteration process to obtain the intermediate model parameters of the next round of iteration process.

[0329] As a possible implementation method, the training termination conditions include at least one of the following: the training time of the intrusion detection model reaches the set time; the training rounds of the intrusion detection model reach the set rounds; the first KPI indicator of the intrusion detection model on the validation set is higher than the corresponding first threshold; the second KPI indicator of the intrusion detection model on the validation set is lower than the corresponding second threshold; wherein, the first KPI indicator includes at least one of the following: accuracy; precision; recall rate; F1 value; R2 value; AUC-ROC; AUC-PR; wherein, the second KPI indicator includes at least one of the following: MSE; MAE; RMSE.

[0330] As a possible implementation method, the aggregation timing of the encryption model parameters includes at least one of the following: the received encryption model parameters include the updated model parameters for setting the training round; wherein the encryption model parameters include the first encryption model parameters or the second encryption model parameters; receiving the model parameter aggregation instruction sent by the central node; arriving at the target time; wherein the target time is determined by the aggregation node based on the predicted training end time of each computing node; and determining that each computing node has completed the update of the model parameters.

[0331] As a possible implementation, when the aggregation opportunity is receiving a model parameter aggregation instruction sent by the central node, the sending unit 1310 is further used to: send a broadcast message to each computing node, wherein the broadcast message is used to reset the training round.

[0332] As a possible implementation, the sending unit 1310 is specifically configured to: broadcast the initial model parameters to each computing node; or, based on a private key of the central node, encrypt the initial model parameters and send the encrypted initial model parameters to each computing node; or, based on a secure communication channel with each computing node, send the initial model parameters to each computing node;

[0333] Among them, the secure communication channel is established when the central node sends an authentication request to the computing node and receives an authentication success response from the computing node; wherein, the authentication request carries the security certificate of the central node, and the authentication success response is generated when the computing node authenticates the security certificate and passes the authentication.

[0334] It should be noted that the federated learning device of the above-mentioned intrusion detection model provided in the embodiment of the present application can realize the above-mentioned Figures 1 to 4 All the method steps implemented in the method embodiment can achieve the same technical effects, and the parts and beneficial effects of this embodiment that are the same as those in the method embodiment will not be described in detail here.

[0335] With the above Figure 5 Corresponding to the federated learning method of the intrusion detection model provided in the embodiment, the present application also provides a federated learning device for the intrusion detection model. Figure 5 The federated learning method of the intrusion detection model provided in the embodiment corresponds to the embodiment, so the implementation method of the federated learning method of the intrusion detection model is also applicable to the federated learning device of the intrusion detection model provided in the embodiment of the present application, and will not be described in detail in the embodiment of the present application.

[0336] Figure 14 A schematic diagram of the structure of a federated learning device for another intrusion detection model provided in an embodiment of the present application.

[0337] like Figure 14 As shown, the federated learning device 1400 of the intrusion detection model can be applied to an aggregation node, including: a receiving unit 1410, an aggregation unit 1420 and a sending unit 1430.

[0338] Among them, the receiving unit 1410 is used to receive the first encrypted model parameters sent by at least one computing node; wherein the first encrypted model parameters are obtained by the computing node using local training data to update the initial model parameters of the intrusion detection model sent by the central node, and encrypting the updated model parameters.

[0339] Among them, the intrusion detection model is used to detect whether there is a network attack in the network traffic data, and if there is a network attack, detect the attack type to which the network attack belongs.

[0340] The aggregation unit 1420 is configured to aggregate the first encryption model parameters to obtain a first aggregation parameter.

[0341] The sending unit 1430 is configured to send the first aggregation parameter to the central node; wherein the first aggregation parameter is used by the central node to perform decryption and calculation processing to obtain the target model parameter of the intrusion detection model.

[0342] As a possible implementation, the aggregation unit 1420 is specifically configured to: aggregate the first encryption model parameters to obtain a first aggregation parameter when an aggregation opportunity is met;

[0343] Among them, the aggregation timing includes at least one of the following: the received encrypted model parameters include the updated model parameters for setting the training rounds; the model parameter aggregation instruction sent by the central node is received; the target time is reached; wherein the target time is determined by the aggregation node based on the predicted training end time of each computing node; and it is determined that each computing node has completed the update of the model parameters.

[0344] As a possible implementation, when the aggregation timing reaches the target time, the sending unit 1430 is further used to: send an indication message to each computing node; wherein the indication message is used to instruct the computing node to stop updating the model parameters.

[0345] As a possible implementation method, the computing node is a software-defined security (SDS) node.

[0346] It should be noted that the federated learning device of the above-mentioned intrusion detection model provided in the embodiment of the present application can realize the above-mentioned Figure 5 All the method steps implemented in the method embodiment can achieve the same technical effects, and the parts and beneficial effects of this embodiment that are the same as those in the method embodiment will not be described in detail here.

[0347] With the above Figure 6 Corresponding to the federated learning method of the intrusion detection model provided in the embodiment, the present application also provides a federated learning device for the intrusion detection model. Figure 6 The federated learning method of the intrusion detection model provided in the embodiment corresponds to the embodiment, so the implementation method of the federated learning method of the intrusion detection model is also applicable to the federated learning device of the intrusion detection model provided in the embodiment of the present application, and will not be described in detail in the embodiment of the present application.

[0348] Figure 15 A schematic diagram of the structure of a federated learning device for another intrusion detection model provided in an embodiment of the present application.

[0349] like Figure 15 As shown, the federated learning device 1500 of the intrusion detection model can be applied to a computing node, including: a receiving unit 1510, an updating unit 1520, an encryption unit 1530 and a sending unit 1540.

[0350] The receiving unit 1510 is used to receive the initial model parameters of the intrusion detection model sent by the central node; wherein the intrusion detection model is used to detect whether there is a network attack in the network traffic data, and if there is a network attack, detect the attack type of the network attack.

[0351] The updating unit 1520 is configured to update the initial model parameters using the local training data to obtain updated model parameters.

[0352] The encryption unit 1530 is configured to encrypt the updated model parameters to obtain first encrypted model parameters.

[0353] The sending unit 1540 is used to send the first encryption model parameter to the aggregation node; wherein the first encryption model parameter is used for the aggregation node to perform aggregation processing, obtain the first aggregation parameter, and send the first aggregation parameter to the central node; the first aggregation parameter is used for the central node to perform decryption and calculation processing to obtain the target model parameter of the intrusion detection model.

[0354] As a possible implementation method, the computing node is a software-defined security (SDS) node.

[0355] As a possible implementation, the encryption unit 1530 is specifically configured to: encrypt the updated model parameter using the public key of the central node to obtain the first encrypted model parameter;

[0356] Correspondingly, the first aggregation parameter is used to decrypt the first aggregation parameter using the private key of the central node, and to calculate the model parameters obtained by decryption to obtain the target model parameters of the intrusion detection model.

[0357] It should be noted that the federated learning device of the above-mentioned intrusion detection model provided in the embodiment of the present application can realize the above-mentioned Figure 6 All the method steps implemented in the method embodiment can achieve the same technical effects, and the parts and beneficial effects of this embodiment that are the same as those in the method embodiment will not be described in detail here.

[0358] It should be noted that the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0359] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) or a processor to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, and other media that can store program code.

[0360] In order to implement the above embodiments, the present application also proposes a processor-readable storage medium.

[0361] The processor-readable storage medium stores a computer program for causing the processor to execute the present application. Figures 1 to 6 The federated learning method of the intrusion detection model of any embodiment.

[0362] Among them, the processor-readable storage medium can be any available medium or data storage device that can be accessed by the processor, including but not limited to magnetic storage (such as floppy disks, hard disks, tapes, magneto-optical disks (MO)), optical storage (such as CDs, DVDs, BDs, HVDs, etc.), and semiconductor storage (such as ROM, EPROM, EEPROM, non-volatile memory (NANDFLASH), solid-state drives (SSDs)), etc.

[0363] In order to implement the above embodiments, the present application also proposes a computer program product.

[0364] The computer program product includes a computer program that, when executed by a processor, implements the present application. Figures 1 to 6 The federated learning method of the intrusion detection model of any embodiment.

[0365] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage and optical storage, etc.) that contain computer-usable program code.

[0366] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer-executable instructions. These computer-executable instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0367] These processor-executable instructions may also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the processor-readable memory produce an article of manufacture comprising an instruction device that implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0368] These processor-executable instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps for the function specified in one or more boxes.

[0369] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

Claims

1. A federated learning method for an intrusion detection model, characterized in that: Applied to the central node, including: Sending initial model parameters of the intrusion detection model to at least one computing node; wherein the intrusion detection model is used to detect whether there is a network attack in the network traffic data, and if there is the network attack, detect the attack type to which the network attack belongs; Receiving a first aggregation parameter sent by an aggregation node; wherein the first aggregation parameter is obtained by the aggregation node aggregating the first encrypted model parameters sent by each of the computing nodes; the first encrypted model parameter is obtained by the computing node updating the initial model parameter using local training data to obtain an updated model parameter, and encrypting the updated model parameter; The first aggregation parameters are decrypted and calculated to obtain target model parameters of the intrusion detection model.

2. The method according to claim 1, characterized in that The computing node is a software-defined security SDS node.

3. The method according to claim 1, characterized in that The central node and the aggregation node are arranged in different core network devices, and the at least one computing node is arranged in different edge nodes or access network devices.

4. The method according to claim 1, wherein The first encrypted model parameter is obtained by the computing node encrypting the updated model parameter using the public key of the central node; Accordingly, the decrypting and calculating the first aggregation parameter includes: Decrypting the first aggregation parameter based on the private key of the central node; The model parameters obtained by decryption are calculated to obtain target model parameters of the intrusion detection model.

5. The method according to claim 1, wherein The decrypting and calculating the first aggregated parameters to obtain target model parameters of the intrusion detection model includes: Decrypting and calculating the first aggregated parameters to obtain global model parameters; Determining whether a termination condition for training the intrusion detection model is met; If yes, then use the global model parameters as target model parameters of the intrusion detection model; If not, at least one round of iteration is performed according to the global model parameters to obtain target model parameters of the intrusion detection model.

6. The method according to claim 5, characterized in that The first iteration process includes: Using the global model parameters as the intermediate model parameters of the first round of iterative process, and sending the intermediate model parameters of the first round of iterative process to the at least one computing node; Receiving the second aggregation parameter of the first-round iterative process sent by the aggregation node; wherein the second aggregation parameter of the first-round iterative process is obtained by the aggregation node aggregating the second encryption model parameters of the first-round iterative process sent by each of the computing nodes; the second encryption model parameters of the first-round iterative process are obtained by the computing node updating and encrypting the intermediate model parameters of the first-round iterative process using local training data; Determining whether the training termination condition is met; If yes, stop the iteration, and decrypt and calculate the second aggregation parameter of the first round of iteration process to obtain the target model parameter of the intrusion detection model; If not, the second aggregation parameters of the first round of iterative process are decrypted and calculated to obtain the intermediate model parameters of the second round of iterative process.

7. The method according to claim 6, characterized in that The non-first round iteration process includes: Sending intermediate model parameters of this round of iterative process to the at least one computing node; Receiving a second aggregation parameter of the current iterative process sent by the aggregation node; wherein the second aggregation parameter of the current iterative process is obtained by the aggregation node aggregating the second encryption model parameters of the current iterative process sent by each of the computing nodes; the second encryption model parameters of the current iterative process are obtained by the computing node updating and encrypting the intermediate model parameters of the current iterative process using local training data; Determining whether the training termination condition is met; If yes, stop the iteration, and decrypt and calculate the second aggregation parameter of the current iteration process to obtain the target model parameter of the intrusion detection model; If not, the second aggregation parameter of the current iterative process is decrypted and calculated to obtain the intermediate model parameters of the next iterative process.

8. The method according to any one of claims 5 to 7, characterized in that The training termination condition includes at least one of the following: The training time of the intrusion detection model reaches the set time; The training rounds of the intrusion detection model reach the set rounds; A first key performance indicator (KPI) of the intrusion detection model on the validation set is higher than a corresponding first threshold; A second KPI indicator of the intrusion detection model on the validation set is lower than a corresponding second threshold; The first KPI indicator includes at least one of the following: accuracy; precision; recall rate; F1 value; R2 value; area under the receiver operating characteristic curve AUC-ROC; area under the precision-recall curve AUC-PR; The second KPI indicator includes at least one of the following: mean square error (MSE); mean absolute error (MAE); and root mean square error (RMSE).

9. The method according to any one of claims 1 to 7, characterized in that Aggregation timing for encryption model parameters includes at least one of the following: The received encryption model parameters include updated model parameters for setting training rounds; wherein the encryption model parameters include first encryption model parameters or second encryption model parameters; Receiving a model parameter aggregation instruction sent by the central node; Arriving at a target time; wherein the target time is determined by the aggregation node based on the predicted training end time of each computing node; It is determined that each of the computing nodes has completed the update of the model parameters.

10. The method according to claim 9, characterized in that In a case where the aggregation opportunity is receiving a model parameter aggregation instruction sent by the central node, the method further includes: Send a broadcast message to each of the computing nodes, wherein the broadcast message is used to reset the training round.

11. The method according to any one of claims 1 to 7, characterized in that The sending of the initial model parameters of the intrusion detection model to at least one computing node includes: broadcasting the initial model parameters to each of the computing nodes; or, Encrypting the initial model parameters based on the private key of the central node, and sending the encrypted initial model parameters to each of the computing nodes; or, Sending the initial model parameters to each computing node based on a secure communication channel with each computing node; The secure communication channel is established when the central node sends an authentication request to the computing node and receives an authentication success response from the computing node; The authentication request carries the security certificate of the central node, and the authentication success response is generated when the computing node authenticates the security certificate and passes the authentication.

12. A federated learning method for an intrusion detection model, characterized in that: Applicable to aggregation nodes, including: Receive a first encrypted model parameter sent by at least one computing node; wherein the first encrypted model parameter is obtained by the computing node updating the initial model parameter of the intrusion detection model sent by the central node using local training data, and encrypting the updated model parameter; Aggregating the first encryption model parameters to obtain a first aggregated parameter; Sending the first aggregation parameter to the central node; wherein the first aggregation parameter is used by the central node to perform decryption and calculation processing to obtain the target model parameter of the intrusion detection model; The intrusion detection model is used to detect whether there is a network attack in the network traffic data, and if there is a network attack, detect the attack type of the network attack.

13. The method according to claim 12, characterized in that The aggregating the first encryption model parameters to obtain a first aggregate parameter includes: When the aggregation opportunity is met, aggregating the first encryption model parameters to obtain a first aggregation parameter; The aggregation opportunity includes at least one of the following: The received encrypted model parameters include updated model parameters for setting training rounds; Receiving a model parameter aggregation instruction sent by the central node; Arriving at a target time; wherein the target time is determined by the aggregation node based on the predicted training end time of each computing node; It is determined that each of the computing nodes has completed the update of the model parameters.

14. The method according to claim 13, characterized in that When the aggregation timing is a target arrival time, the method further includes: An instruction message is sent to each of the computing nodes; wherein the instruction message is used to instruct the computing node to stop updating the model parameters.

15. The method according to any one of claims 12 to 14, characterized in that The computing node is a software-defined security SDS node.

16. A federated learning method for an intrusion detection model, characterized in that: Applied to compute nodes, including: Receiving initial model parameters of the intrusion detection model sent by the central node; wherein the intrusion detection model is used to detect whether there is a network attack in the network traffic data, and if there is the network attack, detect the attack type to which the network attack belongs; Updating the initial model parameters using local training data to obtain updated model parameters; encrypting the updated model parameters to obtain first encrypted model parameters; The first encryption model parameter is sent to the aggregation node; wherein the first encryption model parameter is used by the aggregation node to perform aggregation processing to obtain a first aggregation parameter, and the first aggregation parameter is sent to the central node; the first aggregation parameter is used by the central node to perform decryption and calculation processing to obtain the target model parameter of the intrusion detection model.

17. The method according to claim 16, characterized in that The computing node is a software-defined security SDS node.

18. The method according to claim 16, characterized in that The step of encrypting the updated model parameters to obtain first encrypted model parameters includes: Encrypting the updated model parameters using the public key of the central node to obtain the first encrypted model parameters; Correspondingly, the first aggregation parameter is used to decrypt the first aggregation parameter using the private key of the central node, and to calculate the model parameters obtained by decryption to obtain the target model parameters of the intrusion detection model.

19. A central node, characterized in that: Including memory, transceiver, processor; Memory for storing computer programs; a transceiver, configured to transmit and receive data under the control of the processor; A processor is configured to read the computer program in the memory and perform the following operations: Sending initial model parameters of the intrusion detection model to at least one computing node; wherein the intrusion detection model is used to detect whether there is a network attack in the network traffic data, and if there is the network attack, detect the attack type to which the network attack belongs; Receiving a first aggregation parameter sent by an aggregation node; wherein the first aggregation parameter is obtained by the aggregation node aggregating the first encrypted model parameters sent by each of the computing nodes; the first encrypted model parameter is obtained by the computing node updating the initial model parameter using local training data to obtain an updated model parameter, and encrypting the updated model parameter; The first aggregation parameters are decrypted and calculated to obtain target model parameters of the intrusion detection model.

20. The central node according to claim 19, characterized in that: The computing node is a software-defined security SDS node.

21. The central node according to claim 19, characterized in that The central node and the aggregation node are arranged in different core network devices, and the at least one computing node is arranged in different edge nodes or access network devices.

22. The central node according to claim 19, characterized in that The first encrypted model parameter is obtained by the computing node encrypting the updated model parameter using the public key of the central node; Accordingly, the processor performs decryption and calculation processing on the first aggregation parameter, specifically: Decrypting the first aggregation parameter based on the private key of the central node; The model parameters obtained by decryption are calculated to obtain target model parameters of the intrusion detection model.

23. The central node according to claim 19, characterized in that The processor performs decryption and calculation processing on the first aggregation parameter to obtain the target model parameter of the intrusion detection model, specifically: Decrypting and calculating the first aggregated parameters to obtain global model parameters; Determining whether a termination condition for training the intrusion detection model is met; If yes, then use the global model parameters as target model parameters of the intrusion detection model; If not, at least one round of iteration is performed according to the global model parameters to obtain target model parameters of the intrusion detection model.

24. The central node according to claim 23, characterized in that The processor performs a first round of iteration, specifically: Using the global model parameters as the intermediate model parameters of the first round of iterative process, and sending the intermediate model parameters of the first round of iterative process to the at least one computing node; Receiving the second aggregation parameter of the first-round iterative process sent by the aggregation node; wherein the second aggregation parameter of the first-round iterative process is obtained by the aggregation node aggregating the second encryption model parameters of the first-round iterative process sent by each of the computing nodes; the second encryption model parameters of the first-round iterative process are obtained by the computing node updating and encrypting the intermediate model parameters of the first-round iterative process using local training data; Determining whether the training termination condition is met; If yes, stop the iteration, and decrypt and calculate the second aggregation parameter of the first round of iteration process to obtain the target model parameter of the intrusion detection model; If not, the second aggregation parameters of the first round of iterative process are decrypted and calculated to obtain the intermediate model parameters of the second round of iterative process.

25. The central node according to claim 24, characterized in that The processor performs a non-first round of iteration process, specifically: Sending intermediate model parameters of this round of iterative process to the at least one computing node; Receiving a second aggregation parameter of the current iterative process sent by the aggregation node; wherein the second aggregation parameter of the current iterative process is obtained by the aggregation node aggregating the second encryption model parameters of the current iterative process sent by each of the computing nodes; the second encryption model parameters of the current iterative process are obtained by the computing node updating and encrypting the intermediate model parameters of the current iterative process using local training data; Determining whether the training termination condition is met; If yes, stop the iteration, and decrypt and calculate the second aggregation parameter of the current iteration process to obtain the target model parameter of the intrusion detection model; If not, the second aggregation parameter of the current iterative process is decrypted and calculated to obtain the intermediate model parameters of the next iterative process.

26. The central node according to any one of claims 23-25, characterized in that: The training termination condition includes at least one of the following: The training time of the intrusion detection model reaches the set time; The training rounds of the intrusion detection model reach the set rounds; A first KPI indicator of the intrusion detection model on the validation set is higher than a corresponding first threshold; A second KPI indicator of the intrusion detection model on the validation set is lower than a corresponding second threshold; The first KPI indicator includes at least one of the following: accuracy; precision; recall rate; F1 value; R2 value; AUC-ROC; AUC-PR; The second KPI indicator includes at least one of the following: MSE; MAE; RMSE.

27. The central node according to any one of claims 19 to 25, characterized in that: Aggregation timing for encryption model parameters includes at least one of the following: The received encryption model parameters include updated model parameters for setting training rounds; wherein the encryption model parameters include first encryption model parameters or second encryption model parameters; Receiving a model parameter aggregation instruction sent by the central node; Arriving at a target time; wherein the target time is determined by the aggregation node based on the predicted training end time of each computing node; It is determined that each of the computing nodes has completed the update of the model parameters.

28. The central node according to claim 27, characterized in that When the aggregation opportunity is receiving a model parameter aggregation instruction sent by the central node, the processor is further configured to perform the following operations: Send a broadcast message to each of the computing nodes, wherein the broadcast message is used to reset the training round.

29. The central node according to any one of claims 19 to 25, characterized in that: The processor executes sending the initial model parameters of the intrusion detection model to at least one computing node, specifically: broadcasting the initial model parameters to each of the computing nodes; or, Encrypting the initial model parameters based on the private key of the central node, and sending the encrypted initial model parameters to each of the computing nodes; or, Sending the initial model parameters to each computing node based on a secure communication channel with each computing node; The secure communication channel is established when the central node sends an authentication request to the computing node and receives an authentication success response from the computing node; The authentication request carries the security certificate of the central node, and the authentication success response is generated when the computing node authenticates the security certificate and passes the authentication.

30. An aggregation node, characterized in that: Including memory, transceiver, processor; Memory for storing computer programs; a transceiver, configured to transmit and receive data under the control of the processor; and a processor, configured to read the computer program in the memory and perform the following operations: Receive a first encrypted model parameter sent by at least one computing node; wherein the first encrypted model parameter is obtained by the computing node updating the initial model parameter of the intrusion detection model sent by the central node using local training data, and encrypting the updated model parameter; Aggregating the first encryption model parameters to obtain a first aggregated parameter; Sending the first aggregation parameter to the central node; wherein the first aggregation parameter is used by the central node to perform decryption and calculation processing to obtain the target model parameter of the intrusion detection model; The intrusion detection model is used to detect whether there is a network attack in the network traffic data, and if there is a network attack, detect the attack type of the network attack.

31. The aggregation node according to claim 30, characterized in that The processor aggregates the first encryption model parameters to obtain a first aggregate parameter, specifically: When the aggregation opportunity is met, aggregating the first encryption model parameters to obtain a first aggregation parameter; The aggregation opportunity includes at least one of the following: The received encrypted model parameters include updated model parameters for setting training rounds; Receiving a model parameter aggregation instruction sent by the central node; Arriving at a target time; wherein the target time is determined by the aggregation node based on the predicted training end time of each computing node; It is determined that each of the computing nodes has completed the update of the model parameters.

32. The aggregation node according to claim 31, characterized in that When the aggregation timing is the target arrival time, the processor is further configured to perform the following operations: An instruction message is sent to each of the computing nodes; wherein the instruction message is used to instruct the computing node to stop updating the model parameters.

33. The aggregation node according to any one of claims 30 to 32, characterized in that: The computing node is a software-defined security SDS node.

34. A computing node, characterized in that Including memory, transceiver, processor; A memory for storing a computer program; a transceiver for transmitting and receiving data under the control of the processor; and a processor for reading the computer program in the memory and performing the following operations: Receiving initial model parameters of the intrusion detection model sent by the central node; wherein the intrusion detection model is used to detect whether there is a network attack in the network traffic data, and if there is the network attack, detect the attack type to which the network attack belongs; Updating the initial model parameters using local training data to obtain updated model parameters; encrypting the updated model parameters to obtain first encrypted model parameters; The first encryption model parameter is sent to the aggregation node; wherein the first encryption model parameter is used by the aggregation node to perform aggregation processing to obtain a first aggregation parameter, and the first aggregation parameter is sent to the central node; the first aggregation parameter is used by the central node to perform decryption and calculation processing to obtain the target model parameter of the intrusion detection model.

35. The computing node according to claim 34, wherein: The computing node is a software-defined security SDS node.

36. The computing node according to claim 34, characterized in that The processor encrypts the updated model parameters to obtain first encrypted model parameters, specifically: Encrypting the updated model parameters using the public key of the central node to obtain the first encrypted model parameters; Correspondingly, the first aggregation parameter is used to decrypt the first aggregation parameter using the private key of the central node, and to calculate the model parameters obtained by decryption to obtain the target model parameters of the intrusion detection model.

37. A federated learning device for an intrusion detection model, characterized in that: Applied to the central node, including: A sending unit, configured to send initial model parameters of the intrusion detection model to at least one computing node; wherein the intrusion detection model is configured to detect whether network traffic data contains a network attack, and if so, to detect the attack type to which the network attack belongs; a receiving unit, configured to receive a first aggregation parameter sent by an aggregation node; wherein the first aggregation parameter is obtained by the aggregation node aggregating the first encrypted model parameters sent by each of the computing nodes; and the first encrypted model parameter is obtained by the computing node updating the initial model parameter using local training data to obtain an updated model parameter, and encrypting the updated model parameter; A processing unit is used to decrypt and calculate the first aggregation parameters to obtain target model parameters of the intrusion detection model.

38. A federated learning device for an intrusion detection model, characterized in that: Applicable to aggregation nodes, including: A receiving unit, configured to receive a first encrypted model parameter sent by at least one computing node; wherein the first encrypted model parameter is an updated model parameter obtained by the computing node updating the initial model parameter of the intrusion detection model sent by the central node using local training data, and encrypting the updated model parameter; an aggregation unit, configured to aggregate the first encryption model parameters to obtain a first aggregate parameter; a sending unit, configured to send the first aggregation parameter to the central node; wherein the first aggregation parameter is used by the central node to perform decryption and calculation processing to obtain the target model parameter of the intrusion detection model; The intrusion detection model is used to detect whether there is a network attack in the network traffic data, and if there is a network attack, detect the attack type of the network attack.

39. A federated learning device for an intrusion detection model, characterized in that: Applied to compute nodes, including: A receiving unit, configured to receive initial model parameters of the intrusion detection model sent by the central node; wherein the intrusion detection model is configured to detect whether network traffic data contains a network attack, and if so, to detect the attack type to which the network attack belongs; An updating unit, configured to update the initial model parameters using local training data to obtain updated model parameters; an encryption unit, configured to encrypt the updated model parameters to obtain first encrypted model parameters; A sending unit is used to send the first encryption model parameter to the aggregation node; wherein the first encryption model parameter is used by the aggregation node to perform aggregation processing to obtain the first aggregation parameter, and the first aggregation parameter is sent to the central node; the first aggregation parameter is used by the central node to perform decryption and calculation processing to obtain the target model parameter of the intrusion detection model.

40. A processor-readable storage medium, characterized in that The processor-readable storage medium stores a computer program, and the computer program is used to enable the processor to execute the method according to any one of claims 1 to 11, or the method according to any one of claims 12 to 15, or the method according to any one of claims 16 to 18.