A cloud-edge collaborative decision-making method and device capable of defending against backdoor attacks

Through the collaborative decision-making method of data converters, edge node private models and correction mappers, combined with the federated trusted optimization algorithm and dynamic perception selection strategy, the concealment problem of backdoor attacks in the cloud-edge-end collaborative system is solved, and the security and robustness of the system are enhanced.

CN120474852BActive Publication Date: 2025-09-16YUNNAN NORMAL UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510984115.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-17
Publication Date
2025-09-16
Estimated Expiration
2045-07-17

AI Technical Summary

Technical Problem

The concealment and destructive threats of backdoor attacks in cloud-edge-end collaborative systems are difficult to defend against. The heterogeneity of terminal devices, the complexity of model aggregation and the limitations of traditional detection methods lead to insufficient system security and robustness.

Method used

Data converters are used to eliminate the impact of poisoned data, edge node private model prediction and correction mappers are used to correct uncertain results, federated trusted optimization algorithms update parameters, and collaborative decision-making of dynamic perception selection strategies is carried out through cloud aggregators.

Benefits of technology

It improves the security and robustness of cloud-edge-end collaborative computing, adapts to the heterogeneity of terminal devices, reduces decision-making time overhead, and improves resource utilization and model aggregation reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120474852B_ABST
    Figure CN120474852B_ABST
Patent Text Reader

Abstract

The present invention relates to a cloud-edge collaborative decision-making method and device that can defend against backdoor attacks, and belongs to the field of cloud-edge collaborative edge computing. The method first uses a data converter to convert the data uploaded by each terminal that may be contaminated by backdoor attacks to eliminate the influence of poisoned data; secondly, the correction mapper corrects and maps the abnormal backdoor behavior predicted by each edge private model to ensure the accuracy and reliability of the decision; then, each edge node uses a federal trusted optimization algorithm to update the parameters of the data converter and the correction mapper; finally, the cloud aggregator uses a dynamic perception selection strategy to aggregate and update the parameters uploaded by the edge node, and sends them down for the next round of training, so as to interact and achieve efficient and secure cloud-edge collaborative decision-making. The present invention mainly uses three core modules: data converter, correction mapper and cloud aggregator to enhance the security and robustness of cloud-edge collaborative computing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a cloud-edge-terminal collaborative decision-making method and device capable of defending against backdoor attacks, belonging to the field of cloud-edge-terminal collaborative edge computing. Background Art

[0002] Current cloud-edge-end collaborative systems, combining the powerful computing power of cloud computing, the low latency of edge computing, and the local perception capabilities of terminal devices, have been widely adopted in fields such as intelligent transportation, smart cities, the Industrial Internet, intelligent manufacturing, and smart healthcare. However, backdoor attacks, such as clean label attacks, hidden trigger attacks, model replacement attacks, and semantic backdoors, are highly insidious and destructive security threats in cloud-edge-end collaborative systems. With the continuous development of generative artificial intelligence (AIGC), attackers can more easily generate poisoned data with backdoors in terminals to influence collaborative decision-making and undermine the security and robustness of cloud-edge-end collaborative systems.

[0003] Among related technologies, current approaches to improving the security of cloud-edge-end collaborative systems primarily rely on encryption, authentication, data privacy protection, model encryption, and watermarking. These approaches primarily consider security at the communication level, overlooking the potential threats posed by poisoned data and backdoor attacks. With the deep integration of artificial intelligence (AI) and the Internet of Things (IoT), attackers can exploit heterogeneous terminal devices and, with the help of generative AI, simulate shadow data, quietly inserting backdoors and thereby influencing model behavior without detection. These attacks not only circumvent traditional encryption protection mechanisms but can also gradually erode the security of the model as the training process iterates. Although many backdoor defense mechanisms have been proposed, their actual deployment in cloud-edge-end collaborative systems still suffers from the following deficiencies:

[0004] (1) The heterogeneity of terminal devices exacerbates the difficulty of defense. Due to differences in backdoor triggering behaviors, the input distribution and application scenarios of terminal heterogeneous models running on different nodes are different, making the backdoor defense mechanism more difficult;

[0005] (2) The complexity of backdoor attacks brought by model aggregation. Since attackers can hide malicious behaviors within the model by uploading malicious updates (such as backdoor data), cloud aggregation further deepens the security and credibility of the overall system;

[0006] (3) Traditional backdoor detection methods are difficult to deploy at the edge / end. Since cloud models or data are private, the edge or end cannot access their structure or parameters, which limits the applicability of traditional detection algorithms.

[0007] (4) Traditional defense collaborative decision-making has high latency: Due to the lack of common definitions and response rules for backdoor attacks among cloud, edge, and end, traditional defense collaborative decision-making requires back-and-forth communication, which increases response latency and is not suitable for real-time systems.

[0008] In the face of these challenges, there is an urgent need to introduce safer and more efficient mechanisms into the cloud-edge-end collaborative system to enhance the robustness of the system and improve the defense capabilities against backdoor attacks. While ensuring security, it is also necessary to take into account computing efficiency and resource optimization to enhance the security and robustness of cloud-edge-end collaborative decision-making. Summary of the Invention

[0009] The technical problem to be solved by the present invention is to provide a cloud-edge-end collaborative decision-making method and device that can defend against backdoor attacks. It solves the problems in related technologies such as the difficulty of cloud-edge-end systems in adapting to the heterogeneity of terminal devices, the complexity of model aggregation, and the concealment of backdoor attacks, and significantly improves the security and robustness of cloud-edge-end collaborative computing.

[0010] The technical solution of the present invention is: a cloud-edge collaborative decision-making method that can defend against backdoor attacks, the specific steps are:

[0011] S1: Use a data converter to convert the data uploaded by each terminal that may be contaminated by backdoor attacks to eliminate the impact of the poisoned data;

[0012] S2: Use the edge node private model to predict the obtained conversion data and obtain uncertain prediction results;

[0013] S3: The obtained uncertain prediction results are corrected and mapped using a correction mapper to obtain a decision result;

[0014] S4: Based on the obtained decision results, each edge node uses the federated trusted optimization algorithm to update the parameters of the data converter and correction mapper;

[0015] S5: The updated data converter and correction mapper parameters uploaded by each edge node are aggregated and updated through the cloud aggregator using a dynamic perception selection strategy, and sent down for the next round of training. This interaction enables collaborative decision-making between the cloud and the edge.

[0016] Optionally, the step S1 uses a data converter to convert data uploaded by each terminal that may be contaminated by a backdoor attack to eliminate the influence of the poisoned data, and the steps include:

[0017] S1.1: Each edge node receives data uploaded by multiple terminals that may be contaminated by backdoor attacks, forming an edge node dataset. edge nodes that participate in decision-making, each of which has its own poisoned dataset that may be implanted with a backdoor ,in Indicates the The amount of privacy data of edge nodes, represents a data sample;

[0018] S1.2: Poisoning the acquired dataset The input data converter is converted and the converted data is obtained by adding Gaussian noise. The data converter is a VAE autoencoder structure based on DP privacy protection.

[0019] Optionally, the step S2 uses a private model of an edge node to predict the obtained conversion data to obtain an uncertain prediction result, and the steps include:

[0020] S2.1: Edge nodes load their own private model parameters ,in represents the network coding part, Represents the task prediction part;

[0021] S2.2: Use the edge node private model to predict the obtained conversion data and obtain uncertain prediction results .

[0022] Optionally, the step S3 uses a correction mapper to correct and map the obtained uncertain prediction result to obtain a decision result, and the steps include:

[0023] S3.1: Uncertain prediction results will be obtained The input correction mapper is corrected. The correction is a fully connected mapping layer based on DP-protected block matrix decomposition and reconstruction, specifically:

[0024] Split the weight matrix of the fully connected mapping layer into N blocks;

[0025] For each block, a circulant matrix is ​​set so that each row in the matrix is ​​a cyclic right shift of the previous row to compress the number of parameters;

[0026] Diagonalize the circulant matrix by discrete Fourier transform to obtain a diagonal matrix;

[0027] Add Gaussian noise to the diagonal elements of each frequency domain diagonal matrix to obtain a diagonal matrix with added noise;

[0028] Perform an inverse Fourier transform on the noise-added diagonal matrix to recover the noise-perturbed circulant matrix, thereby obtaining the fully connected layer weights of each block. The fully connected layer weights have differential privacy protection capabilities due to the addition of noise;

[0029] All the circulant matrices processed in the above steps are recombined to obtain a complete fully connected layer weight parameter matrix protected by differential privacy, and multiplied by the uncertain prediction result to obtain the corrected prediction result;

[0030] S3.2: Map the obtained correction prediction results to obtain decision results , the mapping is a hard-coded label remapping function.

[0031] Optionally, in S4, each edge node updates parameters of a data converter and a correction mapper using a federated trusted optimization algorithm based on the obtained decision result, and the steps include:

[0032] S4.1: Each edge node optimizes the data converter and correction mapper using a federated trusted optimization algorithm. The federated trusted optimization algorithm is a federated trusted algorithm based on comparison and correction knowledge distillation. Specifically,

[0033] Predict the poisoned dataset based on the private model of each edge node and obtain the pseudo labels predicted by the private model;

[0034] Divide the samples into a positive sample set and a negative sample set according to the pseudo labels, wherein the positive sample set contains other samples with the same prediction results as the target sample, and the negative sample set contains samples with different prediction results;

[0035] Designing a loss function that includes a contrast loss and a corrected knowledge distillation loss, and optimizing the model based on a set of positive and negative samples, thereby selecting credible contrast samples to adjust parameters of the data converter and the corrected mapper to enhance backdoor defense;

[0036] S4.2: Update the parameters of the data converter and the correction mapper based on the optimization results.

[0037] Optionally, S5 aggregates and updates the updated data converter and correction mapper parameters uploaded by each edge node using a dynamic perception selection strategy through the cloud aggregator, and sends them for the next round of training. This interaction is used to achieve cloud-edge collaborative decision-making. The steps include:

[0038] S5.1: Each edge node uploads the updated data converter and correction mapper parameters to the cloud aggregator, which uses the dynamic perception selection strategy to perform aggregation updates and issue global aggregation parameters. Specifically:

[0039] Based on the federated trusted optimization algorithm, the gradient of each edge node is calculated to evaluate its contribution to the overall model update;

[0040] The sum of cosine similarities between the edge node and other edge nodes is calculated based on the obtained gradient. The higher the sum of cosine similarities, the higher the consistency between the edge node and other edge nodes, and the more trustworthy the edge node is.

[0041] Based on the cosine similarity and the results, the cloud aggregator updates the data converter and correction mapper parameters uploaded by all edge nodes, generates new data converter and correction mapper parameters, and sends them to each edge node for the next round of training;

[0042] S5.2: Based on multiple data interactions between each participating edge node and the cloud, repeat the above steps to achieve cloud-edge collaborative decision-making.

[0043] In addition, the present application also proposes a device for a cloud-edge collaborative decision-making method that can defend against backdoor attacks. The cloud-edge collaborative decision-making device that can defend against backdoor attacks includes:

[0044] The data collection module is used by edge nodes to receive poisoned data uploaded by each terminal that may have backdoors implanted, forming a poisoned data set ;

[0045] The data converter module is responsible for converting the data uploaded by each terminal that may be contaminated by backdoor attacks to eliminate the impact of the poisoned data;

[0046] The private model prediction module is used to input the features converted by the data converter into the private model for prediction and obtain uncertain prediction results;

[0047] The correction mapper module is responsible for correcting and mapping abnormal backdoor behaviors in the predictions of each edge private model to ensure the accuracy and reliability of decisions;

[0048] A parameter updating module, for updating parameters of a data converter and a correction mapper using a federated trusted optimization algorithm;

[0049] The cloud aggregation module is used to aggregate and update the parameters uploaded by the edge nodes using a dynamic perception selection strategy, and send them down for the next round of training of the edge nodes.

[0050] In addition, the present application also proposes a cloud-edge collaborative decision-making device that can defend against backdoor attacks, including a memory, a processor, and a cloud-edge collaborative decision-making method program that can defend against backdoor attacks that is stored on the memory and can be run on the processor. The processor executes the cloud-edge collaborative decision-making method program that can defend against backdoor attacks to implement the steps of the cloud-edge collaborative decision-making method that can defend against backdoor attacks as described above.

[0051] In addition, the present application also proposes a computer-readable storage medium, on which is stored a cloud-edge collaborative decision-making method program that can defend against backdoor attacks. When the cloud-edge collaborative decision-making method program that can defend against backdoor attacks is executed by a processor, the steps of the cloud-edge collaborative decision-making method that can defend against backdoor attacks as described above are implemented.

[0052] The beneficial effects of the present invention are:

[0053] (1) Each edge node supports heterogeneous network deployment, which is more powerful and universal than existing methods;

[0054] (2) Each edge node automatically processes backdoors through the data converter module and the correction mapper module, eliminating the need for complex backdoor detection methods and effectively reducing decision-making time overhead;

[0055] (3) Based on the correction, a fully connected mapping layer is reconstructed based on the block matrix decomposition of DP protection, which uses differential privacy for protection while reducing the number of model parameters and improving the utilization of edge resources;

[0056] (4) Based on the above-mentioned federated trusted optimization algorithm, the credibility of task decisions can be effectively improved and the success rate of backdoor attacks can be reduced;

[0057] (5) Based on the dynamic perception selection strategy described above, the model parameters are aggregated to improve the reliability of model aggregation while enhancing the cloud-edge interaction capability. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] Figure 1 is a flow chart of the steps of the present invention;

[0059] Figure 2 This is an overall schematic diagram of cloud-edge-device collaborative decision-making that can defend against backdoor attacks according to Example 1 of the present invention;

[0060] Figure 3 This is a schematic diagram of a specific process of interactive collaborative decision-making between an edge node and the cloud in Example 1 of the present invention;

[0061] Figure 4 Schematic diagram of a VAE autoencoder model based on DP privacy protection according to Example 1 of the present invention;

[0062] Figure 5 Schematic diagram of a fully connected mapping layer of block matrix decomposition and reconstruction based on DP protection according to embodiment 1 of the present invention;

[0063] Figure 6 Schematic diagram of a federated trusted algorithm based on comparison and correction knowledge distillation according to Example 1 of the present invention;

[0064] Figure 7This is a schematic diagram of the hardware structure involved in Example 1 of the present invention. DETAILED DESCRIPTION

[0065] The present invention will be further described below with reference to the accompanying drawings and specific embodiments.

[0066] Example 1: Figure 1 The figure shows an overall diagram of a cloud-edge collaborative decision-making method that can defend against backdoor attacks. The implementation process mainly includes five modules: S1: data converter module; S2: private model prediction module; S3: correction mapper module; S4: parameter update module; S5: cloud aggregator module. Figure 3 The figure shows a schematic diagram of the specific process of collaborative decision-making of a single edge node. The following describes each step in detail:

[0067] S1: Data converter module specific implementation steps:

[0068] The data uploaded by each terminal that may be contaminated by backdoor attacks is converted using a data converter to eliminate the impact of the poisoned data. Specifically:

[0069] S1.1: Each edge node receives data uploaded by multiple terminals that may be contaminated by backdoor attacks, forming an edge node dataset. edge nodes that participate in decision-making, each of which has its own poisoned dataset that may be implanted with a backdoor ,in Indicates the The amount of privacy data of edge nodes, represents a data sample;

[0070] S1.2: The poisoning data set obtained in S1.1 The input data converter is converted to obtain the converted data. The data converter is a variational autoencoder (VAE) structure based on DP privacy protection. Specifically:

[0071] like Figure 4 As shown, it is a schematic diagram of the VAE autoencoder model based on DP privacy protection. Given the VAE autoencoder model ,in represents the VAE encoder training parameters for the poisoned dataset obtained in S1.1 use Perform data conversion to obtain converted data ,in represents Gaussian noise that follows a standard normal distribution.

[0072] Specifically, the present invention uses the MobileNetV2 network with fewer parameters that can be run on mobile terminals. The overall VAE autoencoder adopts the UNet architecture. In order to meet the differential privacy protection conditions, the present invention generates data by adding Gaussian noise into the code. , thereby obtaining differentially private protected transformation data , the following conditions are met:

[0073] (1)

[0074] Where S represents the output range. , VAE autoencoder network supply - Differential privacy (DP) is privacy-aware if and only if any two adjacent datasets and Different on a single instance, where represents the probability of failure, represents the probability of the random mechanism under differential privacy conditions.

[0075] S2: Specific implementation steps of the private model prediction module:

[0076] The obtained conversion data is predicted using the edge node private model to obtain uncertain prediction results, specifically:

[0077] S2.1: Edge nodes load their own private model parameters ,in represents the network coding part, Represents the task prediction part;

[0078] S2.2: Use the edge node private model to predict the conversion data obtained in S1.2 to obtain an uncertain prediction result , specifically:

[0079] The data to be converted Enter your own private model , and obtain uncertain prediction results .

[0080] S3: Correction mapper module specific implementation steps:

[0081] The obtained uncertain prediction results are corrected and mapped using a correction mapper to obtain decision results, specifically:

[0082] S3.1: The uncertain prediction results obtained in S2.2 The input correction mapper is corrected. The correction is a fully connected mapping layer based on DP-protected block matrix decomposition and reconstruction. Specifically:

[0083] like Figure 5 As shown in Figure 1, it represents a schematic diagram of the fully connected mapping layer based on DP-protected block matrix decomposition and reconstruction. Given the weight matrix of the fully connected mapping layer is First, Divided into blocks, each block size is ,make Should be as close as possible to the original weight matrix For each block, set it to a circulant matrix , so that each row in the matrix is ​​a circular right shift of the previous row. In this way, the original The block of parameters now only needs free parameters, compressing the number of original parameters; then, each The circulant matrix It is diagonalized by discrete Fourier transform, the formula is:

[0084] (2)

[0085] in yes The discrete Fourier transform matrix of is its conjugate transpose, and is a diagonal matrix whose diagonal elements are The representation in the frequency domain shows the weight distribution of the block on each frequency component. According to the differential privacy requirements, in each frequency domain diagonal matrix Add Gaussian noise to the diagonal elements of , get the diagonal matrix of added noise , and then perform inverse Fourier transform to recover the circulant matrix after noise disturbance , the formula is:

[0086] (3)

[0087] The present invention transforms the noised information in the frequency domain back to the time domain through formula (3) to obtain the fully connected layer weights of each block. These weights have the ability to protect differential privacy due to the addition of noise. Then, all the circulant matrix blocks processed by the above steps are recombined to obtain a complete weight matrix Since each block contains only a few free parameters and noise has been added in the frequency domain, the entire fully connected layer has lower sensitivity, which reduces the number of parameters while increasing the security of model training. Finally, the fully connected layer weight parameter matrix protected by differential privacy is , the corrected prediction results can be obtained ,in Represents the multiplication of two matrices.

[0088] S3.2: Map the corrected prediction results obtained in S3.1 to obtain a decision result , the mapping is a hard-coded label remapping function, specifically:

[0089] Given a hard-coded label remapping function ,in represents the input, i.e. the correction prediction result, Represents the output, that is, the decision result, both of which come from a set of labels for a specific task , making It is a one-to-one mapping, where each old label uniquely corresponds to a new label. By disrupting the order of the original labels and remapping the output layer, it effectively protects privacy while improving the robustness of the model, making the model more reliable in the face of adversarial attacks.

[0090] S4: Specific implementation steps of parameter update module:

[0091] Based on the obtained decision results, each edge node uses the federated trusted optimization algorithm to update the parameters of the data converter and correction mapper, specifically:

[0092] S4.1: Each edge node optimizes the data converter and correction mapper using a federated trusted optimization algorithm. The federated trusted optimization algorithm is a federated trusted algorithm based on comparison and correction knowledge distillation. Specifically:

[0093] like Figure 6 As shown in Figure 2, it represents a federated trustworthy algorithm based on contrast and correction knowledge distillation. Given a poisoned dataset , based on the private model of each edge node , you can get the pseudo labels predicted by the private model Given the pseudo labels predicted by the private model , for each transformed data sample ,set up Indicates the sample index number of the current training batch, set , where i represents a value in the set U, then the candidate positive sample set can be defined in the current batch , and Pseudo labels of two samples that represent different predictions of the model, negative sample set Therefore, this paper proposes a federated trusted optimization algorithm, which aims to select trusted comparison samples to adjust data converter and correction mapper parameters to better enhance backdoor defense. The formula is described as follows:

[0094] (4)

[0095] in represents the number of positive sample sets in each training batch, is the scale temperature parameter, is the pseudo label predicted by the model, is the corrected prediction result obtained in S3.1, For the transformed data sample A positive sample from the same sample set, For A negative sample from a different sample set. In formula (4), the first term represents the contrast loss of federated credibility, and the second cross entropy Representing the correction knowledge distillation loss, it can effectively optimize the parameters of the data converter and correction mapper.

[0096] S4.2: Update the parameters of the data converter and the correction mapper based on the algorithm optimization in S4.1, specifically:

[0097] According to the federated trusted optimization algorithm proposed in S4.1, the present invention uses differential privacy stochastic gradient descent (DP-SGD) to update the parameters of the data converter and the correction mapper.

[0098] S5: Specific implementation steps of the cloud aggregator module:

[0099] The data converter and correction mapper parameters uploaded by each edge node are aggregated and updated by the cloud aggregator using a dynamic perception selection strategy and sent down for the next round of training. This interaction enables efficient and secure cloud-edge collaborative decision-making. Specifically:

[0100] S5.1: Each edge node uploads the updated data converter and correction mapper parameters to the cloud aggregator, which uses the dynamic perception selection strategy to perform aggregation updates and issue global aggregation parameters. Specifically:

[0101] With edge nodes, when the During round interaction, each edge node The parameters of the data converter uploaded to the cloud aggregator are expressed as , the correction mapper parameters uploaded to the cloud aggregator are expressed as Based on the federated trusted optimization algorithm proposed in S4.1, we can get Wheel The gradient calculated by the edge nodes is ,To better achieve trusted cloud aggregation, this paper proposes a dynamic perception selection strategy, which is described as:

[0102] (5)

[0103] in Indicates the Wheel edge node The sum of cosine similarities calculated with other edge nodes, express Wheel The gradient calculated by the edge nodes, The higher the The edge nodes with high consistency with other edge nodes are considered more trustworthy. On the contrary, untrustworthy edge nodes will be given smaller , to achieve dynamic perception of cloud aggregation, the cloud aggregator parameter aggregation update description is:

[0104] (6)

[0105] in Indicates the data converter parameters aggregated by the cloud aggregator, which are sent to each edge node for wheel training; Indicates the correction mapper parameters aggregated by the cloud aggregator, which are sent to each edge node for the wheel training;

[0106] S5.2: Based on multiple data interactions between each participating edge node and the cloud, repeat the above steps to achieve efficient and secure cloud-edge collaborative decision-making.

[0107] This application also proposes a cloud-edge collaborative decision-making device that can defend against backdoor attacks, such as Figure 7 As shown, this is a schematic diagram of the program running device structure of a cloud-edge collaborative decision-making method that can defend against backdoor attacks in the hardware running environment involved in the embodiment of the present application.

[0108] like Figure 7 As shown, a cloud-edge collaborative decision-making device that can defend against backdoor attacks includes: a processor 1001, such as a central processing unit CPU, a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. Among them, the communication bus 1002 is used to realize the connection and communication between the various component modules, the user interface 1003 may include a display screen, an input unit such as a keyboard, etc., and the user interface 1003 may optionally include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 1005 may be a high-speed random access memory RAM, or a stable non-volatile memory NVM, such as a disk storage. The memory 1005 may optionally be a storage device independent of the aforementioned processor 1001.

[0109] Those skilled in the art will understand that Figure 7 The structure shown in does not constitute a limitation on a cloud-edge collaborative decision-making system that can defend against backdoor attacks, and may include more or fewer components than shown in the figure, or a combination of certain components, or a different arrangement of components.

[0110] Optionally, the memory 1005 is connected to the processor 1001, and the processor 1001 can be used to control the operation of the memory 1005, and can also read the data in the memory 1005 to implement a cloud-edge collaborative decision-making method that can defend against backdoor attacks.

[0111] Alternatively, as Figure 7 As shown, the memory 1005 as a storage medium may include an operating system, a data storage module, a network communication module, a user interface module, and a cloud-edge collaborative decision-making method program that can defend against backdoor attacks.

[0112] Optionally, in Figure 7 In the cloud-edge collaborative decision-making device that can defend against backdoor attacks shown in the figure, the network interface 1004 is mainly used for data communication with other devices; the user interface 1003 is mainly used for data interaction with the user; the processor 1001 and the memory 1005 in the cloud-edge collaborative decision-making device that can defend against backdoor attacks in the present application can be set in a cloud-edge collaborative decision-making device that can defend against backdoor attacks.

[0113] like Figure 7 As shown, the cloud-edge collaborative decision-making device capable of defending against backdoor attacks calls a cloud-edge collaborative decision-making method program capable of defending against backdoor attacks stored in the memory 1005 through the processor 1001, and executes the following Figure 2 As shown, the first embodiment of the present application provides five modules related to a cloud-edge collaborative decision-making method that can defend against backdoor attacks: S1: data converter module; S2: private model prediction module; S3: correction mapper module; S4: parameter update module; S5: cloud aggregator module.

[0114] In addition, the present application also proposes a computer-readable storage medium, on which is stored a cloud-edge collaborative decision-making method program that can defend against backdoor attacks. When the cloud-edge collaborative decision-making method program that can defend against backdoor attacks is executed by a processor, the steps of the cloud-edge collaborative decision-making method that can defend against backdoor attacks as described above are implemented.

[0115] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0116] It should be noted that in the claims, any reference signs placed between brackets shall not be construed as limiting the claims. The word "comprising" does not exclude the presence of components or steps not listed in the claim. The word "a" or "an" preceding a component does not exclude the presence of a plurality of such components. The present application may be implemented by means of hardware comprising several different components and by means of a suitably programmed computer. In a unit claim enumerating several means, several of these means may be embodied by one and the same item of hardware. The use of the words first, second, and third etc. does not indicate any order. These words may be interpreted as names.

[0117] Although the preferred embodiments of the present application have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present application.

[0118] Obviously, those skilled in the art may make various changes and modifications to this application without departing from the spirit and scope of this application. Thus, if these modifications and variations of this application fall within the scope of the claims of this application and their equivalents, this application is intended to include these modifications and variations.

Claims

1. A cloud-edge collaborative decision-making method that can defend against backdoor attacks, characterized in that: The cloud-edge-device collaborative decision-making method capable of defending against backdoor attacks includes: S1: Use a data converter to convert the data uploaded by each terminal that may be contaminated by backdoor attacks to eliminate the impact of the poisoned data; S2: Use the edge node private model to predict the obtained conversion data and obtain uncertain prediction results; S3: The obtained uncertain prediction results are corrected and mapped using a correction mapper to obtain a decision result; S4: Based on the obtained decision results, each edge node uses the federated trusted optimization algorithm to update the parameters of the data converter and correction mapper; S5: The updated data converter and correction mapper parameters uploaded by each edge node are aggregated and updated by the cloud aggregator using a dynamic perception selection strategy, and then sent down for the next round of training. This interaction enables collaborative decision-making between the cloud, edge, and device. In step S4, each edge node uses a federated trusted optimization algorithm to update parameters of a data converter and a correction mapper based on the obtained decision result. The steps include: S4.1: Each edge node optimizes the data converter and correction mapper using a federated trusted optimization algorithm. The federated trusted optimization algorithm is a federated trusted algorithm based on comparison and correction knowledge distillation. Specifically, Predict the poisoned dataset based on the private model of each edge node and obtain the pseudo labels predicted by the private model; Divide the samples into a positive sample set and a negative sample set according to the pseudo labels, wherein the positive sample set contains other samples with the same prediction results as the target sample, and the negative sample set contains samples with different prediction results; Designing a loss function that includes a contrast loss and a corrected knowledge distillation loss, and optimizing the model based on a set of positive and negative samples, thereby selecting credible contrast samples to adjust parameters of the data converter and the corrected mapper to enhance backdoor defense; S4.2: Update the parameters of the data converter and the correction mapper based on the optimization results.

2. A cloud-edge-device collaborative decision-making method capable of defending against backdoor attacks as claimed in claim 1, characterized in that: The S1 converts the data uploaded by each terminal that may be contaminated by the backdoor attack using a data converter to eliminate the influence of the poisoned data. The steps include: S1.1: Each edge node receives data uploaded by multiple terminals that may be contaminated by backdoor attacks, forming an edge node dataset. edge nodes that participate in decision-making, each of which has its own poisoned dataset that may be implanted with a backdoor ,in Indicates the The amount of privacy data of edge nodes, represents a data sample; S1.2: Poisoning the acquired dataset The input data converter is converted and the converted data is obtained by adding Gaussian noise. The data converter is a VAE autoencoder structure based on DP privacy protection.

3. The cloud-edge-device collaborative decision-making method capable of defending against backdoor attacks as claimed in claim 1 is characterized in that: The step S2 uses the edge node private model to predict the obtained conversion data to obtain an uncertain prediction result, and the steps include: S2.1: Edge nodes load their own private model parameters ,in represents the network coding part, Represents the task prediction part; S2.2: Use the edge node private model to predict the obtained conversion data and obtain uncertain prediction results .

4. The cloud-edge-device collaborative decision-making method capable of defending against backdoor attacks according to claim 1 is characterized in that: The step S3 uses a correction mapper to correct and map the obtained uncertain prediction result to obtain a decision result, and the steps include: S3.1: Uncertain prediction results will be obtained The input correction mapper is corrected. The correction is a fully connected mapping layer based on DP-protected block matrix decomposition and reconstruction, specifically: Split the weight matrix of the fully connected mapping layer into N blocks; For each block, a circulant matrix is ​​set so that each row in the matrix is ​​a cyclic right shift of the previous row to compress the number of parameters; Diagonalize the circulant matrix by discrete Fourier transform to obtain a diagonal matrix; Add Gaussian noise to the diagonal elements of each frequency domain diagonal matrix to obtain a diagonal matrix with added noise; Perform an inverse Fourier transform on the noise-added diagonal matrix to recover the noise-perturbed circulant matrix, thereby obtaining the fully connected layer weights of each block. The fully connected layer weights have differential privacy protection capabilities due to the addition of noise; All the circulant matrices processed in the above steps are recombined to obtain a complete fully connected layer weight parameter matrix protected by differential privacy, and multiplied by the uncertain prediction result to obtain the corrected prediction result; S3.2: Map the obtained correction prediction results to obtain decision results , the mapping is a hard-coded label remapping function.

5. The cloud-edge-device collaborative decision-making method capable of defending against backdoor attacks as claimed in claim 1 is characterized in that: S5 aggregates and updates the updated data converter and correction mapper parameters uploaded by each edge node through the cloud aggregator using a dynamic perception selection strategy, and sends them for the next round of training. This interaction enables cloud-edge collaborative decision-making. The steps include: S5.1: Each edge node uploads the updated data converter and correction mapper parameters to the cloud aggregator, which uses the dynamic perception selection strategy to perform aggregation updates and issue global aggregation parameters. Specifically: Based on the federated trusted optimization algorithm, the gradient of each edge node is calculated to evaluate its contribution to the overall model update; The sum of cosine similarities between the edge node and other edge nodes is calculated based on the obtained gradient. The higher the sum of cosine similarities, the higher the consistency between the edge node and other edge nodes, and the more trustworthy the edge node is. Based on the cosine similarity and the results, the cloud aggregator updates the data converter and correction mapper parameters uploaded by all edge nodes, generates new data converter and correction mapper parameters, and sends them to each edge node for the next round of training; S5.2: Based on multiple data interactions between each participating edge node and the cloud, repeat the above steps to achieve cloud-edge collaborative decision-making.

6. A device for implementing the cloud-edge-device collaborative decision-making method capable of defending against backdoor attacks as claimed in claim 1, characterized in that: The cloud-edge collaborative decision-making device capable of defending against backdoor attacks includes: The data collection module is used by edge nodes to receive poisoned data uploaded by each terminal that may have backdoors implanted, forming a poisoned data set ; The data converter module is responsible for converting the data uploaded by each terminal that may be contaminated by backdoor attacks to eliminate the impact of the poisoned data; The private model prediction module is used to input the features converted by the data converter into the private model for prediction and obtain uncertain prediction results; The correction mapper module is responsible for correcting and mapping abnormal backdoor behaviors in the predictions of each edge private model; A parameter updating module, for updating parameters of a data converter and a correction mapper using a federated trusted optimization algorithm; The cloud aggregation module is used to aggregate and update the parameters uploaded by the edge nodes using a dynamic perception selection strategy, and send them down for the next round of training of the edge nodes.

7. A cloud-edge collaborative decision-making device capable of defending against backdoor attacks, characterized in that: It includes a memory, a processor, and a cloud-edge collaborative decision-making method program that can defend against backdoor attacks, which is stored in the memory and can be run on the processor. The processor executes the cloud-edge collaborative decision-making method program that can defend against backdoor attacks to implement the steps of the cloud-edge collaborative decision-making method that can defend against backdoor attacks as described in any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a cloud-edge collaborative decision-making method program that can defend against backdoor attacks. When the cloud-edge collaborative decision-making method program that can defend against backdoor attacks is executed by the processor, the steps of the cloud-edge collaborative decision-making method that can defend against backdoor attacks as described in any one of claims 1 to 5 are implemented.

Citation Information

Patent Citations

  • Method and system for resisting backdoor attack based on federated learning

    CN118036072A

  • Federal learning backdoor attack defense method and system

    CN118070278A