Federal learning-based intelligent terminal network anomaly detection method and system
Through federated learning, training and updating the smart terminal network abnormality detection model on servers of different local platforms has solved the problem of data privacy leakage and computing burden in the smart terminal network abnormality detection, and achieved efficient and secure network abnormality detection.
Patent Information
- Application Number
- CN202510857632.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-25
- Publication Date
- 2025-08-15
AI Technical Summary
The prior art has problems such as data privacy leakage risk, excessive computing burden and degraded model training performance in the detection of abnormal data in smart terminal networks, especially the inefficiency of model training caused by the differences in data distribution in different regions.
Using federated learning methods, network anomaly detection models are collected and trained on different local platform servers, and model difference values are sent to the central platform for weighted aggregation, and global model parameters are generated to realize distributed training and updates, protect data privacy and improve model accuracy.
It effectively reduces the computing burden of a single platform, improves the accuracy and generalization capabilities of network anomaly detection, protects data privacy, and ensures the security and detection efficiency of smart terminals.
Smart Images

Figure CN120498867A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of smart terminals, and in particular to a method and system for detecting anomalies in smart terminal networks based on federated learning. Background Art
[0002] With the rapid development of smart terminals, smart terminals such as smartphones and IoT devices generate a large amount of operational data, including user events and system logs. On the one hand, operational data is highly valuable and can assist in data mining and model training; on the other hand, direct transmission or utilization can potentially lead to privacy breaches and other issues. Existing technologies use centralized data processing methods to collect and transmit smart terminal operational data to a central server, where it is trained and analyzed using a time-series network anomaly detection model to identify and detect anomalies in smart terminals. Specifically, directly transmitting smart terminal operational data for training may pose a risk of data leakage, making it difficult to protect user privacy. Furthermore, regional differences in data distribution can lead to performance degradation during model training. For example, different smart terminal usage habits and network environments in different regions can affect the distribution of data features. Furthermore, relying on a single platform to process all operational data can result in a significant computational burden, reducing system efficiency and processing power. Summary of the Invention
[0003] The present invention aims to provide a method and system for detecting network anomalies in smart terminals based on federated learning. The method collects and preprocesses the operating data of smart terminals and uploads it to different local platform servers for aggregation and collation, thereby updating the local database corresponding to each local platform server. A network anomaly detection model is trained based on the local database of each local platform server, and the computational burden of a single platform is reduced through distributed local training, thereby improving processing performance and efficiency. The difference values between the network anomaly detection models trained by all local platform servers and the global model are sent to a central platform server. The difference values corresponding to all network anomaly detection models received by the central platform server are weighted and aggregated to generate new global model parameters, which are distributed back to each local platform server. This enables the central platform server to handle inconsistent data features caused by different regions, improve the accuracy and generalization ability of the network anomaly detection model, and effectively protect data privacy and security by ensuring that each local platform server only shares model update parameters rather than original data through federated learning. The model parameters of the network anomaly detection model of each local platform server are updated. After the federated learning training is completed, network anomaly detection is performed on the smart terminals corresponding to each local platform server, more effectively detecting anomalies in the operating data of the smart terminals and improving the accuracy of network anomaly detection.
[0004] In a first aspect of the present invention, a method for detecting anomalies in a smart terminal network based on federated learning is proposed, comprising the following steps:
[0005] Collecting the operating data of smart terminals and preprocessing the operating data to obtain normalized operating data; uploading the normalized operating data from different smart terminals to different local platform servers for aggregation and collation, thereby updating the local database corresponding to each local platform server;
[0006] Based on the local database of each local platform server, the network anomaly detection model of each local platform server is trained; the difference between the trained network anomaly detection model of all local platform servers and the global model is sent to the central platform server;
[0007] The difference values corresponding to all network anomaly detection models received by the central platform server are aggregated to generate new global model parameters and distributed back to each local platform server; based on the new global model parameters, the model parameters of the network anomaly detection model of each local platform server are updated; after the federated learning training is completed, network anomaly detection is performed on the corresponding smart terminals of each local platform server.
[0008] Optionally, operating data of smart terminals are collected and pre-processed to obtain normalized operating data; normalized operating data from different smart terminals are uploaded to different local platform servers for aggregation and collation, thereby updating the local database corresponding to each local platform server, including:
[0009] Monitor all smart terminals under the terminal cluster to obtain user event triggering information and system thread execution information of each smart terminal; based on the user event triggering information and the system thread execution information, collect operation data of each smart terminal; wherein the operation data includes user event records and / or system operation logs; and perform data verification and encryption preprocessing on the operation data to obtain standardized operation data;
[0010] Based on the IP information and historical communication records of all smart terminals, the stability and historical success rate of data transmission are obtained, and the local platform server that matches each smart terminal is determined. The standardized operation data of each smart terminal is uploaded to the matching local platform server.
[0011] After decoding the normalized operation data received by the local platform server, data fusion processing is performed with the local database of the local platform server, thereby updating the local database corresponding to the local platform server.
[0012] Optionally, based on the local database of each local platform server, a network anomaly detection model of each local platform server is trained; and the difference between the trained network anomaly detection model of all local platform servers and the global model is sent to the central platform server, including:
[0013] Based on the local database of the local platform server, corresponding data is selected to form a training data set; based on the training data set, a time series network anomaly detection model of the local platform server is trained;
[0014] During the first training, the training degree of the temporal network anomaly detection model is identified in each round to determine whether the temporal network anomaly detection model has reached the target accuracy threshold; if so, the first training is terminated; if not, the temporal network anomaly detection model will continue to be trained until the target accuracy threshold is reached; and in subsequent training, the difference value between the trained network anomaly detection model corresponding to the local platform server in each round and the global model is sent to the central platform server.
[0015] Optionally, the difference values corresponding to all network anomaly detection models received by the central platform server are aggregated to generate new global model parameters and distributed back to each local platform server; based on the new global model parameters, the model parameters of the network anomaly detection model of each local platform server are updated; after the federated learning training is completed, network anomaly detection is performed on the smart terminal corresponding to each local platform server, including:
[0016] Perform weighted aggregation processing on the difference values corresponding to all network anomaly detection models received by the central platform server according to the number of samples, generate new global model parameters and distribute them back to each local platform server;
[0017] Each local platform server updates its local model parameters based on the new global model parameters and FredProx rules, thereby conducting the next round of training for the network anomaly detection model of each local platform server, and sending the retrained network anomaly detection model to the central platform server for federated learning again; and the corresponding smart terminal based on the retrained network anomaly detection model of each local platform server performs operation anomaly event detection.
[0018] Optionally, the method further includes: determining whether it is necessary to retrain the network anomaly detection model based on the number of anomalies detected by the smart terminal corresponding to each local platform server, which includes:
[0019] Based on the number of anomalies detected by the corresponding smart terminals of each local platform server, determine whether the network anomaly detection model needs to be trained again:
[0020]
[0021] Where R represents the control value of whether the network anomaly detection model needs to be trained again; D k (a) represents the number of anomalies detected by the current network anomaly detection model for the a-th smart terminal corresponding to the k-th local platform server; N k represents the total number of anomalies detected by the previous network anomaly detection model on the k-th local platform server; M k represents the total number of smart terminals corresponding to the k-th local platform server; d k (a) represents the number of anomalies detected by the previous network anomaly detection model for the a-th smart terminal corresponding to the k-th local platform server; && represents a logical AND operation; Indicates that 1≤a≤M k Under the condition, for all a values, if D k (a)-d k (a) ≥ 0, the overall output value is 1, otherwise the overall output value is 0;
[0022] If R=1, it means that the network anomaly detection model needs to be trained again;
[0023] If R=0, it means that there is no need to train the network anomaly detection model again;
[0024] If the network anomaly detection model needs to be trained again, the data upload method for retraining the network anomaly detection model is determined based on the total usage time of the current network anomaly detection model and the difference between the current network anomaly detection model and the previous network anomaly detection model:
[0025]
[0026] Where H represents the data upload mode control value when retraining the network anomaly detection model;
[0027] If H=1, it means that the data upload method when retraining the network anomaly detection model is to upload only the operation data of the smart terminal collected during the current network anomaly detection model, and then retrain the network anomaly detection model to optimize the network anomaly detection model;
[0028] If H=2, it means that the data upload method for retraining the network anomaly detection model is to upload all the collected operation data of the smart terminals and then retrain the network anomaly detection model to form a new network anomaly detection model;
[0029] Determine the restart times for each smart terminal based on the number and duration of abnormalities detected by the corresponding smart terminal on each local platform server:
[0030]
[0031] Where Q k (a) represents the number of restarts of the a-th smart terminal corresponding to the k-th local platform server; Q max Indicates the maximum number of restarts of the smart terminal within a preset time interval; T k (a) represents the running time of the a-th smart terminal corresponding to the k-th local platform server within the detection time of the current network anomaly detection model; T ka (p) represents the abnormal duration when the current network anomaly detection model detects the p-th abnormality of the a-th smart terminal corresponding to the k-th local platform server.
[0032] The intelligent terminal network anomaly detection system based on federated learning includes:
[0033] An operation data collection and preprocessing module is used to collect operation data of the intelligent terminal and preprocess the operation data to obtain normalized operation data;
[0034] The operation data aggregation and collation module is used to upload the standardized operation data from different smart terminals to different local platform servers for aggregation and collation, thereby updating the local database corresponding to each local platform server;
[0035] The local platform model training module is used to train the network anomaly detection model of each local platform server based on the local database of each local platform server;
[0036] The model sending module is used to send the difference between the network anomaly detection model trained by all local platform servers and the global model to the central platform server;
[0037] A model aggregation processing module is used to aggregate the difference values corresponding to all network anomaly detection models received by the central platform server, generate new global model parameters and distribute them back to each local platform server;
[0038] The model update and network anomaly detection execution module is used to update the model parameters of the network anomaly detection model of each local platform server based on the new global model parameters; after completing the federated learning training, network anomaly detection is performed on the corresponding smart terminals of each local platform server.
[0039] Optionally, the operation data collection and preprocessing module is used to collect the operation data of the smart terminal and preprocess the operation data to obtain normalized operation data, including:
[0040] Monitor all smart terminals under the terminal cluster to obtain user event triggering information and system thread execution information of each smart terminal; based on the user event triggering information and the system thread execution information, collect operation data of each smart terminal; wherein the operation data includes user event records and / or system operation logs; and perform data verification and encryption preprocessing on the operation data to obtain standardized operation data;
[0041] The operation data aggregation and collating module is used to upload standardized operation data from different smart terminals to different local platform servers for aggregation and collating, thereby updating the local database corresponding to each local platform server, including:
[0042] Based on the IP information and historical communication records of all smart terminals, the stability and historical success rate of data transmission are obtained, and the local platform server that matches each smart terminal is determined. The standardized operation data of each smart terminal is uploaded to the matching local platform server.
[0043] After decoding the normalized operation data received by the local platform server, data fusion processing is performed with the local database of the local platform server, thereby updating the local database corresponding to the local platform server.
[0044] Optionally, the local platform model training module is used to train the network anomaly detection model of each local platform server based on the local database of each local platform server, including:
[0045] Based on the local database of the local platform server, corresponding data is selected to form a training data set; based on the training data set, a time series network anomaly detection model of the local platform server is trained;
[0046] The model sending module is used to send the difference between the network anomaly detection model trained by all local platform servers and the global model to the central platform server, including:
[0047] During the first training, the training degree of the temporal network anomaly detection model is identified in each round to determine whether the temporal network anomaly detection model has reached the target accuracy threshold; if so, the first training is terminated; if not, the temporal network anomaly detection model will continue to be trained until the target accuracy threshold is reached; and in subsequent training, the difference value between the trained network anomaly detection model corresponding to the local platform server in each round and the global model is sent to the central platform server.
[0048] Optionally, the model aggregation processing module is used to aggregate the difference values corresponding to all network anomaly detection models received by the central platform server, generate new global model parameters and distribute them back to each local platform server, including:
[0049] Perform weighted aggregation processing on the difference values corresponding to all network anomaly detection models received by the central platform server according to the number of samples, generate new global model parameters and distribute them back to each local platform server;
[0050] The model update and network anomaly detection execution module is used to update the model parameters of the network anomaly detection model of each local platform server based on the new global model parameters; after completing the federated learning training, network anomaly detection is performed on the smart terminal corresponding to each local platform server, including:
[0051] Each local platform server updates its local model parameters based on the new global model parameters and FredProx rules, thereby conducting the next round of training for the network anomaly detection model of each local platform server, and sending the retrained network anomaly detection model to the central platform server for federated learning again; and the corresponding smart terminal based on the retrained network anomaly detection model of each local platform server performs operation anomaly event detection.
[0052] Compared with the prior art, the present invention has the following beneficial effects:
[0053] The federated learning-based smart terminal network anomaly detection method and system provided in this application collect and pre-process the operating data of smart terminals, and upload it to different local platform servers for aggregation and collation, thereby updating the local database corresponding to each local platform server; train a network anomaly detection model based on the local database of each local platform server, reduce the computational burden of a single platform through distributed local training, and improve processing performance and efficiency; send the difference values between the network anomaly detection models trained by all local platform servers and the global model to the central platform server; perform weighted aggregation processing on the difference values corresponding to all network anomaly detection models received by the central platform server, generate new global model parameters and distribute them back to each local platform server, so that the central platform server can handle the problem of inconsistent data features caused by different regions, improve the accuracy and generalization ability of the network anomaly detection model, and through federated learning, each local platform server only shares model update parameters rather than original data, effectively protecting data privacy and security; update the model parameters of the network anomaly detection model of each local platform server; after completing the federated learning training, perform network anomaly detection on the smart terminals corresponding to each local platform server, more effectively detect anomalies in the operating data of the smart terminals, and improve the accuracy of network anomaly detection. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative work. Among them:
[0055] Figure 1 A flow chart of the intelligent terminal network anomaly detection method based on federated learning provided by the present invention.
[0056] Figure 2 This is a structural diagram of the intelligent terminal network anomaly detection system based on federated learning provided by the present invention. DETAILED DESCRIPTION
[0057] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are described in detail below in conjunction with the accompanying drawings. It will be understood that the specific embodiments described herein are only used to explain the present application, rather than to limit the present application. It should also be noted that, for ease of description, only some, rather than all, structures related to the present application are shown in the accompanying drawings. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.
[0058] As used herein, the terms "comprise," "comprising," and "having," and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, product, or apparatus comprising a series of steps or elements is not limited to the listed steps or elements but may optionally include steps or elements not listed, or may optionally include other steps or elements inherent to the process, method, product, or apparatus.
[0059] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.
[0060] See also Figure 1 As shown, an embodiment of the present application provides a method for detecting anomalies in a smart terminal network based on federated learning. The method for detecting anomalies in a smart terminal network based on federated learning includes:
[0061] Collect the operating data of smart terminals and pre-process the operating data to obtain standardized operating data; upload the standardized operating data from different smart terminals to different local platform servers for aggregation and collation, thereby updating the local database corresponding to each local platform server;
[0062] Based on the local database of each local platform server, the network anomaly detection model of each local platform server is trained; the difference between the trained network anomaly detection model of all local platform servers and the global model is sent to the central platform server;
[0063] The difference values corresponding to all network anomaly detection models received by the central platform server are aggregated to generate new global model parameters and distributed back to each local platform server; based on the new global model parameters, the model parameters of the network anomaly detection model of each local platform server are updated; after the federated learning training is completed, network anomaly detection is performed on the corresponding smart terminals of each local platform server.
[0064] The beneficial effects of the above embodiments are as follows: the smart terminal network anomaly detection method based on federated learning collects and preprocesses the operating data of the smart terminal, and uploads it to different local platform servers for aggregation and collation, thereby updating the local database corresponding to each local platform server; trains the network anomaly detection model based on the local database of each local platform server, reduces the computational burden of a single platform through distributed local training, and improves processing performance and efficiency; sends the difference values between the network anomaly detection models trained by all local platform servers and the global model to the central platform server; performs weighted aggregation processing on the difference values corresponding to all network anomaly detection models received by the central platform server, generates new global model parameters and distributes them back to each local platform server, so that the central platform server can handle the problem of inconsistent data features caused by different regions, improves the accuracy and generalization ability of the network anomaly detection model, and through federated learning, the local platform servers only share model update parameters instead of original data, effectively protecting data privacy and security; updates the model parameters of the network anomaly detection model of each local platform server; after completing the federated learning training, performs network anomaly detection on the smart terminal corresponding to each local platform server, more effectively detecting anomalies in the operating data of the smart terminal, and improving the accuracy of network anomaly detection.
[0065] In another embodiment, operating data of smart terminals is collected and pre-processed to obtain normalized operating data; normalized operating data from different smart terminals is uploaded to different local platform servers for aggregation and collation, thereby updating the local database corresponding to each local platform server, including:
[0066] Monitor all smart terminals in the terminal cluster to obtain user event triggering information and system thread execution information for each smart terminal; based on the user event triggering information and the system thread execution information, collect the operation data of each smart terminal; wherein the operation data includes user event records and / or system operation logs; and perform data verification and encryption preprocessing on the operation data to obtain standardized operation data;
[0067] Based on the IP information and historical communication records of all smart terminals, the stability and historical success rate of data transmission are obtained, and the local platform server that matches each smart terminal is determined. The standardized operation data of each smart terminal is uploaded to the matching local platform server.
[0068] After decoding the normalized operation data received by the local platform server, data fusion processing is performed with the local database of the local platform server, thereby updating the local database corresponding to the local platform server.
[0069] The beneficial effect of the above embodiment is that the terminal cluster includes several smart terminals located in different regions, and the users corresponding to each smart terminal are different, so that the operation data of different smart terminals have different characteristics. In this way, all smart terminals under the terminal cluster can cover the differences in terminal operation data in different regions to the maximum extent. In order to comprehensively and accurately obtain the operation data under the smart terminal, all smart terminals under the terminal cluster are monitored separately to obtain the user event triggering information and system thread execution information of all smart terminals, wherein the user event triggering information and the system thread execution information are used to characterize the operation data such as the operation event data of the user during the operation of the smart terminal and the data corresponding to the thread of the application program in the system executing the corresponding task; based on the user event triggering information and the system thread execution information, it is judged whether the corresponding operation data has been completely generated, so that the operation data corresponding to the smart terminal is collected after the operation data is completely generated, so as to ensure the integrity of the operation data. The collected operation data is then subjected to data verification (i.e., eliminating the obviously erroneous data part in the operation data) and encryption preprocessing (i.e., selecting an appropriate encryption method for encryption processing according to the format and content of the operation data), thereby obtaining standardized operation data, effectively reducing the redundancy of the operation data and ensuring the security of subsequent operation data transmission. In addition, based on the IP information and historical communication records of all smart terminals, the stability and historical success rate of data transmission are obtained, and the local platform server that matches each smart terminal is determined. In this way, the standardized operation data of each smart terminal is uploaded to the matching local platform server, and the matching between the corresponding smart terminal and the specific local platform server is achieved. In this way, the standardized operation data of each smart terminal is uploaded to the matching local platform server. In this way, distributed operation data reception of all smart terminals can be achieved by using different local platform servers. After decoding the standardized operation data received by the local platform server, data fusion processing is performed with the local database of the local platform server (that is, the decoded standardized operation data is combined with the original local data in the local database of the local platform server for data deduplication and data format consistency processing, and the standardized operation data is accurately integrated into the local database), thereby updating the local database corresponding to the local platform server and achieving data diversification and enrichment processing of the local database.
[0070] In another embodiment, a network anomaly detection model of each local platform server is trained based on the local database of each local platform server; and the difference between the trained network anomaly detection model of each local platform server and the global model is sent to the central platform server, including:
[0071] Based on the local database of the local platform server, corresponding data is selected to form a training data set; based on the training data set, a time series network anomaly detection model of the local platform server is trained;
[0072] During the first training, the training degree of the time series network anomaly detection model is identified in each round to determine whether the time series network anomaly detection model has reached the target accuracy threshold; if so, the first training is ended; if not, the time series network anomaly detection model will continue to be trained until the target accuracy threshold is reached; and in subsequent training, the difference value between the trained network anomaly detection model corresponding to the local platform server and the global model in each round will be sent to the central platform service.
[0073] The beneficial effect of the above embodiment is that the local data contained in the local database of the local platform server is used to train the temporal network anomaly detection model. In order to achieve generalization and diversified training of the temporal network anomaly detection model, it is necessary to avoid reusing the same local data in the local database for model training. To this end, based on the training usage history of the local database of the local platform server, the training usage history is analyzed to determine the data portion of the local database of the local platform server that has not been used for training the model, and a training data set for current model training is generated based on the data portion, that is, an appropriate amount of data is selected from it to form a training data set. The training data set is then used to train the temporal network anomaly detection model of the local platform server, so that different local platform servers can train the temporal network anomaly detection model locally. This distributed local training method can reduce the model training computational burden of a single platform and improve the model training performance and efficiency of all platform servers. The training degree of the time series network anomaly detection model is also identified to determine whether the time series network anomaly detection model has reached the target accuracy threshold. If so, the first training is terminated; if not, the time series network anomaly detection model will continue to be trained until the target accuracy threshold is reached; and in subsequent training, the difference value between the trained network anomaly detection model corresponding to each round of the local platform server and the global model is sent to the central platform server to ensure that the time series network anomaly detection model received by the central platform server can obtain a higher performance model for federated learning, thereby improving the reliability of federated learning.
[0074] In another embodiment, the central platform server aggregates the difference values corresponding to all network anomaly detection models received by the central platform server to generate new global model parameters and distribute them back to each local platform server; based on the new global model parameters, the network anomaly detection model of each local platform server is updated with model parameters; after the federated learning training is completed, network anomaly detection is performed on the smart terminals corresponding to each local platform server, including:
[0075] The difference values corresponding to all network anomaly detection models received by the central platform server are weighted and aggregated according to the number of samples to generate new global model parameters and distribute them back to each local platform server;
[0076] Each local platform server updates its local model parameters based on the new global model parameters and FredProx rules, thereby conducting the next round of training for the network anomaly detection model of each local platform server, and sends the retrained network anomaly detection model to the central platform server for federated learning again; the corresponding smart terminal also performs operation anomaly event detection based on the retrained network anomaly detection model of each local platform server.
[0077] The beneficial effects of the above embodiment are that the purpose of the central platform server performing federated learning on the network anomaly detection models from different local platform servers is to deal with the problem of inconsistent data features caused by different regions and improve the accuracy and generalization ability of the network anomaly detection model. If there is a high similarity between the network anomaly detection models received by the central platform server, the federated learning will not be able to effectively generalize the data feature differences in different regions. In order to improve the reliability of the federated learning of the central platform server, all network anomaly detection models received by the central platform server are subjected to model similarity identification to determine whether all network anomaly detection models meet the preset model differentiation conditions; if not, the difference values of the network anomaly detection models sent by the local platform server are continued to be received; if satisfied, the difference values corresponding to all network anomaly detection models received by the central platform server are weighted and aggregated according to the number of samples to generate new global model parameters and distribute them back to each local platform server. Generate new global model parameters and distribute them back to each local platform server, which can improve the accuracy and generalization ability of the network anomaly detection model. Furthermore, the aggregation processing strategy of the central platform server can be as follows:
[0078]
[0079] In the above formula (1), w t+1 is the updated global model parameter; K is the total number of participants; n k is the number of data samples of the kth participant; n is the total number of data samples of all participants; are the local model parameters of the kth participant after round t.
[0080] In addition, each local platform server updates the local model parameters based on the new global model parameters and FredProx rules, so as to conduct the next round of training for the network anomaly detection model of each local platform server, and sends the trained network anomaly detection model to the central platform server for federated learning again. In this way, regardless of whether the local platform server has not conducted local training of the network anomaly detection model or is conducting local training of the network anomaly detection model, it can use the new global model parameters fed back by the central platform server to improve the training of the model. The local platform server can perform the next round of model parameter updates and the next round of local training according to the FedProx strategy. The FedProx strategy is as follows: Compared with the classic federated learning algorithm FedAvg, the local objective function of FedProx contains an additional approximation term, and the formula is as follows:
[0081]
[0082] In the above formula (2), F k (w) is the local objective function of the kth participant; n k is the number of data samples of k participants; is the dataset of the kth participant; f i (w) is the loss function of sample i to model parameter w; μ is a hyperparameter that adjusts the proximal term and is used to control the strength of regularization; w t is the current global model parameter; |ww t | 2 is the current local model parameter w and the global model parameter w t The squared Euclidean distance between
[0083] Finally, based on the network anomaly detection model trained again by each local platform server, the corresponding smart terminal performs operation anomaly event detection. This can more effectively detect anomalies in the operation data of the smart terminal and improve the accuracy of network anomaly detection.
[0084] In another embodiment, the method further includes: determining whether it is necessary to retrain the network anomaly detection model based on the number of anomalies detected by the smart terminal corresponding to each local platform server, which includes:
[0085] Step S1, using the following formula (3), according to the number of anomalies detected by the corresponding smart terminal of each local platform server, it is determined whether the network anomaly detection model needs to be trained again.
[0086]
[0087] In the above formula (3), R represents the control value of whether the network anomaly detection model needs to be trained again; Dk (a) represents the number of anomalies detected by the current network anomaly detection model for the a-th smart terminal corresponding to the k-th local platform server; N k represents the total number of anomalies detected by the previous network anomaly detection model on the k-th local platform server; M k represents the total number of smart terminals corresponding to the k-th local platform server; d k (a) represents the number of anomalies detected by the previous network anomaly detection model for the a-th smart terminal corresponding to the k-th local platform server; && represents a logical AND operation; It means that under the condition of 1≤a≤Mk, for all values of a, if Dk(a)-dk(a)≥0, the overall output value is 1, otherwise the overall output value is 0;
[0088] If R=1, it means that the network anomaly detection model needs to be trained again;
[0089] If R=0, it means that there is no need to train the network anomaly detection model again;
[0090] Step S2: If the network anomaly detection model needs to be trained again, the following formula (4) is used to determine the data upload method for training the network anomaly detection model again based on the total time the current network anomaly detection model is used and the difference between the current network anomaly detection model and the previous network anomaly detection model.
[0091]
[0092] In the above formula (4), H represents the data upload mode control value when retraining the network anomaly detection model;
[0093] If H=1, it means that the data upload method when retraining the network anomaly detection model is to upload only the operation data of the smart terminal collected during the current network anomaly detection model, and then retrain the network anomaly detection model to optimize the network anomaly detection model;
[0094] If H=2, it means that the data upload method for retraining the network anomaly detection model is to upload all the collected operation data of the smart terminals and then retrain the network anomaly detection model to form a new network anomaly detection model;
[0095] Step S3, using the following formula (5), according to the number of abnormalities and abnormal duration detected by the corresponding intelligent terminal of each local platform server, the number of restarts of each intelligent terminal is determined.
[0096]
[0097] In the above formula (5), Q k (a) represents the number of restarts of the a-th smart terminal corresponding to the k-th local platform server; Q max Indicates the maximum number of restarts of the smart terminal within a preset time interval; T k (a) represents the running time of the a-th smart terminal corresponding to the k-th local platform server within the detection time of the current network anomaly detection model; T ka (p) represents the abnormal duration when the current network anomaly detection model detects the p-th abnormality of the a-th smart terminal corresponding to the k-th local platform server.
[0098] The beneficial effects of the above embodiment are as follows: using the above formula (1), according to the number of anomalies detected by the smart terminal corresponding to each local platform server, it is determined whether the network anomaly detection model needs to be trained again, so that the network anomaly detection model is continuously optimized when the model is imperfect, thereby ensuring the reliability of the system; then using the above formula (2), according to the total time the current network anomaly detection model is used and the difference between the current network anomaly detection model and the previous network anomaly detection model, the data upload method when the network anomaly detection model is trained again is determined, so that all data training is performed again when there are major problems in model optimization, thereby ensuring the accuracy of the model; then using the above formula (3), according to the number of anomalies detected by the smart terminal corresponding to each local platform server and the duration of the anomalies, the number of restarts of each smart terminal is determined, so that when there are many anomalies in the smart terminal, the anomaly is automatically resolved by restarting within a preset time interval such as evening, reflecting the automatic repair capability of the system.
[0099] See also Figure 2 As shown, an embodiment of the present application provides a smart terminal network anomaly detection system based on federated learning. The smart terminal network anomaly detection system based on federated learning includes:
[0100] The operation data collection and preprocessing module is used to collect the operation data of the intelligent terminal and preprocess the operation data to obtain standardized operation data;
[0101] The operation data aggregation and collation module is used to upload the standardized operation data from different smart terminals to different local platform servers for aggregation and collation, thereby updating the local database corresponding to each local platform server;
[0102] The local platform model training module is used to train the network anomaly detection model of each local platform server based on the local database of each local platform server;
[0103] The model sending module is used to send the difference between the network anomaly detection model trained by all local platform servers and the global model to the central platform server;
[0104] The model aggregation processing module is used to aggregate the difference values corresponding to all network anomaly detection models received by the central platform server, generate new global model parameters and distribute them back to each local platform server;
[0105] The model update and network anomaly detection execution module is used to update the model parameters of the network anomaly detection model of each local platform server based on the new global model parameters; after the federated learning training is completed, network anomaly detection is performed on the corresponding smart terminals of each local platform server.
[0106] The beneficial effects of the above embodiments are as follows: the smart terminal network anomaly detection system based on federated learning collects and pre-processes the operating data of smart terminals, and uploads it to different local platform servers for aggregation and collation, thereby updating the local database corresponding to each local platform server; trains a network anomaly detection model based on the local database of each local platform server, reduces the computational burden of a single platform through distributed local training, and improves processing performance and efficiency; sends the difference values between the network anomaly detection models trained by all local platform servers and the global model to the central platform server; performs weighted aggregation processing on the difference values corresponding to all network anomaly detection models received by the central platform server, generates new global model parameters, and distributes them back to each local platform server, so that the central platform server can handle the problem of inconsistent data features caused by different regions, improves the accuracy and generalization ability of the network anomaly detection model, and through federated learning, each local platform server only shares model update parameters rather than original data, effectively protecting data privacy and security; updates the model parameters of the network anomaly detection model of each local platform server; after completing the federated learning training, performs network anomaly detection on the smart terminals corresponding to each local platform server, more effectively detecting anomalies in the operating data of the smart terminals, and improving the accuracy of network anomaly detection.
[0107] In another embodiment, the operation data collection and preprocessing module is used to collect the operation data of the smart terminal and preprocess the operation data to obtain normalized operation data, including:
[0108] Monitor all smart terminals in the terminal cluster to obtain user event triggering information and system thread execution information for each smart terminal; based on the user event triggering information and the system thread execution information, collect the operation data of each smart terminal; wherein the operation data includes user event records and / or system operation logs; and perform data verification and encryption preprocessing on the operation data to obtain standardized operation data;
[0109] The operation data aggregation module is used to upload standardized operation data from different smart terminals to different local platform servers for aggregation and collation, thereby updating the local database corresponding to each local platform server, including:
[0110] Based on the IP information and historical communication records of all smart terminals, the stability and historical success rate of data transmission are obtained, and the local platform server that matches each smart terminal is determined. The standardized operation data of each smart terminal is uploaded to the matching local platform server.
[0111] After decoding the normalized operation data received by the local platform server, data fusion processing is performed with the local database of the local platform server, thereby updating the local database corresponding to the local platform server.
[0112] The beneficial effect of the above embodiment is that the terminal cluster includes several smart terminals located in different regions, and the users corresponding to each smart terminal are different, so that the operation data of different smart terminals have different characteristics. In this way, all smart terminals under the terminal cluster can cover the differences in terminal operation data in different regions to the maximum extent. In order to comprehensively and accurately obtain the operation data under the smart terminal, all smart terminals under the terminal cluster are monitored separately to obtain the user event triggering information and system thread execution information of all smart terminals, wherein the user event triggering information and the system thread execution information are used to characterize the operation data such as the operation event data of the user during the operation of the smart terminal and the data corresponding to the thread of the application program in the system executing the corresponding task; based on the user event triggering information and the system thread execution information, it is judged whether the corresponding operation data has been completely generated, so that the operation data corresponding to the smart terminal is collected after the operation data is completely generated, so as to ensure the integrity of the operation data. The collected operation data is then subjected to data verification (i.e., eliminating the obviously erroneous data part in the operation data) and encryption preprocessing (i.e., selecting an appropriate encryption method for encryption processing according to the format and content of the operation data), thereby obtaining standardized operation data, effectively reducing the redundancy of the operation data and ensuring the security of subsequent operation data transmission. In addition, based on the IP information and historical communication records of all smart terminals, the stability and historical success rate of data transmission are obtained, and the local platform server that matches each smart terminal is determined. In this way, the standardized operation data of each smart terminal is uploaded to the matching local platform server, and the matching between the corresponding smart terminal and the specific local platform server is achieved. In this way, the standardized operation data of each smart terminal is uploaded to the matching local platform server. In this way, distributed operation data reception of all smart terminals can be achieved by using different local platform servers. After decoding the standardized operation data received by the local platform server, data fusion processing is performed with the local database of the local platform server (that is, the decoded standardized operation data is combined with the original local data in the local database of the local platform server for data deduplication and data format consistency processing, and the standardized operation data is accurately integrated into the local database), thereby updating the local database corresponding to the local platform server and achieving data diversification and enrichment processing of the local database.
[0113] In another embodiment, the local platform model training module is used to train the network anomaly detection model of each local platform server based on the local database of each local platform server, including:
[0114] Based on the local database of the local platform server, corresponding data is selected to form a training data set; based on the training data set, a time series network anomaly detection model of the local platform server is trained;
[0115] The model sending module is used to send the difference between the network anomaly detection model trained by all local platform servers and the global model to the central platform server, including:
[0116] During the first training, the training degree of the time series network anomaly detection model is identified in each round to determine whether the time series network anomaly detection model has reached the target accuracy threshold; if so, the first training is ended; if not, the time series network anomaly detection model will continue to be trained until the target accuracy threshold is reached; and in subsequent training, the difference value between the trained network anomaly detection model corresponding to the local platform server and the global model in each round will be sent to the central platform server.
[0117] The beneficial effect of the above embodiment is that the local data contained in the local database of the local platform server is used to train the temporal network anomaly detection model. In order to achieve generalization and diversified training of the temporal network anomaly detection model, it is necessary to avoid reusing the same local data in the local database for model training. To this end, based on the training usage history of the local database of the local platform server, the training usage history is analyzed to determine the data portion of the local database of the local platform server that has not been used for training the model, and a training data set for current model training is generated based on the data portion, that is, an appropriate amount of data is selected from it to form a training data set. The training data set is then used to train the temporal network anomaly detection model of the local platform server, so that different local platform servers can train the temporal network anomaly detection model locally. This distributed local training method can reduce the model training computational burden of a single platform and improve the model training performance and efficiency of all platform servers. The training degree of the time series network anomaly detection model is also identified to determine whether the time series network anomaly detection model has reached the target accuracy threshold. If so, the first training is terminated; if not, the time series network anomaly detection model will continue to be trained until the target accuracy threshold is reached; and in subsequent training, the difference value between the trained network anomaly detection model corresponding to each round of the local platform server and the global model is sent to the central platform server to ensure that the time series network anomaly detection model received by the central platform server can obtain a higher performance model for federated learning, thereby improving the reliability of federated learning.
[0118] In another embodiment, the model aggregation processing module is used to aggregate the difference values corresponding to all network anomaly detection models received by the central platform server, generate new global model parameters and distribute them back to each local platform server, including:
[0119] The difference values corresponding to all network anomaly detection models received by the central platform server are weighted and aggregated according to the number of samples to generate new global model parameters and distribute them back to each local platform server;
[0120] The model update and network anomaly detection execution module is used to update the model parameters of the network anomaly detection model of each local platform server based on the new global model parameters. After the federated learning training is completed, network anomaly detection is performed on the smart terminals corresponding to each local platform server, including:
[0121] Each local platform server updates its local model parameters based on the new global model parameters and FredProx rules, thereby conducting the next round of training for the network anomaly detection model of each local platform server, and sends the retrained network anomaly detection model to the central platform server for federated learning again; the corresponding smart terminal also performs operation anomaly event detection based on the retrained network anomaly detection model of each local platform server.
[0122] The beneficial effects of the above embodiment are that the purpose of the central platform server performing federated learning on the network anomaly detection models from different local platform servers is to deal with the problem of inconsistent data features caused by different regions and improve the accuracy and generalization ability of the network anomaly detection model. If there is a high similarity between the network anomaly detection models received by the central platform server, the federated learning will not be able to effectively generalize the data feature differences in different regions. In order to improve the reliability of the federated learning of the central platform server, all network anomaly detection models received by the central platform server are subjected to model similarity identification to determine whether all network anomaly detection models meet the preset model differentiation conditions; if not, the difference values of the network anomaly detection models sent by the local platform server are continued to be received; if satisfied, the difference values corresponding to all network anomaly detection models received by the central platform server are weighted and aggregated according to the number of samples to generate new global model parameters and distribute them back to each local platform server. Generate new global model parameters and distribute them back to each local platform server, which can improve the accuracy and generalization ability of the network anomaly detection model. Furthermore, the aggregation processing strategy of the central platform server can be as follows:
[0123]
[0124] w t+1 is the updated global model parameter; K is the total number of participants; n k is the number of data samples of the kth participant; n is the total number of data samples of all participants; are the local model parameters of the kth participant after round t.
[0125] In addition, each local platform server updates the local model parameters based on the new global model parameters and FredProx rules, so as to conduct the next round of training for the network anomaly detection model of each local platform server, and sends the trained network anomaly detection model to the central platform server for federated learning again. In this way, regardless of whether the local platform server has not conducted local training of the network anomaly detection model or is conducting local training of the network anomaly detection model, it can use the new global model parameters fed back by the central platform server to improve the training of the model. The local platform server can perform the next round of model parameter updates and the next round of local training according to the FedProx strategy. The FedProx strategy is as follows: Compared with the classic federated learning algorithm FedAvg, the local objective function of FedProx contains an additional approximation term, and the formula is as follows:
[0126]
[0127] F k (w) is the local objective function of the kth participant; n k is the number of data samples of k participants; is the dataset of the kth participant; f i (w) is the loss function of sample i to model parameter w; μ is a hyperparameter that adjusts the proximal term and is used to control the strength of regularization; w t is the current global model parameter; |ww t | 2 is the current local model parameter w and the global model parameter w t The squared Euclidean distance between
[0128] Finally, based on the network anomaly detection model trained again by each local platform server, the corresponding smart terminal performs operation anomaly event detection. This can more effectively detect anomalies in the operation data of the smart terminal and improve the accuracy of network anomaly detection.
[0129] In general, the smart terminal network anomaly detection method and system based on federated learning collects and preprocesses the operating data of smart terminals, and uploads it to different local platform servers for aggregation and collation, thereby updating the local database corresponding to each local platform server; trains the network anomaly detection model based on the local database of each local platform server, reduces the computational burden of a single platform through distributed local training, and improves processing performance and efficiency; sends the difference values between the network anomaly detection models trained by all local platform servers and the global model to the central platform server; performs weighted aggregation processing on the difference values corresponding to all network anomaly detection models received by the central platform server, generates new global model parameters and distributes them back to each local platform server, so that the central platform server can handle the problem of inconsistent data features caused by different regions, improve the accuracy and generalization ability of the network anomaly detection model, and through federated learning, the local platform servers only share model update parameters instead of original data, effectively protecting data privacy and security; updates the model parameters of the network anomaly detection model of each local platform server; after completing the federated learning training, performs network anomaly detection on the smart terminals corresponding to each local platform server, more effectively detecting anomalies in the operating data of the smart terminals, and improving the accuracy of network anomaly detection.
[0130] The above is only a specific embodiment of the present invention, and any other improvements made based on the concept of the present invention are considered to be within the scope of protection of the present invention.
Claims
1. A method for detecting anomalies in smart terminal networks based on federated learning, characterized in that: The steps include: Collecting the operating data of the smart terminals and preprocessing the operating data to obtain normalized operating data; uploading the normalized operating data from different smart terminals to different local platform servers for aggregation and collation, thereby updating the local database corresponding to each local platform server; Based on the local database of each local platform server, the network anomaly detection model of each local platform server is trained; the difference between the trained network anomaly detection model of all local platform servers and the global model is sent to the central platform server; The difference values corresponding to all network anomaly detection models received by the central platform server are aggregated to generate new global model parameters and distributed back to each local platform server; based on the new global model parameters, the model parameters of the network anomaly detection model of each local platform server are updated; after the federated learning training is completed, network anomaly detection is performed on the corresponding smart terminals of each local platform server.
2. The method for detecting anomalies in a smart terminal network based on federated learning according to claim 1, characterized in that: Collecting the operating data of smart terminals and pre-processing the operating data to obtain standardized operating data; uploading the standardized operating data from different smart terminals to different local platform servers for aggregation and collation, thereby updating the local database corresponding to each local platform server, specifically including: Monitor all smart terminals under the terminal cluster to obtain user event triggering information and system thread execution information of each smart terminal; based on the user event triggering information and the system thread execution information, collect operation data of each smart terminal; wherein the operation data includes user event records and / or system operation logs; and perform data verification and encryption preprocessing on the operation data to obtain standardized operation data; Based on the IP information and historical communication records of all smart terminals, the stability and historical success rate of data transmission are obtained, and the local platform server that matches each smart terminal is determined. The standardized operation data of each smart terminal is uploaded to the matching local platform server. After decoding the normalized operation data received by the local platform server, data fusion processing is performed with the local database of the local platform server, thereby updating the local database corresponding to the local platform server.
3. The method for detecting anomalies in smart terminal networks based on federated learning according to claim 1, characterized in that: Based on the local database of each local platform server, train the network anomaly detection model of each local platform server; Send the difference between the network anomaly detection model trained by all local platform servers and the global model to the central platform server, including: Based on the local database of the local platform server, corresponding data is selected to form a training data set; based on the training data set, a time series network anomaly detection model of the local platform server is trained; During the first training, the training degree of the temporal network anomaly detection model is identified in each round to determine whether the temporal network anomaly detection model has reached the target accuracy threshold; if so, the first training is terminated; if not, the temporal network anomaly detection model will continue to be trained until the target accuracy threshold is reached; and in subsequent training, the difference value between the trained network anomaly detection model corresponding to the local platform server and the global model in each round is sent to the central platform server.
4. The method for detecting anomalies in a smart terminal network based on federated learning according to claim 1, characterized in that: Aggregating the difference values corresponding to all network anomaly detection models received by the central platform server to generate new global model parameters and distributing them back to each local platform server; updating the model parameters of the network anomaly detection model of each local platform server based on the new global model parameters; After the federated learning training is completed, network anomaly detection is performed on the smart terminals corresponding to each local platform server, specifically including: Perform weighted aggregation processing on the difference values corresponding to all network anomaly detection models received by the central platform server according to the number of samples, generate new global model parameters and distribute them back to each local platform server; Each local platform server updates its local model parameters based on the new global model parameters and FredProx rules, thereby training the network anomaly detection model of each local platform server for the next round, and sends the retrained network anomaly detection model to the central platform server for federated learning again; The corresponding smart terminals also perform operation anomaly event detection based on the network anomaly detection model trained again by each local platform server.
5. The method for detecting anomalies in a smart terminal network based on federated learning according to claim 1, characterized in that: Also includes: Based on the number of anomalies detected by the corresponding smart terminals of each local platform server, it is determined whether the network anomaly detection model needs to be trained again.
6. The method for detecting anomalies in smart terminal networks based on federated learning according to claim 5, characterized in that: The determining whether it is necessary to retrain the network anomaly detection model based on the number of anomalies detected by the smart terminal corresponding to each local platform server specifically includes: Based on the number of anomalies detected by the corresponding smart terminals of each local platform server, determine whether the network anomaly detection model needs to be trained again: Where R represents the control value of whether the network anomaly detection model needs to be trained again; D k (a) represents the number of anomalies detected by the current network anomaly detection model for the a-th smart terminal corresponding to the k-th local platform server; N k represents the total number of anomalies detected by the previous network anomaly detection model on the k-th local platform server; M k represents the total number of smart terminals corresponding to the k-th local platform server; d k (a) represents the number of anomalies detected by the previous network anomaly detection model for the a-th smart terminal corresponding to the k-th local platform server; && represents a logical AND operation; Indicates that 1≤a≤M k Under the condition, for all a values, if D k (a)-d k (a) ≥ 0, the overall output value is 1, otherwise the overall output value is 0; If R=1, it means that the network anomaly detection model needs to be trained again; If R=0, it means that there is no need to train the network anomaly detection model again; If the network anomaly detection model needs to be trained again, the data upload method for retraining the network anomaly detection model is determined based on the total usage time of the current network anomaly detection model and the difference between the current network anomaly detection model and the previous network anomaly detection model: Where H represents the data upload mode control value when retraining the network anomaly detection model; If H=1, it means that the data upload method when retraining the network anomaly detection model is to upload only the operation data of the smart terminal collected during the current network anomaly detection model, and then retrain the network anomaly detection model to optimize the network anomaly detection model; If H=2, it means that the data upload method for retraining the network anomaly detection model is to upload all the collected operation data of the smart terminals and then retrain the network anomaly detection model to form a new network anomaly detection model; Determine the restart times Q of each smart terminal based on the number and duration of abnormalities detected by the corresponding smart terminal of each local platform server. k (a): Where Q max Indicates the maximum number of restarts of the smart terminal within a preset time interval; T k (a) represents the running time of the a-th smart terminal corresponding to the k-th local platform server within the detection time of the current network anomaly detection model; T ka (p) represents the abnormal duration when the current network anomaly detection model detects the p-th abnormality of the a-th smart terminal corresponding to the k-th local platform server.
7. A smart terminal network anomaly detection system, characterized in that: include: An operation data collection and preprocessing module is used to collect operation data of the intelligent terminal and preprocess the operation data to obtain normalized operation data; The operation data aggregation and collation module is used to upload the standardized operation data from different smart terminals to different local platform servers for aggregation and collation, thereby updating the local database corresponding to each local platform server; The local platform model training module is used to train the network anomaly detection model of each local platform server based on the local database of each local platform server; The model sending module is used to send the difference between the network anomaly detection model trained by all local platform servers and the global model to the central platform server; A model aggregation processing module is used to aggregate the difference values corresponding to all network anomaly detection models received by the central platform server, generate new global model parameters and distribute them back to each local platform server; The model update and network anomaly detection execution module is used to update the model parameters of the network anomaly detection model of each local platform server based on the new global model parameters; after completing the federated learning training, network anomaly detection is performed on the corresponding smart terminals of each local platform server.
8. The intelligent terminal network anomaly detection system according to claim 7, characterized in that: The operation data collection and preprocessing module is used to collect the operation data of the intelligent terminal and preprocess the operation data to obtain normalized operation data, including: Monitor all smart terminals under the terminal cluster to obtain user event triggering information and system thread execution information of each smart terminal; based on the user event triggering information and the system thread execution information, collect operation data of each smart terminal; wherein the operation data includes user event records and / or system operation logs; and perform data verification and encryption preprocessing on the operation data to obtain standardized operation data; The operation data aggregation and collating module is used to upload standardized operation data from different smart terminals to different local platform servers for aggregation and collating, thereby updating the local database corresponding to each local platform server, including: Based on the IP information and historical communication records of all smart terminals, the stability and historical success rate of data transmission are obtained, and the local platform server that matches each smart terminal is determined. The standardized operation data of each smart terminal is uploaded to the matching local platform server. After decoding the normalized operation data received by the local platform server, data fusion processing is performed with the local database of the local platform server, thereby updating the local database corresponding to the local platform server.
9. The intelligent terminal network anomaly detection system according to claim 7, characterized in that: The local platform model training module is used to train the network anomaly detection model of each local platform server based on the local database of each local platform server, including: Based on the local database of the local platform server, corresponding data is selected to form a training data set; based on the training data set, a time series network anomaly detection model of the local platform server is trained; The model sending module is used to send the difference between the network anomaly detection model trained by all local platform servers and the global model to the central platform server, including: During the first training, the training degree of the temporal network anomaly detection model is identified in each round to determine whether the temporal network anomaly detection model has reached the target accuracy threshold; if so, the first training is terminated; if not, the temporal network anomaly detection model will continue to be trained until the target accuracy threshold is reached; and in subsequent training, the difference value between the trained network anomaly detection model corresponding to the local platform server and the global model in each round is sent to the central platform server.
10. The intelligent terminal network anomaly detection system according to claim 7, characterized in that: The model aggregation processing module is used to aggregate the difference values corresponding to all network anomaly detection models received by the central platform server, generate new global model parameters and distribute them back to each local platform server, including: Perform weighted aggregation processing on the difference values corresponding to all network anomaly detection models received by the central platform server according to the number of samples, generate new global model parameters and distribute them back to each local platform server; The model update and network anomaly detection execution module is used to update the model parameters of the network anomaly detection model of each local platform server based on the new global model parameters; after completing the federated learning training, network anomaly detection is performed on the smart terminal corresponding to each local platform server, including: Each local platform server updates its local model parameters based on the new global model parameters and FredProx rules, thereby conducting the next round of training for the network anomaly detection model of each local platform server, and sending the retrained network anomaly detection model to the central platform server for federated learning again; and the corresponding smart terminal based on the retrained network anomaly detection model of each local platform server performs operation anomaly event detection.
Citation Information
Patent Citations
Method and equipment for realizing model updating
CN113159332A
Internet of Things equipment abnormal flow detection method based on clustering federated learning
CN114900343A
Network intrusion detection method fusing federated learning and differential privacy
CN118118215A
Application program security protection method and system based on federated learning
CN119939442A
System and method for DNN-based cyber-security using federated learning-based generative adversarial network
US20230308465A1