Pre-training model data poisoning monitoring method fusing graph neural network and feature self-adaption

By constructing data correlation graphs and graph neural networks to extract higher-order topological features, combined with feature adaptive modules and anomaly detection algorithms, the problem of insufficient detection accuracy in traditional methods is solved, and efficient and accurate data poisoning monitoring is achieved, which is suitable for scenes such as image classification models.

CN120524481APending Publication Date: 2025-08-22THE THIRD RES INST OF MIN OF PUBLIC SECURITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510604978.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-12
Publication Date
2025-08-22

AI Technical Summary

Technical Problem

The prior art is difficult to effectively detect complex data poisoning attacks, and traditional methods ignore the correlation between data samples, resulting in insufficient detection accuracy.

Method used

The pre-trained model data poisoning monitoring method that integrates graph neural network and feature adaptation is adopted. By constructing a data correlation graph, multi-layer message delivery features are extracted using graph neural network, and a poisoning risk assessment vector is generated by combining feature adaptation modules. Anomaly detection algorithm is used for real-time monitoring and iterative optimization.

Benefits of technology

It significantly improves the accuracy and applicability of data poisoning detection, can adapt to new poisoning attacks, reduce the false detection rate, and provides a reliable defense solution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120524481A_ABST
    Figure CN120524481A_ABST
Patent Text Reader

Abstract

The invention relates to a pre-training model data poisoning monitoring method fusing a graph neural network and feature self-adaption, and relates to the technical field of artificial intelligence safety. According to the method, a graph structure model is constructed for training data and model behaviors, a graph neural network is utilized to model complex association between data, and meanwhile, a feature adaptive mechanism is introduced to dynamically correct the influence of abnormal data, so that real-time monitoring and early warning of the model data poisoning behaviors are realized. The method comprises the following specific steps: performing multi-dimensional feature extraction and standardized preprocessing on original training data to be monitored and a model running log; constructing a data association graph based on feature similarity, and optimizing a graph structure by adopting a dynamic threshold strategy; node features are aggregated through a multi-layer graph convolutional network, and feature adaptive fusion is realized in combination with an attention mechanism; constructing a poisoning risk assessment model based on a time sequence, and performing anomaly detection by adopting an isolated forest algorithm; and designing a feedback closed-loop system to realize online updating of model parameters and dynamic adjustment of a defense strategy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence security, and in particular to a data poisoning monitoring method for pre-trained models that integrates graph neural networks and feature adaptation, which is suitable for data poisoning defense in various scenarios such as image classification models. Background Art

[0002] With the widespread adoption of deep learning technology, model security has received increasing attention. Data poisoning attacks are a common adversarial attack method. Attackers inject malicious samples into training data to disrupt model performance or induce erroneous behavior. Traditional data poisoning detection methods, typically based on statistical features or simple machine learning models, struggle to address complex poisoning attack patterns. Furthermore, existing methods often overlook the correlation between data samples, resulting in insufficient detection accuracy. Therefore, there is an urgent need for an efficient and accurate data poisoning monitoring method that can enhance detection capabilities by leveraging data correlation and feature adaptation. Summary of the Invention

[0003] The purpose of the present invention is to overcome the shortcomings of the existing technology and provide a data poisoning monitoring method that integrates graph neural network and feature adaptive pre-training model with high detection accuracy and strong applicability.

[0004] To achieve the above objectives, the data poisoning monitoring method of the present invention that integrates graph neural network and feature adaptive pre-training model is as follows:

[0005] The data poisoning monitoring method of the fusion graph neural network and feature adaptive pre-training model has the following main features:

[0006] (1) Preprocess the original training data and model operation logs to be monitored and extract multidimensional feature information;

[0007] (2) Construct a data association graph based on the preprocessed data, where nodes represent data samples and edges represent similarities or dependencies between samples;

[0008] (3) Using graph neural networks to perform multi-layer message passing on data association graphs to extract implicit features of nodes and edges;

[0009] (4) Combined with the feature adaptation module, the extracted node features are weighted and fused to generate a poisoning risk assessment vector;

[0010] (5) Use anomaly detection algorithms to monitor the generated risk assessment vectors in real time to determine whether there is data poisoning behavior;

[0011] (6) Based on anomaly detection, the detection results are fed back to the monitoring system, and the monitoring model is iteratively updated and optimized.

[0012] Preferably, the pretreatment in step (1) includes the following operations:

[0013] (1.1) Standardize the original training data to eliminate dimensional differences;

[0014] (1.2) Extract statistical, structural, and semantic features of data samples;

[0015] (1.3) Analyze the model operation log to extract the gradient information, loss value and classification confidence during the model training process.

[0016] Preferably, the specific method of constructing the data association graph in step (2) is:

[0017] (2.1) Calculate the similarity between data samples, using cosine similarity or Euclidean distance as the similarity metric;

[0018] (2.2) Determine the connection relationship between nodes based on the similarity threshold and generate the adjacency matrix of the data association graph;

[0019] (2.3) The adjacency matrix is ​​sparsely processed to preserve the dependency relationship.

[0020] Preferably, the graph neural network in step (3) adopts a graph convolutional network or a graph attention network, which aggregates neighbor node information through multi-layer message passing to generate implicit feature representations of nodes and edges.

[0021] Preferably, the specific implementation of the feature adaptation module in step (4) is as follows:

[0022] (4.1) Use the attention mechanism to calculate the weight of each node feature;

[0023] (4.2) Perform weighted summation on node features to generate global feature representation;

[0024] (4.3) Combine global features with local features to generate a poisoning risk assessment vector.

[0025] Preferably, the anomaly detection algorithm in step (5) adopts an isolation forest or a class of support vector machines to perform real-time analysis on the risk assessment vector and output an anomaly score and a poisoning determination result.

[0026] Preferably, the specific operations of iterative update optimization in step (6) are:

[0027] (6.1) Adjust model parameters based on test results and optimize feature extraction and anomaly detection modules;

[0028] (6.2) Regularly rebuild the data association graph and update the graph neural network and feature adaptation module;

[0029] (6.3) Adapt to new poisoning attack patterns in real time through online learning mechanism.

[0030] The model data poisoning monitoring method of the present invention that integrates graph neural network and feature adaptation is adopted. By constructing a data association graph to capture the dependency relationship between samples from the spatial dimension, and combining the multi-layer message passing mechanism of the graph neural network to extract high-order topological features, the sensitivity of abnormal pattern recognition is significantly improved; the feature adaptation module is introduced to dynamically adjust the node feature weights, which solves the false detection problem caused by the fixed feature importance of traditional methods; the model parameters are continuously optimized through the online learning mechanism, so that the system can adapt to the evolution of new poisoning attacks. This method innovatively combines graph structure with feature adaptation, which not only provides a reliable active defense solution for image classification pre-training models, but its modular design can also be extended to scenarios such as natural language processing and recommendation systems. It has significant application value in the fields of AI model security auditing, data quality monitoring, and intelligent system protection, and is expected to become a core technology to ensure the safe deployment of AI systems in key areas. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 This is a flow chart of the data poisoning monitoring method of the present invention that integrates graph neural network and feature adaptive pre-training model. DETAILED DESCRIPTION

[0032] In order to more clearly describe the technical content of the present invention, further description is given below in conjunction with specific embodiments.

[0033] The data poisoning monitoring method of the present invention, which integrates a graph neural network and a feature-adaptive pre-training model, includes the following steps:

[0034] (1) Preprocess the original training data and model operation logs to be monitored and extract multidimensional feature information;

[0035] (2) Construct a data association graph based on the preprocessed data, where nodes represent data samples and edges represent similarities or dependencies between samples;

[0036] (3) Using graph neural networks to perform multi-layer message passing on data association graphs to extract implicit features of nodes and edges;

[0037] (4) Combined with the feature adaptation module, the extracted node features are weighted and fused to generate a poisoning risk assessment vector;

[0038] (5) Use anomaly detection algorithms to monitor the generated risk assessment vectors in real time to determine whether there is data poisoning behavior;

[0039] (6) Based on anomaly detection, the detection results are fed back to the monitoring system, and the monitoring model is iteratively updated and optimized.

[0040] As a preferred embodiment of the present invention, the pretreatment in step (1) includes the following operations:

[0041] (1.1) Standardize the original training data to eliminate dimensional differences;

[0042] (1.2) Extract statistical, structural, and semantic features of data samples;

[0043] (1.3) Analyze the model operation log to extract the gradient information, loss value and classification confidence during the model training process.

[0044] As a preferred embodiment of the present invention, the specific method of constructing the data association graph in step (2) is:

[0045] (2.1) Calculate the similarity between data samples, using cosine similarity or Euclidean distance as the similarity metric;

[0046] (2.2) Determine the connection relationship between nodes based on the similarity threshold and generate the adjacency matrix of the data association graph;

[0047] (2.3) The adjacency matrix is ​​sparsely processed to preserve the dependency relationship.

[0048] As a preferred embodiment of the present invention, the graph neural network in step (3) adopts a graph convolutional network or a graph attention network to aggregate neighbor node information through multi-layer message passing to generate implicit feature representations of nodes and edges.

[0049] As a preferred embodiment of the present invention, the specific implementation of the feature adaptation module in step (4) is as follows:

[0050] (4.1) Use the attention mechanism to calculate the weight of each node feature;

[0051] (4.2) Perform weighted summation on node features to generate global feature representation;

[0052] (4.3) Combine global features with local features to generate a poisoning risk assessment vector.

[0053] As a preferred embodiment of the present invention, the anomaly detection algorithm in step (5) adopts an isolation forest or a class of support vector machines to perform real-time analysis on the risk assessment vector and output an anomaly score and a poisoning determination result.

[0054] As a preferred embodiment of the present invention, the specific operation of iterative update optimization in step (6) is:

[0055] (6.1) Adjust model parameters based on test results and optimize feature extraction and anomaly detection modules;

[0056] (6.2) Regularly rebuild the data association graph and update the graph neural network and feature adaptation module;

[0057] (6.3) Adapt to new poisoning attack patterns in real time through online learning mechanism.

[0058] In specific embodiments of the present invention, by combining a multi-layer message-passing mechanism with a graph neural network to extract high-order topological features and introducing a feature-adaptive module to dynamically adjust node feature weights, this method can detect data poisoning attacks with high accuracy and low false positive rates. This method also possesses broad applicability and good real-time performance, and has significant application value in the field of artificial intelligence security. This method, based on graph neural networks and feature-adaptive technology, detects data poisoning attacks on pre-trained models, a technique currently unavailable in the field.

[0059] The pre-training model data poisoning monitoring method of the present invention is as follows:

[0060] The main feature of the pre-trained model data poisoning monitoring method is that the method includes the following steps:

[0061] (1) Preprocess the original training data and model operation logs to be monitored and extract multidimensional feature information;

[0062] (2) Construct a data association graph based on the preprocessed data, where nodes represent data samples and edges represent similarities or dependencies between samples;

[0063] (3) Using graph neural networks to perform multi-layer message passing on data association graphs to extract implicit features of nodes and edges;

[0064] (4) Combined with the feature adaptation module, the extracted node features are weighted and fused to generate a poisoning risk assessment vector;

[0065] (5) Use anomaly detection algorithms to monitor the generated risk assessment vectors in real time to determine whether there is data poisoning behavior;

[0066] (6) Based on anomaly detection, the detection results are fed back to the monitoring system, and the monitoring model is iteratively updated and optimized.

[0067] The pretreatment in step (1) includes the following operations:

[0068] (1.1) Standardize the original training data to eliminate dimensional differences;

[0069] (1.2) Extract statistical, structural, and semantic features of data samples;

[0070] (1.3) Analyze the model operation log to extract the gradient information, loss value and classification confidence during the model training process.

[0071] The specific method for constructing the data association graph in step (2) is:

[0072] (2.1) Calculate the similarity between data samples, using cosine similarity or Euclidean distance as the similarity metric;

[0073] (2.2) Determine the connection relationship between nodes based on the similarity threshold and generate the adjacency matrix of the data association graph;

[0074] (2.3) The adjacency matrix is ​​sparsely processed to retain significant dependencies.

[0075] In step (3), the graph neural network adopts a graph convolutional network (GCN) or a graph attention network (GAT) to aggregate neighbor node information through multi-layer message passing to generate implicit feature representations of nodes and edges.

[0076] The specific implementation of the feature adaptation module in step (4) is as follows:

[0077] (4.1) Use the attention mechanism to calculate the weight of each node feature;

[0078] (4.2) Perform weighted summation on node features to generate global feature representation;

[0079] (4.3) Combine global features with local features to generate a poisoning risk assessment vector.

[0080] In the step (5), the anomaly detection algorithm uses an isolation forest or a one-class support vector machine to perform real-time analysis on the risk assessment vector and output an anomaly score and a poisoning determination result.

[0081] The specific operations of iterative update optimization in step (6) are:

[0082] (6.1) Adjust model parameters based on test results and optimize feature extraction and anomaly detection modules;

[0083] (6.2) Regularly rebuild the data association graph and update the graph neural network and feature adaptation module;

[0084] (6.3) Adapt to new poisoning attack patterns in real time through online learning mechanism.

[0085] The flowchart of the pre-training model data poisoning monitoring method of the present invention is as follows: Figure 1 As shown, in order to more clearly describe the technical content of the present invention, when the pre-trained model is an image classification model (ResNet-50), a further description is given below in conjunction with a specific embodiment:

[0086] (1) Data preprocessing and feature extraction. For the training dataset of the ResNet-50 model (such as CIFAR-10), the image data is first standardized and the pixel values ​​are normalized to the range [0, 1]. Subsequently, the statistical features (such as mean and variance), structural features (such as edge gradients), and semantic features (high-dimensional features extracted by the pre-trained model) of each image are extracted. At the same time, the model training log is parsed to record the gradient distribution, loss value changes, and classification confidence of each round of training to form a multi-dimensional feature matrix.

[0087] (2) Construct a data association graph. Based on the preprocessed feature matrix, calculate the cosine similarity between image samples, set the similarity threshold to 0.7, and generate an adjacency matrix. Sparse the adjacency matrix, retaining only the top 10% of edges with the highest similarity, and construct a data association graph. Each node in the graph represents an image, and the edges represent high-similarity relationships between images.

[0088] (3) Graph Neural Network Feature Extraction. A graph convolutional network (GCN) is used to extract features from the data association graph. The GCN consists of two layers of convolution, with each layer having an output dimension of 256. Through a message passing mechanism, the neighbor information of each node is aggregated to generate a node-level feature representation. Simultaneously, an edge feature enhancement module is used to extract the implicit dependency relationships of edges and output an edge feature matrix.

[0089] (4) Feature Adaptive Fusion. The node features output by the GCN are input into the feature adaptive module, and the weights of each node feature are calculated through the multi-head attention mechanism. The weighted features are globally averaged and pooled to generate a global feature vector. The global features are concatenated with the local node features and mapped into a 128-dimensional poisoning risk assessment vector through a fully connected layer.

[0090] (5) Anomaly detection and poisoning determination. The risk assessment vector is analyzed using the isolation forest algorithm. The anomaly score threshold is set to 0.6, and samples exceeding this threshold are identified as potential poisoning samples. The training data stream is monitored in real time, and anomaly detection results and risk scores are output.

[0091] (6) Feedback and model optimization. Based on the detection results, samples identified as poisoned are isolated and the ResNet-50 model is retrained. At the same time, the detection results are used to optimize the parameters of the GCN and feature adaptation modules to improve the model's adaptability to new poisoning attacks. After each round of training, the data association graph is reconstructed to ensure the real-time performance of the monitoring model.

[0092] (7) Online learning and dynamic updating. Newly collected training data is dynamically added to the monitoring system through the online learning mechanism. The anomaly detection algorithm parameters are regularly updated to adapt to changes in data distribution. Combined with the historical poisoning sample library, the model's ability to identify known attack patterns is enhanced.

[0093] The specific implementation scheme of this embodiment can be found in the relevant descriptions in the above embodiments and will not be repeated here.

[0094] It can be understood that the same or similar parts of the above embodiments can be referenced to each other, and the contents not described in detail in some embodiments can refer to the same or similar contents in other embodiments.

[0095] It should be noted that, in the description of the present invention, the terms "first", "second", etc. are used for descriptive purposes only and should not be understood as indicating or implying relative importance. In addition, in the description of the present invention, unless otherwise specified, the meaning of "plurality" is at least two.

[0096] Any process or method description in a flowchart or otherwise described herein may be understood to represent a module, segment or portion of code comprising one or more executable instructions for implementing the steps of a specific logical function or process, and the scope of the preferred embodiments of the present invention includes alternative implementations in which functions may be performed out of the order shown or discussed, including performing functions in a substantially simultaneous manner or in the reverse order depending on the functions involved, which should be understood by those skilled in the art to which the embodiments of the present invention pertain.

[0097] It should be understood that various parts of the present invention can be implemented using hardware, software, firmware, or a combination thereof. In the above-described embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution device. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.

[0098] Those skilled in the art will understand that all or part of the steps in the method for implementing the above-mentioned embodiment can be completed by instructing related hardware through a program, and the corresponding program can be stored in a computer-readable storage medium. When the program is executed, it includes one of the steps of the method embodiment or a combination thereof.

[0099] Furthermore, the functional units in the various embodiments of the present invention may be integrated into a single processing module, each unit may exist physically separately, or two or more units may be integrated into a single module. The aforementioned integrated modules may be implemented in the form of hardware or software functional modules. If the integrated modules are implemented in the form of software functional modules and sold or used as independent products, they may also be stored in a computer-readable storage medium.

[0100] The storage medium mentioned above can be a read-only memory, a magnetic disk or an optical disk, etc.

[0101] Throughout this specification, reference to terms such as "one embodiment," "some embodiments," "examples," "specific examples," or "some examples" means that a specific feature, structure, material, or characteristic described in conjunction with that embodiment or example is included in at least one embodiment or example of the present invention. In this specification, schematic representations of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in any one or more embodiments or examples.

[0102] The model data poisoning monitoring method of the present invention that integrates graph neural network and feature adaptation is adopted. By constructing a data association graph to capture the dependency relationship between samples from the spatial dimension, and combining the multi-layer message passing mechanism of the graph neural network to extract high-order topological features, the sensitivity of abnormal pattern recognition is significantly improved; the feature adaptation module is introduced to dynamically adjust the node feature weights, which solves the false detection problem caused by the fixed feature importance of traditional methods; the model parameters are continuously optimized through the online learning mechanism, so that the system can adapt to the evolution of new poisoning attacks. This method innovatively combines graph structure with feature adaptation, which not only provides a reliable active defense solution for image classification pre-training models, but its modular design can also be extended to scenarios such as natural language processing and recommendation systems. It has significant application value in the fields of AI model security auditing, data quality monitoring, and intelligent system protection, and is expected to become a core technology to ensure the safe deployment of AI systems in key areas.

[0103] In this specification, the present invention has been described with reference to specific embodiments thereof. However, it will be apparent that various modifications and variations may be made without departing from the spirit and scope of the present invention. Accordingly, the specification and drawings are to be regarded as illustrative rather than restrictive.

Claims

1. A data poisoning monitoring method that integrates graph neural networks and feature adaptive pre-training models, characterized by: The method comprises the following steps: (1) Preprocess the original training data and model operation logs to be monitored and extract multidimensional feature information; (2) Construct a data association graph based on the preprocessed data, where nodes represent data samples and edges represent similarities or dependencies between samples; (3) Using graph neural networks to perform multi-layer message passing on data association graphs to extract implicit features of nodes and edges; (4) Combined with the feature adaptation module, the extracted node features are weighted and fused to generate a poisoning risk assessment vector; (5) Use anomaly detection algorithms to monitor the generated risk assessment vectors in real time to determine whether there is data poisoning behavior; (6) Based on anomaly detection, the detection results are fed back to the monitoring system, and the monitoring model is iteratively updated and optimized.

2. The data poisoning monitoring method of the pre-trained model integrating graph neural network and feature adaptation according to claim 1 is characterized in that: The pretreatment in step (1) includes the following operations: (1.1) Standardize the original training data to eliminate dimensional differences; (1.2) Extract statistical, structural, and semantic features of data samples; (1.3) Analyze the model operation log to extract the gradient information, loss value and classification confidence during the model training process.

3. The data poisoning monitoring method of the pre-trained model integrating graph neural network and feature adaptation according to claim 1 is characterized in that: The specific method for constructing the data association graph in step (2) is: (2.1) Calculate the similarity between data samples, using cosine similarity or Euclidean distance as the similarity metric; (2.2) Determine the connection relationship between nodes based on the similarity threshold and generate the adjacency matrix of the data association graph; (2.3) The adjacency matrix is ​​sparsely processed to preserve the dependency relationship.

4. The data poisoning monitoring method of the pre-trained model integrating graph neural network and feature adaptation according to claim 1 is characterized in that: In step (3), the graph neural network adopts a graph convolutional network or a graph attention network to aggregate neighbor node information through multi-layer message passing to generate implicit feature representations of nodes and edges.

5. The data poisoning monitoring method of the pre-trained model integrating graph neural network and feature adaptation according to claim 1 is characterized in that: The specific implementation of the feature adaptation module in step (4) is as follows: (4.1) Use the attention mechanism to calculate the weight of each node feature; (4.2) Perform weighted summation on node features to generate global feature representation; (4.3) Combine global features with local features to generate a poisoning risk assessment vector.

6. The data poisoning monitoring method of the pre-trained model integrating graph neural network and feature adaptation according to claim 1 is characterized in that: In the step (5), the anomaly detection algorithm uses an isolation forest or a class of support vector machines to perform real-time analysis on the risk assessment vector and output an anomaly score and a poisoning determination result.

7. The data poisoning monitoring method of the pre-trained model integrating graph neural network and feature adaptation according to claim 1 is characterized in that: The specific operations of iterative update optimization in step (6) are: (6.1) Adjust model parameters based on test results and optimize feature extraction and anomaly detection modules; (6.2) Regularly rebuild the data association graph and update the graph neural network and feature adaptation module; (6.3) Adapt to new poisoning attack patterns in real time through online learning mechanism.