Model training method, device, equipment and product
By using random number encryption and decryption verification mechanisms in federated learning, the problem of collaborative parties being vulnerable to malicious attacks is solved, and the accuracy and data security of the intrusion detection model are improved.
Patent Information
- Application Number
- CN202510799316.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-16
- Publication Date
- 2025-08-22
AI Technical Summary
When training the intrusion detection model through federated learning, the collaborative parties are susceptible to attacks from malicious clients, which makes the processing data obtained by the collaborative parties incorrect, resulting in deviations in the construction of the final intrusion detection model and reducing the accuracy of the model.
By obtaining encrypted data and encryption parameters, decrypting using the private key of the first device, and when the decrypted data is verified, the models of each collaborative party are aggregated, and the model is encrypted using random numbers to increase the difficulty of attack and improve data security.
The accuracy of the intrusion detection model is improved, and the security of data aggregation of collaborative parties is enhanced through the random number encryption and decryption verification mechanism, and the impact of malicious attacks is prevented.
Smart Images

Figure CN120528677A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technology, and in particular to a model training method, device, equipment and product. Background Art
[0002] In recent years, with the widespread adoption of big data, the internet has become an indispensable tool for everyone. The explosive growth in the number of internet users has also led to an exponential increase in network traffic, but this has also led to increasingly severe network security issues. As a crucial component of network security, network intrusion detection systems have long been a hot topic of research in the field. Currently, intrusion detection of data traffic is achieved by generating an intrusion detection network model. First, data traffic is collected, and features are extracted from the traffic samples to train the intrusion detection network model. The trained intrusion detection network model is then used to identify data traffic and determine whether it represents attacking behavior. Federated learning can be used to train intrusion detection models. Participants in this process do not need to exchange original data; instead, they exchange only a small amount of intermediate computational results, all encrypted, to train a global intrusion detection model based on virtual fused data.
[0003] Currently, when training intrusion detection models through federated learning, although the user (initiator) of the calculated intrusion detection model cannot access the original data of other participants (collaborators), thus ensuring data security, the collaborators themselves are vulnerable to attacks from malicious clients, resulting in erroneous processed data, which in turn leads to deviations in the final intrusion detection model construction and reduces the accuracy of the intrusion detection model. Summary of the Invention
[0004] The purpose of the present invention is to provide a model training method, device, equipment and product, which are used to solve the problem in the prior art that when training an intrusion detection model through federated learning, the collaborating party itself is vulnerable to attacks by malicious clients, resulting in erroneous processing data obtained by the collaborating party, which in turn leads to deviations in the construction of the final intrusion detection model and reduces the accuracy of the intrusion detection model.
[0005] To achieve the above objectives, an embodiment of the present invention provides a model training method, wherein the method is performed by a first device and includes:
[0006] Obtaining encrypted data sent by at least one second device for encrypting a first model, and obtaining a first encryption parameter for encrypting a random number using a public key of the first device; wherein the first model is obtained after the corresponding second device collects data traffic for intrusion detection training, and the first key used to encrypt the first model is generated based on the random number;
[0007] Decrypting the first encryption parameter using the private key of the first device to obtain the random number, decrypting the encrypted data to obtain decrypted data of the encrypted data;
[0008] If the decrypted data is verified to be successful, obtaining a first model corresponding to the second device according to the decrypted data;
[0009] An aggregation operation is performed on the first model corresponding to each of the second devices to obtain a second model for intrusion detection.
[0010] Optionally, in the method, the encrypted data includes one or more of the following:
[0011] first encrypted data obtained by encrypting the first model using the first key;
[0012] Second encrypted data obtained by encrypting the digest of the first model using a second key, wherein the second key is generated based on the model information of the first model;
[0013] The third encrypted data is obtained by encrypting the model information using the private key of the first device.
[0014] Optionally, the method, wherein the model information includes the completion time of the second device acquiring the first model and the data volume of the first model.
[0015] Optionally, the method further includes:
[0016] Decrypting the third encrypted data using the private key of the first device to obtain the model information;
[0017] Decrypting the first encryption parameter using the private key of the first device to obtain the random number and the model information, thereby obtaining the first key;
[0018] The second key is obtained according to the model information.
[0019] Optionally, the method further includes:
[0020] Obtaining a first decryption model for decrypting the first encrypted data using the first key, and obtaining a second decryption model for decrypting the second encrypted data using the second key;
[0021] The digest of the first decryption model is matched with the second decryption model. If the match is successful, it is determined that the decrypted data verification is passed and the first decryption model is the first model.
[0022] Optionally, the method, wherein obtaining the first key by using the random number and the model information obtained after decrypting the first encryption parameter according to the private key of the first device, includes:
[0023] Obtaining a first hash value according to the random number, the model information, and the initiation time; wherein the initiation time is the time when the first device initiates the intrusion detection training task to the second device;
[0024] Obtain a second Hash value according to the random number;
[0025] The first key is obtained according to an exclusive OR operation of the first hash value and the second hash value.
[0026] Optionally, the method, wherein obtaining the second key according to the model information, includes:
[0027] Obtaining a third hash value according to the model information;
[0028] The third hash value is used as the second key.
[0029] To achieve the above-mentioned object, an embodiment of the present invention further provides a model training method, which is executed by a second device and includes:
[0030] Perform intrusion detection training based on the collected data traffic to obtain a first model;
[0031] Encrypting the first model using a first key generated according to a random number to obtain encrypted data corresponding to the first model;
[0032] The first encryption parameter and the encrypted data are sent to the first device, so that the first device obtains the first model according to the first encryption parameter and the encrypted data; wherein the first encryption parameter is obtained by encrypting a random number using the public key of the first device.
[0033] Optionally, the method, wherein encrypting the model using a first key generated according to a random number to obtain encrypted data corresponding to the first model, includes:
[0034] Encrypting the first model using the first key to obtain first encrypted data;
[0035] Encrypting the digest of the first model using a second key to obtain second encrypted data; wherein the second key is generated based on the model information of the first model;
[0036] The model information is encrypted using the private key of the first device to obtain third encrypted data.
[0037] Optionally, the method, wherein the model information includes the completion time of the second device acquiring the first model and the data volume of the first model.
[0038] Optionally, the method further includes:
[0039] Obtain a first hash value according to the random number, model information, and initiation time; wherein the initiation time is the time when the first device initiates the intrusion detection training task to the second device;
[0040] Obtain a second Hash value according to the random number;
[0041] The first key is obtained according to an exclusive OR operation of the first hash value and the second hash value.
[0042] Optionally, the method further includes:
[0043] Obtaining a third hash value according to the model information;
[0044] The third hash value is used as the second key.
[0045] In order to achieve the above-mentioned object, an embodiment of the present invention further provides a model training apparatus, which is executed by a first device and includes:
[0046] a first acquisition module, configured to obtain encrypted data sent by at least one second device for encrypting a first model, and to obtain a first encryption parameter for encrypting a random number using a public key of the first device; wherein the first model is obtained by collecting data traffic from the corresponding second device for intrusion detection training, and the first key used for encrypting the first model is generated based on the random number;
[0047] a first processing module, configured to decrypt the encrypted data using the private key of the first device to obtain the random number obtained after decrypting the first encryption parameter, thereby obtaining decrypted data of the encrypted data;
[0048] a second processing module, configured to obtain a first model corresponding to the second device according to the decrypted data if the decrypted data is verified to be successful;
[0049] The third processing module is used to aggregate the first models corresponding to each of the second devices to obtain a second model for intrusion detection.
[0050] In order to achieve the above-mentioned object, an embodiment of the present invention further provides a model training apparatus, which is executed by a second device and includes:
[0051] A fourth processing module is used to perform intrusion detection training based on the collected data traffic to obtain a first model;
[0052] a fifth processing module, configured to encrypt the first model using a first key generated according to a random number to obtain encrypted data corresponding to the first model;
[0053] A first sending module is used to send a first encryption parameter and the encrypted data to a first device, so that the first device obtains the first model based on the first encryption parameter and the encrypted data; wherein the first encryption parameter is obtained by encrypting a random number using the public key of the first device.
[0054] In order to achieve the above-mentioned purpose, an embodiment of the present invention also provides a model training device, including: a transceiver, a processor, a memory, and a program or instruction stored on the memory and runnable on the processor; wherein, when the processor executes the program or instruction, the model training method as described above is implemented, as well as the model training method as described above.
[0055] In order to achieve the above-mentioned purpose, an embodiment of the present invention also provides a readable storage medium on which a program or instruction is stored, wherein when the program or instruction is executed by a processor, the steps in the model training method as described above, and the steps in the model training method as described above are implemented.
[0056] In order to achieve the above-mentioned purpose, an embodiment of the present invention also provides a computer program product, which includes computer instructions, and when the computer instructions are executed by a processor, implements the steps in the model training method described above, as well as the steps in the model training method described above.
[0057] In an embodiment of the present invention, encrypted data of a first model obtained after intrusion detection training using data traffic collected by the second device is obtained, which is sent by at least one second device, as well as a first encryption parameter for encrypting a random number using the public key of the first device, the encrypted data and the first encryption parameter are decrypted, and the first model is obtained when the decrypted data is verified to be successful, and the first model corresponding to each second device is aggregated to obtain a second model for intrusion detection. By encrypting the first model with a random number, each training task of the intrusion detection model has a different key, which increases the difficulty of attack, and verifies the decrypted data, thereby improving the security of the collaborative party's data aggregation. This solves the problem in the prior art that when training an intrusion detection model through federated learning, the collaborative party itself is vulnerable to attacks by malicious clients, resulting in erroneous processed data obtained by the collaborative party, which in turn leads to deviations in the construction of the final intrusion detection model and reduces the accuracy of the intrusion detection model. BRIEF DESCRIPTION OF THE DRAWINGS
[0058] Figure 1 A schematic diagram of a model training method performed by a first device according to an embodiment of the present invention;
[0059] Figure 2 This is a flow chart of the model training method according to an embodiment of the present invention;
[0060] Figure 3 A schematic diagram of a model training method performed by a second device according to an embodiment of the present invention;
[0061] Figure 4 A schematic diagram of a model training apparatus executed by a first device according to an embodiment of the present invention;
[0062] Figure 5 This is a schematic diagram of a model training apparatus executed by a second device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0063] In order to make the technical problems, technical solutions and advantages to be solved by the present invention clearer, a detailed description will be given below with reference to the accompanying drawings and specific embodiments.
[0064] It should be understood that references throughout this specification to "one embodiment" or "an embodiment" mean that a particular feature, structure, or characteristic associated with the embodiment is included in at least one embodiment of the present invention. Therefore, the appearances of "in one embodiment" or "in an embodiment" throughout this specification do not necessarily refer to the same embodiment. Furthermore, these particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0065] In various embodiments of the present invention, it should be understood that the size of the serial numbers of the following processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0066] Additionally, the terms "system" and "network" are often used interchangeably herein.
[0067] In the embodiments provided herein, it should be understood that "B corresponding to A" means that B is associated with A and B can be determined based on A. However, it should also be understood that determining B based on A does not mean determining B based solely on A; B can also be determined based on A and / or other information.
[0068] For ease of understanding, some contents involved in the embodiments of the present invention are described below:
[0069] like Figure 1 As shown, a model training method according to an embodiment of the present invention is performed by a first device and includes:
[0070] S10: Obtaining encrypted data for encrypting a first model sent by at least one second device, and obtaining a first encryption parameter for encrypting a random number using a public key of the first device; wherein the first model is obtained after the corresponding second device collects data traffic for intrusion detection training, and the first key used to encrypt the first model is generated based on the random number;
[0071] It should be noted that if Figure 2 As shown, the present invention provides an example, the first device is the initiator of the intrusion detection model training task, the second device is the collaborator of the intrusion detection model training task, usually, there are multiple collaborators who each complete the intrusion detection model training task and send the obtained first model to the initiator. Figure 2 In step 1, each collaborator trains the intrusion detection model based on its own stored data and obtains the corresponding training results, i.e., the first model. The following description is made by taking the i-th collaborator among multiple collaborators as an example. In step 2, each collaborator generates a random number and obtains a key for the intrusion detection model training task based on the random number, i.e., the first key used to encrypt the first model is generated based on the random number. Among them, the first encryption parameter collaborator (i.e., the second device) uses the public key of the initiator (i.e., the first device) to encrypt the random number x. i The encrypted data is obtained and sent to the initiator. In step 3, each collaborator encrypts the calculation result obtained in step 1 using the key for the intrusion detection model training task obtained in step 2 to obtain the encrypted data (i.e., the encrypted data). In step 4, each collaborator sends its final encrypted data to the initiator, i.e., obtains the encrypted data of the first model sent by at least one second device.
[0072] S20, decrypting the first encryption parameter using the private key of the first device to obtain the random number, decrypting the encrypted data to obtain decrypted data of the encrypted data;
[0073] It should be noted that the encrypted x received previously is encrypted using the private key of the first device. i (i.e. the first encryption parameter) is decrypted to obtain the random number x i Since the sending time of the first encryption parameter and the obtaining time of the encrypted data are different and the time is irregular, the time required to obtain the random number x at the same time is reduced. i The possibility of encrypting the data avoids the leakage of calculated data caused by obtaining two data at the same time.
[0074] S30, if the decrypted data is verified to be successful, obtaining a first model corresponding to the second device according to the decrypted data;
[0075] It should be noted that if Figure 2 As shown, in step 5, the initiator decrypts the encrypted data of all federated learning collaborators using its private key to obtain the training result (i.e., the first model). During the decryption of the encrypted data, the same parameters obtained in different ways are compared and verified to confirm the security of the first model.
[0076] S40, performing an aggregation operation on the first model corresponding to each of the second devices to obtain a second model for intrusion detection;
[0077] It should be noted that if Figure 2 As shown, in step 6, after obtaining the normal training results of all coordinators, the initiator performs a weighted aggregation operation on the normal training results of all coordinators to obtain a global model, which is the trained intrusion detection model (ie, the second model).
[0078] In this embodiment, the encrypted data of the first model obtained after the second device collects data traffic for intrusion detection training and the first encryption parameter encrypted with the public key of the first device are obtained, the encrypted data and the first encryption parameter are decrypted, and the first model is obtained when the decrypted data is verified to be successful, and the first model corresponding to each second device is aggregated to obtain the second model for intrusion detection. The first model is encrypted by the random number, so that each training task of the intrusion detection model has a different key, which increases the difficulty of attack, and the decrypted data is verified to improve the security of the collaborative party when aggregating data. This solves the problem in the prior art that when the intrusion detection model is trained through federated learning, the collaborative party itself is vulnerable to attacks by malicious clients, resulting in erroneous processed data obtained by the collaborative party, which in turn leads to deviations in the construction of the final intrusion detection model and reduces the accuracy of the intrusion detection model.
[0079] Optionally, in the method, the encrypted data includes one or more of the following:
[0080] first encrypted data obtained by encrypting the first model using the first key;
[0081] Second encrypted data obtained by encrypting the digest of the first model using a second key, wherein the second key is generated based on the model information of the first model;
[0082] The third encrypted data is obtained by encrypting the model information using the private key of the first device.
[0083] In this embodiment, the random number x is used i The first key obtained is used to symmetrically encrypt the data composed of the first model to obtain the first encrypted data DM i (1) Using the second key generated according to the model information of the first model, encrypt the summary of the first model to obtain the second encrypted data DM i (2) Using the private key of the first device to calculate the completion time t of the first model in the model information i And the data volume n of the first model i The data composed of the above mentioned data is encrypted to obtain the third encrypted data DM i (3).
[0084] Optionally, the method, wherein the model information includes the completion time of the second device acquiring the first model and the data volume of the first model.
[0085] In this embodiment, the model information includes the completion time t of the second device acquiring the first model. i And the data volume n of the first model i .
[0086] Optionally, the method further includes:
[0087] Decrypting the third encrypted data using the private key of the first device to obtain the model information;
[0088] Decrypting the first encryption parameter using the private key of the first device to obtain the random number and the model information, thereby obtaining the first key;
[0089] The second key is obtained according to the model information.
[0090] In this embodiment, the third encrypted data DM is encrypted using the private key of the first device. i (3) Decrypt and obtain the model information t of the i-th collaborative party (the second device) i and n i The random number x obtained by decrypting the first encryption parameter using the private key of the first device i , and the completion time t of the first model in the model information i And the data volume n of the first model i , forming the first key. According to the data volume n of the first model in the model information i, obtain the second key.
[0091] Optionally, the method further includes:
[0092] Obtaining a first decryption model for decrypting the first encrypted data using the first key, and obtaining a second decryption model for decrypting the second encrypted data using the second key;
[0093] The digest of the first decryption model is matched with the second decryption model. If the match is successful, it is determined that the decrypted data verification is passed and the first decryption model is the first model.
[0094] In this embodiment, the first key is used to encrypt the first encrypted data DM i (1) Decryption is performed to obtain the first decryption model M i , using the second key to encrypt the second data DM i (2) Decryption is performed to obtain the second decryption model (i.e., M i Generate the first decryption model M i The digest generation scheme can be implemented by using an existing digest generation algorithm, such as using the MD5 algorithm to generate a digest. The MD5 algorithm processes the input information in 512-bit groups (such as M i ), and each group is divided into 16 32-bit sub-groups. After a series of processing, the output of the algorithm consists of four 32-bit groups. These four 32-bit groups are concatenated to generate a 128-bit hash value. The digest of the first decryption model is matched with the second decryption model. If the match is successful, it is determined that the decrypted data has passed the verification and the first decryption model is the first model. i The training result (i.e., the first model) is compared with the summary to confirm whether they are the same. If they are not the same, the training result (i.e., the first model) is abnormal, an early warning is issued, and the reception and use of the training result (i.e., the first model) is rejected. If they are the same, the training result (i.e., the first model) is normal and the training result (i.e., the first model) is stored.
[0095] Optionally, the method, wherein obtaining the first key by using the random number and the model information obtained after decrypting the first encryption parameter according to the private key of the first device, includes:
[0096] Obtaining a first hash value according to the random number, the model information, and the initiation time; wherein the initiation time is the time when the first device initiates the intrusion detection training task to the second device;
[0097] Obtain a second Hash value according to the random number;
[0098] The first key is obtained according to an exclusive OR operation of the first hash value and the second hash value.
[0099] In this embodiment, the first hash value is The second hash value is the random number x i The first key is obtained by performing an exclusive OR operation on the first hash value and the second hash value. i is the completion time of the first model in the model information, t0 is the initiation time, n i is the data volume of the first model in the model information.
[0100] Optionally, the method, wherein obtaining the second key according to the model information, includes:
[0101] Obtaining a third hash value according to the model information;
[0102] The third hash value is used as the second key.
[0103] In this embodiment, the third hash value is the data amount n of the first model in the model information. i The hash value is used as the second key.
[0104] like Figure 3 As shown, in order to achieve the above-mentioned purpose, an embodiment of the present invention further provides a model training method, which is executed by a second device and includes:
[0105] A10, performs intrusion detection training based on the collected data traffic to obtain a first model;
[0106] It should be noted that if Figure 2 As shown, in step 1, each collaborator trains an intrusion detection model based on its own stored data to obtain a corresponding training result, namely the first model.
[0107] A20: Encrypt the first model using a first key generated according to a random number to obtain encrypted data corresponding to the first model;
[0108] It should be noted that if Figure 2 As shown, in step 2, each collaborating party generates a random number and, based on the random number, obtains a key for this intrusion detection model training task. That is, the first key used to encrypt the first model is generated based on the random number. In step 3, each collaborating party encrypts the calculation result obtained in step 1 using the key for this intrusion detection model training task obtained in step 2 to obtain encrypted data (i.e., the encrypted data).
[0109] A30: Sending a first encryption parameter and the encrypted data to a first device, so that the first device obtains the first model based on the first encryption parameter and the encrypted data; wherein the first encryption parameter is obtained by encrypting a random number using a public key of the first device;
[0110] It should be noted that if Figure 2 As shown, in step 4, each collaborative party sends its final encrypted data to the initiator (i.e., the first device), that is, obtains the encrypted data sent by at least one second device to encrypt the first model. Usually, before sending the encrypted data, the first encryption parameter is sent to the initiator (i.e., the first device). Since the sending time of the first encryption parameter and the acquisition time of the encrypted data are different and the time is irregular, the simultaneous acquisition of x is reduced. i The possibility of encrypting data avoids the leakage of calculated data caused by obtaining two data at the same time.
[0111] Optionally, in the method, step A20 includes:
[0112] Encrypting the first model using the first key to obtain first encrypted data;
[0113] Encrypting the digest of the first model using a second key to obtain second encrypted data; wherein the second key is generated based on the model information of the first model;
[0114] The model information is encrypted using the private key of the first device to obtain the third encrypted data.
[0115] In this embodiment, the random number x is used i The first key obtained is used to symmetrically encrypt the data composed of the first model to obtain the first encrypted data DM i (1) Using the second key generated according to the model information of the first model, encrypt the summary of the first model to obtain the second encrypted data DM i (2) Using the private key of the first device to calculate the completion time t of the first model in the model information i And the data volume n of the first model i The data composed of the above mentioned data is encrypted to obtain the third encrypted data DM i (3).
[0116] Optionally, the method, wherein the model information includes the completion time of the second device acquiring the first model and the data volume of the first model.
[0117] In this embodiment, the model information includes the completion time t of the second device acquiring the first model. i And the data volume n of the first model i .
[0118] Optionally, the method further includes:
[0119] Obtaining a first hash value according to the random number, the model information, and the initiation time; wherein the initiation time is the time when the first device initiates the intrusion detection training task to the second device;
[0120] Obtain a second Hash value according to the random number;
[0121] The first key is obtained according to an exclusive OR operation of the first hash value and the second hash value.
[0122] In this embodiment, the first hash value is The second hash value is the random number x i The first key is obtained by performing an exclusive OR operation on the first hash value and the second hash value. i is the completion time of the first model in the model information, t0 is the initiation time, n i is the data volume of the first model in the model information.
[0123] Optionally, the method further includes:
[0124] Obtaining a third hash value according to the model information;
[0125] The third hash value is used as the second key.
[0126] In this embodiment, the third hash value is the data amount n of the first model in the model information. i The hash value is used as the second key.
[0127] like Figure 4 As shown, in order to achieve the above-mentioned purpose, an embodiment of the present invention further provides a model training device, which is executed by a first device and includes:
[0128] A first acquisition module 401 is configured to obtain encrypted data sent by at least one second device for encrypting a first model, and to obtain a first encryption parameter for encrypting a random number using a public key of the first device; wherein the first model is obtained by collecting data traffic from the corresponding second device for intrusion detection training, and the first key used to encrypt the first model is generated based on the random number;
[0129] A first processing module 402 is configured to decrypt the encrypted data using the private key of the first device to obtain the random number obtained after decrypting the first encryption parameter, thereby obtaining decrypted data of the encrypted data;
[0130] The second processing module 403 is configured to obtain a first model corresponding to the second device according to the decrypted data if the decrypted data is verified to be successful;
[0131] The third processing module 404 is configured to aggregate the first models corresponding to each of the second devices to obtain a second model for intrusion detection.
[0132] Optionally, in the device, the encrypted data includes one or more of the following:
[0133] first encrypted data obtained by encrypting the first model using the first key;
[0134] Second encrypted data obtained by encrypting the digest of the first model using a second key, wherein the second key is generated based on the model information of the first model;
[0135] The third encrypted data is obtained by encrypting the model information using the private key of the first device.
[0136] Optionally, in the apparatus, the model information includes the completion time of the second device acquiring the first model and the amount of data of the first model.
[0137] Optionally, the device further comprises:
[0138] a second acquisition module, configured to decrypt the third encrypted data using the private key of the first device to obtain the model information;
[0139] A sixth processing module, configured to obtain the first key by decrypting the first encryption parameter using the private key of the first device and the random number and the model information obtained;
[0140] A seventh processing module is used to obtain the second key according to the model information.
[0141] Optionally, the device further comprises:
[0142] a third acquisition module, configured to acquire a first decryption model for decrypting the first encrypted data using the first key, and to acquire a second decryption model for decrypting the second encrypted data using the second key;
[0143] The first determination module is configured to match the digest of the first decryption model with the second decryption model, and if the match succeeds, determine that the decrypted data verification has passed and the first decryption model is the first model.
[0144] Optionally, in the device, the sixth processing module includes:
[0145] A first acquiring unit, configured to acquire a first hash value according to the random number, the model information, and an initiation time; wherein the initiation time is the time when the first device initiates the intrusion detection training task to the second device;
[0146] A second acquiring unit, configured to acquire a second Hash value according to the random number;
[0147] A third obtaining unit is configured to obtain the first key according to an exclusive OR operation of the first hash value and the second hash value.
[0148] Optionally, in the device, the seventh processing module includes:
[0149] a fourth acquiring unit, configured to acquire a third hash value according to the model information;
[0150] The first processing unit is configured to use the third hash value as the second key.
[0151] like Figure 5 As shown, in order to achieve the above-mentioned purpose, an embodiment of the present invention further provides a model training device, which is executed by a second device and includes:
[0152] The fourth processing module 501 is used to perform intrusion detection training based on the collected data traffic to obtain a first model;
[0153] A fifth processing module 502 is configured to encrypt the first model using a first key generated according to a random number to obtain encrypted data corresponding to the first model;
[0154] The first sending module 503 is used to send the first encryption parameter and the encrypted data to the first device, so that the first device obtains the first model based on the first encryption parameter and the encrypted data; wherein the first encryption parameter is obtained by encrypting a random number using the public key of the first device.
[0155] Optionally, in the device, the fifth processing module 502 includes:
[0156] a fifth acquiring unit, configured to encrypt the first model using the first key to acquire first encrypted data;
[0157] a sixth obtaining unit, configured to encrypt the digest of the first model using a second key to obtain second encrypted data; wherein the second key is generated according to model information of the first model;
[0158] A seventh acquiring unit is configured to encrypt the model information using the private key of the first device to acquire third encrypted data.
[0159] Optionally, in the apparatus, the model information includes the completion time of the second device acquiring the first model and the amount of data of the first model.
[0160] Optionally, the device further comprises:
[0161] a fourth acquisition module, configured to acquire a first hash value according to the random number, the model information, and an initiation time; wherein the initiation time is the time when the first device initiates the intrusion detection training task to the second device;
[0162] A fifth acquisition module, configured to acquire a second Hash value according to the random number;
[0163] A sixth acquisition module is configured to acquire the first key according to an exclusive OR operation of the first hash value and the second hash value.
[0164] Optionally, the device further comprises:
[0165] a seventh acquisition module, configured to acquire a third hash value according to the model information;
[0166] An eighth processing module is configured to use the third hash value as a second key.
[0167] In order to achieve the above-mentioned purpose, an embodiment of the present invention also provides a model training device, including: a transceiver, a processor, a memory, and a program or instruction stored on the memory and runnable on the processor; wherein, when the processor executes the program or instruction, the model training method as described above is implemented, as well as the model training method as described above.
[0168] In order to achieve the above-mentioned purpose, an embodiment of the present invention also provides a readable storage medium on which a program or instruction is stored, wherein when the program or instruction is executed by a processor, the steps in the model training method as described above, and the steps in the model training method as described above are implemented.
[0169] In order to achieve the above-mentioned purpose, an embodiment of the present invention also provides a computer program product, which includes computer instructions, and when the computer instructions are executed by a processor, implements the steps in the model training method described above, as well as the steps in the model training method described above.
[0170] It should be further noted that the terminals described in this specification include but are not limited to smartphones, tablet computers, etc., and many functional components described are referred to as modules in order to more particularly emphasize the independence of their implementation methods.
[0171] In embodiments of the present invention, modules can be implemented in software so that they can be executed by various types of processors. For example, an identified executable code module can include one or more physical or logical blocks of computer instructions, for example, which can be constructed as objects, procedures, or functions. Nevertheless, the executable code of the identified module does not need to be physically located together, but can include different instructions stored in different locations, which, when logically combined together, constitute the module and achieve the specified purpose of the module.
[0172] In fact, executable code module can be a single instruction or many instructions, and can even be distributed on a plurality of different code segments, distributed in the middle of different programs, and distributed across a plurality of memory devices.Similarly, operating data can be identified in the module, and can be implemented and organized in the data structure of any appropriate type according to any appropriate form.Described operating data can be collected as a single data set, or can be distributed in different locations (including on different storage devices), and can only be present on a system or network as an electronic signal at least in part.
[0173] When a module can be implemented using software, given the current state of hardware technology, those skilled in the art can build corresponding hardware circuits to implement the corresponding functions of the module, regardless of cost. The hardware circuits may include conventional very large scale integration (VLSI) circuits or gate arrays, as well as existing semiconductors such as logic chips and transistors, or other discrete components. Modules may also be implemented using programmable hardware devices, such as field programmable gate arrays, programmable array logic, or programmable logic devices.
[0174] The above exemplary embodiments are described with reference to the accompanying drawings. Many different forms and embodiments are possible without departing from the spirit and teachings of the present invention. Therefore, the present invention should not be construed as limited to the exemplary embodiments set forth herein. Rather, these exemplary embodiments are provided so that this disclosure will be complete and perfect and will convey the scope of the invention to those skilled in the art. In the drawings, component sizes and relative sizes may be exaggerated for clarity. The terminology used herein is for purposes of describing specific exemplary embodiments only and is not intended to be limiting. As used herein, the singular forms "a," "an," and "the" are intended to include plural forms, unless the context clearly indicates otherwise. It will be further understood that the terms "comprising" and / or "including," when used in this specification, indicate the presence of stated features, integers, steps, operations, components, and / or elements, but do not preclude the presence or addition of one or more other features, integers, steps, operations, components, elements, and / or groups thereof. Unless otherwise indicated, when stated, a range of values includes the upper and lower limits of that range and any subranges therebetween.
[0175] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the principles of the present invention. These improvements and modifications should also be regarded as within the scope of protection of the present invention.
Claims
1. A model training method, characterized in that: Executed by a first device, the method includes: Obtaining encrypted data sent by at least one second device for encrypting a first model, and obtaining a first encryption parameter for encrypting a random number using a public key of the first device; wherein the first model is obtained after the corresponding second device collects data traffic for intrusion detection training, and the first key used to encrypt the first model is generated based on the random number; Decrypting the first encryption parameter using the private key of the first device to obtain the random number, decrypting the encrypted data to obtain decrypted data of the encrypted data; If the decrypted data is verified to be successful, obtaining a first model corresponding to the second device according to the decrypted data; An aggregation operation is performed on the first model corresponding to each of the second devices to obtain a second model for intrusion detection.
2. The method according to claim 1, characterized in that The encrypted data includes one or more of the following: first encrypted data obtained by encrypting the first model using the first key; Second encrypted data obtained by encrypting the digest of the first model using a second key, wherein the second key is generated based on the model information of the first model; The third encrypted data is obtained by encrypting the model information using the private key of the first device.
3. The method according to claim 2, characterized in that The model information includes the completion time when the second device obtains the first model and the data volume of the first model.
4. The method according to claim 2, characterized in that The method further comprises: Decrypting the third encrypted data using the private key of the first device to obtain the model information; Decrypting the first encryption parameter using the private key of the first device to obtain the random number and the model information, thereby obtaining the first key; The second key is obtained according to the model information.
5. The method according to claim 2 or 4, characterized in that The method further comprises: Obtaining a first decryption model for decrypting the first encrypted data using the first key, and obtaining a second decryption model for decrypting the second encrypted data using the second key; The digest of the first decryption model is matched with the second decryption model. If the match is successful, it is determined that the decrypted data verification is passed and the first decryption model is the first model.
6. The method according to claim 4, characterized in that Obtaining the first key by decrypting the first encryption parameter using the private key of the first device and obtaining the random number and the model information includes: Obtaining a first hash value according to the random number, the model information, and the initiation time; wherein the initiation time is the time when the first device initiates the intrusion detection training task to the second device; Obtain a second Hash value according to the random number; The first key is obtained according to an exclusive OR operation of the first hash value and the second hash value.
7. The method according to claim 4, characterized in that Obtaining the second key according to the model information includes: Obtaining a third hash value according to the model information; The third hash value is used as the second key.
8. A model training method, characterized in that: Executed by the second device, including: Perform intrusion detection training based on the collected data traffic to obtain a first model; Encrypting the first model using a first key generated according to a random number to obtain encrypted data corresponding to the first model; The first encryption parameter and the encrypted data are sent to the first device, so that the first device obtains the first model according to the first encryption parameter and the encrypted data; wherein the first encryption parameter is obtained by encrypting a random number using the public key of the first device.
9. The method according to claim 8, characterized in that Encrypting the first model using a first key generated according to a random number to obtain encrypted data corresponding to the first model includes: Encrypting the first model using the first key to obtain first encrypted data; Encrypting the digest of the first model using a second key to obtain second encrypted data; wherein the second key is generated based on the model information of the first model; The model information is encrypted using the private key of the first device to obtain third encrypted data.
10. The method according to claim 9, characterized in that The model information includes the completion time when the second device obtains the first model and the data volume of the first model.
11. The method according to claim 8 or 9, characterized in that The method further comprises: Obtain a first hash value according to the random number, model information, and initiation time; wherein the initiation time is the time when the first device initiates the intrusion detection training task to the second device; Obtain a second Hash value according to the random number; The first key is obtained according to an exclusive OR operation of the first hash value and the second hash value.
12. The method according to claim 8 or 9, characterized in that The method further comprises: Obtain a third hash value according to the model information; The third hash value is used as the second key.
13. A model training device, characterized in that: Executed by a first device, the apparatus includes: a first acquisition module, configured to obtain encrypted data sent by at least one second device for encrypting a first model, and to obtain a first encryption parameter for encrypting a random number using a public key of the first device; wherein the first model is obtained by collecting data traffic from the corresponding second device for intrusion detection training, and the first key used for encrypting the first model is generated based on the random number; a first processing module, configured to decrypt the encrypted data using the private key of the first device to obtain the random number obtained after decrypting the first encryption parameter, thereby obtaining decrypted data of the encrypted data; a second processing module, configured to obtain a first model corresponding to the second device according to the decrypted data if the decrypted data is verified to be successful; The third processing module is used to aggregate the first models corresponding to each of the second devices to obtain a second model for intrusion detection.
14. A model training device, characterized in that: Executed by the second device, including: A fourth processing module is used to perform intrusion detection training based on the collected data traffic to obtain a first model; a fifth processing module, configured to encrypt the first model using a first key generated according to a random number to obtain encrypted data corresponding to the first model; A first sending module is used to send a first encryption parameter and the encrypted data to a first device, so that the first device obtains the first model based on the first encryption parameter and the encrypted data; wherein the first encryption parameter is obtained by encrypting a random number using the public key of the first device.
15. A model training device comprising: A transceiver, a processor, a memory, and a program or instruction stored in the memory and executable on the processor; characterized in that when the processor executes the program or instruction, the model training method according to any one of claims 1 to 7 and the model training method according to any one of claims 8 to 12 are implemented.
16. A readable storage medium having a program or instruction stored thereon, characterized in that: When the program or instruction is executed by the processor, the steps in the model training method as described in any one of claims 1 to 7 and the steps in the model training method as described in any one of claims 8 to 12 are implemented.
17. A computer program product, characterized in that The method comprises computer instructions, which, when executed by a processor, implement the steps in the model training method according to any one of claims 1 to 7, and the steps in the model training method according to any one of claims 8 to 12.