Federal learning method based on malicious behavior recognition

Through the methods of pre-training joint models, noise processing and consensus verification, the problems of data sharing and privacy protection in traditional malicious behavior identification methods are solved, and efficient malicious behavior identification and model accuracy improvement are achieved in a federated learning environment.

CN120633771APending Publication Date: 2025-09-12ECONOMIC TECH RES INST OF STATE GRID HENAN ELECTRIC POWER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510611396.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-13
Publication Date
2025-09-12

AI Technical Summary

Technical Problem

In a distributed environment, traditional malicious behavior identification methods face problems with data sharing, privacy protection, and insufficient model training accuracy, resulting in reduced model accuracy and the risk of malicious node attacks and model inference leakage.

Method used

The joint model is pre-trained using public datasets, sensitive data is identified through fine-tuning and noise processing, adaptive differential privacy is used for noise addition, aggregation weights are calculated and consensus verification is performed to ensure the encrypted upload and aggregation of model parameters, and a blockchain penalty mechanism is combined to improve the credibility of the model.

Benefits of technology

Without leaking user data, the accuracy of malicious behavior identification is improved, ensuring the credibility of federated learning and the security of the model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120633771A_ABST
    Figure CN120633771A_ABST
Patent Text Reader

Abstract

The invention relates to a federal learning method based on malicious behavior recognition. The method comprises the following steps: pre-training a joint model by adopting a public data set; performing fine tuning on the pre-training model based on the private data to obtain a fine-tuned model; identifying sensitive data in the private data based on the fine-tuned model, and carrying out noise addition processing on the sensitive data to obtain noise-added private data; training a local model based on the noise-added private data to obtain a trained local model; calculating an aggregation weight of each local model according to the model output; performing consensus verification on each local model, and determining the local model passing the consensus verification; and based on the aggregation weight of each local model, aggregating the model parameters of the local models passing the consensus verification to obtain an aggregated model. Through sensitive data identification, adaptive differential privacy and a consensus verification mechanism, on the premise of not leaking user data, the malicious behavior identification accuracy is improved, and the credibility of federal learning is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of federated learning, and in particular, to a federated learning method based on malicious behavior identification. Background Art

[0002] With the development of the internet and big data technologies, data privacy and security issues are receiving increasing attention. Especially in distributed environments, protecting user data privacy while simultaneously conducting efficient behavior analysis and anomaly detection has become a major challenge in the current field of data privacy protection. Malicious behavior identification is crucial in a variety of fields, including cybersecurity, financial fraud, and smart contracts. However, traditional malicious behavior identification methods face challenges with data sharing, privacy protection, and model training accuracy. In federated learning, the inability to share data between different nodes reduces model accuracy and even creates the risk of malicious node attacks and model inference leaks. Summary of the Invention

[0003] In order to overcome at least one deficiency in the prior art, the present application provides a federated learning method based on malicious behavior identification.

[0004] First, a federated learning method based on malicious behavior identification is provided, including:

[0005] Use public datasets to pre-train the joint model to obtain a pre-trained model;

[0006] Fine-tune the pre-trained model based on private data to obtain a fine-tuned model;

[0007] Identify sensitive data in private data based on the fine-tuned model and perform noise processing on the sensitive data to obtain the noisy private data.

[0008] Train the local model based on the noisy private data to obtain a trained local model;

[0009] Encrypt and upload the model parameters and model output of the trained local model;

[0010] Calculate the aggregation weight of each local model based on the model output;

[0011] Conduct consensus verification on each local model and determine the local model that passes the consensus verification;

[0012] Based on the aggregation weights of each local model, the model parameters of the local models verified by consensus are aggregated to obtain the aggregated model.

[0013] In one embodiment, the joint model is VAE-CRF.

[0014] In one embodiment, sensitive data is denoised using adaptive differential privacy denoising.

[0015] In one embodiment, the aggregation weight of each local model is calculated based on the model output using the following formula:

[0016]

[0017] Among them, ω i is the aggregation weight of the i-th local model, p i is the output of the i-th local model, λ is the temperature coefficient, and M is the number of local models.

[0018] In one embodiment, consensus verification is performed on each local model to determine a local model that passes the consensus verification, including:

[0019] Calculate the contribution of each local model;

[0020] The local model with the greatest contribution is used as the primary node, and other local models are used as backup nodes;

[0021] When the master node receives a request from any backup node, it creates a pre-prepare message and broadcasts it to all backup nodes. The pre-prepare message includes detailed information about the request and a unique sequence number.

[0022] Each backup node verifies the pre-prepare information after receiving it, generates the preparation information after verification, and broadcasts the preparation information to the master node and other backup nodes;

[0023] When any node receives more than 2f+1 legitimate prepare messages, it generates a commit message and broadcasts it to other nodes; f is the maximum number of malicious nodes that can be tolerated;

[0024] When more than 2f+1 commit messages are generated, the backup node that sent the request passes the consensus verification, otherwise, it fails the consensus verification.

[0025] In one embodiment, the contribution of each local model is calculated using the following formula:

[0026] Contribution i =α·Accuracy i +β(1-false alarm rate i )

[0027] Among them, Contribution i is the contribution of the i-th local model, α is the accuracy weight, Accuracy iis the malicious behavior detection accuracy of the i-th local model, β is the false alarm rate weight, and false alarm rate i is the false alarm rate of the i-th local model.

[0028] Secondly, a federated learning system based on malicious behavior identification is provided, including:

[0029] The local model training module is used to pre-train the joint model using a public dataset to obtain a pre-trained model; fine-tune the pre-trained model based on private data to obtain a fine-tuned model; identify sensitive data in the private data based on the fine-tuned model and perform noise processing on the sensitive data to obtain noisy private data; and train the local model based on the noisy private data to obtain a trained local model.

[0030] The data upload module is used to encrypt and upload the model parameters and model output of the trained local model;

[0031] The central server is used to calculate the aggregation weight of each local model based on the model output; perform consensus verification on each local model to determine the local model that has passed the consensus verification; based on the aggregation weight of each local model, aggregate the model parameters of the local models that have passed the consensus verification to obtain the aggregated model.

[0032] In a third aspect, a computer-readable storage medium is provided, which stores a computer program. When the computer program is executed by a processor, it implements the above-mentioned federated learning method based on malicious behavior identification.

[0033] In a fourth aspect, a computer program product is provided, comprising a computer program / instruction, which, when executed by a processor, implements the above-mentioned federated learning method based on malicious behavior identification.

[0034] Compared with the existing technology, the present application has the following beneficial effects: the federated learning method based on malicious behavior identification of the present application improves the accuracy of malicious behavior identification and ensures the credibility of federated learning without leaking user data through sensitive data identification, adaptive differential privacy, and consensus verification mechanism. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] The present application may be better understood by referring to the following description taken in conjunction with the accompanying drawings, which together with the following detailed description are incorporated into and form a part of this specification. In the drawings:

[0036] Figure 1 A flowchart of a federated learning method based on malicious behavior identification is shown;

[0037] Figure 2The structural block diagram of the federated learning system based on malicious behavior identification is shown. DETAILED DESCRIPTION

[0038] Exemplary embodiments of the present application are described below with reference to the accompanying drawings. For the sake of clarity and conciseness, not all features of actual embodiments are described in this specification. However, it should be understood that in the process of developing any such actual embodiment, many implementation-specific decisions may be made to achieve the developer's specific goals, and these decisions may vary from one implementation to another.

[0039] It is also necessary to explain here that, in order to avoid obscuring the present application due to unnecessary details, the accompanying drawings only show the device structure closely related to the solution according to the present application, while other details that are not closely related to the present application are omitted.

[0040] It should be understood that the present application is not limited to the described embodiments due to the following description with reference to the accompanying drawings. In this document, where feasible, the embodiments may be combined with each other, features between different embodiments may be replaced or borrowed, and one or more features may be omitted in one embodiment.

[0041] This application embodiment provides a federated learning method based on malicious behavior identification. Figure 1 A flowchart of the federated learning method based on malicious behavior identification is shown in Figure 1 , methods include:

[0042] Step S1: Use a public dataset to pre-train the joint model to obtain a pre-trained model.

[0043] Here, the joint model adopts VAE-CRF, which includes VAE layer and CRF layer. The VAE layer is used to model the potential distribution of user behavior data and extract high-dimensional features; the CRF layer is used to capture the timing and dependency of sensitive behaviors and improve the recognition ability of high-frequency sensitive sequences.

[0044] Step S2: fine-tune the pre-trained model based on the private data to obtain a fine-tuned model.

[0045] Each node fine-tunes the pre-trained model on private data to improve its adaptability to the distribution of private data, and introduces SHAP value analysis to explain and model the importance of each feature.

[0046] Step S3: identifying sensitive data in the private data based on the fine-tuned model, and performing noise processing on the sensitive data to obtain noisy private data.

[0047] Here, the output of the CRF layer is the label probability. If the label probability is greater than a set value, which may be 0.7, for example, the input data is determined to be sensitive data; otherwise, it is not sensitive data.

[0048] Adaptive differential privacy noising is used to perform noise processing on sensitive data.

[0049] Step S4: training the local model based on the noisy private data to obtain a trained local model.

[0050] Step S5: Encrypt and upload the model parameters and model output of the trained local model.

[0051] Step S6: Calculate the aggregation weight of each local model based on the model output.

[0052] Specifically, the following formula is used:

[0053]

[0054] Among them, ω i is the aggregation weight of the i-th local model, p i is the output of the i-th local model, λ is the temperature coefficient, and M is the number of local models.

[0055] Step S7: Perform consensus verification on each local model to determine the local model that passes the consensus verification.

[0056] Step S8: Aggregate the model parameters of the local models that have passed the consensus verification based on the aggregation weights of the local models to obtain an aggregated model.

[0057] Here, the model parameters of the local model verified by consensus are multiplied by the corresponding aggregation weights, and then all the multiplication results are accumulated to obtain the aggregated model parameters, and the aggregated model can be determined.

[0058] In this embodiment, through sensitive data identification, adaptive differential privacy, and consensus verification mechanism, the accuracy of malicious behavior identification is improved without leaking user data, ensuring the credibility of federated learning.

[0059] In one embodiment, step S7, performing consensus verification on each local model and determining a local model that passes the consensus verification, includes:

[0060] Step S71, calculating the contribution of each local model;

[0061] Specifically, the following formula is used:

[0062] Contribution i =α·Accuracyi +β(1-false alarm rate i )

[0063] Among them, Contriiibuttion i is the contribution of the i-th local model, α is the accuracy weight, Accuracy i is the malicious behavior detection accuracy of the i-th local model, β is the false alarm rate weight, and the false alarm rate i is the false alarm rate of the i-th local model.

[0064] Among them, α is a weight coefficient for controlling the accuracy of malicious behavior detection of the node, for example, 0.7, and β is a weight coefficient for controlling the false alarm rate of the node, for example, 0.3.

[0065] Step S72: The local model with the greatest contribution is used as the master node, and the other local models are used as backup nodes;

[0066] Step S73: When the master node receives a request from any backup node, it creates a pre-prepared message and broadcasts it to all backup nodes; the pre-prepared message includes detailed information of the request and a unique sequence number;

[0067] Step S74: Each backup node verifies the pre-preparation information after receiving it, generates preparation information after passing the verification, and broadcasts the preparation information to the master node and other backup nodes;

[0068] Step S75: When any node receives more than 2f+1 legitimate prepare messages, it generates a commit message and broadcasts it to other nodes; f is the maximum number of malicious nodes that can be tolerated;

[0069] Step S76: When more than 2f+1 commit messages are generated, the backup node that sends the request passes the consensus verification; otherwise, it fails the consensus verification.

[0070] Furthermore, the federated learning method based on malicious behavior identification also includes a blockchain penalty process. The blockchain penalty process is applied in the process of each message transmission in step 7, including a malicious behavior monitoring contract, a malicious behavior identification contract, a malicious behavior recording contract, a malicious behavior penalty contract, etc.

[0071] Using the same inventive concept as the federated learning method based on malicious behavior identification, this embodiment also provides a corresponding federated learning system based on malicious behavior identification. Figure 2 The following figure shows the structural block diagram of the federated learning system based on malicious behavior identification. The system includes:

[0072] The local model training module is used to pre-train the joint model using a public dataset to obtain a pre-trained model; fine-tune the pre-trained model based on private data to obtain a fine-tuned model; identify sensitive data in the private data based on the fine-tuned model and perform noise processing on the sensitive data to obtain noisy private data; and train the local model based on the noisy private data to obtain a trained local model.

[0073] The data upload module is used to encrypt and upload the model parameters and model output of the trained local model;

[0074] The central server is used to calculate the aggregation weight of each local model based on the model output; perform consensus verification on each local model to determine the local model that has passed the consensus verification; based on the aggregation weight of each local model, aggregate the model parameters of the local models that have passed the consensus verification to obtain the aggregated model.

[0075] The federated learning system based on malicious behavior identification in this embodiment has the same inventive concept as the federated learning method based on malicious behavior identification mentioned above. Therefore, the specific implementation method of this system can be seen in the embodiment part of the federated learning method based on malicious behavior identification mentioned above, and its technical effects correspond to the technical effects of the above method, which will not be repeated here.

[0076] An embodiment of the present application provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the above-mentioned federated learning method based on malicious behavior identification.

[0077] An embodiment of the present application provides a computer program product, including a computer program / instruction. When the computer program / instruction is executed by a processor, it implements the above-mentioned federated learning method based on malicious behavior identification.

[0078] The above descriptions are merely examples of various embodiments of the present application, but the scope of protection of the present application is not limited thereto. Any modifications or substitutions that can be readily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included within the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A federated learning method based on malicious behavior identification, characterized in that: include: Use public datasets to pre-train the joint model to obtain a pre-trained model; Fine-tuning the pre-trained model based on private data to obtain a fine-tuned model; identifying sensitive data in the private data based on the fine-tuned model, and performing noise processing on the sensitive data to obtain noisy private data; Training a local model based on the noisy private data to obtain a trained local model; Encrypt and upload the model parameters and model output of the trained local model; Calculating the aggregation weight of each local model based on the model output; Conduct consensus verification on each local model and determine the local model that passes the consensus verification; Based on the aggregation weights of the local models, the model parameters of the local models verified by consensus are aggregated to obtain an aggregated model.

2. The method according to claim 1, wherein The joint model is VAE-CRF.

3. The method according to claim 1, wherein in, The sensitive data is subjected to noise processing, and adaptive differential privacy noise addition is adopted.

4. The method according to claim 1, wherein in, The aggregation weight of each local model is calculated based on the model output, using the following formula: Among them, ω i is the aggregation weight of the i-th local model, p i is the output of the i-th local model, λ is the temperature coefficient, and M is the number of local models.

5. The method according to claim 1, wherein in, Conduct consensus verification on each local model and determine the local models that have passed the consensus verification, including: Calculate the contribution of each local model; The local model with the greatest contribution is used as the primary node, and other local models are used as backup nodes; When the master node receives a request from any backup node, it creates a pre-prepare message and broadcasts it to all backup nodes; the pre-prepare message includes detailed information about the request and a unique sequence number; Each backup node verifies the pre-preparation information after receiving it, generates preparation information after passing the verification, and broadcasts the preparation information to the master node and other backup nodes; When any node receives more than 2f+1 legitimate prepare messages, it generates a commit message and broadcasts it to other nodes; f is the maximum number of malicious nodes that can be tolerated; When more than 2f+1 commit messages are generated, the backup node that sent the request passes the consensus verification, otherwise, it fails the consensus verification.

6. The method according to claim 5, wherein: The contribution of each local model is calculated using the following formula: Contribution i =α·Accuracy i +β(1-false alarm rate i ) Among them, Contribution i is the contribution of the i-th local model, α is the accuracy weight, Accuracy i is the malicious behavior detection accuracy of the i-th local model, β is the false alarm rate weight, and the false alarm rate i is the false alarm rate of the i-th local model.

7. A federated learning system based on malicious behavior identification, characterized in that: include: The local model training module is used to pre-train the joint model using a public dataset to obtain a pre-trained model; Fine-tuning the pre-trained model based on the private data to obtain a fine-tuned model; identifying sensitive data in the private data based on the fine-tuned model, and performing noise processing on the sensitive data to obtain noisy private data; Training a local model based on the noisy private data to obtain a trained local model; The data upload module is used to encrypt and upload the model parameters and model output of the trained local model; A central server, configured to calculate the aggregate weights of the local models based on the model output; Consensus verification is performed on each local model to determine a local model that passes the consensus verification; and based on the aggregation weights of the local models, model parameters of the local models that pass the consensus verification are aggregated to obtain an aggregated model.

8. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the federated learning method based on malicious behavior identification according to any one of claims 1 to 6.

9. A computer program product, characterized in that The method comprises a computer program / instruction, which, when executed by a processor, implements the federated learning method based on malicious behavior identification as described in any one of claims 1 to 6.