Immune federal learning big data analysis method and system
By introducing an immune reverse selection mechanism and a weighted average method, the parameter aggregation process of federated learning is optimized, which solves the problem of federated learning being vulnerable to malicious attacks, achieves higher stability and accuracy, and enhances the security and reliability of big data analysis.
Patent Information
- Application Number
- CN202510763528.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-09
- Publication Date
- 2025-11-11
AI Technical Summary
Federated learning is vulnerable to malicious attacks in big data analytics, making it difficult to guarantee the security and reliability of model training. Traditional security mechanisms are also unable to identify and defend against complex malicious attacks.
An immune reverse selection mechanism is introduced, which identifies and excludes the model parameters of malicious clients through clustering algorithms, aggregates the parameters of trusted clients using a weighted average method, and trains the CNN global model of the CBAM module, thereby optimizing the local training process on the client and the detection process on the server.
It improves the stability and accuracy of federated learning systems in big data analysis, enhances data privacy and security, improves the stability and accuracy of model training, and improves the analytical performance of the global model.
Smart Images

Figure CN120930725A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of federated learning, and in particular to an immune federated learning big data analysis method and system. Background Technology
[0002] In today's rapidly evolving digital transformation and intelligent era, big data has become a core asset driving innovation and enhancing competitiveness across all industries. Big data sources are extremely diverse, encompassing a wealth of data including financial transaction records, e-commerce platform user shopping behavior, medical case information, educational institution student learning data, and various data from traditional industrial production. This data contains crucial information on risk control, market trend insights, service quality optimization, and improved teaching effectiveness, making it of paramount importance for refined management and intelligent decision-making across various industries.
[0003] However, the effective analysis and utilization of big data faces numerous severe challenges. First, data is highly sensitive to privacy. Core business secrets of enterprises, sensitive personal information of users, and critical business data of organizations are all important advantages in market competition or operations. Once leaked, they will cause huge economic losses and hinder development for the relevant parties. Traditional centralized data analysis models require the centralized storage and processing of data from various data sources, which exposes data to extremely high security risks during transmission and storage, such as hacker attacks and unauthorized internal operations, making it difficult to meet the stringent data privacy protection requirements of various industries. Second, big data is extremely complex. Data exhibits high dimensionality and multimodal characteristics, with different types of data having vastly different features, often accompanied by a large amount of noise and missing values. For example, in the e-commerce field, user browsing history, search records, purchase preferences, and review information are intertwined, exhibiting complex nonlinear relationships. This makes it difficult for traditional data analysis algorithms to accurately extract valuable information from massive amounts of data, resulting in low analysis efficiency and inaccurate results.
[0004] To address the challenges of data privacy protection and complex data analysis, federated learning, an emerging distributed machine learning technology, has emerged. Federated learning allows various participants (such as companies in different industries, different departments within an organization, partners, etc.) to collaboratively train a global model by exchanging model parameters without directly sharing the original data. This approach effectively avoids the leakage of original data and protects data privacy. However, federated learning faces serious security threats in practical applications. Malicious actors may intentionally upload abnormal model parameters for various purposes, interfering with the normal training process of the global model. Common attack methods include constant model attacks, which set all model parameters to fixed values, and sign-flipping attacks, which change the positive or negative sign of model parameters. These attacks can mislead the optimization direction of the global model, leading to a significant drop in model performance, inaccurate data analysis, and consequently impacting decision-making and business operations across various industries.
[0005] Traditional security defense mechanisms for federated learning primarily focus on encryption and access control, but these methods have limited effectiveness in detecting and defending against complex malicious attacks. For example, while encryption can protect data security during transmission and storage, it cannot identify and exclude maliciously uploaded abnormal model parameters; access control can only restrict access by unauthorized users, but cannot prevent malicious behavior by legitimate users. Therefore, a more effective security mechanism is needed to ensure the reliability and stability of federated learning in big data analytics. Summary of the Invention
[0006] This invention addresses the technical problems existing in the prior art by providing an immune federated learning big data analysis method, in order to overcome the problems that federated learning is vulnerable to malicious attacks and has difficulty in ensuring the security and reliability of model training in big data analysis scenarios.
[0007] According to a first aspect of the present invention, an immune federated learning big data analysis method is provided, comprising: Step 1: The server sends the initial parameters of the global model to each client, and each client initializes its local model based on the initial parameters. Step 2: Each client trains the local model based on its local training strategy to obtain the trained model parameters, and then uploads the trained model parameters to the server; the local training strategy may or may not include a preset attack strategy. Step 3: The server uses an immune reverse selection mechanism to identify malicious clients for each of the received trained model parameters; the trained model parameters that are not identified as malicious clients are aggregated to obtain updated global model parameters.
[0008] Based on the above technical solution, the present invention can also be improved as follows.
[0009] Optionally, the global model is a CNN global model with a CBAM module. The server determines the structure of the CNN global model according to the task requirements of big data analysis. The parameters of the structure of the CNN global model include: the number of convolutional layers, the size of the convolutional kernels, and the type of pooling layers.
[0010] Optionally, the process of each client training the local model in step 2 includes: Step 201: Collect feature data and corresponding tag data collected by various sensors in the industrial scenario; Step 202: Encode the string features in the feature data and convert them into numerical features, then normalize the numerical features to generate a local dataset; Step 203: Train the local model for e rounds based on the local dataset. Calculate the loss using a loss function in each round of training. Construct a stochastic gradient descent optimizer based on the loss function. Update the local model parameters based on the stochastic gradient descent optimizer. The formula for updating the local model parameters by the stochastic gradient descent optimizer is:
[0011] in, These are the parameters of the local model during the e-th training round; It is the hyperparameter learning rate used to control the step size of each parameter update; The loss function L with respect to the parameters The gradient; These are the local model parameters updated during the (e+1)th training round.
[0012] Optionally, the preset attack strategies include: constant model attack and sign-flipping attack; The constant model attack includes setting all parameters of the local model to a fixed value; The sign-flipping attack includes reversing the sign of the parameters of the local model.
[0013] Optionally, step 3, where the server-side uses an immune reverse selection mechanism to identify malicious clients from the received trained model parameters, includes: Step 301: The server stores parameters for m trusted clients. Receive model parameters uploaded by n clients to be tested , parameters and Expand into one-dimensional vectors respectively and ; Step 302, use a clustering algorithm to process the vectors. Perform clustering to obtain k cluster centers. ; Step 303: Calculate the distance from each vector in each cluster of trusted clients to the cluster center. distance Calculate the radius of this cluster as ;in, ; Step 304: Calculate the distance from all vectors in each cluster of the i-th client to be tested to the cluster center. For all They all If the i-th client to be tested is determined to be a malicious client, then the i-th client to be tested is determined to be a malicious client.
[0014] Optionally, in step 3, the formula for aggregating the trained model parameters that were not identified as malicious clients to obtain the updated global model parameters is as follows: ; Where T is the set of trusted clients that have not been identified as malicious clients, and the element i in the set represents the number of the trusted client; is the size of the local dataset of the i-th trusted client; N is the sum of the sizes of the local datasets of all trusted clients; These are the model parameters uploaded by the i-th trusted client; These are the updated global model parameters after parameter aggregation.
[0015] Optionally, step 3 may be followed by: Step 4: The server distributes the updated global model parameters to each client. Step 5: Repeat steps 2-4 for multiple rounds of iterative training until the preset model training termination condition is met, and the final global model is obtained. Step 6: Use the test dataset to evaluate the performance metrics of the final global model and visualize the evaluation results. The performance metrics include: model accuracy, recall, and loss value.
[0016] According to a second aspect of the present invention, an immune federated learning big data analysis system is provided, comprising: a server and a client; The server sends the initial parameters of the global model to each client, and each client initializes its local model based on the initial parameters. Each client trains its local model based on its local training strategy to obtain trained model parameters, and then uploads the trained model parameters to the server. The local training strategy may or may not include a preset attack strategy. The server employs an immune reverse selection mechanism to identify malicious clients among the received trained model parameters; the trained model parameters that are not identified as malicious clients are aggregated to obtain updated global model parameters.
[0017] According to a third aspect of the present invention, an electronic device is provided, including a memory and a processor, wherein the processor is configured to implement the steps of an immune federated learning big data analysis method when executing a computer management program stored in the memory.
[0018] According to a fourth aspect of the present invention, a computer-readable storage medium is provided having a computer management class program stored thereon, which, when executed by a processor, implements the steps of an immune federated learning big data analysis method.
[0019] This invention provides an immune federated learning big data analysis method, system, electronic device, and storage medium. It introduces an immune reverse selection mechanism to improve the parameter aggregation process of federated learning, while optimizing the client-side local training and server-side detection processes. This achieves effective detection and defense against malicious attacks, resulting in better stability and accuracy in big data analysis. A dynamic adjustment mechanism for anomaly detection thresholds based on cluster boundaries is proposed, optimizing the malicious node detection process for more accurate malicious node detection, thus enhancing the security and reliability of the federated learning system in big data analysis. By rationally controlling the learning rate and updating parameters based on gradient direction, the stability and accuracy of local model training are improved, thereby enhancing the overall performance of the federated learning system in big data analysis. A weighted average based on dataset size allows for more efficient use of data from trusted clients, improving the accuracy and generalization ability of the global model in big data analysis. A parameter aggregation concept based on dataset size weighting is proposed, achieving more reasonable and effective model parameter fusion performance, resulting in better comprehensive analytical performance of the federated learning system in big data analysis. By deeply integrating the immune reverse selection mechanism into federated learning, the following steps are taken: First, a dataset is collected, and the data from each client is preprocessed. Then, the server initializes a global CNN model with a CBAM module and distributes initial parameters to the clients. The clients train their models on their local datasets, and some clients simulate malicious attacks. The server uses the immune reverse selection mechanism to detect malicious nodes and aggregates the model parameters of trusted clients to update the global model. The training is repeated iteratively until the termination condition is met. This approach can effectively protect data privacy and security during big data analysis, providing a more effective technical means to reduce the security risks of federated learning and improve the efficiency of big data analysis. Attached Figure Description
[0020] Figure 1 A flowchart illustrating an embodiment of an immune federated learning big data analysis method provided by the present invention; Figure 2 A flowchart of the immune reverse selection algorithm in an immune federated learning big data analysis method provided by the present invention; Figure 3 A schematic diagram of the hardware structure of a possible electronic device provided by the present invention; Figure 4 This is a schematic diagram of the hardware structure of a possible computer-readable storage medium provided by the present invention. Detailed Implementation
[0021] The principles and features of the present invention are described below with reference to the accompanying drawings. The examples given are only for explaining the present invention and are not intended to limit the scope of the present invention.
[0022] Figure 1 A flowchart illustrating an embodiment of an immune federated learning big data analysis method provided by the present invention is shown below. Figure 1 As shown, the analytical method includes: Step 1: The server sends the initial parameters of the global model to each client, and each client initializes its local model based on the initial parameters.
[0023] Step 2: Each client trains its local model based on its local training strategy to obtain the trained model parameters, and then uploads the trained model parameters to the server. The local training strategy may or may not include a preset attack strategy.
[0024] Step 3: The server uses an immune reverse selection mechanism to identify malicious clients for each of the received trained model parameters; the trained model parameters that are not identified as malicious clients are aggregated to obtain the updated global model parameters.
[0025] This invention provides an immune federated learning big data analysis method that can effectively resist malicious attacks during the federated learning process, improve the accuracy and reliability of big data analysis, and provide strong support for production decision-making.
[0026] Example 1 Embodiment 1 provided by this invention is an embodiment of immune federated learning big data analysis provided by this invention, combined with... Figure 1 As can be seen, embodiments of this analytical method include: Step 1: The server sends the initial parameters of the global model to each client, and each client initializes its local model based on the initial parameters.
[0027] In one possible implementation, the global model is a CNN (Convolutional Neural Networks) global model with a CBAM module. The server determines the structure of the CNN global model according to the task requirements of big data analysis. The parameters of the CNN global model structure include: the number of convolutional layers, the size of the convolutional kernels, and the type of pooling layers.
[0028] In practice, CBAM (Convolutional Block Attention Module) can adaptively adjust the attention distribution of the feature map's channels and spatial dimensions, enhancing the model's focus on important features. After the server randomly initializes the model's parameters, it sends the initial parameters to each client via network communication.
[0029] Step 2: Each client trains its local model based on its local training strategy to obtain the trained model parameters, and then uploads the trained model parameters to the server. The local training strategy may or may not include a preset attack strategy.
[0030] In one possible embodiment, step 2, where each client trains its local model, includes: Step 201: Collect feature data and corresponding tag data collected by various sensors in the industrial scenario.
[0031] In practical implementation, in real industrial scenarios, feature data can be collected through various sensors deployed on production lines, monitoring systems for industrial equipment, and enterprise management information systems. For example, in manufacturing, equipment operating parameters (such as temperature, pressure, and speed) can be collected as feature data, and product quality inspection results can be used as label data.
[0032] Step 202: Encode the string features in the feature data and convert them into numerical features, then normalize the numerical features to generate a local dataset.
[0033] In practice, the feature data collected from each client is preprocessed, including encoding the string features in the feature data and converting them into numerical features; normalizing the feature data; and performing necessary conversions and encoding on the label data.
[0034] For string feature encoding, common methods such as one-hot encoding or label encoding can be used. For example, if the feature data includes the string feature "device model," one-hot encoding can be used to convert different device models into binary vectors. Feature data normalization can employ min-max normalization or Z-score normalization to ensure that the feature data has a uniform scale range, preventing some features from having excessively large numerical ranges that could significantly impact model training. For labeled data, for classification problems, the category labels can be converted into numeric codes, such as 0, 1, 2, etc.; for regression problems, appropriate numerical transformations can be performed according to specific needs.
[0035] Step 203: Train the local model for e rounds based on the local dataset. Calculate the loss using a loss function in each round of training. Construct a stochastic gradient descent optimizer based on the loss function. Update the local model parameters based on the stochastic gradient descent optimizer.
[0036] The formula for updating the local model parameters using the stochastic gradient descent optimizer is:
[0037] in, These are the parameters of the local model during the e-th training round; It is the hyperparameter learning rate used to control the step size of each parameter update; The loss function L with respect to the parameters The gradient of the loss function represents the rate of change of the loss function with respect to the current parameters and indicates the direction of parameter updates. These are the local model parameters updated during the (e+1)th training round, reflecting the iterative optimization results of the model in each training round.
[0038] The formula for updating local model parameters using the stochastic gradient descent optimizer optimizes the training process of the local model on the federated learning client. By reasonably controlling the learning rate and updating parameters according to the gradient direction, it improves the stability and accuracy of local model training, thereby enhancing the performance of the entire federated learning system in big data analysis. The loss function can be selected according to the specific analysis task; for example, the cross-entropy loss function can be used for classification problems, and the mean squared error loss function can be used for regression problems.
[0039] In one possible embodiment, the preset attack strategies include constant model attacks and sign-flipping attacks, etc.
[0040] Constant model attacks include malicious clients setting all parameters of a local model to a fixed value.
[0041] Sign-flipping attacks include reversing the sign of parameters in a local model.
[0042] By simulating these malicious attacks, the effectiveness of the immune reverse selection mechanism was tested.
[0043] Step 3: The server uses an immune reverse selection mechanism to identify malicious clients for each of the received trained model parameters; the trained model parameters that are not identified as malicious clients are aggregated to obtain the updated global model parameters.
[0044] The immune reverse selection mechanism originates from the self-non-self recognition principle of the biological immune system. In the biological immune system, immune cells can accurately identify and eliminate foreign pathogens (non-self) while protecting their own normal tissues (self). By constructing a detection system based on the immune reverse selection mechanism, it is possible to effectively identify and exclude abnormal model parameters uploaded by malicious participants, ensuring that the training process of the global model is not disturbed, thereby improving the accuracy and reliability of big data analysis.
[0045] In one possible embodiment, step 3, where the server employs an immune reverse selection mechanism to identify malicious clients from the received trained model parameters, includes: Step 301: The server stores parameters for m trusted clients. Receive model parameters uploaded by n clients to be tested , parameters and Expand into one-dimensional vectors respectively and .
[0046] Since model parameters are usually multidimensional arrays, they are expanded into one-dimensional vectors to facilitate subsequent cluster analysis.
[0047] Step 302, use a clustering algorithm to process the vectors. Perform clustering to obtain k cluster centers. .
[0048] In specific implementation, the K-Means algorithm can be used for clustering. The K-Means algorithm is a commonly used clustering algorithm that divides data points into different clusters through iteration and calculates the center of each cluster.
[0049] Step 303: Calculate the distance from each vector in each cluster of trusted clients to the cluster center. distance Given the vector index of this cluster, calculate the radius of this cluster as... ;in, .
[0050] Distance can be calculated using the Euclidean distance formula. By calculating the distance from each vector to the cluster center, the boundary range of each cluster can be determined.
[0051] Step 304: Calculate the distance from all vectors in each cluster of the i-th client to be tested to the cluster center. For all They all If the i-th client to be tested is determined to be a malicious client, then the i-th client to be tested is determined to be a malicious client.
[0052] Where n represents the total number of model parameters uploaded by the client received by the server; m represents the number of known trusted clients; These are the model parameters uploaded by the i-th client; These are the model parameters for the j-th trusted client; and They are respectively to and The expanded one-dimensional vector; k is the number of cluster centers obtained by the K-Means algorithm; It is the l-th cluster center; It is the distance from the j-th trusted client vector to the l-th cluster center; It is the radius of the l-th cluster; It is the distance from the i-th client vector to be detected to the l-th cluster center.
[0053] In the immune reverse selection algorithm, detector generation and malicious node detection are crucial steps in ensuring system reliability. The first step is detector generation. Based on the client state, parameters of trustworthy nodes are accurately selected; these parameters form the basis for a reliable detection mechanism. To facilitate subsequent analysis and processing, the selected trustworthy node parameters are expanded into one-dimensional vectors, making their data format more suitable for clustering algorithms. Then, the K-Means clustering algorithm is used to cluster these one-dimensional vectors. Through continuous iteration, similar data points are grouped into the same cluster based on the distance relationship between data points. The centroid and maximum distance of each cluster are then calculated. This maximum distance defines the boundary range of the cluster and is a key indicator for measuring the normal fluctuation range of the data. Based on these cluster centers and boundary ranges, a detector is successfully generated. This detector can effectively identify data features, providing a basis for subsequent malicious node detection.
[0054] In the abnormal node detection phase, the parameters of the node to be detected are first expanded into a one-dimensional vector to standardize the data format and facilitate comparison and analysis with the previously generated clustering features. Next, the distance between the node's parameters and the cluster center is calculated, and the node's nature is determined by comparing this distance with the cluster boundary range. If the distance exceeds the cluster boundary range, it means the node's parameters deviate from the normal fluctuation range, thus identifying it as a malicious node; if the distance is within the boundary range, it is identified as a normal node. This rigorous detector generation and malicious node detection process effectively identifies and eliminates malicious nodes, ensuring the system's stability and accuracy.
[0055] In one possible embodiment, the formula for calculating the updated global model parameters by aggregating the trained model parameters that were not identified as malicious clients in step 3 is as follows: .
[0056] Where T is the set of trusted clients that have not been identified as malicious clients, and the element i in the set represents the number of the trusted client; is the size of the local dataset of the i-th trusted client; N is the sum of the sizes of the local datasets of all trusted clients; These are the model parameters uploaded by the i-th trusted client; These are the updated global model parameters after parameter aggregation.
[0057] The parameter aggregation is performed using a weighted average method. Let the set of trusted clients be . The size of the local dataset of client i is Total dataset size By assigning different weights to each client's local dataset based on its size, clients with larger datasets contribute more to the global model update. This dataset-weighted parameter aggregation concept achieves more reasonable and effective model parameter fusion performance, enabling the federated learning system to exhibit better comprehensive analytical performance in big data analysis.
[0058] In one possible embodiment, step 3 is followed by: Step 4: The server distributes the updated global model parameters to each client.
[0059] The server sends the updated global model parameters to each client. After receiving the new parameters, the client initializes and trains its local model again based on these parameters.
[0060] Step 5: Repeat steps 2-4 for multiple rounds of iterative training until the preset model training termination condition is met, and the final global model is obtained.
[0061] The preset termination conditions can be reaching the maximum number of iterations, the model's loss value converging to a small threshold, or the model's performance metrics (such as accuracy, recall, etc.) reaching a preset standard.
[0062] Step 6: Use the test dataset to evaluate the performance metrics of the final global model and visualize the evaluation results. The performance metrics include: model accuracy, recall, and loss value.
[0063] Example 2 Embodiment 2 of the present invention is an embodiment of an immune federated learning big data analysis system provided by the present invention. The embodiment of the analysis system includes a server and a client.
[0064] The server sends the initial parameters of the global model to each client, and each client initializes its local model based on the initial parameters.
[0065] Each client trains its local model based on its local training strategy to obtain the trained model parameters, and then uploads the trained model parameters to the server. The local training strategy may or may not include a preset attack strategy.
[0066] The server employs an immune reverse selection mechanism to identify malicious clients among the received trained model parameters; the trained model parameters that are not identified as malicious clients are aggregated to obtain the updated global model parameters.
[0067] It is understood that the immune federated learning big data analysis system provided by the present invention corresponds to the immune federated learning big data analysis method provided in the foregoing embodiments. The relevant technical features of the immune federated learning big data analysis system can be referred to the relevant technical features of the immune federated learning big data analysis method, and will not be repeated here.
[0068] Please see Figure 3 , Figure 3 This is a schematic diagram illustrating an embodiment of the electronic device provided in this invention. For example... Figure 3 As shown, this embodiment of the invention provides an electronic device, including a memory 1310, a processor 1320, and a computer program 1311 stored in the memory 1310 and executable on the processor 1320. When the processor 1320 executes the computer program 1311, it performs the following steps: the server sends initial parameters of the global model to each client, and each client initializes its local model based on the initial parameters; each client trains its local model according to its local training strategy to obtain trained model parameters, and uploads the trained model parameters to the server; the local training strategy may or may not include a preset attack strategy; the server uses an immune reverse selection mechanism to identify malicious clients for each of the received trained model parameters; and the trained model parameters that are not identified as malicious clients are aggregated to obtain updated global model parameters.
[0069] Please see Figure 4 , Figure 4 This is a schematic diagram illustrating an embodiment of a computer-readable storage medium provided by the present invention. (See diagram below.) Figure 4 As shown, this embodiment provides a computer-readable storage medium 1400, on which a computer program 1411 is stored. When the computer program 1411 is executed by a processor, it performs the following steps: the server sends the initial parameters of the global model to each client, and each client initializes its local model based on the initial parameters; each client trains its local model according to its local training strategy to obtain trained model parameters, and uploads the trained model parameters to the server; the local training strategy may or may not contain a preset attack strategy; the server uses an immune reverse selection mechanism to identify malicious clients for each of the received trained model parameters; and the trained model parameters that are not identified as malicious clients are aggregated to obtain updated global model parameters.
[0070] This invention provides an immune federated learning big data analysis method, system, electronic device, and storage medium. It introduces an immune reverse selection mechanism to improve the parameter aggregation process of federated learning, while optimizing the client-side local training and server-side detection processes. This effectively detects and defends against malicious attacks, resulting in better stability and accuracy in big data analysis. A dynamic adjustment mechanism for anomaly detection thresholds based on cluster boundaries is proposed, optimizing the malicious node detection process for more accurate malicious node detection, thus enhancing the security and reliability of the federated learning system in big data analysis. By reasonably controlling the learning rate and updating parameters based on gradient direction, the stability and accuracy of local model training are improved, thereby enhancing the overall performance of the federated learning system in big data analysis. A weighted average based on dataset size allows for more efficient use of data from trusted clients, improving the accuracy and generalization ability of the global model in big data analysis. A parameter aggregation concept based on dataset size weighting is proposed, achieving more reasonable and effective model parameter fusion performance, resulting in better comprehensive analysis performance of the federated learning system in big data analysis. By deeply integrating the immune reverse selection mechanism into federated learning, the following steps are taken: First, a dataset is collected, and the data from each client is preprocessed. Then, the server initializes a global CNN model with a CBAM module and distributes initial parameters to the clients. The clients train their models on their local datasets, and some clients simulate malicious attacks. The server uses the immune reverse selection mechanism to detect malicious nodes and aggregates the model parameters of trusted clients to update the global model. The training is repeated iteratively until the termination condition is met. This approach can effectively protect data privacy and security during big data analysis, providing a more effective technical means to reduce the security risks of federated learning and improve the efficiency of big data analysis.
[0071] It should be noted that the descriptions of each embodiment in the above embodiments have different focuses. For parts that are not described in detail in a certain embodiment, please refer to the relevant descriptions in other embodiments.
[0072] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0073] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0074] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0075] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0076] Although preferred embodiments of the invention have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including both the preferred embodiments and all changes and modifications falling within the scope of the invention.
[0077] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.
Claims
1. A method for big data analysis of immune federated learning, characterized in that, The analytical method includes: Step 1: The server sends the initial parameters of the global model to each client, and each client initializes its local model based on the initial parameters. Step 2: Each client trains the local model based on its local training strategy to obtain the trained model parameters, and then uploads the trained model parameters to the server; the local training strategy may or may not include a preset attack strategy. Step 3: The server uses an immune reverse selection mechanism to identify malicious clients for each of the received trained model parameters; the trained model parameters that are not identified as malicious clients are aggregated to obtain updated global model parameters.
2. The analytical method according to claim 1, characterized in that, The global model is a CNN global model with a CBAM module. The server determines the structure of the CNN global model according to the task requirements of big data analysis. The parameters of the structure of the CNN global model include: the number of convolutional layers, the size of the convolutional kernels, and the type of pooling layers.
3. The analytical method according to claim 1, characterized in that, The process of each client training the local model in step 2 includes: Step 201: Collect feature data and corresponding tag data collected by various sensors in the industrial scenario; Step 202: Encode the string features in the feature data and convert them into numerical features, then normalize the numerical features to generate a local dataset; Step 203: Train the local model for e rounds based on the local dataset. Calculate the loss using a loss function in each round of training. Construct a stochastic gradient descent optimizer based on the loss function. Update the local model parameters based on the stochastic gradient descent optimizer. The formula for updating the local model parameters by the stochastic gradient descent optimizer is: in, These are the parameters of the local model during the e-th training round; It is the hyperparameter learning rate used to control the step size of each parameter update; The loss function L with respect to the parameters The gradient; These are the local model parameters updated during the (e+1)th training round.
4. The analytical method according to claim 1, characterized in that, The preset attack strategies include: constant model attack and sign-flipping attack; The constant model attack includes setting all parameters of the local model to a fixed value; The sign-flipping attack includes reversing the sign of the parameters of the local model.
5. The analytical method according to claim 1, characterized in that, Step 3, where the server uses an immune reverse selection mechanism to identify malicious clients from the received trained model parameters, includes the following steps: Step 301: The server stores parameters for m trusted clients. Receive model parameters uploaded by n clients to be tested , parameters and Expand into one-dimensional vectors respectively and ; Step 302, use a clustering algorithm to process the vectors. Perform clustering to obtain k cluster centers. ; Step 303: Calculate the distance from each vector in each cluster of trusted clients to the cluster center. distance Calculate the radius of this cluster as ;in, ; Step 304: Calculate the distance from all vectors in each cluster of the i-th client to be tested to the cluster center. For all They all If the i-th client to be tested is determined to be a malicious client, then the i-th client to be tested is determined to be a malicious client.
6. The analytical method according to claim 1, characterized in that, The formula for calculating the updated global model parameters by aggregating the trained model parameters that were not identified as malicious clients in step 3 is as follows: ; Where T is the set of trusted clients that have not been identified as malicious clients, and the element i in the set represents the number of the trusted client; is the size of the local dataset of the i-th trusted client; N is the sum of the sizes of the local datasets of all trusted clients; These are the model parameters uploaded by the i-th trusted client; These are the updated global model parameters after parameter aggregation.
7. The analytical method according to claim 1, characterized in that, Step 3 is followed by: Step 4: The server distributes the updated global model parameters to each client. Step 5: Repeat steps 2-4 for multiple rounds of iterative training until the preset model training termination condition is met, and the final global model is obtained. Step 6: Use the test dataset to evaluate the performance metrics of the final global model and visualize the evaluation results. The performance metrics include: model accuracy, recall, and loss value.
8. An immune federated learning big data analysis system, characterized in that, The analysis system includes: a server and a client; The server sends the initial parameters of the global model to each client, and each client initializes its local model based on the initial parameters. Each client trains its local model based on its local training strategy to obtain trained model parameters, and then uploads the trained model parameters to the server. The local training strategy may or may not include a preset attack strategy. The server employs an immune reverse selection mechanism to identify malicious clients among the received trained model parameters; the trained model parameters that are not identified as malicious clients are aggregated to obtain updated global model parameters.
9. An electronic device, characterized in that, It includes a memory and a processor, wherein the processor is used to implement the steps of the immune federated learning big data analysis method as described in any one of claims 1-7 when executing a computer management program stored in the memory.
10. A computer-readable storage medium, characterized in that, It stores a computer management program, which, when executed by a processor, implements the steps of the immune federated learning big data analysis method as described in any one of claims 1-7.