Clustering federal privacy anomaly detection method and device, equipment and medium
By acquiring encrypted statistics and generating global cluster statistics in a data-scattered and compliance-restricted environment, updating the cluster center and establishing a cluster model, and receiving protected increments in real time for secure aggregation, the system solves the stability and timeliness issues of anomaly detection in data-scattered environments and achieves efficient anomaly detection.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-24
- Publication Date
- 2026-03-10
AI Technical Summary
In environments where data is fragmented and subject to compliance restrictions, unified modeling struggles to consistently provide stable and timely anomaly detection outputs without distributing data externally.
By obtaining and aggregating encrypted statistics from the edge, global cluster statistics are generated, the cluster center is updated and a cluster model is established, protected increments are received in real time for secure aggregation, and anomaly detection requests are processed based on the converged cluster center to generate anomaly detection results.
Without disclosing individual information, the effectiveness, adaptability, stability, and accuracy of the model are improved. The feasibility and traceability of the cluster training process are ensured, center jitter is reduced, and the stability and accuracy of anomaly detection results are improved.
Smart Images

Figure CN121644151A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the technical field of privacy computing, and in particular relates to a clustered federated privacy anomaly detection method, apparatus, device and medium. Background Technology
[0002] Currently, in the context of multi-source and dispersed data scenarios, anomaly detection needs to complete statistical aggregation and model discrimination without distributing the original data. At the same time, it needs to adapt to the distribution differences of different data subgroups and the drift over time. In actual business, common issues include data heterogeneity, uneven sample size, communication limitations, and compliance constraints, which directly affect the stability and timeliness of anomaly detection.
[0003] Currently, anomaly detection generally adopts a unified modeling and centralized release approach. This means that within the scope of compliance, processed data is collected to train a unified detection model, and then the same strategy is implemented on each business side. This can easily lead to problems such as alarm fluctuations, adaptation delays, frequent parameter maintenance, and limited release rhythm when there are large differences in data sources and frequent changes in business conditions. In this way, it can affect the continuity and predictability of the production process.
[0004] The existing technical solutions mentioned above have the following drawbacks: in an environment where data is scattered and subject to compliance restrictions, unified modeling is difficult to continuously provide stable and timely anomaly detection output without externalizing data, and therefore there is room for improvement. Summary of the Invention
[0005] The purpose of this invention is to provide a clustered federated privacy anomaly detection method, apparatus, device, and medium to solve the technical problem that unified modeling is unable to continuously provide stable and timely anomaly detection output without external data transmission in an environment where data is dispersed and subject to compliance restrictions.
[0006] To achieve the above objectives, the present invention adopts the following technical solution: In a first aspect, the present invention provides a clustered federated privacy anomaly detection method, the method comprising: Ciphertext statistics are obtained from the edge side, and the ciphertext statistics are aggregated to obtain authorized decryption of the aggregation result, thus obtaining global cluster statistics; Based on global cluster statistics, the corresponding cluster centers are updated under preset center update constraints to generate convergent cluster centers and cluster identifiers. Establish a cluster model based on the cluster identifier, and send the initial parameters and protected update constraints corresponding to the cluster model to the edge side; The protected increments generated based on the protected update constraints are received in real time. The protected increments are then securely aggregated by cluster to obtain the model update parameters. The cluster model is then updated based on the model update parameters. Obtain anomaly detection requests, select the corresponding cluster model based on the convergence cluster center to process the anomaly detection requests, and generate anomaly detection results.
[0007] By adopting the above technical solutions, and by obtaining encrypted statistics from the edge and authorizing the decryption of only the aggregation results, global cluster statistics can be obtained without disclosing the original data, thus completely restoring the cluster distribution information under compliance constraints. By updating the cluster center and generating converged cluster centers and cluster identifiers based on the global cluster statistics under preset center update constraints, center jitter can be reduced and data subgroups can be stably characterized, thus providing a reliable basis for subsequent cluster modeling. By establishing cluster models based on cluster identifiers and issuing initial parameters and protected update constraints, the training and protection criteria of each cluster can be unified, thus ensuring the executability and traceability of the cluster training process. By receiving protected increments in real time and performing secure aggregation by cluster to obtain model update parameters and update cluster models, the effectiveness of the model can be continuously improved without disclosing individual information, thus maintaining the model's adaptability to scene changes. By obtaining anomaly discrimination requests and selecting the corresponding cluster model for processing based on the converged cluster center, targeted discrimination can be performed by data subgroups, thereby improving the stability and accuracy of anomaly detection results.
[0008] In one example, the present invention can be further configured to: obtain ciphertext statistics from the edge side and aggregate the ciphertext statistics to authorize decryption of the aggregated results, thereby obtaining global cluster statistics, including: Obtain the preset security encapsulation specification and receive ciphertext statistics that are consistent with the security encapsulation specification; Perform a consistency check on the encrypted statistics, and after passing the consistency check, aggregate the encrypted statistics to obtain the aggregated result. The aggregation results are authorized for decryption. In the event of a decryption exception, a rollback is triggered and re-aggregation is performed until global cluster statistics are obtained.
[0009] By adopting the above technical solution, by obtaining the preset confidential encapsulation specification and only receiving ciphertext statistics that are consistent with the specification, aggregating them after the consistency verification is passed, and performing authorized decryption on the aggregation results until the global cluster statistics are obtained, an end-to-end encrypted reception and controlled decryption process can be formed, thereby ensuring the correctness and security of statistical aggregation and providing reliable input for central updates.
[0010] In one example, the present invention can be further configured as follows: authorizing the decryption of the aggregation result, triggering a rollback and re-aggregation in the event of a decryption exception, until the global cluster statistics are obtained, includes: Based on a preset multi-party authorization mechanism, several authorization entities are configured and corresponding authorization quantity thresholds are set. Authorization session identifiers are generated based on the participation data during the aggregation process. If the number of authorized entities of the authorized entity reaches the authorization quantity threshold and passes the authorization consistency check, joint decryption is performed on the aggregation result to obtain the aggregated plaintext corresponding to this aggregation process; If the number of authorized entities of the authorized entity does not reach the authorization quantity threshold or the authorization consistency verification fails, the authorization session information is recorded and a rollback is triggered until the corresponding aggregated plaintext is obtained; The global cluster statistics are generated based on the aggregated plaintext.
[0011] By adopting the above technical solutions, and configuring several authorized entities based on a preset multi-party authorization mechanism and setting an authorization quantity threshold, and generating authorization session identifiers based on the data participating in the aggregation process, the decryption process can be constrained on a session-by-session basis, and the boundaries of participants and versions can be clearly defined, thereby improving the traceability and anti-impersonation capabilities of the authorization process. By performing joint decryption on the aggregation result only when the number of agreed authorized entities reaches the authorization quantity threshold and passes the authorization consistency check, single-point authorization and unauthorized decryption can be prevented, and the consistency between the aggregated plaintext and batch information can be guaranteed, thereby improving the security and data integrity of the decryption process. By recording the authorization session information and triggering rollback when the threshold is not reached or the consistency check fails, and re-performing consistency verification and ciphertext field aggregation before re-authorization, the process can be restored to the verifiable previous step in abnormal situations and ensure that a legitimate aggregated plaintext is finally obtained, thereby enhancing the robustness and availability of the process. By generating global cluster statistics based on the aggregated plaintext, a reliable input can be provided for subsequent cluster center updates and cluster-by-cluster modeling, thereby stably supporting the accuracy and continuity of the anomaly detection link.
[0012] In one example, the present invention can be further configured to: update the corresponding cluster center according to global cluster statistics under a preset center update constraint, and generate a convergent cluster center and a cluster identifier, including: Each cluster statistical item in the global cluster statistics is used as the central reference data to generate update candidates for the current round of cluster centers; The update candidates are normalized according to the center update constraint to obtain standard update candidates. The change magnitude of the standard update candidates is compared with that of the previous round of cluster centers. If the change magnitude is lower than the magnitude threshold of the center update constraint, the convergent cluster center is determined and a corresponding cluster identifier is generated for the convergent cluster center.
[0013] By adopting the above technical solution, center update candidates are generated by using the statistical items of each cluster in the global cluster statistics, and normalization and amplitude threshold comparison are performed under the center update constraint to determine the convergent cluster center and generate cluster identifier. This can effectively suppress center drift caused by small samples and noise, thereby obtaining a more stable cluster characterization and reducing the accumulation of subsequent routing errors.
[0014] In one example, the present invention can be further configured to: establish a cluster model based on the cluster identifier, and distribute the initial parameters and protected update constraints corresponding to the cluster model to the edge side, including: Create a cluster model entry using the cluster identifier as the index, write the parameter structure definition and initial parameters into the cluster model entry, and register the corresponding model identifier and version information to obtain the cluster model; Obtain the preset protected update constraints, associate the protected update constraints with the adapted cluster model, and then send the initial parameters and protected update constraints to the edge side.
[0015] By adopting the above technical solution, the process of establishing and publishing clustered models can be standardized by creating cluster model entries with cluster identifiers as indexes, writing parameter structures and initial parameters, registering model identifiers and version information, associating protected update constraints with cluster models and distributing them, thereby ensuring parameter alignment and constraint consistency in the subsequent training and inference stages.
[0016] In one example, the present invention can be further configured to: receive protected increments generated according to protected update constraints in real time, perform secure aggregation of the protected increments by cluster to obtain model update parameters, and then update the cluster model according to the model update parameters, including: Receive the protected increment, perform source verification and version verification on the protected increment, and obtain the verification increment after the verification passes. The verification increments are grouped according to the cluster identifiers to obtain a cluster candidate increment set; The mask pairing relationship of the cluster candidate increment set is checked according to the protected update constraint, and the aggregateable increment set is obtained if the check passes. Securely aggregate the aggregatable incremental set by cluster to obtain the model update parameters; The corresponding cluster model is updated according to the model update parameters, and the updated model version information is registered. The updated model version information is then associated with the corresponding cluster identifier and the converged cluster center.
[0017] By adopting the above technical solution, after verifying the source and version of the protected increments, clustering and aggregating them, completing mask pairing verification according to the protected update constraints, and performing secure aggregation to obtain model update parameters, and updating the cluster model and registered version information accordingly, robust updates by cluster can be achieved while ensuring privacy and consistency, thereby improving the reliability and traceability of model evolution.
[0018] In one example, the present invention can be further configured to: obtain an anomaly detection request, select the corresponding cluster model based on the convergence cluster center to process the anomaly detection request, and generate anomaly detection results, including: Receive an anomaly detection request and obtain the request data to be detected; Based on the convergence cluster center, the cluster-level affiliation of the requested data is determined to obtain the target cluster identifier; Select the corresponding cluster model based on the target cluster identifier, process the requested data, and obtain the anomaly detection results.
[0019] By adopting the above technical solution, after receiving anomaly discrimination requests and completing the cluster-level affiliation determination based on the convergent cluster center, the corresponding cluster model is selected for processing. This enables the discrimination process to be self-adapted to the characteristics of data subgroups, thereby obtaining anomaly detection results that are closer to the business distribution and reducing false alarms and missed alarms.
[0020] In a second aspect, the present invention provides a clustered federated privacy anomaly detection device, the device comprising: The statistics aggregation module is used to obtain encrypted statistics from the edge side, aggregate the encrypted statistics to authorize and decrypt the aggregation results, and obtain global cluster statistics. The center update module is used to update the corresponding cluster center according to the global cluster statistics under the preset center update constraint, and generate converged cluster center and cluster identifier; The model distribution module is used to establish a cluster model based on the cluster identifier and distribute the initial parameters and protected update constraints corresponding to the cluster model to the edge side. The incremental aggregation module is used to receive protected increments generated according to the protected update constraints in real time, perform secure aggregation of the protected increments by cluster to obtain model update parameters, and then update the cluster model according to the model update parameters; The anomaly detection module is used to obtain anomaly detection requests, select the corresponding cluster model according to the convergence cluster center to process the anomaly detection requests, and generate anomaly detection results.
[0021] By adopting the above technical solutions, and by obtaining encrypted statistics from the edge and authorizing the decryption of only the aggregation results, global cluster statistics can be obtained without disclosing the original data, thus completely restoring the cluster distribution information under compliance constraints. By updating the cluster center and generating converged cluster centers and cluster identifiers based on the global cluster statistics under preset center update constraints, center jitter can be reduced and data subgroups can be stably characterized, thus providing a reliable basis for subsequent cluster modeling. By establishing cluster models based on cluster identifiers and issuing initial parameters and protected update constraints, the training and protection criteria of each cluster can be unified, thus ensuring the executability and traceability of the cluster training process. By receiving protected increments in real time and performing secure aggregation by cluster to obtain model update parameters and update cluster models, the effectiveness of the model can be continuously improved without disclosing individual information, thus maintaining the model's adaptability to scene changes. By obtaining anomaly discrimination requests and selecting the corresponding cluster model for processing based on the converged cluster center, targeted discrimination can be performed by data subgroups, thereby improving the stability and accuracy of anomaly detection results.
[0022] In a third aspect, the present invention provides an electronic device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the clustered federated privacy anomaly detection method described above.
[0023] In a fourth aspect, the present invention provides a storage medium having a computer program stored thereon, wherein the computer program, when executed by a processor, implements the steps of the clustered federated privacy anomaly detection method described above. Attached Figure Description
[0024] The accompanying drawings, which form part of this specification, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an undue limitation of the invention. In the drawings: Figure 1 This is a flowchart of a clustered federation privacy anomaly detection method in an embodiment of the present invention; Figure 2 This is a structural block diagram of the clustered federal privacy anomaly detection device according to an embodiment of the present invention; Figure 3 This is a structural block diagram of an electronic device according to an embodiment of the present invention. Detailed Implementation
[0025] The present invention will now be described in detail with reference to the accompanying drawings and embodiments. It should be noted that, unless otherwise specified, the embodiments and features described herein can be combined with each other.
[0026] The following detailed description is exemplary and intended to provide further detailed explanation of the invention. Unless otherwise specified, all technical terms used in this invention have the same meaning as commonly understood by one of ordinary skill in the art. The terminology used in this invention is for describing particular embodiments only and is not intended to limit the scope of exemplary embodiments according to the invention.
[0027] Example 1 like Figure 1 As shown, this invention discloses a clustered federated privacy anomaly detection method, which specifically includes the following steps: S10: Obtain ciphertext statistics from the edge side, aggregate the ciphertext statistics to authorize and decrypt the aggregated results, and obtain global cluster statistics.
[0028] Specifically, within a specified sampling batch, encrypted statistics from multiple participating sides are received and organized according to batch and time window. After source verification and integrity check are completed based on the identifier of the encrypted statistics, the corresponding aggregation operation is performed in the encrypted field to generate aggregated encrypted text. Only the aggregated encrypted text is authorized for decryption to obtain the combined statistics and count information of each cluster. The decrypted cluster statistics results are summarized to form global cluster statistics.
[0029] S20: Update the corresponding cluster center under the preset center update constraint based on the global cluster statistics, and generate the convergent cluster center and cluster identifier.
[0030] Specifically, the combined statistics and count information of each cluster in the global cluster statistics are used as the center reference data to generate the current round of center update candidates. The update candidates are controlled in terms of amplitude and step according to the preset center update constraints and compared with the changes of the previous round center. When the stopping condition is met, the converged cluster center is determined and a unique cluster identifier is generated for each converged cluster center.
[0031] S30: Establish a cluster model based on the cluster identifier, and send the initial parameters and protected update constraints corresponding to the cluster model to the edge side.
[0032] Specifically, cluster model entries are created according to cluster identifiers and written into parameter structure definitions and initial parameters. Simultaneously, model identifiers and version information are registered to obtain cluster models. Protected update constraints that match the cluster model are extracted from the configuration and a corresponding relationship is established with the cluster model. The initial parameters and protected update constraints are then distributed to the edge side according to the current release version.
[0033] S40: Receives protected increments generated based on protected update constraints in real time, performs secure aggregation of protected increments by cluster to obtain model update parameters, and then updates the cluster model based on the model update parameters.
[0034] Specifically, during the training process, protected increments generated and reported by the edge side based on protected update constraints are continuously received and merged according to cluster identifier and model version. After performing necessary compliance and consistency checks on the merging results based on protected update constraints, the protected increments within the same cluster are securely aggregated to obtain the model update parameters of that cluster, so as to update the model parameters of the corresponding cluster model.
[0035] S50: Obtain anomaly detection requests, select the corresponding cluster model based on the convergence cluster center to process the anomaly detection requests, and generate anomaly detection results.
[0036] Specifically, the system receives anomaly detection requests and parses the request data and associated metadata to be detected. Based on the convergence cluster center, it calculates the cluster-level affiliation of the request data to determine the target cluster identifier. It selects the cluster model corresponding to the target cluster identifier from the mapping set, performs a discrimination operation on the request data to generate anomaly detection results, and outputs the anomaly detection results along with the cluster identifier and model version used for business-side processing and recording.
[0037] In one embodiment, step S10, namely obtaining ciphertext statistics from the edge side and aggregating the ciphertext statistics to authorize decryption of the aggregation result, to obtain global cluster statistics, includes: S11: Obtain the preset security encapsulation specification and receive ciphertext statistics that are consistent with the security encapsulation specification.
[0038] Specifically, when receiving encrypted data according to the confidentiality encapsulation specification, the batch identifier and version identifier are first checked, and the consistency of the public key fingerprint is compared. Each participating side receives the global cluster center set initialized in the cloud locally. Then, the detection data vector x is processed. 2. Cutting Where R is the pruning threshold representing the maximum allowed norm of the uploaded vector, and ||x||2 is the vector's L2 norm, used to define sensitivity so that the Gaussian mechanism can be calibrated, followed by allocation based on the nearest center. ,in, Given the k-th center vector at the start of this iteration, the cumulative vector sum and count statistics for each cluster are obtained from the allocation results. and Here, i identifies the participating side or node, K identifies the cluster number, #{·} represents the cardinality count, and a differential privacy Gaussian mechanism is applied to the statistics to form... and in, The zero-mean covariance of d-dimensional vectors is Gaussian noise, For scalars with zero mean and variance: Gaussian noise, σ S σ N The noise standard deviation is calibrated by the privacy budget and sensitivity, Id is a d×d identity matrix, and then Paillier additive homomorphic encryption is performed element-wise to obtain the ciphertext. and Among them, Enc pk (·) represents a cryptographic operator executed with the public key pk, which supports subsequent ciphertext field summation without exposing the plaintext, and is sent and accepted according to specifications to obtain the received ciphertext statistics {U i,k V i,k}
[0039] S12: Perform consistency verification on the encrypted statistics. After passing the consistency verification, aggregate the encrypted statistics to obtain the aggregated result.
[0040] Specifically, the statistics of the ciphertext that have passed the consistency check are aggregated in the ciphertext domain by cluster to generate the aggregation result. The plaintext is then summed by using Paillier's additive homomorphic property through ciphertext multiplication. The superscript ⊕ serves only as a notation to distinguish data types after homomorphic aggregation and does not change the data type. After aggregation, the result is { , } k=1..K As an aggregation result of ciphertext, statistical summarization is achieved while maintaining key holding and minimum visibility requirements.
[0041] S13: Authorize and decrypt the aggregation result. If a decryption error occurs, trigger a rollback and re-aggregate until the global cluster statistics are obtained.
[0042] Specifically, authorized decryption is performed only on the aggregated ciphertext to obtain global cluster statistics. During the decryption phase, the decryption committee uses the private key sk and the decryption operator Dec. sk (·)calculate in, Represents the global vector sum of the k-th cluster in this batch. The superscript `sum` indicates that the summation across the participating sides has been completed on the plaintext domain, and the summation is collected by cluster. , } k=1..K The global cluster statistics are composed of clusters organized by clusters. K is the number of clusters, which is given by initialization or through the central update process. The output of this step is the global cluster statistics used for subsequent central update calculations.
[0043] In one embodiment, step S13 involves authorizing decryption of the aggregation result, triggering a rollback and re-aggregation in case of a decryption error, until global cluster statistics are obtained, including: S131: Based on a preset multi-party authorization mechanism, configure several authorization entities and set corresponding authorization quantity thresholds, and generate authorization session identifiers based on the participation data during the aggregation process.
[0044] Specifically, based on a preset multi-party authorization mechanism, several authorized entities are configured and an authorization quantity threshold is set. An authorization session is established using the current ciphertext aggregation result as the object, where the ciphertext aggregation result is a clustered homomorphic summation of { , The authorization session identifier corresponding to the batch is generated based on the homomorphic summation and registered in the session context of the authorization entity. The authorization session outputs the authorization session identifier and the cluster index set of the object to be decrypted.
[0045] S132: If the number of authorized entities reaches the authorization quantity threshold and the authorization consistency check is passed, perform joint decryption on the aggregation result to obtain the aggregation plaintext corresponding to this aggregation process.
[0046] Specifically, consent information from authorized entities is collected based on the authorized session identifier, and the number of consents is counted and compared with a threshold for the number of consents. If the number of consents reaches the threshold and passes the authorization consistency check, only the aggregated result is considered. and Perform joint decryption, through Perform decryption to obtain the aggregated plaintext corresponding to this aggregation process, where Decsk(·) represents the joint decryption operation triggered by the authorization set. Sum the plaintext of the aggregation vector for cluster k. The plaintext is used to aggregate sample counts for cluster k, while maintaining the correspondence with the cluster index k.
[0047] S133: If the number of authorized entities of an authorized entity does not reach the authorization quantity threshold or the authorization consistency verification fails, record the authorization session information and trigger a rollback until the corresponding aggregate plaintext is obtained.
[0048] Specifically, if the number of authorized entities does not reach the threshold or the authorization consistency check fails, the authorized entity list associated with the authorization session identifier, the reason for failure, and the timestamp are recorded, the current session is closed, and the process is rolled back to the state where the ciphertext statistical aggregation is complete. Then, the consistency check and ciphertext domain aggregation are re-executed to obtain a new result. and This process generates a new authorization session identifier and initiates authorization again, until the authorization is completed when the threshold and consistency conditions are met. and The joint decryption yields the corresponding aggregated plaintext.
[0049] S134: Generate global cluster statistics based on aggregated plaintext.
[0050] Specifically, based on the decrypted... and The data is combined to form global cluster statistics. For each cluster k, the vector summation and sample count are recorded, and the validity of the values and the consistency of the cluster index are checked. After the checks are passed, { , } k The global cluster statistics for this round are persistently stored, and a mapping relationship is established between the batch number, model version, and cluster identifier for subsequent cluster center updates and cluster-by-cluster modeling.
[0051] In one embodiment, step S20, namely updating the corresponding cluster center according to global cluster statistics under a preset center update constraint, and generating convergent cluster centers and cluster identifiers, includes: S21: Obtain the statistical items of each cluster in the global cluster statistics as the central reference data to generate the update candidate of the current round cluster center.
[0052] Specifically, the cluster vector sum and cluster count in the global cluster statistics are used as central reference data, and are denoted as follows: and Calculate the updated candidate centers for this round. First, a minimum cluster size threshold m is introduced to suppress fluctuations in small samples, and the denominator is then used... Implement lower bound protection and obtain Where k∈{1,…,K} is the cluster number, and K is the number of clusters. Let the sum of the global vectors of the k-th cluster in the current batch be denoted as . Here, m represents the corresponding global count, and m is the minimum cluster size threshold used to prevent center jitter caused by an excessively small denominator. To update the candidate centers after jitter reduction, the following calculations are performed for each cluster: } k=1..K .
[0053] S22: Normalize the update candidates according to the center update constraint to obtain standard update candidates. Compare the change magnitude of the standard update candidates with the cluster centers of the previous round. If the change magnitude is lower than the magnitude threshold of the center update constraint, determine the convergent cluster center and generate the corresponding cluster identifier for the convergent cluster center.
[0054] Specifically, upon obtaining updated candidates A smoothing coefficient α∈(0,1] is then introduced to smooth the center update in order to limit the magnitude of single-step change, and the center of the previous round is updated. The convex combination of this round of candidates yields Subsequently, based on the convergence criterion of the L2 norm change, the stopping condition is simultaneously detected for all clusters. If the condition is satisfied... Then determine the set of convergent cluster centers for this round { } k=1..K The output results are configured with a corresponding cluster identifier k for each convergence center, where ε c >0 is the convergence threshold used to limit the upper limit of the center displacement. α controls the step size and smoothing intensity to achieve a balance between stability and responsiveness. If the criterion is not met, the next iteration is started with t←t+1 until the stopping condition is met.
[0055] In one embodiment, step S30, namely establishing a cluster model based on the cluster identifier and distributing the initial parameters and protected update constraints corresponding to the cluster model to the edge side, includes: S31: Create a cluster model entry using the cluster identifier as the index, write the parameter structure definition and initial parameters into the cluster model entry, and register the corresponding model identifier and version information to obtain the cluster model.
[0056] Specifically, a cluster model entry is created using the cluster identifier k as an index, and the cluster model is obtained. The parameter structure of this cluster model is defined as a vector θ. k ∈R p Let the agreed-upon parameter dimension and hierarchical mapping relationship be denoted as θ0 for the global initialization parameter and θ for the published parameter at the beginning of the current training round. (t-1) Write the initial parameters of this cluster as =θ (t-1) And register the model identifier ID. k With version number Record and convergence cluster center c k The correspondence between the data and timestamps, along with parameter checksums, is used to ensure consistency and traceability across batches, while also specifying the function notation f for the cluster model. k (·;θ k This serves as the computational carrier for subsequent training and discrimination, and completes the persistence of entries, thus forming a cluster model that can be referenced and updated.
[0057] S32: Obtain the preset protected update constraints, associate the protected update constraints with the adapted cluster model, and then send the initial parameters and protected update constraints to the edge side.
[0058] Specifically, after obtaining the preset protected update constraints and establishing a one-to-one correspondence with the cluster model, the constraints are distributed. The protected update constraints provide the protection and verification criteria for the upload increment during the training period. First, the parameter pruning radius C>0 is given to limit the maximum norm of the upload vector. For the parameters of client i in the t-th round after local training in cluster k, implement 2. Cutting C is used to suppress amplitude anomalies in one-end updates to unify sensitivity; subsequently, the local differential privacy noise intensity σ is set. θ >0 and add Gaussian noise to the clipped parameters. in, The zero mean covariance is A Gaussian distribution is used, and I is the identity matrix, to achieve calibrable randomization protection under a given privacy budget; then, pairing and consistency rules for masked secure aggregation are defined to generate an additive mask for each participating side. And construct the upload object At the same time, it requires participants in the current round to join the group. The above satisfies zero-sum consistency To ensure that the masks cancel each other out after aggregation without exposing individual updates, the constraint also defines the number of valid samples n in the current round.i,k and the total amount within the cluster This serves as the standard for subsequent aggregation weights, and provides verification fields for version alignment and batch identification to ensure that uploaded objects under the same release version can be correctly merged. Ultimately, this will be integrated with the cluster model idk. ,ck corresponds to the initial parameters The aforementioned protected update constraints will be issued and take effect as a whole.
[0059] In one embodiment, step S40 involves receiving protected increments generated based on protected update constraints in real time, performing secure aggregation of the protected increments by cluster to obtain model update parameters, and then updating the cluster model based on the model update parameters, including: S41: Receive the protected increment, perform source verification and version verification on the protected increment, and obtain the verification increment after the verification passes.
[0060] Specifically, the protected increment generated and reported by the edge side in round t according to the protected update constraints is received. For each record, the source signature, batch identifier, and model version number are verified, and the cluster identifier k is compared to the target cluster. After verifying the parameter dimensions and numerical encoding according to the field integrity, it is marked as a protected increment that has passed the verification. The protected increment is composed of parameters after local pruning and local differential privacy. With additive mask Superimposed Where, subscript i represents the participating side number, superscript (t) represents the t-th round, and k represents the cluster number. After verification, the process enters the merging process.
[0061] S42: The verification increments are aggregated according to the cluster identifier to obtain a cluster candidate increment set.
[0062] Specifically, based on the cluster identifier k and the model version number, the verified protected increments are grouped by cluster and version to form a clustered candidate increment set { | Then, the records in the set are deduplicated and aligned in batches, and the number of valid samples n for each participating side in this round is extracted. i,k With Participation Set and its total amount within the cluster As a statistical caliber required for subsequent aggregation and weighting, it ensures that data from the same cluster and version within the same round is viewed... Figure 1 After that, proceed to the matching and verification.
[0063] S43: Verify the mask pairing relationship of the cluster candidate increment set according to the protected update constraint, and obtain the aggregateable increment set if the verification is successful.
[0064] Specifically, the mask pairing relationship of the clustering candidate increment set is checked to ensure the executability and correctness of safe aggregation, and the participating set in the current round is verified. Verify that the mask generation and cancellation records are paired and batch-consistent, and confirm that the zero-sum consistency condition is met. When passing through, the set is marked as an aggregatable incremental set, and it is confirmed that no single-ended mask value needs to be explicitly revealed during aggregation. Since the zero-sum condition is met, the protected sum after aggregation will be equivalent to each end. The weighted sum does not reveal individual updates.
[0065] S44: Perform secure aggregation of the aggregatable incremental set by cluster to obtain the model update parameters.
[0066] Specifically, secure aggregation is performed on the aggregatable incremental set by cluster to obtain the model update parameters for that cluster in round t. Weighted aggregation based on the number of valid samples is used to reflect the contribution of different participants to this round of updates. The specific calculation is as follows: Where η>0 is the global aggregation step size coefficient used to control the update scale, n i,k N represents the number of valid samples in cluster k for participant i in the current round. k This represents the total number of samples in that round for that cluster. For the local parameters or parameter increments that have been pruned and noise-added, the above weighted aggregation can be performed without revealing the one-sided plaintext, using the zero-sum mask property, to obtain the model update parameters. .
[0067] S45: Update the corresponding cluster model according to the model update parameters, register the updated model version information, and associate the updated model version information with the corresponding cluster identifier and converged cluster center.
[0068] Specifically, the model update parameters are applied to the corresponding cluster model to complete the parameter update and register the new version information, specifically by... Update the cluster model parameter vector θ k Generate version number Record the effective timestamp and the cluster identifier k and its convergent cluster center c. k The association relationships are used for subsequent routing and audit tracing, while also saving the set of participants in this round. Sample diameter {n i,k N k A metadata snapshot of the step size coefficient η is used to ensure that the update history is verifiable. After completion, the updated cluster model and corresponding version information are output.
[0069] In one embodiment, in step S50, namely obtaining an anomaly detection request, selecting the corresponding cluster model based on the convergence cluster center to process the anomaly detection request, and generating an anomaly detection result, including: S51: Receives an anomaly detection request and obtains the request data to be detected.
[0070] Specifically, after receiving the anomaly detection request, the original observation sequence and associated metadata are parsed and transformed into a feature vector x according to the consistent window and feature caliber of the training phase. Specifically, the time window length and step size are aligned to obtain the segment y. The statistics and frequency domain quantities are extracted through the same preprocessing mapping Φ(·) and standardized according to the training mean and standard deviation: x=Norm(Φ(y))=(Φ(y)). μ) σ, where μ and σ are the mean and standard deviation of the features registered during training. This indicates that the components are divided, and the result is the request data vector x to be judged.
[0071] S52: Determine the cluster-level affiliation of the requested data based on the convergence cluster center to obtain the target cluster identifier.
[0072] Specifically, based on the converged set of cluster centers {ck} k=1..K Perform the nearest center route determination for x and calculate... Determine the target cluster identifier k, where K is the number of clusters. When there is an equidistant situation, disambiguation is performed according to a fixed order or the most recently updated timestamp to ensure single-value output. Thus, the target cluster identifier k used for subsequent discrimination is obtained.
[0073] S53: Select the corresponding cluster model based on the target cluster identifier, process the requested data, and obtain the anomaly detection result.
[0074] Specifically, the corresponding cluster model f is selected according to the target cluster identifier k. k (· ;θ k And perform forward computation on x to obtain the anomaly correlation score s=f k (x ;θ k ), where θ k Here are the cluster model parameters for the current release version, where p is the parameter dimension, followed by the cluster's operating threshold τ. k The comparison provides a binary decision r=1[ s≥τ k Alternatively, output interval levels to meet business requirements, and simultaneously use (r,s,k,ver(k)) as the judgment result for this time, along with the model version information used, to form an output record.
[0075] Example 2 like Figure 2 As shown, based on the same inventive concept as the above embodiments, the present invention also provides a clustered federated privacy anomaly detection device, comprising: The statistics aggregation module is used to obtain encrypted statistics from the edge side, aggregate the encrypted statistics, and authorize the decryption of the aggregation results to obtain global cluster statistics. The center update module is used to update the corresponding cluster center according to the global cluster statistics under the preset center update constraints, and generate the converged cluster center and cluster identifier. The model distribution module is used to build a cluster model based on the cluster identifier and distribute the initial parameters and protected update constraints corresponding to the cluster model to the edge side. The incremental aggregation module is used to receive protected increments generated according to the protected update constraints in real time, perform secure aggregation of the protected increments by cluster to obtain model update parameters, and then update the cluster model according to the model update parameters; The anomaly detection module is used to obtain anomaly detection requests, select the corresponding cluster model based on the convergence cluster center to process the anomaly detection requests, and generate anomaly detection results.
[0076] Optionally, the statistical aggregation module includes: The encapsulation receiving submodule is used to obtain the preset security encapsulation specification and receive ciphertext statistics that are consistent with the security encapsulation specification; The aggregation and verification submodule is used to perform consistency verification on the encrypted statistics. After passing the consistency verification, the encrypted statistics are aggregated to obtain the aggregation result. The authorization and decryption submodule is used to authorize and decrypt the aggregation results. In the event of a decryption exception, it triggers a rollback and re-aggregation until the global cluster statistics are obtained.
[0077] Optionally, the authorized decryption submodule includes: The authorization session submodule is used to configure several authorization entities and set corresponding authorization quantity thresholds based on a preset multi-party authorization mechanism, and generate authorization session identifiers based on the participation data in the aggregation process; The joint decryption submodule is used by the joint decryption module to perform joint decryption on the aggregation result when the number of authorized entities of the authorized entity reaches the authorization quantity threshold and passes the authorization consistency check, so as to obtain the aggregated plaintext corresponding to this aggregation process; The rollback and re-aggregation submodule is used to record authorization session information and trigger rollback when the number of authorized entities of the authorized entity does not reach the authorization quantity threshold or the authorization consistency verification fails, until the corresponding aggregated plaintext is obtained; The cluster statistics generation submodule is used to generate the global cluster statistics based on the aggregated plaintext.
[0078] Optionally, the central update module includes: The candidate generation submodule is used to obtain the statistical items of each cluster in the global cluster statistics as the center reference data and generate the update candidates of the current round of cluster centers. The convergence determination submodule is used to normalize the update candidates according to the center update constraint to obtain standard update candidates. The standard update candidates are compared with the change magnitude of the previous round cluster centers. If the change magnitude is lower than the magnitude threshold of the center update constraint, the convergent cluster center is determined and a corresponding cluster identifier is generated for the convergent cluster center.
[0079] Optionally, the model distribution module includes: The model archiving submodule is used to create cluster model entries with cluster identifiers as indexes. The parameter structure definition and initial parameters are written into the cluster model entries, and the corresponding model identifier and version information are registered to obtain the cluster model. The constraint association submodule is used to obtain the preset protected update constraints, associate the protected update constraints with the adapted cluster model, and then send the initial parameters and protected update constraints to the edge side.
[0080] Optionally, the incremental aggregation module includes: The incremental verification submodule is used to receive the protected increment, perform source verification and version verification on the protected increment, and obtain the verification increment after the verification passes. The clustering and aggregation submodule is used to aggregate the verification increments according to the cluster identifier to obtain a clustered candidate increment set; The mask verification submodule is used to verify the mask pairing relationship of the cluster candidate increment set according to the protected update constraint, and obtain the aggregateable increment set if the verification is successful. The secure aggregation submodule is used to securely aggregate the aggregatable incremental set by cluster to obtain the model update parameters; The version registration submodule updates the corresponding cluster model according to the model update parameters, registers the updated model version information, and associates the updated model version information with the corresponding cluster identifier and converged cluster center.
[0081] Optionally, the anomaly detection module includes: The request access submodule is used to receive exception detection requests and obtain the request data to be detected; The cluster routing submodule is used to determine the cluster-level affiliation of the requested data based on the converged cluster center and obtain the target cluster identifier. The model discrimination submodule is used to select the corresponding cluster model based on the target cluster identifier, process the request data, and obtain the anomaly detection results.
[0082] Example 3 like Figure 3 As shown, the present invention also provides an electronic device 100 for implementing a clustered federated privacy anomaly detection method; The electronic device 100 includes a memory 101, at least one processor 102, a computer program 103 stored in the memory 101 and executable on at least one processor 102, and at least one communication bus 104.
[0083] The memory 101 can be used to store computer program 103. The processor 102 implements the steps of the clustered federal privacy anomaly detection method of Embodiment 1 by running or executing the computer program stored in the memory 101 and calling the data stored in the memory 101.
[0084] The memory 101 may primarily include a program storage area and a data storage area. The program storage area may store the operating system, application programs required for at least one function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created based on the use of the electronic device 100 (such as audio data), etc. In addition, the memory 101 may include non-volatile memory, such as hard disk, RAM, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other non-volatile solid-state storage device.
[0085] At least one processor 102 may be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Processor 102 may be a microprocessor or any conventional processor. Processor 102 is the control center of electronic device 100, connecting various parts of electronic device 100 via various interfaces and lines.
[0086] The memory 101 in the electronic device 100 stores multiple instructions to implement a clustered federated privacy anomaly detection method, and the processor 102 can execute multiple instructions to achieve the following: Ciphertext statistics are obtained from the edge side, and the ciphertext statistics are aggregated to obtain authorized decryption of the aggregation result, thus obtaining global cluster statistics; Based on global cluster statistics, the corresponding cluster centers are updated under preset center update constraints to generate convergent cluster centers and cluster identifiers. Establish a cluster model based on the cluster identifier, and send the initial parameters and protected update constraints corresponding to the cluster model to the edge side; The protected increments generated based on the protected update constraints are received in real time. The protected increments are then securely aggregated by cluster to obtain the model update parameters. The cluster model is then updated based on the model update parameters. Obtain anomaly detection requests, select the corresponding cluster model based on the convergence cluster center to process the anomaly detection requests, and generate anomaly detection results.
[0087] Example 4 If the modules / units integrated in the electronic device 100 are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, and read-only memory (ROM).
[0088] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0089] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0090] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0091] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0092] In the description of this specification, references to terms such as "an embodiment," "example," "specific example," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0093] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that modifications or equivalent substitutions can still be made to the specific implementation of the present invention. Any modifications or equivalent substitutions that do not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.
Claims
1. A clustering federated privacy-preserving anomaly detection method, characterized in that, The method comprises: obtaining ciphertext statistics from the edge side, aggregating the ciphertext statistics to authorize decryption of the aggregation result to obtain global cluster statistics; updating the corresponding cluster center under a preset center update constraint according to the global cluster statistics to generate a converged cluster center and a cluster identifier; establishing a cluster model according to the cluster identifier, and distributing initial parameters and protected update constraints of the cluster model to the edge side; receiving a protected increment generated according to the protected update constraint in real time, securely aggregating the protected increment by cluster to obtain model update parameters, and then updating the cluster model according to the model update parameters; obtaining an anomaly discrimination request, processing the anomaly discrimination request according to the corresponding cluster model selected according to the converged cluster center to generate an anomaly detection result.
2. The cluster-based federated privacy-preserving anomaly detection method of claim 1, wherein, The method of obtaining ciphertext statistics from the edge side and aggregating the ciphertext statistics to authorize decryption of the aggregation result to obtain global cluster statistics comprises: obtaining a preset secure packaging specification, and receiving the ciphertext statistics consistent with the secure packaging specification; performing consistency verification on the ciphertext statistics, and aggregating the ciphertext statistics after passing the consistency verification to obtain an aggregation result; authorizing decryption of the aggregation result, triggering rollback and re-aggregation in the case of decryption exception until the global cluster statistics are obtained.
3. The cluster-based federated privacy-preserving anomaly detection method of claim 2, wherein, The method of authorizing decryption of the aggregation result, triggering rollback and re-aggregation in the case of decryption exception until the global cluster statistics are obtained comprises: based on a preset multi-party authorization mechanism, configuring a plurality of authorization entities and setting a corresponding authorization quantity threshold, and generating an authorization session identifier according to the participating data in the aggregation process; in the case that the number of authorization entities of the authorization entity reaches the authorization quantity threshold and passes the authorization consistency check, performing joint decryption on the aggregation result to obtain an aggregation plaintext corresponding to the current aggregation process; in the case that the number of authorization entities of the authorization entity does not reach the authorization quantity threshold or the authorization consistency check does not pass, recording authorization session information and triggering rollback until the corresponding aggregation plaintext is obtained; generating the global cluster statistics according to the aggregation plaintext. 4.The cluster-based federated privacy-preserving anomaly detection method of claim 1, wherein, The method of updating the corresponding cluster center under a preset center update constraint according to the global cluster statistics to generate a converged cluster center and a cluster identifier comprises: obtaining each cluster statistical item in the global cluster statistics as center reference data to generate an update candidate of the cluster center of this round; normalizing the update candidate according to the center update constraint to obtain a standard update candidate, comparing the standard update candidate with the cluster center of the last round in terms of change amplitude, and determining the converged cluster center in the case that the change amplitude is lower than an amplitude threshold of the center update constraint, and generating a corresponding cluster identifier for the converged cluster center.
5. The cluster-based federated privacy-preserving anomaly detection method of claim 1, wherein, The method of establishing a cluster model according to the cluster identifier, and distributing initial parameters and protected update constraints of the cluster model to the edge side comprises: creating a cluster model entry with the cluster identifier as an index, writing parameter structure definition and initial parameters in the cluster model entry, and registering corresponding model identifier and version information to obtain the cluster model; Obtain a preset protected update constraint, associate the protected update constraint with an adapted cluster model, and then distribute the initial parameters and the protected update constraint to the edge side under the protected update constraint.
6. The cluster-based federated privacy-preserving anomaly detection method of claim 1, wherein, The real-time receiving generates a protected increment according to the protected update constraint, securely aggregates the protected increment by cluster to obtain model update parameters, and then updates the cluster model according to the model update parameters, including: Receiving the protected increment, performing source verification and version verification on the protected increment, and obtaining a verification increment after the verification passes; According to the cluster identifier, the verification increment is collected to obtain a clustering candidate increment set; According to the protected update constraint, the mask pairing relationship of the clustering candidate increment set is checked, and a set of aggregable increments is obtained if the check passes; The aggregable increment set is securely aggregated by cluster to obtain the model update parameter; According to the model update parameter, the corresponding cluster model is updated, and the updated model version information is associated with the corresponding cluster identifier and the converged cluster center.
7. The cluster-based federated privacy-preserving anomaly detection method of claim 1, wherein, The device includes: The statistical aggregation module is configured to obtain ciphertext statistics from the edge side, aggregate the ciphertext statistics to authorize decryption of the aggregation result, and obtain global cluster statistics; The center update module is configured to update the corresponding cluster center under a preset center update constraint according to the global cluster statistics, generate a converged cluster center and a cluster identifier; The model distribution module is configured to establish a cluster model according to the cluster identifier, and distribute the initial parameters and the protected update constraint corresponding to the cluster model to the edge side; 8. A clustered federated privacy-preserving anomaly detection apparatus, comprising: The increment aggregation module is configured to real-time receive a protected increment generated according to the protected update constraint, securely aggregate the protected increment by cluster to obtain model update parameters, and then update the cluster model according to the model update parameters; The anomaly discrimination module is configured to obtain an anomaly discrimination request, select the corresponding cluster model according to the converged cluster center, process the anomaly discrimination request, and generate an anomaly detection result. The device includes: The statistical aggregation module is configured to obtain ciphertext statistics from the edge side, aggregate the ciphertext statistics to authorize decryption of the aggregation result, and obtain global cluster statistics; The center update module is configured to update the corresponding cluster center under a preset center update constraint according to the global cluster statistics, generate a converged cluster center and a cluster identifier; The model distribution module is configured to establish a cluster model according to the cluster identifier, and distribute the initial parameters and the protected update constraint corresponding to the cluster model to the edge side; 9. An electronic device, comprising: The increment aggregation module is configured to real-time receive a protected increment generated according to the protected update constraint, securely aggregate the protected increment by cluster to obtain model update parameters, and then update the cluster model according to the model update parameters; 10. A computer-readable storage medium, characterized in that, The anomaly discrimination module is configured to obtain an anomaly discrimination request, select the corresponding cluster model according to the converged cluster center, process the anomaly discrimination request, and generate an anomaly detection result. The device includes: The statistical aggregation module is configured to obtain ciphertext statistics from the edge side, aggregate the ciphertext statistics to authorize decryption of the aggregation result, and obtain global cluster statistics; The center update module is configured to update the corresponding cluster center under a preset center update constraint according to the global cluster statistics, generate a converged cluster center and a cluster identifier; The model distribution module is configured to establish a cluster model according to the cluster identifier, and distribute the initial parameters and the protected update constraint corresponding to the cluster model to the edge side; The increment aggregation module is configured to real-time receive a protected increment generated according to the protected update constraint, securely aggregate the protected increment by cluster to obtain model update parameters, and then update the cluster model according to the model update parameters; The anomaly discrimination module is configured to obtain an anomaly discrimination request, select the corresponding cluster model according to the converged cluster center, process the anomaly discrimination request, and generate an anomaly detection result. The device includes: The statistical aggregation module is configured to obtain ciphertext statistics from the edge side, aggregate the ciphertext statistics to authorize decryption of the aggregation result, and obtain global cluster statistics; The center update module is configured to update the corresponding cluster center under a preset center update constraint according to the global cluster statistics, generate a converged cluster center and a cluster identifier; The model distribution module is configured to establish a cluster model according to the cluster identifier, and distribute the initial parameters and the protected update constraint corresponding to the cluster model to the edge side; The increment aggregation module is configured to real-time receive a protected increment generated according to the protected update constraint, securely aggregate the protected increment by cluster to obtain model update parameters, and then update the cluster model according to the model update parameters; The anomaly discrimination module is configured to obtain an anomaly discrimination request, select the corresponding cluster model according to the converged cluster center, process the anomaly discrimination request, and generate an anomaly detection result.