Traffic classification method and device, equipment, storage medium and product

By optimizing the initial perturbation and constructing the target model parameters, and by adopting a dual-objective optimization equation and a feature separation tuning mechanism, the vulnerability of deep learning models to backdoor attacks is solved, achieving efficient defense against backdoor attacks and accurate traffic classification.

CN121841669APending Publication Date: 2026-04-10PENG CHENG LAB
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-01
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Existing deep learning models are vulnerable to backdoor attacks, making it difficult to accurately classify traffic and effectively defend against them, thus posing a threat to system security.

Method used

By optimizing the initial perturbation, the target model parameters are constructed. A pre-defined traffic classification model is built by adopting a dual-objective optimization equation and a feature separation tuning mechanism, thereby enhancing the model's ability to defend against backdoor attacks.

Benefits of technology

It achieves efficient defense against backdoor attacks, ensures the accuracy and robustness of traffic classification, and reduces the risk of the model being attacked by backdoors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121841669A_ABST
    Figure CN121841669A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of deep learning, and discloses a traffic classification method and device, equipment, a storage medium and a product. According to the method, the to-be-classified traffic is obtained and then input into the preset traffic classification model, the traffic classification result is obtained, and the preset traffic classification model is constructed based on the target model parameter corresponding to the target disturbance carried by the original sample. According to the method and the device, the initial disturbance carried by the original sample is optimized, the corresponding target model parameter is obtained according to the obtained target disturbance, and the preset traffic classification model is constructed according to the target model parameter, so that the to-be-classified traffic can be classified through the preset traffic classification model, and an accurate traffic classification result is obtained; the disturbance is continuously optimized, so that the obtained preset traffic classification model can realize efficient defense of the backdoor attack.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of deep learning, in particular to a traffic classification method and device, equipment, storage medium and product. BACKGROUND

[0002] Traffic classifiers based on deep learning have been widely applied in the field of network security, providing an effective means for malicious traffic detection. Researchers have proposed various classification schemes based on different neural network architectures, such as using convolutional neural networks (CNN) and recurrent neural networks (RNN) models to achieve accurate identification of malicious traffic. However, such methods also inherit the inherent security flaws of deep learning models, particularly their vulnerability to backdoor attacks. Backdoor attacks inject hidden malicious functions into the model, causing the model to behave normally on normal traffic samples, but when input contains a specific trigger, the embedded backdoor is activated, causing the model output to be a maliciously manipulated misclassification result, thereby seriously threatening system security. Therefore, how to accurately obtain traffic classification results and effectively defend against backdoor attacks has become a pressing problem. SUMMARY

[0003] The main purpose of the present application is to provide a traffic classification method, device, equipment, storage medium and product, aiming to solve the technical problem of how to accurately obtain traffic classification results and effectively defend against backdoor attacks.

[0004] To achieve the above purpose, the present application provides a traffic classification method, which comprises the following steps: Obtaining traffic to be classified; Inputting the traffic to be classified into a preset traffic classification model to obtain a traffic classification result, the preset traffic classification model being constructed based on target model parameters corresponding to target perturbations carried by original samples.

[0005] Optionally, before the step of inputting the traffic to be classified into a preset traffic classification model to obtain a traffic classification result, the method further comprises: Training an initial traffic classification model based on original samples carrying initial perturbations, the initial traffic classification model corresponding to initial model parameters; Optimizing the initial perturbations through a double-target optimization equation during model training, and optimizing the initial model parameters according to the obtained target perturbations to obtain target model parameters; Constructing a preset traffic classification model based on the target model parameters.

[0006] Optionally, the double-target optimization equation comprises an upper optimization equation and a lower optimization equation. During model training, the initial perturbation is optimized using a bi-objective optimization equation, and the initial model parameters are optimized based on the obtained target perturbation to obtain the target model parameters, including: During model training, the risk measurement index variable corresponding to the initial traffic classification model is determined based on the true category corresponding to the original sample, the initial model parameters, and the model parameter variables. The lower-level optimization equation is constructed based on the risk metric variable, and the lower-level optimization equation is used to determine the target perturbation that maximizes the risk metric variable. The upper-level optimization equation is constructed based on the target perturbation, the true category, and the model parameter variables; The target model parameters are obtained by solving the lower-level optimization equation and the upper-level optimization equation.

[0007] Optionally, before constructing the preset traffic classification model based on the target model parameters, the method further includes: A weight optimization equation is constructed based on the Manhattan distance between the initial classifier weights and the classifier weight variables corresponding to the initial traffic classification model. The weight optimization equation is solved to obtain the target classifier weights; Accordingly, constructing a preset traffic classification model based on the target model parameters includes: A preset traffic classification model is constructed based on the target classifier weights and the target model parameters.

[0008] Optionally, constructing a preset traffic classification model based on the target model parameters includes: Construct a target traffic classification model based on the target model parameters; The original sample is input into the target traffic classification model to obtain the model's predicted category; Calculate the cross-entropy loss value between the true category and the model-predicted category; The cross-entropy loss value is used to determine whether the target traffic classification model has been trained, and the preset traffic classification model is determined based on the determination result.

[0009] Optionally, the step of determining whether the target traffic classification model has been trained successfully based on the cross-entropy loss value, and determining the preset traffic classification model based on the determination result, includes: If the cross-entropy loss value is greater than a preset threshold, a new perturbation is constructed; Return to the step of training the initial traffic classification model based on the original samples carrying the initial perturbation, until a new cross-entropy loss value is obtained that is less than or equal to the preset threshold, and use the new traffic classification model as the preset traffic classification model.

[0010] In addition, to achieve the above object, the present application also provides a traffic classification device, which comprises: a traffic acquisition module, configured to acquire traffic to be classified; a traffic classification module, configured to input the traffic to be classified into a preset traffic classification model to obtain a traffic classification result, wherein the preset traffic classification model is constructed based on target model parameters corresponding to target perturbations carried by original samples.

[0011] In addition, to achieve the above object, the present application also provides a traffic classification device, which comprises: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of the traffic classification method as described above.

[0012] In addition, to achieve the above object, the present application also provides a storage medium, which is a computer-readable storage medium, and the storage medium stores a computer program, wherein the computer program is executed by a processor to implement the steps of the traffic classification method as described above.

[0013] In addition, to achieve the above object, the present application also provides a computer program product, which comprises a computer program, wherein the computer program is executed by a processor to implement the steps of the traffic classification method as described above.

[0014] The present application acquires traffic to be classified, inputs the traffic to be classified into a preset traffic classification model to obtain a traffic classification result, and constructs the preset traffic classification model based on target model parameters corresponding to target perturbations carried by original samples. The present application optimizes initial perturbations carried by original samples, obtains corresponding target model parameters according to the obtained target perturbations, and constructs a preset traffic classification model according to the target model parameters, so as to classify the traffic to be classified by using the preset traffic classification model and obtain an accurate traffic classification result. Since the perturbations are continuously optimized, the preset traffic classification model obtained can efficiently defend against backdoor attacks. BRIEF DESCRIPTION OF DRAWINGS

[0015] The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate embodiments consistent with the present application and serve to explain the principles of the present application together with the specification.

[0016] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the accompanying drawings needed to be used in the embodiments or prior art description will be briefly introduced as follows. Obviously, those skilled in the art can obtain other drawings from these drawings without any creative effort.

[0017] Figure 1 Flowchart of a first embodiment of the traffic classification method of the present application; Figure 2 Flowchart of a second embodiment of the traffic classification method of the present application; Figure 3 Flowchart of a third embodiment of the traffic classification method of the present application; Figure 4 Block diagram of a first embodiment of the traffic classification device of the present application; Figure 5 Block diagram of a traffic classification device of the hardware running environment involved in the embodiment scheme of the present application.

[0018] The implementation, functional features and advantages of the present application will be further described with reference to the accompanying drawings in conjunction with the embodiments. DETAILED DESCRIPTION

[0019] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and do not limit the present application.

[0020] In order to better understand the technical solutions of the present application, the following will be described in detail in conjunction with the drawings and specific embodiments of the specification.

[0021] The main solution of the embodiment of the present application is: obtaining the traffic to be classified; inputting the traffic to be classified into a preset traffic classification model to obtain a traffic classification result, and the preset traffic classification model is constructed based on target model parameters corresponding to target perturbations carried by original samples.

[0022] Traffic classifiers based on deep learning have been widely used in the field of network security, providing an effective means for malicious traffic detection. Researchers have proposed various classification schemes based on different neural network architectures, such as using convolutional neural networks (CNN) and recurrent neural networks (RNN) models to achieve accurate identification of malicious traffic. However, such methods also inherit the inherent security flaws of deep learning models, especially the vulnerability to backdoor attacks. Backdoor attacks inject hidden malicious functions into the model, making the model behave normally on normal traffic samples, but when input contains a specific trigger, the embedded backdoor is activated, causing the model output to be maliciously manipulated and resulting in incorrect classification results, thereby seriously threatening system security.

[0023] The application obtains to-be-classified traffic, inputs the to-be-classified traffic into a preset traffic classification model, obtains a traffic classification result, and the preset traffic classification model is constructed based on target model parameters corresponding to target disturbance carried by an original sample. The application optimizes initial disturbance carried by the original sample, obtains corresponding target model parameters according to the obtained target disturbance, and constructs the preset traffic classification model according to the target model parameters, so that the to-be-classified traffic can be classified by the preset traffic classification model, and an accurate traffic classification result is obtained. Since the disturbance is continuously optimized, the obtained preset traffic classification model can efficiently defend against a backdoor attack.

[0024] It should be noted that the execution subject of the application can be a computing service device with data processing, network communication and program running functions, such as a computer.

[0025] Based on this, the application embodiment provides a traffic classification method, referring to Figure 1 , Figure 1 The flowchart of the first embodiment of the traffic classification method of the application is shown in FIG. 1.

[0026] In this embodiment, the traffic classification method comprises the following steps: Step S10: obtaining to-be-classified traffic.

[0027] It can be understood that the to-be-classified traffic refers to traffic that needs to be classified, and the traffic can be obtained from a network device, such as a router or a switch, and can be a data packet, a data stream or a session.

[0028] Step S20: inputting the to-be-classified traffic into a preset traffic classification model to obtain a traffic classification result, and the preset traffic classification model is constructed based on target model parameters corresponding to target disturbance carried by an original sample.

[0029] It should be understood that the to-be-classified traffic is input into the preset traffic classification model to obtain the traffic classification result, which can be classified according to application types, business functions, security risks, performance requirements, etc., to obtain corresponding traffic classification results.

[0030] In a specific implementation, the preset traffic classification model in this embodiment is constructed based on target model parameters corresponding to target disturbance carried by an original sample. In a feasible embodiment, the disturbance is effective when the initial disturbance is added to the original sample, because this phenomenon largely simulates the function of a backdoor trigger. The initial disturbance can be continuously optimized in this embodiment to reduce the risk of successful attack on the model by a backdoor, and corresponding target model parameters are obtained based on the target disturbance carried by the original sample. The parameters of the preset traffic classification model can be the target model parameters.

[0031] This embodiment acquires the traffic to be classified and then inputs it into a preset traffic classification model to obtain the traffic classification result. The preset traffic classification model is constructed based on the target model parameters corresponding to the target perturbation carried by the original sample. This embodiment optimizes the initial perturbation carried by the original sample and obtains the corresponding target model parameters based on the obtained target perturbation. Then, it constructs the preset traffic classification model based on the target model parameters. Thus, the preset traffic classification model can classify the traffic to be classified and obtain accurate traffic classification results. Because the perturbation is continuously optimized, the obtained preset traffic classification model can achieve efficient defense against backdoor attacks.

[0032] refer to Figure 2 , Figure 2 This is a flowchart illustrating the second embodiment of the traffic classification method of this application.

[0033] Based on the first embodiment described above, in this embodiment, before step S20, the method further includes: Step S01: Train the initial traffic classification model based on the original samples carrying the initial perturbation, wherein the initial traffic classification model corresponds to the initial model parameters.

[0034] Understandably, it is assumed that the perturbation is effective when the initial perturbation is added to the original sample, as this phenomenon largely mimics the function of a backdoor trigger. Let... For the original sample, For the initial disturbance, This is the prediction function for the initial traffic classification model. These are the initial model parameters corresponding to the initial traffic classification model. The true class of the original sample. The model predicts the class. Typically, the condition for an effective perturbation can be expressed as: .

[0035] It should be understood that in order to construct a more effective perturbation, the conditions in the above equations must be further constrained. The concept of a voting mechanism is adopted to achieve this goal. By jointly considering the predictions of the poisoned model and the fine-tuning model in the current round, the poisoned model is the initial flow classification model, and the fine-tuning model is the model that fine-tunes the parameters of the initial model corresponding to the initial flow classification model. A more effective initial perturbation δ should satisfy the following condition (1):

[0036]

[0037]

[0038] in is the model parameter of the current round of fine-tuning model. The first two terms in the equation ensure that the perturbation effectively modifies the original prediction result of each model, while the last term ensures that it effectively guides different models to produce consistent prediction results for the perturbed sample. If adding perturbation to the sample can change the original prediction results of different models and make their new prediction results consistent, it indicates that such perturbation is more meaningful.

[0039] For the original sample carrying the initial perturbation, i.e. the perturbed sample, the fine-tuning strategy should offset the impact of the perturbation. Specifically, when the poisoned model and the fine-tuned model produce the same erroneous prediction for the perturbed sample, it indicates the risk of a successful backdoor attack. Targeted fine-tuning should correct the prediction of the model for the perturbed sample, destroy the consistency between its predictions, and thus adjust the feature representation learned by the model to mitigate such risks. This case can be represented as condition (2):

[0040]

[0041]

[0042] Step S02: In the model training process, the initial perturbation is optimized by the double-target optimization equation, and the initial model parameter is optimized according to the obtained target perturbation, to obtain a target model parameter.

[0043] It can be understood that in the model training, the initial perturbation can be optimized by the double-target optimization equation first, and then the initial model parameter is optimized according to the obtained target perturbation to obtain the target model parameter, therefore, the double-target optimization equation and the optimization of the initial perturbation and the initial model parameter.

[0044] Further, in order to obtain the double-target optimization equation, in the embodiment, the step S02 includes: in the model training process, determining a risk measurement index variable corresponding to the initial traffic classification model based on the real category corresponding to the original sample, the initial model parameter and the model parameter variable; constructing the lower optimization equation according to the risk measurement index variable, the lower optimization equation being used for determining a target perturbation for maximizing the risk measurement index variable; constructing the upper optimization equation according to the target perturbation, the real category and the model parameter variable; solving the lower optimization equation and the upper optimization equation to obtain a target model parameter.

[0045] It should be understood that in order to find more effective perturbations while achieving targeted model parameter fine-tuning, the target found needs to meet the above constraints, i.e. conditions (1) and (2) at the same time. The dual-objective optimization equation in this embodiment can include: an upper optimization equation and a lower optimization equation, which can be represented as:

[0046]

[0047] The following equation is the lower optimization equation, and the goal of the lower optimization equation is to find the perturbation that maximizes the risk metric variable wherein represents the risk of the model being successfully attacked. The above equation is the upper optimization equation, and the upper optimization equation aims to minimize the loss function so that the predicted class of the model deviates from the backdoor class caused by the adjustment process , reducing the risk of the model being successfully subjected to a backdoor attack, and avoiding the coupling of the intermediate representation in the original model, as the target perturbation.

[0048] In order to solve the lower optimization equation, the perturbation needs to be continuously optimized to reduce the probability of the perturbed sample being predicted as its true label, while improving its prediction consistency in two models, i.e. the prediction consistency of the poisoned model and the fine-tuned model. To this end, the risk metric variable is defined as:

[0049]

[0050] wherein, represents the cross-entropy loss, which measures the consistency between the predicted results of the two models and the true class , is the initial perturbation, is the initial model parameter, is the model parameter variable, divergence is used to measure the consistency of the predicted results of the two models on the sample, represents the probability distribution of the output. As the lower optimization is optimized in the direction of maximization, the prediction of the model on the sample will deviate more and more from , and the predicted result distribution between the two models will become more consistent.

[0051] ​The upper layer optimization equation needs to modify the prediction of the model on the perturbed sample, adjust the sample feature representation learned by the model, so as to prevent the fine-tuned model from predicting the perturbed sample consistent with the original model, and reduce the risk of successful attack on the model by backdoor. Therefore, we design the following alternative loss:

[0052] Wherein . For preventing the fine-tuned model from aligning the probability distribution of its prediction with that of the original model when the prediction of the original model on the perturbed sample contradicts the ground truth label; is a binary function, the value of the function is 1 when the condition in the bracket is true, otherwise it is 0. The mechanism aims to adjust the sample features learned by the model, so as to create a divergence between the representations of the perturbed sample and the normal sample.

[0053] Based on the above equation, we construct the risk reduction robustness tuning (RRT) to solve the backdoor attack on the network traffic classifier under the normal poisoning rate. The optimization objective of RRT is as follows, that is, the double objective optimization equation is as follows:

[0054]

[0055]

[0056] In the specific implementation, by solving the above double objective optimization equation, the value of the model parameter variable can be obtained, that is, the target model parameter .

[0057] Step S03: constructing a preset traffic classification model based on the target model parameter.

[0058] It should be understood that the parameter of the preset traffic classification model is the target model parameter.

[0059] Further, in order to enable the preset traffic classification model to also achieve efficient defense against backdoor attacks under the condition of low poisoning rate, in the embodiment, before the step S03, it further includes: constructing a weight optimization equation based on the Manhattan distance between the initial classifier weight corresponding to the initial traffic classification model and the classifier weight variable; solving the weight optimization equation to obtain the target classifier weight; accordingly, the step of constructing a preset traffic classification model based on the target model parameter includes: constructing a preset traffic classification model based on the target classifier weight and the target model parameter.

[0060] It can be understood that RRT simulates backdoor samples by adding perturbations to normal samples, guiding the poisoning model to adjust the feature representation of its samples. However, backdoor samples will become more concealed and difficult to imitate under low poisoning rate conditions. In order to solve this problem, the embodiment proposes an enhanced feature shift method, called feature separation tuning (FST). FST is an end-to-end tuning method that achieves feature shift by increasing the difference between the linear classifier weights in the fine-tuning model and the poisoning model (the last linear layer of the model). Specifically, represents the re-initialized linear classifier weights, which can be the initial classifier weights corresponding to the initial traffic classification model, i.e., the classifier weight variable, represents the original linear classifier weights. The goal of FST can be expressed by the following optimization objective, and the weight optimization equation is as follows:

[0061]

[0062] wherein represents the Manhattan distance, is a constant. The norm of the parameter is a constant to prevent it from exploding and dominating the loss function during fine-tuning. For the selection of , it can be set to instead of manual adjustment. This method also helps the optimization process to converge faster.

[0063] It should be understood that solving the above weight optimization equation can obtain the value of the classifier weight variable , i.e., the target classifier weight, and then constructing a preset traffic classification model based on the target classifier weight and the target model parameter, wherein the weight of the last linear layer in the preset traffic classification model is the target classifier weight, and the model parameter of the preset traffic classification model is the target model parameter.

[0064] In a specific implementation, in summary, by combining RRT and FST, and taking into account backdoor defense and model classification accuracy under multiple poisoning rates, the overall optimization objective of RFST is proposed:

[0065]

[0066]

[0067]

[0068] wherein and are hyperparameters of the traffic classification model, is a set of model parameters generated after the previous round of optimization (initialized as a set of random numbers). To find the optimal solution of the above equation, the minimization problem and the maximization problem are solved alternately, specifically, the parameters of the model are updated using stochastic gradient descent, while the perturbation optimization is updated using projected gradient descent.

[0069] The core of the embodiment includes the following two key mechanisms: 1) Risk-reducing Robustness Tuning (RRT for short) mechanism: the core idea is to introduce the idea of adversarial training, aiming at the intermediate feature coupling problem between normal samples and backdoor samples, first apply perturbation to normal network traffic samples to construct "potential backdoor attack samples", and then adjust the prediction class of the model on the perturbed samples, guide the model to learn more robust normal sample feature representation, so as to realize effective decoupling of the intermediate features of normal samples and backdoor samples, and weaken the triggering basis of backdoor attacks. 2) Feature Separation Tuning (FST for short) mechanism: aiming at the problem that low poisoning rate backdoor attacks are more difficult to remove, a more targeted parameter adjustment strategy is adopted, by increasing the difference between the fine-tuned model and the original backdoor model in the "linear classifier parameters", forcing the intermediate feature representation of all samples in the fine-tuned model to deviate from the original distribution, completely destroying the feature mapping relationship relied on by the backdoor attack from the parameter level, and realizing efficient defense against low poisoning rate attacks.

[0070] The embodiment constructs a complete backdoor defense framework of "adversarial training-based purification training under normal poisoning rate - purification training based on model parameter transformation under low poisoning rate - mixed optimization training of different poisoning rates and model classification accuracy", the core feature of the framework is to deeply integrate the "robustness enhancement" of RRT and the "forced separation" of FST, through the optimization strategy of different scenes and different stages, covering both the normal poisoning rate scene and solving the defense problem of the low poisoning rate scene, while guaranteeing the classification performance of the original model on normal traffic.

[0071] Purification training based on adversarial training under normal poisoning rate: in the traffic classification model, the feature distribution of backdoor samples and normal samples in the intermediate layer of the model presents a high coupling, making the existing defense schemes in computer vision field ineffective. In view of the above finding, a feasible defense idea is to adjust the feature representation of the model to the sample, so that it can better deconstruct the coupling relationship between the backdoor sample and the normal sample. For this purpose, the idea of adversarial training is integrated into the model purification training process: on the one hand, construct samples with appropriate perturbation to mislead the model (i.e. simulate backdoor attack); on the other hand, correct the class prediction of the model on the perturbed samples, so as to adjust the sample feature representation learned by the model.

[0072] Purification training based on model parameter transformation under low poisoning rate: Under the condition of low poisoning rate, the backdoor samples only account for a very low rate of the original data set, and the backdoor samples will become more hidden and difficult to imitate through perturbation. Therefore, a more aggressive strategy is adopted: by directly modifying the parameters of the key layers of the model, the feature representation learned by the model is greatly adjusted. Deeply exploring the working mechanism of the model, it can be found that the linear classification layer plays a key role in the model architecture, and its core working principle is to classify samples of different categories according to the intermediate representation obtained after the samples are learned by the multi-layer network. Therefore, the difference between the adjusted classification layer weight (parameter) and the original classification layer weight can be increased to achieve the goal of more effective differentiation of the model between backdoor samples and normal sample representation.

[0073] Multi-objective hybrid optimization training: In defense, it is often impossible to predict the poisoning rate of the model in advance, so the purification training based on adversarial training under the regular poisoning rate is combined with the purification training based on model parameter transformation under the low poisoning rate. In addition, in order to ensure that the model can stably maintain the detection / classification accuracy on normal samples while effectively resisting backdoor attacks, the cross-entropy loss is introduced to balance the defense and classification effects.

[0074] In summary, the three links of "purification training based on adversarial training under regular poisoning rate-purification training based on model parameter transformation under low poisoning rate-hybrid optimization training of different poisoning rates and model classification accuracy" constitute a complete closed-loop defense process. Without reconstructing the core architecture of the deep learning-based network traffic classifier, only through the hierarchical decoupling strategy and the customized cooperative optimization means, the "robustness enhancement" of RRT and the "forced separation" of FST can be deeply integrated, covering the regular poisoning rate scenario and solving the defense problem in the low poisoning rate scenario, while ensuring the classification performance of the original model on normal traffic. Therefore, in a precise, stable and low-invasive manner, the backdoor attack on the deep learning-based network traffic classifier is comprehensively and efficiently defended.

[0075] The embodiment trains an initial traffic classification model based on an original sample carrying an initial perturbation, the initial traffic classification model corresponds to initial model parameters, in the model training process, the initial perturbation is optimized through a double-objective optimization equation, and the initial model parameters are optimized according to the obtained target perturbation to obtain target model parameters, and a preset traffic classification model is constructed based on the target model parameters. In this embodiment, the initial perturbation is optimized through a double-objective optimization equation, and the initial model parameters are optimized according to the obtained target perturbation to obtain target model parameters. Under the condition of regular poisoning rate, the resistance robustness of the model to standard poisoning rate backdoor attack is enhanced by introducing an adversarial training mechanism, and the generalization ability of the model to resist regular poisoning rate attack is enhanced.

[0076] Reference Figure 3 ,Figure 3 A flowchart of a third embodiment of the traffic classification method of the present application.

[0077] Based on the above embodiments, in the present embodiment, the step S03 comprises: Step S031: constructing a target traffic classification model based on the target model parameters.

[0078] It can be understood that the model parameters of the constructed target traffic classification model can be the target model parameters.

[0079] Step S032: inputting the original sample into the target traffic classification model to obtain a model predicted category.

[0080] It should be understood that by inputting the original sample into the target traffic classification model, a model predicted category output by the target traffic classification model can be obtained.

[0081] Step S033: calculating a cross-entropy loss value between the real category and the model predicted category.

[0082] In a specific implementation, the cross-entropy loss value can be used to balance the model defense and the classification effect. The cross-entropy loss value between the real category and the model predicted category can be calculated by the following formula: wherein, is the target traffic classification model the original sample is predicted to be the real category the probability, the closer the model predicted category is to the real category, the smaller the cross-entropy loss value is; otherwise, the larger the cross-entropy loss value is.

[0083] Step S034: determining whether the target traffic classification model is trained according to the cross-entropy loss value, and determining a preset traffic classification model according to the determination result.

[0084] It can be understood that the smaller the cross-entropy loss value is, the more the target traffic classification model is determined to be trained, and the target traffic classification model can be used as the preset traffic classification model. The larger the cross-entropy loss value is, the more the target traffic classification model is determined not to be trained, and the target traffic classification model needs to be continuously trained, and the traffic classification model trained subsequently can be used as the preset traffic classification model.

[0085] Further, in the present embodiment, the step S034 comprises: in the case that the cross-entropy loss value is greater than a preset threshold, constructing a new perturbation; returning to the step of training the initial traffic classification model based on the original sample carrying the initial perturbation until a new cross-entropy loss value is less than or equal to the preset threshold, and using the new traffic classification model as the preset traffic classification model.

[0086] It should be understood that, in the case that the cross-entropy loss value is greater than the preset threshold value, it indicates that the target traffic classification model has not been trained, a new perturbation needs to be constructed, and the new perturbation is added to the original sample, the initial traffic classification model is continuously trained by using the training method proposed in the second embodiment, and a new cross-entropy loss value is obtained. When the new cross-entropy loss value is less than or equal to the preset threshold value, the traffic classification model at this time can be used as the preset traffic classification model.

[0087] In a specific implementation, a formal description of the overall RFST algorithm is as follows: 1. Input: A training data set

[0088] Parameters of an initial traffic classification model ,

[0089] Hyperparameters α, β Learning rate of SGD

[0090] Number of PGD iterations K, PGD step size

[0091] Batch size B 2. Output: Optimized target model parameters

[0092] 3. Initialization: Initialize model parameters with random values (including trainable weights w).

[0093] for each training iteration do Randomly sample a mini-batch from Initialize an empty perturbation list

[0094] Step 1: Find the target perturbation

[0095] for each sample (x, y) in the mini-batch do

[0096] 0 for k = 1 K do

[0097] +

[0098] end for​ Store perturbation: , and add to

[0099] end for Step 2: update model parameters

[0100] 0 for j=1 B do arg max

[0101] [j] -

[0102] -

[0103] +

[0104] end for / B -

[0105] w w

[0106] end for Return

[0107] The embodiment is based on target model parameters to construct a target traffic classification model, and then inputs the original sample into the target traffic classification model to obtain the model prediction category, and then calculates the cross-entropy loss value between the real category and the model prediction category, and then judges whether the target traffic classification model is trained according to the cross-entropy loss value, and determines the preset traffic classification model according to the judgment result. In the context of dealing with backdoor attacks, the cross-entropy loss value loss is introduced into the model training process, which can prompt the model to pay attention to the real category of the sample during the learning process, avoid being disturbed by the backdoor sample and produce the wrong learning direction, and thus obtain the accurate preset traffic classification model.

[0108] Referring to Figure 4 , Figure 4 is the structure block diagram of the first embodiment of the traffic classification device of the present application.

[0109] As Figure 4As shown, the traffic classification device proposed in the embodiments of the present application comprises: The traffic acquisition module 10 is configured to acquire the traffic to be classified. The traffic classification module 20 is configured to input the traffic to be classified into a preset traffic classification model to obtain a traffic classification result, wherein the preset traffic classification model is constructed based on target model parameters corresponding to a target perturbation carried by an original sample.

[0110] The embodiments of the present application acquire the traffic to be classified, input the traffic to be classified into a preset traffic classification model, and obtain a traffic classification result, wherein the preset traffic classification model is constructed based on target model parameters corresponding to a target perturbation carried by an original sample. The embodiments of the present application optimize an initial perturbation carried by an original sample, obtain corresponding target model parameters according to the obtained target perturbation, and construct a preset traffic classification model according to the target model parameters, so as to classify the traffic to be classified by using the preset traffic classification model and obtain an accurate traffic classification result. Since the perturbation is continuously optimized, the obtained preset traffic classification model can efficiently defend against a backdoor attack.

[0111] It should be noted that the above-described workflow is merely illustrative and does not limit the protection scope of the present application. In actual applications, a person skilled in the art can select part or all of the above-described workflow to achieve the purpose of the embodiments of the present application, and the present application is not limited in this regard.

[0112] In addition, technical details not described in detail in the embodiments can be referred to the traffic classification method provided by any embodiment of the present application, and will not be described here.

[0113] Based on the first embodiment of the above-described traffic classification device, the second embodiment of the traffic classification device of the present application is proposed.

[0114] In the embodiments, the traffic classification device further comprises a model training module configured to train an initial traffic classification model based on an original sample carrying an initial perturbation, wherein the initial traffic classification model corresponds to initial model parameters; in the model training process, the initial perturbation is optimized by using a double-target optimization equation, and the initial model parameters are optimized according to the obtained target perturbation to obtain target model parameters; and a preset traffic classification model is constructed based on the target model parameters.

[0115] Further, the double-objective optimization equation comprises: an upper optimization equation and a lower optimization equation; and the model training module is further configured to, in the model training process, determine a risk metric indicator variable corresponding to the initial traffic classification model based on the real class corresponding to the original sample, the initial model parameter, and a model parameter variable; construct the lower optimization equation according to the risk metric indicator variable, the lower optimization equation being used to determine a target perturbation that maximizes the risk metric indicator variable; construct the upper optimization equation according to the target perturbation, the real class, and the model parameter variable; and solve the lower optimization equation and the upper optimization equation to obtain a target model parameter.

[0116] Further, the model training module is further configured to construct a weight optimization equation based on a Manhattan distance between initial classifier weights corresponding to the initial traffic classification model and classifier weight variables; solve the weight optimization equation to obtain target classifier weights; and construct a preset traffic classification model based on the target classifier weights and the target model parameter.

[0117] Further, the model training module is further configured to construct a target traffic classification model based on the target model parameter; input the original sample into the target traffic classification model to obtain a model predicted class; calculate a cross-entropy loss value between the real class and the model predicted class; determine whether the target traffic classification model is trained completely according to the cross-entropy loss value, and determine a preset traffic classification model according to a determination result.

[0118] Further, the model training module is further configured to, in a case where the cross-entropy loss value is greater than a preset threshold, construct a new perturbation; return to the step of training the initial traffic classification model based on the original sample carrying the initial perturbation, until a new cross-entropy loss value is less than or equal to the preset threshold, and take a new traffic classification model as the preset traffic classification model.

[0119] Other embodiments or specific implementations of the traffic classification apparatus provided in the present application can refer to the above-mentioned method embodiments, and will not be described here again.

[0120] The present application provides a traffic classification device, which comprises: at least one processor; and a memory in communication connection with the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the traffic classification method in the above-mentioned embodiment one.

[0121] The following refers to Figure 5The diagram illustrates a structural schematic of a traffic classification device suitable for implementing embodiments of this application. The traffic classification device in these embodiments may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Description), PMPs (Portable Media Players), in-vehicle terminals (e.g., in-vehicle navigation terminals), and fixed terminals such as digital TVs and desktop computers. Figure 5 The traffic classification device shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0122] like Figure 5 As shown, the flow classification device may include a processing unit 1001 (e.g., a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1003 into a random access memory (RAM) 1004. The RAM 1004 also stores various programs and data required for the operation of the flow classification device. The processing unit 1001, ROM 1002, and RAM 1004 are interconnected via a bus 1005. An input / output (I / O) interface 1006 is also connected to the bus. Typically, the following systems can be connected to the I / O interface 1006: input devices 1007 including, for example, a touchscreen, touchpad, keyboard, mouse, image sensor, microphone, accelerometer, gyroscope, etc.; output devices 1008 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 1003 including, for example, magnetic tape, hard disk, etc.; and communication devices 1009. Communication device 1009 allows the traffic classification device to communicate wirelessly or wiredly with other devices to exchange data. Although the figure shows traffic classification devices with various systems, it should be understood that implementation or possession of all the systems shown is not required. More or fewer systems may be implemented alternatively.

[0123] In particular, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product comprising a computer program carried on a computer readable medium, the computer program containing program codes for executing the method shown in the flowchart. In such embodiments, the computer program can be downloaded and installed from a network through a communication device, or installed from the storage device 1003, or installed from the ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiments disclosed in the present application are executed.

[0124] The traffic classification device provided by the present application adopts the traffic classification method in the above-mentioned embodiments, and can solve the technical problem of how to accurately obtain the traffic classification result and realize efficient defense against backdoor attacks. Compared with the prior art, the traffic classification device provided by the present application has the same beneficial effects as the traffic classification method provided by the above-mentioned embodiments, and other technical features in the traffic classification device are the same as the features disclosed in the previous embodiment method, which will not be repeated here.

[0125] It should be understood that parts of the present application can be realized by hardware, software, firmware or their combinations. In the description of the above-mentioned embodiments, specific features, structures, materials or characteristics can be combined in any one or more embodiments or examples in a suitable manner.

[0126] The above is merely specific implementation of the present application, but the protection scope of the present application is not limited thereto, any person skilled in the art can easily think of changes or replacements within the technical scope disclosed in the present application, which should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

[0127] The present application provides a computer readable storage medium having stored thereon computer readable program instructions (i.e. computer program) for executing the traffic classification method in the above-mentioned embodiments.

[0128] The computer readable storage medium provided in the application may be, for example, a U disk, but is not limited to an electric, magnetic, optical, electromagnetic, infrared, or semiconductor system, system, or device, or any combination of the above. More specific examples of the computer readable storage medium may include, but are not limited to, an electric connection with one or more conductive wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the embodiment, the computer readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, system, or device. The program code contained on the computer readable storage medium can be transmitted by any suitable medium, including but not limited to an electric wire, an optical cable, an RF (Radio Frequency), and the like, or any suitable combination of the above.

[0129] The computer readable storage medium described above may be contained in the traffic classification device, or may exist separately without being assembled into the traffic classification device.

[0130] The computer readable storage medium described above carries one or more programs, when the one or more programs are executed by the traffic classification device, the traffic classification device: obtains traffic to be classified; inputs the traffic to be classified into a preset traffic classification model to obtain a traffic classification result, the preset traffic classification model is constructed based on target model parameters corresponding to target disturbance carried by an original sample.

[0131] Computer program code for carrying out operations of the present application can be written in any combination of one or more programming languages, including an object oriented programming language such as Python, Java, Smalltalk, C++, or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider).

[0132] The flow diagrams and the block diagrams in the drawings are illustrations of architectures, functionalities, and operations of possible implementations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flow diagrams or block diagrams can represent a module, a segment, or a portion of code, which comprises one or more executable instructions for implementing the specified logical function(s). It should also be noted that in some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession may, in fact, be executed substantially concurrently or the blocks may

[0133] The modules involved in the embodiments of the present application can be implemented in the form of software or in the form of hardware. In some cases, the name of the module does not constitute a limitation on the module itself.

[0134] The readable storage medium provided by the present application is a computer readable storage medium, which stores computer readable program instructions (i.e., a computer program) for executing the above traffic classification method, and can solve the technical problem of how to accurately obtain the traffic classification result and implement efficient defense against backdoor attacks. Compared with the prior art, the computer readable storage medium provided by the present application has the same beneficial effects as the traffic classification method provided by the above embodiments, and will not be described here.

[0135] The application further provides a computer program product comprising a computer program which, when executed by a processor, implements the steps of the traffic classification method as described above.

[0136] The computer program product provided by the application can solve the technical problem of how to accurately obtain a traffic classification result and realize efficient defense against a backdoor attack. Compared with the prior art, the beneficial effects of the computer program product provided by the application are the same as those of the traffic classification method provided by the above-described embodiments, and are not described herein again.

[0137] The above only describes some embodiments of the application, and does not limit the protection scope of the application. Any equivalent structure transformation made by using the content of the specification and drawings of the application, or direct / indirect application in other related technical fields under the technical concept of the application is included in the protection scope of the application.

Claims

1. A traffic classification method, characterized in that, The traffic classification method includes the following steps: Obtain traffic to be categorized; The traffic to be classified is input into a preset traffic classification model to obtain the traffic classification result. The preset traffic classification model is constructed based on the target model parameters corresponding to the target perturbation carried by the original sample.

2. The traffic classification method as described in claim 1, characterized in that, Before inputting the traffic to be classified into a preset traffic classification model to obtain the traffic classification result, the process also includes: The initial traffic classification model is trained based on the original samples carrying the initial perturbation, and the initial traffic classification model corresponds to the initial model parameters; During model training, the initial perturbation is optimized using a bi-objective optimization equation, and the initial model parameters are optimized based on the obtained target perturbation to obtain the target model parameters. A preset traffic classification model is constructed based on the target model parameters.

3. The traffic classification method as described in claim 2, characterized in that, The dual-objective optimization equation includes: an upper-level optimization equation and a lower-level optimization equation; During model training, the initial perturbation is optimized using a bi-objective optimization equation, and the initial model parameters are optimized based on the obtained target perturbation to obtain the target model parameters, including: During model training, the risk measurement index variable corresponding to the initial traffic classification model is determined based on the true category corresponding to the original sample, the initial model parameters, and the model parameter variables. The lower-level optimization equation is constructed based on the risk metric variable, and the lower-level optimization equation is used to determine the target perturbation that maximizes the risk metric variable. The upper-level optimization equation is constructed based on the target perturbation, the true category, and the model parameter variables; The target model parameters are obtained by solving the lower-level optimization equation and the upper-level optimization equation.

4. The traffic classification method as described in claim 2, characterized in that, Before constructing the preset traffic classification model based on the target model parameters, the method further includes: A weight optimization equation is constructed based on the Manhattan distance between the initial classifier weights and the classifier weight variables corresponding to the initial traffic classification model. The weight optimization equation is solved to obtain the target classifier weights; Accordingly, constructing a preset traffic classification model based on the target model parameters includes: A preset traffic classification model is constructed based on the target classifier weights and the target model parameters.

5. The traffic classification method as described in claim 3, characterized in that, The construction of a preset traffic classification model based on the target model parameters includes: Construct a target traffic classification model based on the target model parameters; The original sample is input into the target traffic classification model to obtain the model's predicted category; Calculate the cross-entropy loss value between the true category and the model-predicted category; The cross-entropy loss value is used to determine whether the target traffic classification model has been trained, and the preset traffic classification model is determined based on the determination result.

6. The traffic classification method as described in claim 5, characterized in that, The step of determining whether the target traffic classification model has been trained successfully based on the cross-entropy loss value, and determining the preset traffic classification model based on the determination result, includes: If the cross-entropy loss value is greater than a preset threshold, a new perturbation is constructed; Return to the step of training the initial traffic classification model based on the original samples carrying the initial perturbation, until a new cross-entropy loss value is obtained that is less than or equal to the preset threshold, and use the new traffic classification model as the preset traffic classification model.

7. A flow classification device, characterized in that, The flow classification device includes: The traffic acquisition module is used to acquire traffic to be categorized. The traffic classification module is used to input the traffic to be classified into a preset traffic classification model to obtain the traffic classification result. The preset traffic classification model is constructed based on the target model parameters corresponding to the target perturbation carried by the original sample.

8. A flow classification device, characterized in that, The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the computer program being configured to implement the steps of the traffic classification method as described in any one of claims 1 to 6.

9. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, it implements the steps of the traffic classification method as described in any one of claims 1 to 6.

10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the steps of the traffic classification method as described in any one of claims 1 to 6.