A cloud-edge retraining and module-level updating method and system based on partitioned risk-benefit summaries

CN122802246APending Publication Date: 2026-09-22ZHONGWEI POWER SUPPLY COMPANY OF STATE GRID NINGXIA ELECTRIC POWER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202611098913.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-07-23
Publication Date
2026-09-22

AI Technical Summary

Technical Problem

[0005]1.现有云边训练方案多为节点级或任务级决策,缺少针对业务分区、资产重要性和攻击家族的细粒度更新优先级判定机制

Benefits of technology

[0024] As can be seen from the above technical solutions, compared with the prior art, the present invention discloses a cloud-edge retraining and module-level update method and system based on partition risk-reward summary. Through the mapping relationship between business partitions, attack families, asset importance, model module contribution and runtime feedback, an interpretable, executable and rollbackable model and strategy joint update mechanism is formed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122802246A_ABST
    Figure CN122802246A_ABST
Patent Text Reader

Abstract

This invention discloses a cloud-edge retraining and module-level update method and system based on partitioned risk-reward summaries. The method includes: mapping multi-source data used for security detection and business anomaly identification to scenarios based on business partitions and attack families at edge nodes, generating a ternary summary containing parameter increments, a partitioned risk-reward matrix, and a resource state vector, and uploading it to the cloud; processing the ternary summaries from multiple edge nodes at the cloud, and finally encapsulating the generated trainable mask, model update amount, and software firewall policy update amount into a consistent release package and distributing it to the edge nodes; synchronously updating the edge-side model and software firewall policy at the edge nodes, and quantifying the runtime feedback and sending it back to the cloud to drive the next round of closed-loop optimization. This method forms an interpretable, executable, and rollbackable joint update mechanism for models and policies through the mapping relationship between business partitions, attack families, asset importance, model module contributions, and runtime feedback.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and more specifically to a cloud-edge retraining and module-level update method and system based on partition risk-benefit summaries. Background Technology

[0002] With the continuous informatization of power companies' marketing, dispatching, operation and maintenance, and office systems, the number of business data streams, host audit logs, database audit logs, equipment alarms, and asset profiles in the management information area is rapidly increasing. Network security protection is gradually evolving from traditional rule-based and feature engineering methods to a detection and analysis paradigm based on deep learning and large-scale models. Compared to traditional methods, large-scale models have significant advantages in multi-source data fusion, semantic understanding, generalization of unknown threats, and cross-host and cross-system attack chain correlation, making them particularly suitable for analyzing complex security events across time windows, business domains, and asset levels in power business networks.

[0003] The power business network scenario differs significantly from the general internet scenario. Edge nodes are dispersed, with deployment locations spanning management information zones, substations, business halls, power supply stations, and boundary security devices; data distribution varies greatly across different sites, and peak business periods and threat landscape changes are inconsistent; raw security data often contains sensitive information such as asset identifiers, account information, business documents, equipment status, and operating parameters, and directly uploading raw data to the cloud poses risks of data leakage and compliance; edge devices have limited processors, accelerators, memory, bandwidth, and power consumption, making it impossible to sustain the training and updating of large-scale models for extended periods.

[0004] Existing cloud-edge collaboration solutions typically revolve around inference offloading, simple model distribution, federated updates, or general resource scheduling. While these solutions can address data transmission and resource allocation issues to some extent, they still lack refined update decision-making mechanisms tailored to power business partitions, attack families, and internal model modules. Specifically, existing technologies suffer from the following shortcomings:

[0005] 1. Existing cloud-edge training solutions mostly involve node-level or task-level decision-making, lacking a fine-grained update priority determination mechanism for business partitions, asset importance, and attack families.

[0006] 2. Existing edge summaries typically only contain parameter difference or gradient information, lacking a summary structure that jointly expresses data drift, detection error, attack popularity, asset importance, and operational feedback.

[0007] 3. Existing retraining methods mostly make coarse-grained choices between full retraining and local fine-tuning, lacking a trainable mask mechanism that selects internal modules of the model based on their contribution to the scenario, which can easily lead to invalid computation.

[0008] 4. General computing power scheduling schemes often only focus on time, bandwidth and resource utilization, and lack a unified mechanism to incorporate business risk and benefit into the selection of model update paths.

[0009] 5. Model updates and software firewall policy updates are usually released separately, lacking consistency verification and dual-object release mechanisms, which may lead to mismatches between model versions and policy versions.

[0010] 6. Low-confidence samples, cloud-edge verification conflicts, rule hits, and rollback events generated during the operation phase are usually not structured and incorporated into the next round of retraining and strategy optimization, resulting in insufficient system evolution efficiency.

[0011] Therefore, how to design a cloud-edge retraining and policy collaborative update mechanism that can make refined decisions based on business partitions, attack families, and model module contributions is a problem that urgently needs to be solved by those skilled in the art. Summary of the Invention

[0012] In view of the above problems, the present invention proposes a cloud-edge retraining and module-level update method and system based on partition risk-reward summary, which aims to overcome or at least partially solve the above problems.

[0013] To achieve the above objectives, the present invention adopts the following technical solution: In a first aspect, the present invention provides a cloud-edge retraining and module-level update method based on partitioned risk-reward summaries, comprising: By using edge nodes, multi-source data used for security detection and business anomaly identification is mapped to a scenario based on business partitions and attack families, generating a ternary summary containing parameter increments, partition risk-benefit matrices, and resource status vectors, and then uploading the ternary summary to the cloud. The global update urgency is calculated based on the partition risk-reward matrix uploaded by multiple edge nodes via the cloud. A trainable mask for each module within the cloud security model is generated by combining this with a pre-defined module-scenario contribution matrix. The update path with the highest overall utility is selected from candidate update paths based on the resource state vectors uploaded by multiple edge nodes. A model update quantity is generated based on the selected update path and the parameter increments uploaded by multiple edge nodes, and a software firewall policy update quantity is generated independently. The trainable mask, the model update quantity, and the software firewall policy update quantity are encapsulated into a consistent release package and distributed to the edge nodes. The edge node receives and parses the consistency release package, synchronously updates the edge-side model and software firewall policy, and quantifies the runtime feedback before sending it back to the cloud to drive the next round of closed-loop optimization.

[0014] Furthermore, the elements in the partition risk-reward matrix are used to characterize the update urgency for each business partition and attack family.

[0015] Furthermore, the update urgency is expressed as:

[0016] in, Indicates the urgency of the update; This represents the normalized distribution drift intensity; express Weighting coefficients; This represents the normalized detection error or uncertainty. express Weighting coefficients; This indicates the normalized attack intensity or risk event strength. express Weighting coefficients; This represents the normalized operational feedback strength; express Weighting coefficients; Indicates the importance weight of a business area or asset domain; Represents the normalization function; Indicates the Jensen-Shannon divergence; and These represent the feature distributions of the current window and the historical baseline window, respectively. Indicates the feature distribution weight coefficients; and These represent the label or pseudo-label distributions of the current window and the historical baseline window, respectively; Indicates the label distribution weight coefficient; Indicates the average prediction confidence level; This represents the confidence weighting coefficient; and These represent the false alarm rate and the false negative rate, respectively. This represents the false alarm rate weighting coefficient; This represents the weighting coefficient for the false negative rate; Indicates the business partition within the current window. and attacking families The number of events under; Indicates attacking the family The hazard level weight; , , and These represent the number of low-confidence events, the number of cloud-edge conflict events, the number of version rollback events, and the number of resource anomaly events, respectively. , , and They are respectively , , and The weighting coefficients.

[0017] Furthermore, the calculation of the global update urgency based on the partition risk-reward matrix uploaded by multiple edge nodes specifically includes: Calculate the trusted aggregation weight of each edge node based on at least one of the following: sample quality, historical stability, operational reliability, and resource availability. The update urgency in the partition risk-reward matrix uploaded by each edge node is weighted and aggregated using the trusted aggregation weight to obtain the global update urgency indexed by business partition and attack family.

[0018] Furthermore, the elements in the module-scenario contribution matrix represent the degree of contribution of each module in the cloud security model to the business partition and attack family.

[0019] Furthermore, the step of generating trainable masks for each module within the cloud security model by combining a preset module-scenario contribution matrix specifically includes: Based on the global update urgency and the module-scenario contribution matrix, the update score of each module within the cloud security model is calculated; wherein, the update score is positively correlated with the sum of the products of the global update urgency and the module-scenario contribution matrix, and negatively correlated with the resource cost required to train the module; When the updated score is greater than or equal to a preset threshold, the trainable mask of the corresponding module is set to 1, indicating that the module participates in this round of training; otherwise, the trainable mask is set to 0, indicating that the module is frozen.

[0020] Furthermore, the candidate update paths include at least: full retraining path, module-level retraining path, adapter update path, and policy-only update path.

[0021] Furthermore, the overall utility of the candidate update path is positively correlated with the accuracy improvement and key category recall improvement brought by the selected path, and negatively correlated with the time cost, bandwidth cost, energy cost and operational risk penalty of the selected path. The selected update path must also satisfy at least one combination of the following constraints: lower limit of accuracy, lower limit of key category recall, upper limit of time cost, and upper limit of bandwidth cost.

[0022] Furthermore, the consistency release package also includes the business partition and attack family to be applied, the cloud security model version, hash signature, and timestamp.

[0023] On the other hand, the present invention provides a cloud-edge retraining and module-level update system based on partitioned risk-reward summaries, which applies the above-mentioned method and includes: The edge module is used to perform scene mapping on multi-source data used for security detection and business anomaly identification through edge nodes, based on business partitions and attack families, to generate a ternary summary containing parameter increments, partition risk-reward matrices, and resource state vectors, and upload the ternary summary to the cloud; and to receive and parse the consistency release package issued by the cloud module through edge nodes, synchronously update the edge-side model and software firewall policies, and quantify the runtime feedback and send it back to the cloud to drive the next round of closed-loop optimization. A cloud server is used to calculate the global update urgency based on the partition risk-reward matrix uploaded by multiple edge nodes via the cloud, and generate trainable masks for each module within the cloud security model by combining them with a preset module-scenario contribution matrix; select the update path with the highest comprehensive utility from candidate update paths based on the resource state vectors uploaded by multiple edge nodes; generate model update quantity based on the selected update path and parameter increments uploaded by multiple edge nodes, and independently generate software firewall policy update quantity; encapsulate the trainable mask, the model update quantity, and the software firewall policy update quantity into a consistent release package and distribute it to the edge nodes.

[0024] As can be seen from the above technical solutions, compared with the prior art, the present invention discloses a cloud-edge retraining and module-level update method and system based on partition risk-reward summary. Through the mapping relationship between business partitions, attack families, asset importance, model module contribution and runtime feedback, an interpretable, executable and rollbackable model and strategy joint update mechanism is formed. Attached Figure Description

[0025] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0026] Figure 1 This is a schematic diagram of the cloud-edge retraining and module-level update method based on partition risk-reward summary provided in this embodiment of the invention; Figure 2 This is a schematic diagram of edge-side ternary summary generation provided in an embodiment of the present invention; Figure 3 This is a schematic diagram of the module-scene contribution matrix and trainable mask generation provided in an embodiment of the present invention; Figure 4 This is a schematic diagram of the four-path unified update selection provided in an embodiment of the present invention; Figure 5 This is a schematic diagram illustrating the consistent deployment of the model and policy objects provided in this embodiment of the invention. Detailed Implementation

[0027] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0028] This invention discloses a cloud-edge retraining and module-level update method based on partitioned risk-reward summaries, such as... Figure 1 As shown, it includes the following steps: By using edge nodes, based on business partitions and attack families, multi-source data used for security detection and business anomaly identification are mapped to generate a ternary summary containing parameter increments, partition risk-benefit matrices, and resource status vectors, and the ternary summary is uploaded to the cloud. The global update urgency is calculated based on the partition risk-reward matrix uploaded by multiple edge nodes via the cloud. Combined with the preset module-scenario contribution matrix, a trainable mask for each module within the cloud security model is generated. The update path with the highest comprehensive utility is selected from the candidate update paths based on the resource state vectors uploaded by multiple edge nodes. The model update quantity is generated based on the selected update path and the parameter increments uploaded by multiple edge nodes, and the software firewall policy update quantity is generated independently. The trainable mask, model update quantity, and software firewall policy update quantity are encapsulated into a consistent release package and distributed to the edge nodes. Through edge nodes, consistent release packets are received and parsed, edge-side models and software firewall policies are updated synchronously, and runtime feedback is quantified and sent back to the cloud to drive the next round of closed-loop optimization.

[0029] Next, we will explain each of the above parts in detail.

[0030] 1. Edge-side partitioned data acquisition and scene mapping: In a preferred embodiment of the present invention, edge nodes are deployed in power management information zones, substation edge gateways, business hall security devices, or power supply station boundary nodes. Edge nodes collect multi-source data for security detection and business anomaly identification, including: network traffic quintuples, protocol field statistical characteristics, traffic timing characteristics, boundary firewall and intrusion detection alarms, host audit logs, database audit logs, critical operation logs of business systems, and security device operating status.

[0031] Instead of performing coarse statistics directly on the raw samples at the edge, the system first establishes a scene mapping relationship, that is, mapping each sample, alarm or runtime event in the multi-source data to the corresponding business partition. and attacking families Specifically: After collecting data from multiple sources, edge nodes need to perform preprocessing, including data anonymization, missing value cleaning, time window alignment, and format standardization; then, they are partitioned according to business needs. With attack family Perform organizational mapping to form a structured sequence of events.

[0032] The above business divisions To represent a business partition or asset domain index, it is used to characterize the business system, asset domain, or security partition to which the event belongs. This can include marketing business domains, office business domains, database service domains, border access domains, substation business domains, business hall business domains, or power supply station business domains, etc.; by introducing business partitions... This invention can extend model update decisions from the single node level to the business scenario level.

[0033] The aforementioned attack families This serves as an index for attack families or anomaly categories, used to characterize the attack type, anomaly type, or risk category corresponding to the event. Categories can include DDoS attacks, DoS attacks, web application attacks, database attacks, lateral movement, abnormal business operations, threat intelligence hits, abnormal logins, batch data export, and unauthorized external connections. By introducing attack families... This invention can generate differentiated update strategies for different threat types.

[0034] For each event This can be represented as:

[0035] in, Indicates characteristics of network communication; Indicates the characteristics of business operations; Indicates the characteristics of an asset or equipment; Indicates the characteristics of a safety rule or alarm being triggered; This indicates whether the label is manually created, a rule-based label, or a pseudo-label. Indicates the event timestamp.

[0036] Edge nodes based on the above events The included feature calculations correspond to the business partitions and attack families:

[0037]

[0038] in, Indicates an event The corresponding business partition; Indicates an event The corresponding attack family; For business partition mapping functions, business partitions can be determined primarily based on the asset list, security partitions, and business system identifiers; when the above information is missing, supplementary mapping can be performed based on IP network segments, system domain names, database instances, interface paths, or business objects matched by rules. For the attack family mapping function, attack families can be determined primarily based on manually confirmed tags or confirmed alarm tags; when manual tags are missing, security rule hit results, threat intelligence, protocol ports, payload characteristics, and model prediction categories can be combined. Perform supplementary mapping.

[0039] If the same event simultaneously hits multiple candidate service partitions or attack families, conflict resolution is performed according to the priority order of manually confirmed labels, asset lists, security rule hits, threat intelligence, and model prediction confidence. For events that absolutely need to retain multiple labels, multiple sets of candidate mapping relationships can be formed, and weighted according to confidence in subsequent statistics. Through the above mapping, the edge side can form a ( The risk statistics unit indexed is used for subsequent calculations of partition risk-return summaries and update urgency. Provides the foundation.

[0040] 2. Edge-side ternary summary generation: like Figure 2 As shown, after completing the scene mapping described above, the edge nodes begin several rounds of local incremental training and generate ternary summaries. In this invention, the edge-side model parameters are composed of the backbone parameters of the cloud-based security large model and the edge pluggable parameter module, expressed as follows:

[0041] in, Indicates the first Wheel edge side model parameters; Indicates the first The backbone parameters of the cloud-based security model are used to carry general representation capabilities across scenarios, business partitions, and attack types. These parameters are typically fixed during edge training, and are only selectively updated according to the trainable mask when performing full retraining or module-level retraining paths in the cloud. This indicates that edge node e is at the 1st epoch. A pluggable parameter module loaded in a round-robin fashion; this module is updated first on the edge side to reduce local training and deployment overhead. ⊕ represents the combination relationship between the backbone parameters of the cloud-based security model and the pluggable parameter module on the edge. Fixed during edge training. Update only The parameter increment or compression gradient in this round is expressed as:

[0042] in, Represents edge nodes In the Pluggable parameter modules loaded by wheels; After completing several rounds of local incremental training or observation, edge nodes do not upload the original data. Instead, they construct ternary summaries and upload them to the cloud. The ternary summaries uploaded by edge nodes are defined as follows:

[0043] in, Represents edge nodes In the The pluggable module parameter increments, gradient differences, or compressed model update summaries generated by the round; Indicates partitioning by business and attacking families The partition risk-reward matrix for indexing; Represents edge nodes The resource state vector may include processor utilization, accelerator utilization, video memory usage, available bandwidth, network latency, task queue length, available power budget, and device health, etc. Explicit monitoring indicators can be used, or runtime statistical characteristics or self-reported status from edge devices can be used.

[0044] Therefore, the urgency of updating Not an isolated indicator, but a ternary summary Mid-zone risk-return matrix The specific matrix elements are used to characterize the update necessity of the edge node in a certain business partition and a certain attack family. Specifically, this update urgency... Represented as:

[0045] in, Indicates the urgency of the update, used to characterize whether the current business scenario warrants prioritizing model updates, adapter updates, or policy updates; This represents the normalized distribution drift intensity; express Weighting coefficients; This represents the normalized detection error or uncertainty. express Weighting coefficients; This indicates the normalized attack intensity or risk event strength. express Weighting coefficients; This represents the normalized operational feedback strength; express Weighting coefficients; Indicates the importance weight of a business area or asset domain; To ensure the feasibility of the above indicators, each component can be calculated as follows:

[0046]

[0047]

[0048]

[0049] in, This represents a normalization function, which can be processed using max-min normalization or standardization. Indicates the Jensen-Shannon divergence; and These represent the feature distributions of the current window and the historical baseline window, respectively. Indicates the feature distribution weight coefficients; and These represent the label or pseudo-label distributions of the current window and the historical baseline window, respectively; Indicates the label distribution weight coefficient; This represents the average prediction confidence level; This represents the confidence weighting coefficient; and These represent the false alarm rate and the false negative rate, respectively. This represents the false alarm rate weighting coefficient; This represents the weighting coefficient for the false negative rate; This indicates the number of events under business partition z and attack family c within the current window; This indicates the severity level weight of attack family c; , , and These represent the number of low-confidence events, the number of cloud-edge conflict events, the number of version rollback events, and the number of resource anomaly events, respectively. , , and They are respectively , , and The weighting coefficients.

[0050] Based on the above definition, the ternary summary uploaded by the edge node can simultaneously express the updated content, the reason for the update, and the resource status, providing a basis for subsequent retraining path selection, module-level updates, and policy updates in the cloud.

[0051] 3. Cloud-based global urgency aggregation: After receiving ternary summaries from multiple edge nodes in the cloud, the system first calculates the trusted aggregation weight of each edge node based on at least one of the following: sample quality, historical stability, operational reliability, and resource availability. For example, in one embodiment, the normalized trusted aggregation weight... It can be represented as:

[0052] in, Represents edge nodes The sample quality or operational reliability score; Represents edge nodes Resource availability or historical stability score; This represents the total number of edge nodes; Subsequently, the update urgency in the partition risk-reward matrix uploaded by each edge node is weighted and aggregated using trusted aggregation weights to obtain a global update urgency indexed by business partition and attack family; this global update urgency... It can be represented as:

[0053] This global update urgency level can answer the question of which business partitions and attack families need to be updated first.

[0054] 4. Module-Scene Contribution Matrix and Trainable Mask Generation: like Figure 3 As shown, the cloud-based pre-maintenance module - scenario contribution matrix This module - Scene Contribution Matrix The elements in this matrix represent the contribution of each module in the cloud security model to the business partition and attack family. Unlike conventional full model retraining, this embodiment of the invention uses this module-scenario contribution matrix. Map scene-level update requirements to the module-level update scope within the model. This module-scene contribution matrix... Represented as:

[0055] in, This represents a module index within a large cloud-based security model or a lightweight edge model. This module can be a Transformer layer, attention head, feedforward network module, convolutional channel, classification head, adapter module, LoRA module, or other model building blocks that can be independently frozen, updated, pruned, or distilled. Indicates removal or freezing of the module. The impact on the detection effectiveness of business partition z and attack family c; Indicates gradient attribution contribution; Indicates sensitivity to distillation or compression; , , These are all weighting coefficients corresponding to each item. This indicates normalization processing.

[0056] In other embodiments, this module-scene contribution matrix It can also be established through offline ablation analysis, gradient attribution, distillation sensitivity analysis, rule knowledge graph mapping, or expert rule initialization.

[0057] At runtime, the cloud calculates the update score of each module within the cloud security model based on the global update urgency and the module-scenario contribution matrix. This update score is positively correlated with the sum of the products of the global update urgency and the module-scenario contribution matrix, and negatively correlated with the resource cost required to train the module; expressed as:

[0058] in, Indicates training module The required resource cost; This represents the resource cost penalty coefficient. Further, a trainable mask is generated based on the updated scores of each module. :

[0059] When updating scores Greater than or equal to the preset threshold At that time, the corresponding module Trainable mask Setting it to 1 indicates that the module participates in this round of training; otherwise, the trainable mask is set to 0, indicating that the module... The model is frozen. Therefore, this embodiment of the invention can train only the modules that significantly contribute to the current high-risk partitions and attack families without requiring the full model to be opened.

[0060] 5. Path retraining and strategy update selection mechanism: like Figure 4 As shown, this invention defines four candidate update paths: Path A (Full Retraining Path): Suitable for situations where there is a large-scale drift and multiple modules are activated; Path B (Module-level Retraining Path): Suitable for situations where a small number of key modules are activated; Path C (Adapter Update Only): Suitable for situations with minor drift but requiring rapid adaptation; Path D (Policy Update Only Path): This path updates only the software firewall or edge rules policy and is suitable for situations where model gains are insufficient but current risks can be covered by the software firewall policy.

[0061] The cloud platform no longer makes coarse-grained judgments between full retraining and local fine-tuning, but instead makes a unified selection among four paths. Specifically, the cloud platform bases its selection on the urgency of global updates. Trainable mask and the resource state vector uploaded by edge nodes Calculate the overall utility of each candidate path. Among them, the urgency of global updates and trainable mask Together, they determine the upper limit of the path's performance gains: urgency indicates the scenarios that need to be prioritized for optimization, while the mask limits the model modules that participate in training. The combination of the two directly affects the path. The resulting increase in accuracy and key category recall rate improvement .at the same time, This directly determines the resource costs of the path: processor and accelerator utilization, video memory usage, and other indicators are used to estimate time costs. and energy consumption costs Available bandwidth and network latency are used to estimate bandwidth costs. Task queue length and device health serve as penalties for operational risks. This is an important reference. The comprehensive utility is used to measure the overall merits of a candidate path in terms of performance gains and various costs, and it is specifically expressed as follows:

[0062] in, Indicate candidate path The improvement in accuracy compared to the current stable or baseline version; To adopt candidate update paths Then, the model's prediction accuracy on the validation set; This represents the prediction accuracy of the stable version of the model currently running on the edge node. Indicate candidate path Increased recall rates in key categories, key asset scenarios, or high-risk business areas; To adopt candidate paths Then, the model's recall rate on predefined key categories (such as APT attacks, data breaches, etc.); This refers to the recall rate of the current stable version model across the same set of key categories. This indicates the time cost required for training, evaluation, deployment, or policy updates. This represents the bandwidth cost incurred from transmitting model parameters, summaries, or policy packets. This represents the computational and energy consumption costs; This indicates penalties for operational risks, false alarm risks, or rollback risks. , , , , , These are the non-negative weight coefficients for the corresponding terms.

[0063] The cloud selects the path with the highest overall utility as the current update path:

[0064] in, This is the set of all candidate update paths, which include full retraining, module-level retraining, adapter updates, and policy-only updates.

[0065] This utility function can also be solved using heuristic scoring, reinforcement learning, multi-armed gambling, Bayesian optimization, or constrained programming.

[0066] In addition, the update path must also satisfy at least one combination of the following constraints: lower limit of accuracy, lower limit of key category recall, upper limit of time cost, and upper limit of bandwidth cost, expressed as:

[0067]

[0068]

[0069]

[0070] Through the above mechanism, when the training benefits of the cloud security model are insufficient and the software firewall policy can effectively cover the risks, the system can choose the policy-only update path to avoid ineffective retraining; when only some cloud security model modules are strongly related to high-risk scenarios, the system can choose the module-level retraining path to reduce training costs and reduce version disturbances.

[0071] 6. Consistent release of both model and policy objects: like Figure 5 As shown, after the cloud completes the path selection, it no longer distributes model updates and software firewall policy updates separately, but instead generates a model-policy consistency release package. This consistency release package It also includes model update amount, policy update amount, trainable mask, affected business partition, affected attack family, version number, hash signature, and timestamp, used to ensure the consistency between the intelligent model and the software firewall policy in the edge device during the release, verification, rollback, and uninstallation processes. Represented as:

[0072] in, Indicates the amount of model updates; This indicates the amount of policy updates for software firewalls or edge rule engines. It can also be reflected in rule weight adjustments, threshold changes, policy whitelist changes, action changes, or partition access control policy changes. This represents the trainable mask for the current cloud security model module; and This indicates the business area and attack family that the release package represents; Indicates the consistency version number; This represents hash or signature verification information; This represents the publication timestamp. This is the consistency release package. It can be carried in the form of containerized images, plug-in update packages, model weight packages, rule increment packages, or combined security patch packages.

[0073] After generating the release package, the cloud performs a compatibility check:

[0074] In the formula, This represents the set of partitions, category codes, and feature indices covered by the model update; This represents the set of partitions, category codes, and rule indexes covered by the policy update. A consistent release package is only allowed to be distributed to edge devices if both are compatible. After the consistent release package passes compatibility verification, the cloud performs signature and integrity verification before selecting a small number of edge nodes for canary release and trial operation. If anomalies occur during the canary observation period, a unified rollback to the previous stable version is implemented to ensure consistency in the intelligent model and software firewall rule versions, actions, and traceability. After the canary release passes the official release, edge devices can simultaneously update both the intelligent model components and the software firewall policy, and audit the release results.

[0075] (7) Runtime feedback enters the next closed loop: After receiving and parsing the consistent release package, the edge node synchronously updates its local security model and software firewall policy, and performs gray-scale observation, compatibility verification, rollback, and audit logging.

[0076] During operation, edge nodes continuously collect runtime feedback, including: low-confidence alarms, inconsistencies between cloud verification results and the original edge judgment, software firewall policy hits, model version rollback events, component uninstallation events, and resource overrun events. Edge nodes update the intensity of the next round of runtime feedback according to a time-decay mechanism.

[0077] in, This is the time decay coefficient, also known as the historical feedback forgetting factor, used to balance the weight of the accumulated historical feedback intensity and the number of new events occurring in the current round; Indicates the first Wheel for business partitions and attacking families The intensity of the feedback; Indicates the number of low-confidence alarms; Indicates the number of cloud-edge verification conflicts; Indicates the number of times the strategy hits; Indicates the number of rollback or resource exception events. (Updated) Advance to the next round The calculations enable the system to continuously adjust the direction of training and policy updates based on real-world operational feedback.

[0078] Based on the same inventive concept, embodiments of the present invention also provide a cloud-edge retraining and module-level update system based on partitioned risk-reward summaries, including: The edge module is used to perform scene mapping on multi-source data used for security detection and business anomaly identification through edge nodes, based on business partitions and attack families, to generate a ternary summary containing parameter increments, partition risk-reward matrices and resource state vectors, and upload the ternary summary to the cloud; and to receive and parse the consistency release package issued by the cloud module through edge nodes, synchronously update the edge-side model and software firewall policies, and quantify the runtime feedback and send it back to the cloud to drive the next round of closed-loop optimization. The cloud server is used to calculate the global update urgency based on the partition risk-reward matrix uploaded by multiple edge nodes via the cloud, and generate trainable masks for each module within the cloud security model by combining them with a preset module-scenario contribution matrix; select the update path with the highest comprehensive utility from candidate update paths based on the resource state vectors uploaded by multiple edge nodes; generate model update quantity based on the selected update path and parameter increments uploaded by multiple edge nodes, and independently generate software firewall policy update quantity; and encapsulate the trainable mask, model update quantity, and software firewall policy update quantity into a consistent release package and distribute it to the edge nodes.

[0079] Since the principle behind the problem solved by this system is similar to that of the aforementioned cloud-edge retraining and module-level update system based on partition risk-reward summary, the implementation of this system can refer to the implementation of the aforementioned method, and the repetitive parts will not be repeated.

[0080] In summary, the cloud-edge retraining and module-level update method and system based on partition risk-benefit summary provided by the embodiments of the present invention no longer focuses on conventional data collection, security aggregation or generalized load balancing. Instead, it forms an interpretable, executable and rollbackable joint update mechanism for models and policies through the mapping relationship between business partitions, attack families, asset importance, model module contributions and runtime feedback.

[0081] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to the method section.

[0082] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A cloud-edge retraining and module-level update method based on partitioned risk-return summaries, characterized in that, include: By using edge nodes, multi-source data used for security detection and business anomaly identification is mapped to a scenario based on business partitions and attack families, generating a ternary summary containing parameter increments, partition risk-benefit matrices, and resource status vectors, and then uploading the ternary summary to the cloud. The global update urgency is calculated based on the partition risk-reward matrix uploaded from multiple edge nodes via the cloud, and a trainable mask for each module within the cloud security model is generated by combining the preset module-scenario contribution matrix. Based on the resource state vectors uploaded from multiple edge nodes, the update path with the highest overall utility is selected from the candidate update paths; The model update volume is generated based on the selected update path and the parameter increments uploaded from multiple edge nodes, and the software firewall policy update volume is generated independently. The trainable mask, the model update amount, and the software firewall policy update amount are encapsulated into a consistent distribution package and sent to the edge nodes; The edge node receives and parses the consistency release package, synchronously updates the edge-side model and software firewall policy, and quantifies the runtime feedback before sending it back to the cloud to drive the next round of closed-loop optimization.

2. The cloud-edge retraining and module-level update method based on partitioned risk-reward summaries as described in claim 1, characterized in that, The elements in the partition risk-reward matrix are used to characterize the update urgency for each business partition and attack family.

3. The cloud-edge retraining and module-level update method based on partitioned risk-reward summaries as described in claim 2, characterized in that, The urgency of the update is expressed as follows: in, Indicates the urgency of the update; This represents the normalized distribution drift intensity; express Weighting coefficients; This represents the normalized detection error or uncertainty. express Weighting coefficients; This indicates the normalized attack intensity or risk event strength. express Weighting coefficients; This represents the normalized operational feedback strength; express Weighting coefficients; Indicates the importance weight of a business area or asset domain; Represents the normalization function; Indicates the Jensen-Shannon divergence; and These represent the feature distributions of the current window and the historical baseline window, respectively. Indicates the feature distribution weight coefficients; and These represent the label or pseudo-label distributions of the current window and the historical baseline window, respectively; Indicates the label distribution weight coefficient; Indicates the average prediction confidence level; This represents the confidence weighting coefficient; and These represent the false alarm rate and the false negative rate, respectively. This represents the false alarm rate weighting coefficient; This represents the weighting coefficient for the false negative rate; Indicates the business partition within the current window. and attacking families The number of events under; Indicates attacking the family The hazard level weight; , , and These represent the number of low-confidence events, the number of cloud-edge conflict events, the number of version rollback events, and the number of resource anomaly events, respectively. , , and They are respectively , , and The weighting coefficients.

4. The cloud-edge retraining and module-level update method based on partitioned risk-reward summaries as described in claim 2, characterized in that, The calculation of the global update urgency based on the partition risk-reward matrix uploaded from multiple edge nodes specifically includes: Calculate the trusted aggregation weight of each edge node based on at least one of the following: sample quality, historical stability, operational reliability, and resource availability. The update urgency in the partition risk-reward matrix uploaded by each edge node is weighted and aggregated using the trusted aggregation weight to obtain the global update urgency indexed by business partition and attack family.

5. The cloud-edge retraining and module-level update method based on partitioned risk-reward summaries as described in claim 1, characterized in that, The elements in the module-scenario contribution matrix represent the degree of contribution of each module in the cloud security model to the business partition and attack family.

6. The cloud-edge retraining and module-level update method based on partitioned risk-reward summaries as described in claim 1, characterized in that, The step of generating trainable masks for each module within the cloud security model by combining a preset module-scenario contribution matrix specifically includes: Based on the global update urgency and the module-scenario contribution matrix, the update score of each module within the cloud security model is calculated; wherein, the update score is positively correlated with the sum of the products of the global update urgency and the module-scenario contribution matrix, and negatively correlated with the resource cost required to train the module; When the updated score is greater than or equal to a preset threshold, the trainable mask of the corresponding module is set to 1, indicating that the module participates in this round of training; otherwise, the trainable mask is set to 0, indicating that the module is frozen.

7. The cloud-edge retraining and module-level update method based on partitioned risk-reward summaries as described in claim 1, characterized in that, The candidate update paths include at least: full retraining path, module-level retraining path, adapter update path, and policy-only update path.

8. The cloud-edge retraining and module-level update method based on partitioned risk-reward summaries as described in claim 1, characterized in that, The overall utility of the candidate update path is positively correlated with the accuracy improvement and key category recall improvement brought by the selected path, and negatively correlated with the time cost, bandwidth cost, energy cost and operational risk penalty of the selected path. The selected update path must also satisfy at least one combination of the following constraints: lower limit of accuracy, lower limit of key category recall, upper limit of time cost, and upper limit of bandwidth cost.

9. The cloud-edge retraining and module-level update method based on partitioned risk-reward summaries as described in claim 1, characterized in that, The consistency release package also includes the business partition and attack family it applies to, the cloud security model version, hash signature, and timestamp.

10. A cloud-edge retraining and module-level update system based on partitioned risk-reward summaries, characterized in that, The method described by any one of claims 1-9 comprises: The edge module is used to perform scene mapping on multi-source data used for security detection and business anomaly identification through edge nodes, based on business partitions and attack families, to generate a ternary summary containing parameter increments, partition risk-reward matrices, and resource state vectors, and upload the ternary summary to the cloud; and to receive and parse the consistency release package issued by the cloud module through edge nodes, synchronously update the edge-side model and software firewall policies, and quantify the runtime feedback and send it back to the cloud to drive the next round of closed-loop optimization. A cloud server is used to calculate the global update urgency based on the partition risk-reward matrix uploaded by multiple edge nodes via the cloud, and generate trainable masks for each module within the cloud security model by combining them with a preset module-scenario contribution matrix; select the update path with the highest comprehensive utility from candidate update paths based on the resource state vectors uploaded by multiple edge nodes; generate model update quantity based on the selected update path and parameter increments uploaded by multiple edge nodes, and independently generate software firewall policy update quantity; encapsulate the trainable mask, the model update quantity, and the software firewall policy update quantity into a consistent release package and distribute it to the edge nodes.