Anti-theft detection for model
By using a combination of cloner and generator before the business model is launched, the anti-theft capability evaluation of the business model is solved, and the problem of difficulty in detecting theft of business models in the existing technology is solved, and efficient and accurate anti-theft detection is achieved.
Patent Information
- Application Number
- PCT/CN2024/128417
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-21
- Filing Date
- 2024-10-30
- Publication Date
- 2025-05-30
AI Technical Summary
The prior art is difficult to effectively evaluate and detect whether the business model has been stolen after it is launched, resulting in attackers using the stolen model to perform illegal operations.
Before the business model is launched, the anti-theft capability evaluation of the business model is performed using a combination of cloner and generator. The specific steps include: initializing the clone and generator, training the generator to generate simulated business data, training the clone to clone the business model, and detecting the anti-theft capability of the business model based on the number of iterations of the clone.
This method can effectively reduce the number of visits to the business model, reduce resource overhead, and improve the accuracy and efficiency of anti-theft detection.
Smart Images

Figure CN2024128417_30052025_PF_FP_ABST
Abstract
Description
Model anti-theft detection Technical Field
[0001] This specification relates to the field of machine learning, and in particular to a model anti-theft detection method, device, storage medium, and electronic device. Background Art
[0002] With the advancement of machine learning technology, it's now possible to leverage machine learning-trained models to conduct risk control on various user-generated transactions. The training samples used to train these models may contain personal privacy data. For example, when a user conducts a large financial transaction, a risk control model (a type of business model) detects the high transaction amount and can verify the user's identity to mitigate the risk of financial loss. While many methods exist to protect personal data during model training, protecting personal data is crucial. However, the threat of attackers stealing business models after they're launched shouldn't be overlooked. This means attackers might, for their own benefit, steal a live business model to obtain a model with the same functionality as the business model.
[0003] To prevent business models from being stolen after they go live, an anti-theft capability assessment can be performed on the business model before it goes live. This allows for timely updates or retraining of the live business model based on the assessment results. However, how to assess the anti-theft capability of business models is an urgent issue.
[0004] Based on this, this specification provides a model anti-theft detection method.
[0005] Summary of the Invention
[0006] This specification provides a model anti-theft detection method, device, storage medium and electronic device to at least partially solve the above-mentioned problems existing in the prior art.
[0007] This manual adopts the following technical solutions.
[0008] The present specification provides a method for detecting theft of a model, wherein the anti-theft detection model includes a cloner and a generator, wherein the cloner is used to clone a pre-trained business model, and the generator is used to generate simulated business data to be input into the cloner, including: inputting pre-acquired noise into the generator to obtain first simulated business data output by the generator; inputting the first simulated business data into the cloner to obtain a first business result output by the cloner; training the generator based on the first business result and the first simulated business data with the aim of improving the error rate of the first business result output by the cloner for the first simulated business data; inputting the noise into the trained generator to obtain second simulated business data output by the trained generator; inputting the second simulated business data into the cloner to obtain a second business result output by the cloner; and inputting the second simulated business data into the business model to obtain the business result output by the business model as a label for the second business result, so as to train the cloner based on the second business result and the label; and detecting the anti-theft capability of the business model based on the number of iterations of the cloner during the training process.
[0009] Optionally, the generator is trained based on the first business result and the first simulation business data, with the training target being to improve the error rate of the first business result output by the cloner for the first simulation business data, specifically including: freezing all parameters of the cloner; and determining the generation loss of the generator based on the first business result and the first simulation business data; and training the generator based on the generation loss, with the training target being to improve the error rate of the first business result output by the cloner for the first simulation business data.
[0010] Optionally, the generation loss of the generator is determined based on the first business result and the first simulation business data, specifically including: determining the current number of iterations of the generator; determining a dynamic adjustment difficulty parameter based on the current number of iterations and a preset total number of iterations, wherein the dynamic adjustment difficulty parameter increases with the increase of the current number of iterations; determining the generation loss function of the generator based on the dynamic adjustment difficulty parameter; determining the generation loss of the generator based on the first business result, the first simulation business data and the generation loss function.
[0011] Optionally, the cloner is trained based on the second business result and the label, specifically including: unfreezing all parameters of the cloner and freezing all parameters of the generator; inputting the second business result and the label into a preset cloning loss function to obtain the cloning loss of the cloner; and training the unfrozen cloner based on the cloning loss.
[0012] Optionally, the cloning loss function includes a KL divergence loss function or an absolute value loss function.
[0013] Optionally, the anti-theft capability of the business model is detected based on the number of iterations of the cloner during the training process, specifically including: judging whether the cloner in the anti-theft detection model after training reaches a preset accuracy; if not, continuing to train the cloner in the anti-theft detection model until the cloner in the anti-theft detection model reaches a preset accuracy; if so, determining the number of iterations of the cloner during the training process, and detecting the anti-theft capability of the business model based on the number of iterations of the cloner during the training process.
[0014] Optionally, the anti-theft capability of the business model is positively correlated with the number of iterations of the cloner during the training process.
[0015] Optionally, the method further includes: when the anti-theft capability of the business model does not reach a preset target anti-theft capability, retraining the business model.
[0016] The present specification provides an anti-theft detection device for a model, wherein the anti-theft detection model includes a cloner and a generator, wherein the cloner is used to clone a pre-trained business model, and the generator is used to generate simulated business data input into the cloner, and the device includes: a first simulated business data acquisition module, which is used to input pre-acquired noise into the generator to obtain first simulated business data output by the generator; a first business result acquisition module, which is used to input the first simulated business data into the cloner to obtain the first business result output by the cloner; a generator training module, which is used to improve the first business result output by the cloner for the first simulated business data according to the first business result and the first simulated business data. The error rate of a business result is used as a training target to train the generator; a second simulation business data acquisition module is used to input the noise into the trained generator to obtain the second simulation business data output by the trained generator; a cloner training module is used to input the second simulation business data into the cloner to obtain the second business result output by the cloner; and the second simulation business data is input into the business model to obtain the business result output by the business model as the label of the second business result, so as to train the cloner according to the second business result and the label; a detection module is used to detect the anti-theft capability of the business model according to the number of iterations of the cloner during the training process.
[0017] Optionally, the generator training module is specifically used to freeze all parameters of the cloner; and determine the generation loss of the generator based on the first business result and the first simulation business data; and train the generator based on the generation loss with the training goal of improving the error rate of the first business result output by the cloner for the first simulation business data.
[0018] Optionally, the generator training module is specifically used to determine the current number of iterations of the generator; determine a dynamic adjustment difficulty parameter based on the current number of iterations and a preset total number of iterations, wherein the dynamic adjustment difficulty parameter increases with the increase of the current number of iterations; determine the generation loss function of the generator based on the dynamic adjustment difficulty parameter; determine the generation loss of the generator based on the first business result, the first simulation business data and the generation loss function.
[0019] Optionally, the cloner training module is specifically used to unfreeze all parameters of the cloner and freeze all parameters of the generator; input the second business result and the label into a preset cloning loss function to obtain the cloning loss of the cloner; and train the unfrozen cloner according to the cloning loss.
[0020] Optionally, the cloning loss function includes a KL divergence loss function or an absolute value loss function.
[0021] Optionally, the detection module is specifically used to determine whether the cloner in the anti-theft detection model after training reaches a preset accuracy; if not, continue to train the cloner in the anti-theft detection model until the cloner in the anti-theft detection model reaches a preset accuracy; if so, determine the number of iterations of the cloner during the training process, and detect the anti-theft capability of the business model based on the number of iterations of the cloner during the training process.
[0022] Optionally, the anti-theft capability of the business model is positively correlated with the number of iterations of the cloner during the training process.
[0023] Optionally, the device further comprises: a business model retraining module, configured to retrain the business model when the anti-theft capability of the business model does not reach a preset target anti-theft capability.
[0024] This specification provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, it implements the anti-theft detection method of the above model.
[0025] This specification provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the program, the anti-theft detection method of the above-mentioned model is implemented.
[0026] At least one of the above technical solutions adopted in this specification can achieve the following beneficial effects.
[0027] As can be seen in the model anti-theft detection method provided in this specification, this method utilizes the output of a pre-trained business model to train a cloner, enabling the cloner to clone the business model's business functions. This allows the cloner to detect the business model's anti-theft capabilities based on the number of cloner iterations during training. Furthermore, this method trains the generator based on the cloner's output and the generator's output, independent of the business model. This eliminates the need to train the generator based on the business model's output, reducing the number of business model uses and thus the resource overhead of training the generator. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] The drawings described herein are used to provide further understanding of this specification and constitute a part of this specification. The illustrative embodiments of this specification and their descriptions are used to explain this specification and do not constitute improper limitations on this specification.
[0029] FIG1 is a flow chart of an anti-theft detection method of a model provided in this specification.
[0030] FIG2 is a flow chart of the training generator provided in this specification.
[0031] FIG3 is a schematic diagram of the process of training a cloner provided in this specification.
[0032] FIG4 is a schematic diagram of a model anti-theft detection device provided in this specification.
[0033] FIG5 is a schematic diagram of an electronic device corresponding to FIG1 provided in this specification. DETAILED DESCRIPTION
[0034] To make the purpose, technical solutions, and advantages of this specification more clear, the technical solutions of this specification will be clearly and completely described below in conjunction with the specific embodiments of this specification and the corresponding drawings. Obviously, the embodiments described are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of this application.
[0035] The technical solutions provided by the embodiments of this specification are described in detail below with reference to the accompanying drawings.
[0036] FIG1 is a flow chart of an anti-theft detection method of a model provided in this specification, which specifically includes the following steps.
[0037] S100: Inputting pre-acquired noise into the generator to obtain first simulated service data output by the generator.
[0038] Usually, training a business model requires a lot of computing resources, time and other costs, making the trained model also an important asset. There are many attackers who try to steal the online business model for their own benefit. That is, they learn the functions of the online business model through improper means. Therefore, in order to prevent the business model from being stolen by attackers, anti-theft detection can be performed before the business model goes online to determine the anti-theft capability of the business model, and anti-theft strategies can be formulated based on the anti-theft capability of the business model. This specification provides a model anti-theft detection method. The execution subject of this specification can be a server that trains the business model, or it can be a server or other electronic device that can use the model training method to determine the anti-theft status of the business model. This specification does not limit this. For the sake of convenience, this specification uses the server as the execution subject for explanation.
[0039] When stealing business models, attackers typically use adversarial training to train generators and cloners. This allows the trained generator to generate simulated business data that can be used to access the business model, while the cloner learns all the functions of the business model and maintains the highest possible precision. Precision refers to the accuracy of the cloner's output. However, adversarial training is relatively unstable, and both generator and cloner training require access to the business model's output, resulting in a high number of business model accesses. Comparing the number of times a normal user accesses the business model with the number of times an attacker accesses the model, it is clear that the attacker accesses the business model more frequently. Therefore, before a business model is released online, the number of accesses can be used to test its security against theft.
[0040] In one or more embodiments of this specification, the anti-theft detection model includes a cloner and a generator. The cloner is used to clone a pre-trained business model, that is, the cloner is used to learn the functions of the pre-trained business model. The generator is used to generate simulated business data for input into the cloner. The simulated business data refers to the data generated by the generator that can be used to execute user business. The simulated business data can be the business data corresponding to the user's payment business, the business data corresponding to the user's scan code to add friends business, or the business data corresponding to the user's after-sales business, etc. This specification does not limit the specific type of simulated business data. It should be noted that the simulated business data is generated by the generator, not the real business data. The business model is a model for executing user business, including risk prediction models, object recognition models, image segmentation models, etc. This specification does not limit the type of business model. The generator includes a convolutional neural network model.
[0041] Before the server trains the cloner and generator in the anti-theft detection model, it needs to initialize the cloner and generator according to the pre-trained business model.
[0042] Specifically, since the business model is pre-trained, the server can obtain the structure of the business model's input data and initialize the structure of the cloner and generator's input data based on the structure of the business model's input data. For example, if the business model's input data is a 30*30 image, the cloner and generator's parameters can be adjusted to ensure that their input data is also a 30*30 image. In other words, the dimensions of the cloner and generator's input data match the dimensions of the pre-trained business model's input data.
[0043] Furthermore, to improve the efficiency of training the cloner and reduce the number of business model accesses, a network structure that matches the business model's can be used as the cloner's network structure. In other words, the business model's network structure can be used as the cloner's network structure, or a network structure that is determined to be highly similar to the business model's network structure can be used as the cloner's network structure. Of course, the cloner's network structure and parameters may differ from those of the business model, but the trained cloner must learn the functionality of the business model.
[0044] After initializing the cloner and generator, the server can first train the generator in the anti-theft detection model.
[0045] FIG2 is a flow chart of the training generator provided in this specification, as shown in FIG2 .
[0046] The server needs to first input the pre-acquired noise into the generator to obtain the first simulated service data output by the generator. The noise includes Gaussian noise and the like.
[0047] S102: Input the first simulation service data into the cloner to obtain a first service result output by the cloner.
[0048] It should be noted that this specification does not limit the type of service result. If the user's service is face authentication, the service result can be whether the face authentication is successful. If the user's service is to detect the risk of the current transaction, the service result can be the probability that the transaction is risky. However, since the server has not yet trained the cloner, the service results output by the untrained cloner may be less accurate.
[0049] S104: Training the generator according to the first business result and the first simulation business data, with improving the error rate of the first business result output by the cloner for the first simulation business data as a training goal.
[0050] The server usually uses the zero-order gradient estimation method to train the generator, but the zero-order gradient estimation method requires access to the business model. When the number of accesses is certain, it will affect the training of the cloner.
[0051] Specifically, when training the generator using zero-order gradient estimation, an attacker cannot obtain information about the business model's internal structure, parameters, and other information. Therefore, when training the generator, for each iteration, the attacker needs to input two simulated business data sets with high similarity into the business model, respectively, to train the generator based on the two business results output by the business model. Furthermore, when training the cloner, the server also needs to use the business model once for each iteration. Each input of simulated business data into the business model is defined as a business model access. A normal user may only access the business model once when performing a business. However, an attacker, training the generator and cloner, may need to access the business model three times per iteration. Clearly, the attacker accesses the business model significantly more frequently. If the business model is only allowed 1,000 times, and the number of accesses required to train the cloner so that it learns the business model's functionality is 100,000, then, since the number of accesses allowed is far less than the number required to train the cloner, the cloner may not be able to learn the business model's functionality, thus affecting the cloner's training.
[0052] From the perspective of the business model owner, if the number of business model accesses during training can be reduced, and a cloner with higher accuracy or equivalent accuracy to the attacker's cloner can be obtained, then the accuracy of detecting the business model's anti-theft capabilities based on the number of business model accesses can be increased, thereby reducing the risk of business model theft. The business model owner is the person who designs and trains the business model. If an attacker accesses the business model 100 times for the cloner to learn the business model's functionality, and before the business model goes live, the business model owner uses a method that only requires 50 accesses to enable the cloner to learn the business model's functionality, then the business model is at risk of theft after being accessed a maximum of 50 times, rather than 100 times. This improves the accuracy of detecting the business model's anti-theft capabilities. Business model owners can also retrain or regularly update their business models through the server to prevent theft.
[0053] In order to reduce the number of times the business model is accessed when training the anti-theft detection model, the server can train the generator based only on the first business result and the first simulated business data, with the goal of improving the error rate of the first business result output by the cloner for the first simulated business data, without using the output result of the business model. That is to say, when training the generator, the business model is not accessed, and the generation loss of the generator is determined based on the first business result and the first simulated business data. Based on the generation loss, the generator is trained with the goal of improving the error rate of the first business result output by the cloner for the first simulated business data. It should be noted that the server also needs to freeze all the parameters of the cloner first to avoid the problem that the parameters of the cloner also change when the parameters of the generator are adjusted, thereby avoiding unstable training. Freezing all the parameters of the cloner means fixing all the parameters of the cloner so that all the parameters of the cloner do not change due to changes in the parameters of the generator.
[0054] S106: Input the noise into the trained generator to obtain second simulation business data output by the trained generator.
[0055] FIG3 is a flow chart of the training cloner provided in this specification, as shown in FIG3 .
[0056] In one or more embodiments of the present specification, the noise may also have a different value from the noise input to the generator before training, but the distributions of the two noises must match.
[0057] S108: Input the second simulation business data into the cloner to obtain the second business result output by the cloner; and input the second simulation business data into the business model to obtain the business result output by the business model as a label of the second business result, so as to train the cloner according to the second business result and the label.
[0058] Since all parameters of the cloner are frozen during generator training, before training the cloner, all parameters of the cloner are first unfrozen and all parameters of the generator are frozen. Unfreezing all parameters of the cloner means that all parameters of the cloner can be adjusted, while freezing all parameters of the generator means that all parameters of the generator are fixed, so that all parameters of the generator cannot change as the parameters of the cloner change.
[0059] Since the goal of the server is to enable the cloner to learn the functions of the business model through training, the cloner can be trained through supervised learning.
[0060] Specifically, as shown in FIG3 , the server inputs the second business result and the label into a preset cloning loss function to obtain the cloning loss of the cloner, and trains the cloner with minimizing the cloning loss as the training goal. The cloning loss function includes a KL divergence loss function or an absolute value loss function. If the cloning loss function includes a KL divergence loss function, the cloning loss function is specifically shown as follows:
[0061] Where p is the business result output by the business model, and q is the business result output by the cloner. When the business result is a probability distribution, the business result can be a K-dimensional vector, and the sum of the values of all dimensions is 1. In the above formula, K is the dimension of the business result.
[0062] If the clone loss function includes the absolute value loss function, the clone loss function is specifically shown as follows:
[0063] S110: Detecting the anti-theft capability of the business model according to the number of iterations of the cloner during the training process.
[0064] Since an attacker needs to access the business model when stealing the business model, the server can detect the anti-theft status of the business model based on the number of times the business model is accessed.
[0065] Specifically, to determine whether the cloner in the anti-theft detection model after training reaches the preset accuracy, the server can determine any one or more model accuracy indicators of the cloner's accuracy, precision, and recall rate, and based on the cloner's model accuracy indicator, determine whether the trained cloner is not less than the preset model accuracy indicator. This specification does not limit the specific method for determining the model accuracy indicator, as long as it can be determined based on the model accuracy indicator whether the accuracy of the cloner reaches the preset accuracy.
[0066] If not, continue to train the cloner in the anti-theft detection model until the cloner in the anti-theft detection model reaches a preset accuracy.
[0067] If so, the number of iterations of the cloner during the training process is determined, and the anti-theft capability of the business model is detected according to the number of iterations of the cloner during the training process.
[0068] This is because when an attacker steals a business model, they need to access the business model in order to train the cloner through the output of the business model, enabling the cloner to learn the business model. In this specification, the training generator does not need to access the business model. When training the cloner, the business model is only accessed once for each iteration. In other words, the number of iterations of the cloner during the training process can reflect the number of times the business model is accessed. Therefore, the anti-theft capability of the business model can be detected based on the number of iterations of the cloner during the training process. The anti-theft capability of the business model is positively correlated with the number of iterations of the cloner during the training process. In other words, the more iterations of the cloner during the training process, the stronger the anti-theft capability of the business model.
[0069] Furthermore, after a business model goes live, the server can determine whether there are attackers among all users by counting the number of business model accesses within a preset timeframe. For example, if the average number of business model accesses is 100 three days after the model goes live, but a user has accessed the model 300 times, this user could be an attacker. A user access threshold can also be determined based on the number of cloner iterations during training. When the number of user accesses reaches the threshold, the business model is updated or retrained.
[0070] Based on the number of cloner iterations during the training process, the business model's anti-theft capability is tested. If the business model's anti-theft capability does not reach the preset target anti-theft capability, the business model is retrained. Specifically, when the business model's anti-theft capability does not reach the preset target anti-theft capability, the business model is retrained. Of course, other anti-theft methods can also be used to improve the business model's anti-theft capability, and this specification does not limit this.
[0071] The anti-theft detection method based on the model shown in Figure 1 utilizes the output of a pre-trained business model to train a cloner, enabling it to clone the business model's functionality. This method then detects the business model's anti-theft capabilities based on the number of cloner iterations during training. Furthermore, this method trains the generator based on the cloner's output and the generator's output, independent of the business model. This eliminates the need to train the generator based on the business model's output, reducing the number of business model iterations and the resource overhead associated with training the generator.
[0072] Regarding step S104, to further improve the stability of the training cloner, during the training of the generator, the generator's parameters can be gradually adjusted so that, during the iteration process, the generator first generates easy-to-process simulated business data, and then generates more difficult-to-process simulated business data. This allows the cloner to gradually converge as it processes simulated business data of varying degrees of difficulty. Specifically, based on the generation loss, the generator is trained with the error rate of the first business result output by the cloner for the first simulated business data as the training target. The difficulty of the simulated business data refers to the accuracy of the business result output by the cloner for the simulated data. If the accuracy of the business result output by the cloner for the simulated data is high, it indicates that the simulated business data is relatively easy to process. If the accuracy of the business result output by the cloner for the simulated data is low, it indicates that the simulated business data is relatively difficult to process. The server can assess the difficulty of the simulated business data by using the error rate of the business result output by the cloner for the simulated business data. The error rate of the business result output by the cloner for the simulated business data can be determined by the cloner's output of the simulated business data. In other words, the server can assess the difficulty of the simulated service data by using the entropy of the cloner's data. Specifically, the server obtains the simulated service data, inputs it into the cloner, and outputs a service result for the simulated service data. This service result may be a probability distribution, and the server assesses the difficulty of the simulated service data by determining the entropy of this probability distribution. If the entropy is greater than a preset entropy, it indicates that the current cloner has poor discrimination ability for the simulated service data and the simulated service data is difficult. Conversely, it indicates that the current cloner has good discrimination ability and the simulated service data is easy.
[0073] In order to gradually adjust the parameters of the generator so that the generator first generates easy-to-process simulation business data and then generates simulation business data that is more difficult to process during the iteration process, the server can first determine the current number of iterations of the generator, and then determine the dynamic adjustment difficulty parameter based on the current number of iterations and the preset total number of iterations, wherein the dynamic adjustment difficulty parameter increases as the current number of iterations increases. Thereafter, the generation loss function of the generator is determined based on the dynamic adjustment difficulty parameter. Finally, the generation loss of the generator is determined based on the first business result, the first simulation business data and the generation loss function, and the generator is trained based on the generation loss.
[0074] This specification provides a formula for determining the dynamically adjusted difficulty parameter, as shown below:
[0075] Where iterations is the preset total number of iterations for the generator, and t is the current number of iterations. As the number of iterations increases, the dynamic parameter changes from -1 to 1. However, since the dynamically adjusted difficulty parameter also includes a cosine function, the dynamically adjusted difficulty parameter may increase and then decrease during iterations within a certain range, but the overall difficulty of the simulated business data generated by the generator increases from simple to difficult.
[0076] The generation loss function of the generator is:
[0077] Among them, q is the business result output by the cloner, and K is the dimension of the business result q.
[0078] Then, for subsequent steps S106-S108, when training the cloner, the difficulty of inputting simulated business data into the cloner increases. During a single iteration, the server can first adjust the parameters of the generator once, and then train the cloner based on the generator after the single parameter adjustment. Alternatively, the generator can be iterated a preset number of times, i.e., the parameters of the generator are adjusted multiple times, and then the cloner is trained based on the multiple adjustments. This specification does not impose any restrictions on this, and it can be set as needed.
[0079] The above is a model anti-theft detection method provided in one or more embodiments of this specification. Based on the same idea, this specification also provides a corresponding model anti-theft detection device, as shown in FIG4 .
[0080] FIG4 is a schematic diagram of an anti-theft detection device of a model provided in this specification. The anti-theft detection model includes a cloner and a generator. The cloner is used to clone a pre-trained business model, and the generator is used to generate simulated business data input into the cloner. The device includes: a first simulated business data acquisition module 400, which is used to input pre-acquired noise into the generator to obtain the first simulated business data output by the generator; a first business result acquisition module 402, which is used to input the first simulated business data into the cloner to obtain the first business result output by the cloner; a generator training module 404, which is used to improve the output of the cloner for the first simulated business data based on the first business result and the first simulated business data. The error rate of the first business result is used as a training target to train the generator; a second simulation business data acquisition module 406 is used to input the noise into the trained generator to obtain the second simulation business data output by the trained generator; a cloner training module 408 is used to input the second simulation business data into the cloner to obtain the second business result output by the cloner; and the second simulation business data is input into the business model to obtain the business result output by the business model as a label for the second business result, so as to train the cloner according to the second business result and the label; a detection module 410 is used to detect the anti-theft capability of the business model according to the number of iterations of the cloner during the training process.
[0081] Optionally, the generator training module 404 is specifically used to freeze all parameters of the cloner; and determine the generation loss of the generator based on the first business result and the first simulation business data; and train the generator based on the generation loss with the training goal of improving the error rate of the first business result output by the cloner for the first simulation business data.
[0082] Optionally, the generator training module 404 is specifically used to determine a dynamic adjustment difficulty parameter based on the current number of iterations and the preset total number of iterations, wherein the dynamic adjustment difficulty parameter increases with the increase of the current number of iterations; determine the generation loss function of the generator based on the dynamic adjustment difficulty parameter; determine the generation loss of the generator based on the first business result, the first simulation business data and the generation loss function.
[0083] Optionally, the cloner training module 408 is specifically used to unfreeze all parameters of the cloner and freeze all parameters of the generator; input the second business result and the label into a preset cloning loss function to obtain the cloning loss of the cloner; and train the unfrozen cloner according to the cloning loss.
[0084] Optionally, the cloning loss function includes a KL divergence loss function or an absolute value loss function.
[0085] Optionally, the detection module 410 is specifically used to determine whether the cloner in the anti-theft detection model after training reaches a preset accuracy; if not, continue to train the cloner in the anti-theft detection model until the cloner in the anti-theft detection model reaches a preset accuracy; if so, determine the number of iterations of the cloner in the training process, and detect the anti-theft capability of the business model based on the number of iterations of the cloner in the training process.
[0086] Optionally, the anti-theft capability of the business model is positively correlated with the number of iterations of the cloner during the training process.
[0087] Optionally, the device further comprises: a business model retraining module, configured to retrain the business model when the anti-theft capability of the business model does not reach a preset target anti-theft capability.
[0088] This specification also provides a computer-readable storage medium, which stores a computer program. The computer program can be used to execute the anti-theft detection method of the model provided in FIG. 1 .
[0089] This specification also provides a structural diagram of the electronic device shown in Figure 5. As shown in Figure 5, at the hardware level, the unmanned driving device includes a processor, an internal bus, a network interface, a memory, and a non-volatile memory, and of course may also include hardware required for other services. The processor reads the corresponding computer program from the non-volatile memory into the memory and then runs it to implement the anti-theft detection method of the model described in Figure 1 above. Of course, in addition to software implementation, this specification does not exclude other implementation methods, such as logic devices or a combination of software and hardware, etc., that is, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.
[0090] In the 1990s, technological improvements could be clearly distinguished as either hardware improvements (for example, improvements to circuit structures like diodes, transistors, and switches) or software improvements (improvements to process flows). However, with the advancement of technology, many process flow improvements today can now be considered direct improvements to hardware circuit structures. Designers almost always create the corresponding hardware circuit structure by programming the improved process flow into the hardware circuit. Therefore, it cannot be said that a process flow improvement cannot be implemented using hardware modules. For example, a programmable logic device (PLD), such as a field programmable gate array (FPGA), is an integrated circuit whose logical function is determined by user programming. Designers can "integrate" a digital system on a PLD by programming it themselves, without having to hire a chip manufacturer to design and manufacture a dedicated integrated circuit chip. Moreover, nowadays, instead of manually fabricating integrated circuit chips, this programming is mostly done using "logic compiler" software. This is similar to the software compiler used when developing programs. Before compilation, the original code must also be written in a specific programming language, called a hardware description language (HDL). There is not just one HDL, but many, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, RHDL (Ruby Hardware Description Language), etc. The most commonly used are VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog. Those skilled in the art will also understand that by simply programming the method flow in one of these hardware description languages and then programming it into an integrated circuit, a hardware circuit that implements the logic method flow can be easily obtained.
[0091] The controller can be implemented in any suitable manner. For example, the controller can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicone Labs C8051F320. The memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also know that in addition to implementing the controller in a purely computer-readable program code format, the controller can be implemented in the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers by logically programming the method steps. Therefore, such a controller can be considered a hardware component, and the devices included therein for implementing various functions can also be considered as structures within the hardware component. Or even, the devices for implementing various functions can be considered as both software modules that implement the method and structures within the hardware component.
[0092] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0093] For the convenience of description, the above devices are described as being divided into various units according to their functions. Of course, when implementing this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0094] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0095] The present invention is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0096] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0097] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0098] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0099] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0100] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0101] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0102] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Thus, this specification may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0103] This specification may be described in the general context of computer-executable instructions, such as program modules, executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communications network. In a distributed computing environment, program modules may be located in both local and remote computer storage media, including storage devices.
[0104] The various embodiments in this specification are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the description of the method embodiments.
[0105] The foregoing is merely an embodiment of the present invention and is not intended to limit the present invention. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention are intended to be included within the scope of the claims of this application.
Claims
1. A method for detecting theft of a model, wherein the anti-theft detection model comprises a cloner and a generator, wherein the cloner is used to clone a pre-trained business model, and the generator is used to generate simulated business data input into the cloner, and the method comprises: Inputting the pre-acquired noise into the generator to obtain the first simulated service data output by the generator; Inputting the first simulation service data into the cloner to obtain a first service result output by the cloner; According to the first business result and the first simulation business data, the generator is trained with the goal of improving the error rate of the first business result output by the cloner for the first simulation business data; Inputting the noise into a trained generator to obtain second simulation service data output by the trained generator; Inputting the second simulation service data into the cloner to obtain a second service result output by the cloner; and inputting the second simulation business data into the business model to obtain a business result output by the business model as a label of the second business result, so as to train the cloner according to the second business result and the label; The anti-theft capability of the business model is detected according to the number of iterations of the cloner during the training process.
2. The method according to claim 1, training the generator according to the first business result and the first simulation business data with the aim of improving the error rate of the first business result output by the cloner for the first simulation business data as a training target, specifically comprising: Freeze all parameters of said cloner; and determining a generation loss of the generator according to the first business result and the first simulation business data; The generator is trained according to the generation loss with the training target of improving the error rate of the first business result output by the cloner for the first simulation business data.
3. The method according to claim 2, determining the generation loss of the generator according to the first business result and the first simulation business data, specifically comprising: determining a current iteration number of the generator; Determining a dynamically adjusted difficulty parameter according to the current number of iterations and a preset total number of iterations, wherein the dynamically adjusted difficulty parameter increases as the current number of iterations increases; Determining a generation loss function of the generator according to the dynamically adjusted difficulty parameter; The generation loss of the generator is determined according to the first business result, the first simulation business data and the generation loss function.
4. The method according to claim 2, training the cloner according to the second business result and the label, specifically comprising: unfreeze all parameters of the cloner and freeze all parameters of the generator; Inputting the second business result and the label into a preset cloning loss function to obtain the cloning loss of the cloner; The thawed cloner is trained according to the clone loss.
5. The method according to claim 4, wherein the cloning loss function comprises a KL divergence loss function or an absolute value loss function.
6. The method according to claim 1, detecting the anti-theft capability of the business model according to the number of iterations of the cloner during the training process, specifically comprising: Determining whether the cloner in the trained anti-theft detection model reaches a preset accuracy; If not, continue to train the cloner in the anti-theft detection model until the cloner in the anti-theft detection model reaches a preset accuracy; If so, the number of iterations of the cloner during the training process is determined, and the anti-theft capability of the business model is detected according to the number of iterations of the cloner during the training process.
7. According to the method of claim 1, the anti-theft capability of the business model is positively correlated with the number of iterations of the cloner during the training process.
8. The method of claim 7, further comprising: When the anti-theft capability of the business model does not reach a preset target anti-theft capability, the business model is retrained.
9. A device for detecting theft of a model, wherein the device comprises a cloner and a generator, wherein the cloner is used to clone a pre-trained business model, and the generator is used to generate simulated business data input into the cloner, and wherein the device comprises: A first simulation service data acquisition module, used for inputting the pre-acquired noise into the generator to obtain the first simulation service data output by the generator; A first business result acquisition module, used for inputting the first simulation business data into the cloner to obtain a first business result output by the cloner; A generator training module, configured to train the generator according to the first business result and the first simulation business data, with the aim of improving the error rate of the first business result output by the cloner for the first simulation business data as a training target; A second simulation business data acquisition module, used for inputting the noise into the trained generator to obtain second simulation business data output by the trained generator; a cloner training module, configured to input the second simulated business data into the cloner to obtain a second business result output by the cloner; and input the second simulated business data into the business model to obtain a business result output by the business model as a label of the second business result, so as to train the cloner according to the second business result and the label; The detection module is used to detect the anti-theft capability of the business model according to the number of iterations of the cloner during the training process.
10. In the device as described in claim 9, the generator training module is specifically used to freeze all parameters of the cloner; and determine the generation loss of the generator based on the first business result and the first simulation business data; based on the generation loss, the generator is trained with the training goal of improving the error rate of the first business result output by the cloner for the first simulation business data.
11. The apparatus according to claim 10, wherein the generator training module is specifically used to determine the current iteration number of the generator; and determine the dynamic adjustment difficulty parameter according to the current iteration number and the preset total iteration number, wherein: The dynamically adjusted difficulty parameter increases as the current number of iterations increases; based on the dynamically adjusted difficulty parameter, the generation loss function of the generator is determined; based on the first business result, the first simulation business data and the generation loss function, the generation loss of the generator is determined.
12. In the device as described in claim 10, the cloner training module is specifically used to unfreeze all parameters of the cloner and freeze all parameters of the generator; input the second business result and the label into a preset cloning loss function to obtain the cloning loss of the cloner; and train the unfrozen cloner according to the cloning loss.
13. The apparatus as claimed in claim 12, wherein the cloning loss function comprises a KL divergence loss function or an absolute value loss function.
14. In the device as described in claim 9, the detection module is specifically used to determine whether the cloner in the anti-theft detection model after training reaches a preset accuracy; if not, continue to train the cloner in the anti-theft detection model until the cloner in the anti-theft detection model reaches a preset accuracy; if so, determine the number of iterations of the cloner in the training process, and detect the anti-theft capability of the business model based on the number of iterations of the cloner in the training process.
15. The device as claimed in claim 9, wherein the anti-theft capability of the business model is positively correlated with the number of iterations of the cloner in the training process.
16. The apparatus of claim 9, further comprising: The business model retraining module is used to retrain the business model when the anti-theft capability of the business model does not reach a preset target anti-theft capability.
17. A computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor, implements the method according to any one of claims 1 to 8.
18. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method according to any one of claims 1 to 8 when executing the program.
Citation Information
Patent Citations
Method and device for preventing model parameters from being stolen, computer equipment and storage medium
CN113821792A
Model stealing detection method combining training set data distribution and W distance
CN115935179A
Rapid model generation method based on diffusion model
CN115935817A
Anti-theft detection method and device for model, storage medium and electronic equipment
CN117592056A
Stolen machine learning model identification
US20190258783A1