Federated learning method and system for decentralized orthogonal encryption based on symmetric noise

By adopting a decentralized orthogonal encryption method based on symmetric noise in federated learning, the problems of high cost and third-party dependence of homomorphic encryption are solved, efficient and secure gradient encryption and decryption are achieved, and the security and efficiency of the system are enhanced.

CN120223312AActive Publication Date: 2025-06-27HUNAN UNIV OF SCI & TECH

Patent Information

Application Number
CN202510682436.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-26
Publication Date
2025-06-27
Estimated Expiration
2045-05-26

AI Technical Summary

Technical Problem

In current federated learning, the high computing and communication costs brought by homomorphic encryption, and most gradient encryption methods rely on trusted third parties to generate masks or keys, which increases the complexity and trust risk of key management, making it difficult to find a balance between efficiency and security.

Method used

Using a decentralized orthogonal encryption method based on symmetric noise, SVD decomposition of the initial model is performed through a central server, and the client generates a local private orthogonal encryption matrix and a global shared orthogonal encryption matrix. The private encryption matrix is ​​divided into sub-shares using the threshold secret sharing mechanism, and the global aggregation result is restored through the iterative decryption process.

Benefits of technology

It realizes efficient encryption and lossless decryption of gradients, effectively resists inference attacks from semi-honest servers, clients and malicious third-party members, maintains the efficiency of model accuracy, does not rely on third-party trusted institutions, and simplifies key management.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223312A_ABST
    Figure CN120223312A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of artificial intelligence security, discloses a federated learning method and system based on decentralized orthogonal encryption of symmetric noise, and realizes efficient and secure communication and calculation in federated learning. Performing SVD decomposition on the initial model to generate a row representation matrix and a column representation matrix, and determining a row and column sampling index value through a Nystrom method and issuing the row and column sampling index value to a client; the client generates a local private orthogonal encryption matrix and a global shared orthogonal encryption matrix, and encrypts a local model matrix; dividing the private encryption matrix into N sub-shares through a threshold secret sharing mechanism, constructing a (t-1)-degree polynomial to realize secret distribution, and forming a distribution matrix; the central server carries out weight sorting instead of aggregation on the encryption matrixes uploaded by the client, and a sorted encryption matrix set is generated; and the client gradually removes an encryption matrix by utilizing transposition of an orthogonal matrix and secret sharing reconstruction through an iterative decryption process, and recovers a global aggregation result through a noise cancellation mechanism.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence security technology, and particularly relates to a federated learning method and system based on symmetric noise decentralized orthogonal encryption. Background Art

[0002] Preventing privacy leakage is a key issue in federated learning. Commonly used methods include gradient obfuscation, compression, and encrypted transmission, etc. For gradient obfuscation, differential privacy is an effective means to protect privacy by adding Gaussian noise to the gradient. However, compared with the fixed parameter strategy, although dynamically adjusting the noise variance and injection amount can improve the privacy protection effect, it often leads to a loss of model accuracy and increases the optimization difficulty; On the other hand, exploring the possibility of privacy protection from the perspective of gradient compression has also received attention. For example, methods such as Top-K and QSGD were initially proposed to reduce the communication overhead in federated learning, but it was found that they also have a certain privacy protection ability. Nevertheless, regarding privacy enhancement as a by-product of gradient compression is not appropriate, and it is necessary to re-examine and design the client data privacy protection mechanism in existing algorithms. Based on this, some new methods such as PEFL (Privacy-Enhanced Federated Learning) have been proposed to resist specific types of attacks without compromising the model performance. However, the security assumptions of these methods usually assume that the server is completely trustworthy, which may not hold in practice; Gradient encryption, as a fundamental data leakage protection measure, allows encrypted transmission of gradients and performs arithmetic operations in the encrypted state. Homomorphic encryption (HE), as a technology to defend against DLG (Deep Leakage from Gradients) attacks, supports gradient aggregation without decryption, while providing privacy protection and security. However, homomorphic encryption is usually accompanied by high computational and communication costs, so it is necessary to seek a balance between efficiency and security; To solve the high overhead problem brought by homomorphic encryption, efficient schemes such as lossless matrix masked federated SVD have been proposed, significantly improving the computational efficiency. However, these methods are mainly applicable to specific scenarios and do not fully consider how to defend against gradient leakage attacks. In addition, most gradient encryption methods rely on a trusted third party to generate masks or keys, increasing the complexity and trust risk of key management in practical applications; In summary, the current research work faces challenges in the balance between efficiency and security and the limitations of security assumptions. Summary of the Invention

[0003] The purpose of the present invention is to solve the above problems, and a federated learning method and system based on decentralized orthogonal encryption with symmetric noise are designed.

[0004] The first aspect of the present invention provides a federated learning method based on decentralized orthogonal encryption with symmetric noise, including the following steps: S1. The central server performs SVD decomposition on the initial model to generate a row representation matrix and a column representation matrix, and determines the row and column sampling index values through the Nystrom method and distributes them to the clients; S2. The client generates a local private orthogonal encryption matrix and a global shared orthogonal encryption matrix. After using Gram-Schmidt orthogonalization processing, a double orthogonal transformation is used to encrypt the local model matrix; S3. The private encryption matrix is divided into N sub-shares through a threshold secret sharing mechanism, and a t-1 degree polynomial is constructed to realize secret distribution, forming a distribution matrix; S4. The central server performs weight sorting rather than aggregation on the encrypted matrices uploaded by the clients to generate a sorted set of encrypted matrices; S5. The client removes the encrypted matrices step by step through an iterative decryption process, using the transpose of the orthogonal matrix and secret sharing reconstruction, and finally restores the global aggregation result through a noise cancellation mechanism.

[0005] Optionally, in the first implementation manner of the first aspect of the present invention, the generation method of the global shared orthogonal matrix in step S2 is: The generation method is: , ; Among them, , The matrices are generated distributively through secure multi-party computation.

[0006] Optionally, in the second implementation manner of the first aspect of the present invention, the specific implementation of the secret sharing in step 3 includes: Construct polynomials independently for each element of the matrix, and use the polynomial calculation results as sub-secrets for distribution; Construct a distribution matrix, and the non-diagonal elements in the distribution matrix contain the shared sub-secrets among the clients.

[0007] Optionally, in the third implementation manner of the first aspect of the present invention, the polynomial construction includes a dynamic threshold adjustment mechanism: Calculate the effective threshold value in real time according to the online status of the clients, and dynamically adjust the number of Lagrange interpolation calculation nodes.

[0008] Optionally, in the fourth implementation manner of the first aspect of the present invention, the server sorting process in step 4 includes: Perform a lexicographical sort on the encrypted client matrix according to the client number to ensure the discrete state of the encrypted data.

[0009] Optionally, in the fifth implementation manner of the first aspect of the present invention, the server sorting process in step 4 includes: Establish an encrypted data verification structure based on the Merkle tree, generate a root hash value for the sorted encrypted matrix set, and the client confirms the data integrity and order consistency by verifying the hash chain.

[0010] Optionally, in the sixth implementation manner of the first aspect of the present invention, the iterative decryption process in step 5 includes: Perform preliminary decryption by right-multiplying the transpose of the global orthogonal matrix; Reconstruct the private encrypted matrix by Lagrange interpolation method; Execute the left-multiplication decryption operation in rounds, and finally obtain the unencrypted global matrix through the noise cancellation mechanism.

[0011] The second aspect of the present invention provides a federated learning system for decentralized orthogonal encryption based on symmetric noise, and the system includes: The SVD decomposition module is used for the central server to perform SVD decomposition on the initial model, generate a row representation matrix and a column representation matrix, and determine the row and column sampling index values through the Nystrom method and send them to the client; The encryption module is used for the client to generate a local private orthogonal encryption matrix and a global shared orthogonal encryption matrix, and after using Gram-Schmidt orthogonalization processing, encrypt the local model matrix by using double orthogonal transformation; The construction module is used to divide the private encrypted matrix into N sub-shares through the threshold secret sharing mechanism, construct a t-1 degree polynomial to realize secret distribution, and form a distribution matrix; The sorting module is used for the central server to perform weight sorting rather than aggregation on the encrypted matrices uploaded by the clients, and generate a sorted set of encrypted matrices; The decryption module is used for the client to gradually remove the encrypted matrix through the iterative decryption process, using the transpose of the orthogonal matrix and secret sharing reconstruction, and finally recover the global aggregation result through the noise cancellation mechanism.

[0012] Optionally, in the first implementation manner of the second aspect of the present invention, the construction module includes: The construction sub-module is used to independently construct polynomials for each element of the matrix, and use the polynomial calculation results as sub-secrets for distribution; The construction sub-module is used to construct a distribution matrix, and the non-diagonal elements in the distribution matrix contain the shared sub-secrets between the clients.

[0013] Optionally, in the second implementation manner of the second aspect of the present invention, the decryption module includes: A preliminary decryption sub-module for performing preliminary decryption by right-multiplying the transpose of the global orthogonal matrix; A reconstruction sub-module for reconstructing the private encryption matrix by Lagrange interpolation method; A cancellation sub-module for performing left-multiplication decryption operations in rounds, and finally obtaining the unencrypted global matrix through a noise cancellation mechanism.

[0014] In the technical solution provided by the present invention, S1, the central server performs SVD decomposition on the initial model to generate a row representation matrix and a column representation matrix, and determines the row and column sampling index values through the Nystrom method and distributes them to the client; the client generates a local private orthogonal encryption matrix and a global shared orthogonal encryption matrix, and after using Gram-Schmidt orthogonalization processing, encrypts the local model matrix by using double orthogonal transformation; the private encryption matrix is divided into N sub-shares through a threshold secret sharing mechanism, and a t-1 degree polynomial is constructed to realize secret distribution to form a distribution matrix; the central server performs weight sorting instead of aggregation on the encrypted matrices uploaded by the client to generate a set of sorted encrypted matrices; the client gradually removes the encrypted matrices through an iterative decryption process by using the transpose of the orthogonal matrix and secret sharing reconstruction, and finally restores the global aggregation result through a noise cancellation mechanism; the present invention designs a decentralized orthogonal encryption framework based on symmetric noise, realizes efficient encryption and lossless decryption of gradients, and effectively resists the inference attacks of semi-honest servers, clients, and malicious third parties; innovatively combines symmetric noise with the secret sharing mechanism, protects the privacy of the intermediate values in the gradient decryption process through the introduction of symmetric noise, and at the same time uses the secret sharing mechanism to ensure the security of the private orthogonal matrix and avoid any single party from reconstructing private information; a lightweight gradient privacy encryption and decryption scheme, while ensuring privacy protection, the method only has a minimal impact on accuracy and does not rely on a third-party trusted institution, realizing efficient and secure communication and computing in federated learning. Description of the Drawings

[0015] By reading the detailed description of the preferred embodiments below, various other advantages and benefits will become clear to those of ordinary skill in the art. The drawings are only for the purpose of showing the preferred embodiments and are not considered to be a limitation of the present invention.

[0016] Figure 1 It is a flowchart of the federated learning method for decentralized orthogonal encryption based on symmetric noise provided by the embodiment of the present invention; Figure 2 It is a visualization schematic diagram of the DLG attack on the MNIST dataset provided by the embodiment of the present invention; Figure 3It is a visualization schematic diagram of the iDLG attack on the MNIST dataset provided by an embodiment of the present invention; Figure 4 It is a visualization schematic diagram of the DLG attack on the CIFAR10 dataset provided by an embodiment of the present invention; Figure 5 It is a visualization schematic diagram of the iDLG attack on the CIFAR10 dataset provided by an embodiment of the present invention; Figure 6 It is a schematic diagram of accuracy comparison on the MNIST dataset provided by an embodiment of the present invention; Figure 7 It is a schematic diagram of accuracy comparison on the CIFAR10 dataset provided by an embodiment of the present invention; Figure 8 It is a schematic diagram of the influence of different Rank values on the accuracy of the embodiment of the present invention on the MNIST dataset; Figure 9 It is a schematic diagram of the influence of different Rank values on the accuracy of the embodiment of the present invention on the CIFAR10 dataset; Figure 10 It is a schematic diagram of the structure of the federated learning system based on symmetric noise decentralized orthogonal encryption provided by an embodiment of the present invention. Detailed implementation manners

[0017] Terms such as "first", "second", "third", "fourth", etc. (if any) in the specification, claims and above-mentioned drawings of the present invention are used to distinguish similar objects and do not necessarily describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments described here can be implemented in an order different from that shown or described here. In addition, the terms "include" or "have" and any deformation thereof are intended to cover non-exclusive inclusion. For example, a process, method, device, product or device that includes a series of steps or units does not necessarily limit to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0018] Embodiment 1 Please refer to Figure 1 , this embodiment provides a federated learning method based on symmetric noise decentralized orthogonal encryption, including the following steps: S1. The central server performs SVD decomposition on the initial model to generate a row representation matrix and a column representation matrix, and determines row and column sampling index values through the Nystrom method and distributes them to the clients; S2. The client generates a local private orthogonal encryption matrix and a global shared orthogonal encryption matrix. After using Gram - Schmidt orthogonalization processing, a double orthogonal transformation is used to encrypt the local model matrix. S3. Through the threshold secret sharing mechanism, the private encryption matrix is divided into N sub - shares, and a t - 1 degree polynomial is constructed to achieve secret distribution, forming a distribution matrix. S4. The central server performs weight sorting instead of aggregation on the encrypted matrices uploaded by the clients, generating a set of sorted encrypted matrices. S5. The client uses an iterative decryption process, and by using the transpose of the orthogonal matrix and secret sharing reconstruction, gradually removes the encrypted matrices. Finally, the global aggregation result is restored through a noise cancellation mechanism.

[0019] In this embodiment, S1: SVD initialization: CS decomposes the initialized model layer - by - layer SVD into two sub - matrix sets and , which represent the row representation matrix and the column representation matrix respectively, and obtains fixed row - column sampling index values and through gradient random sampling by the Nystrom method. The generated sub - matrices and row - column sampling index values are sent to all clients for training and subsequent encryption operations.

[0020] In this embodiment, S2: Generation of encryption matrices: Theorem 1 proves that the product of any orthogonal matrices is still an orthogonal matrix. Data perturbation can be performed through orthogonal matrix transformation, just like adding noise in differential privacy (DP) for privacy protection. Theorem 2 proves that the perturbed and have the same singular values. Using matrices and can orthogonally transform the singular vectors of and , so that the singular vectors of can be obtained by removing matrix perturbation from the singular vectors of . Therefore, through randomly orthogonal matrix multiplication, effective data perturbation can be achieved without changing the data characteristics, thus achieving the purpose of privacy protection. However, if both matrices and are publicly shared, the encryption is in vain. At the same time, if both are privatized, lossless decryption is very difficult and costly. We hope that the encryption of the client can be both public and private like public - private keys. Therefore, the client will generate a locally private orthogonal transformation encryption matrix and a globally shared orthogonal transformation encryption matrix 。

[0021] Theorem 1: For any product of orthogonal matrices is still an orthogonal matrix; Proof. Assume and are both orthogonal matrices, that is, they satisfy and , verify whether their product is still an orthogonal matrix. First, calculate : ; Next, verify whether is equal to : ; Using the associative law of matrix multiplication, the above formula can be expanded: ; Therefore, satisfies the definition of an orthogonal matrix.

[0022] Theorem 2: For any matrix , its SVD is , if two random orthogonal matrices and are used to perturb , forming the encrypted matrix , the encrypted matrix shares the same singular values as the original matrix . Further, through the known orthogonal matrices and , the singular vectors of the encrypted matrix can be transformed back to the singular vectors of the original matrix ; Proof. Substitute the decomposition of and use the associative law of matrix multiplication: ; It can be verified by Theorem 1 that and are also orthogonal matrices. Let : ; Therefore, the encrypted matrix can be decomposed under the condition of having the same singular values as the original matrix , indicating that the singular values of the matrix remain unchanged after orthogonal transformation.

[0023] In this embodiment, S3: Secret sharing of the private encryption matrix: Although we can encrypt data through orthogonal matrix transformation, the multiplication operation of the orthogonal matrix does not preserve the additive homomorphic property. Therefore, after the CS side aggregates the encrypted matrix, it is often difficult for the client to decrypt it losslessly. Therefore, in order to achieve secure and trustworthy aggregation, we designed an iterative solution secret sharing method. The client receives unaggregated ciphertext data and decrypts the data step by step through its own private key and the globally shared key.

[0024] In this stage, our goal is to perform threshold secret sharing on the client's private encryption matrix so that even if the server or some clients obtain part of the encrypted matrix data, they cannot recover the original matrix. Only when enough clients work together can the original private matrix be recovered. Specifically, we divide each client's private encryption matrix (such as or ), through the secret sharing protocol, and share these divided shares with other clients.

[0025] The threshold secret sharing scheme consists of a sharing operation Share() and a recovery operation Rec(). In the sharing operation Share(), the secret distributor randomly generates a -degree polynomial: ; where is the secret of the secret distributor , , , …, are randomly selected coefficients, is the required minimum number of shares, is a large prime number used to define the finite field , and its value must be large enough to ensure that both the secret and the coefficients of the polynomial can be represented in this field. The secret distributor selects different values , calculates the polynomial , and distributes the calculation result of the polynomial as a shared sub-secret to the corresponding participants . Because is a matrix rather than a coefficient, the shape of needs to be the same as the shape of . And the sharing method of each element of the matrix is independent, so in this paper is not affected by the shape of , that is, each matrix element will be mapped to a constant term of a polynomial, and the coefficients of the polynomial will generate sub-secrets for each matrix element: ; Among them is a matrix The number of rows and columns are respectively of the elements, corresponding to the coefficients in the polynomial For each participant, the shared result is the secret matrix , : ; Finally, the distribution matrix is formed: ; In addition to the private matrices , and the shared matrices , , the participating clients also have other secret sub-shares shared by other participating clients , , but any single client cannot know the complete of other clients.

[0026] In this embodiment, S4: Client encryption: In this stage, each client will generate two random real matrices through two integer random seeds and in the initial stage, is used to generate the private random matrix , then generates the public random matrix . To ensure that the matrix has orthogonal properties, we use the Gram-Schmidt scheme to orthogonalize it, generating the private encrypted orthogonal matrix and the shared encrypted matrix to be collaboratively computed. Then, through secure multi-party computation (SMPC), the generation of the global shared orthogonal matrix , is achieved. The CS will perform a cumulative multiplication calculation on all participating in client training to obtain the globally shared orthogonal transformation encrypted matrix , Therefore, the encryption of the sub-matrix can be achieved by multiplying the encryption matrices on the left and right respectively, and the process can be expressed as: ; To enhance privacy protection, we introduce an encryption method based on symmetric noise. Specifically, before encrypting the matrix, a noise term is added to the plaintext data to increase the privacy guarantee during the decryption process. This method can ensure that even if an attacker obtains partial information during the iterative decryption process, it is difficult to recover the original data.

[0027] In this embodiment, when each client encrypts, noise is added to the original matrix, and the formula is as follows: ; Wherein, is the introduced symmetric noise term. Even if the client gradually decrypts the secret sharing and , the intermediate result obtained is also a noise-added interference value. Only when the process of secret sharing ends can the decryption result without noise be obtained in a convergent manner by utilizing the characteristic that the mean value of the noise is zero.

[0028] In this article, noise is part of the encrypted data and is finally processed together through threshold decryption. Therefore, it does not bring additional communication overhead due to the introduction of a new encryption strategy, and at the same time, it avoids the leakage of sensitive information in the intermediate process.

[0029] In this embodiment, S5: Server sorting: The aggregation process of the traditional SVD-based FL model is that the CS side calculates the sum of the products of the matrices and weights of all clients respectively: ; Where the weight , represents the proportion of the dataset size of each client in the total dataset. Since this framework uses a non-homomorphic encryption strategy, directly performing encrypted aggregation in the presence of a private matrix will make it impossible for the client to recover valid information losslessly from the aggregation result, but may instead increase the complexity of decryption, thus affecting the performance of the model. In order to decrypt the aggregated matrix and such a secure model of hybrid encryption losslessly, in this framework, the CS does not perform actual addition operations on the uploaded data, but sorts the encrypted data according to the client number . Therefore, the encrypted information received by the client is as follows: ; And there is a characteristic that the mean value of the noise is zero: .

[0030] S6: Client decryption: After the client receives the and sent by the CS, it decrypts by multiplying the right side by the transpose of the globally shared orthogonal transformation matrix to obtain , : ; ; Since is an orthogonal matrix and satisfies , so can be easily removed during decryption. For the privately encrypted matrix that is secretly shared, we recover the secret through polynomial interpolation. During the secret reconstruction operation Rec(), it is necessary to or more than participant members jointly reconstruct the secret before jointly reconstructing . Specifically, the matrix elements recover the secret by solving the following Lagrange interpolation: ; When the in the polynomial takes the value of 0, the reconstructed secret element , and the final result of the inverse mapping reconstruction is the secret matrix .

[0031] After reconstructing the encrypted matrix, we can gradually left-multiply the transpose of the encrypted matrix to decrypt the global left and right sub-matrices losslessly, as shown in formula (19): ; where represents the result of the client secretly sharing under the secret sub-share , and is a decryption function. Each client uses to partially decrypt the left encrypted matrix. Taking the th client's as an example, the iterative decryption process of the secret sharing is as follows: ; ; … ; And so on until all clients jointly reconstruct the global matrix .

[0032] Although during the step-by-step decryption process, the recursively multiplied secret transpose matrix will expose the left and right sub-matrices of each client, due to the introduction of the noise term, the intermediate result is only a noisy interference value. Only after the secret sharing process ends can we utilize the characteristic that the noise mean is zero to obtain the denoised decryption result in a convergent manner.

[0033] Experimental result analysis: Performance of the experimental platform adopted in the embodiments of the present invention: It is configured with 1 Intel(R) Xeon(R) Gold 6330 CPU with a main frequency of 2.00 GHz, equipped with 32×4 GB of memory and an NVIDIA GeForce RTX 4090 GPU, running the Ubuntu 20.04.4 LTS operating system, the programming language is Python3.10, and PyTorch2.0.0 is used for model training. Set the number of FL iterations T = 300, the number of users N = 20, and all clients participate in each iteration.

[0034] Experiments were conducted on 2 datasets to evaluate the effectiveness of the proposed method: MNIST: It is a widely used computer vision dataset in machine learning. It consists of 70,000 grayscale images of handwritten digits from 0 to 9, of which 60,000 are used for training and 10,000 are used for testing. Each image is a 28×28 pixel grayscale image representing the digits 0 to 9. On the MNIST dataset, we used the classic LeNet-5 model for experiments. LeNet-5 is a lightweight convolutional neural network suitable for handling simple grayscale image classification tasks.

[0035] CIFAR10: It is also commonly used for image classification tasks in machine learning. It consists of 60,000 color images in 10 categories, of which 50,000 images are used for training and 10,000 images are used for testing. Each image is a 32×32 pixel square, divided into 10 categories such as birds, trucks, airplanes, dogs, deer, cats, boats, horses, frogs, and cars. The CIFAR10 dataset is more challenging than SVHN due to the larger image size and the diversity of objects in the images. On the CIFAR-10 dataset, we adopted the ResNet-34 model, whose deep residual network structure can effectively handle the larger image size and diversity problems in the CIFAR-10 dataset, while providing a high classification accuracy.

[0036] Figure 2 Shows the image reconstruction iteration process of the DLG attack on the MNIST dataset. On a simple dataset, the attacker can restore a reconstruction result close to the original image. After increasing the confusion value and sparsity of the gradient, the image reconstruction quality decreases, but the category of the reconstructed image can still be distinguished on a simple dataset.

[0037] Figure 3 Shows the image reconstruction iteration process of the iDLG attack on the MNIST dataset. iDLG replaces the original DLG's SGD algorithm by introducing an adaptive momentum optimizer (Adam). The gradient backpropagation mechanism can better capture local detail features and is visually closer to the continuity and smoothness of real strokes.

[0038] Figure 4 and Figure 5 respectively represent the image reconstruction iteration processes of DLG attack and iDLG attack on the CIFAR10 dataset. Compared with the MNIST dataset, the reconstructed images on CIFAR10 are more difficult. After increasing the confusion value and sparsity of the gradients, the image reconstruction quality deteriorates, and it is almost impossible to reconstruct the original images.

[0039] Figure 6 and Figure 7 respectively show the model accuracies of different defense methods on the MNIST and CIFAR10 datasets. The accuracy of our method on each dataset is not much different from that of FedAvg. In contrast, for the traditional defense methods DP and GC, the accuracy on the simple dataset MNIST may not be affected, but when dealing with more complex datasets, the accuracy of DP and GC drops significantly. This indicates that our method of lossless decryption can better maintain the accuracy when dealing with more complex datasets and does not significantly affect the model performance while protecting privacy.

[0040] Figure 8 and Figure 9 respectively show the influence of different Rank values on the accuracy on the MNIST and CIFAR10 datasets. On relatively simple datasets such as MNIST, as the Rank value decreases, the accuracy changes little, only dropping by 0.36%, indicating that the framework can maintain a high model performance at a lower Rank. On more complex datasets, the decrease in the Rank value leads to a slightly more obvious drop in accuracy, with a 2.61% decrease on CIFAR-10.

[0041] Security analysis: To prove that the encrypted mask matrix is secure in the FedSND framework, we use formulas and mathematical derivations to demonstrate how the mask matrix ensures data privacy and anti-attack capabilities. The following are the relevant formulas and proofs for the encrypted mask matrix and its security.

[0042] A. Privacy analysis against reconstruction attacks An attacker attempts to recover the central matrix through the known sampling indices and : ; When the private matrices of all clients are the same, i.e., , then , . However, when the private matrices are different, the aggregated global sub-matrix is a matrix that depends on and cannot be simply extracted, so , . For convenience of representation, we use the symbol to represent the abstract complex relationship matrix derived from and . After the attacker recovers the central matrix, the original gradient matrix will be reconstructed and the following equation will be attempted to be solved: ; We can see that the reconstructed original gradient matrix still has the abstract complex relationship after being decrypted using the shared matrix , which is mathematically equivalent to solving a system of high-dimensional linear equations: ; Therefore, when the client's private orthogonal matrix has randomness, it ensures that the server cannot restore the secret without stealing enough private matrices.

[0043] B. Threshold Secret Sharing Mechanism Based on Symmetric Noise In FedSND, the system uses the Shamir threshold secret sharing scheme with the threshold set to , and at least shares are required to reconstruct the original secret . Suppose there are attackers jointly attempting to recover the secret . The attacker can obtain shares and the corresponding points . This allows the attacker to list the following linear equations: ; These systems of equations contain unknowns: . However, the attacker only has equations, so the system of equations is under-determined, and the solution set contains infinitely many possible polynomials and cannot be uniquely determined by linear algebra methods or . When , the attacker obtains enough shares to be able to completely recover the polynomial by interpolation, thus leaking the secret .

[0044] Since the values sent by the server are sorted rather than aggregated, the intermediate values during the gradual decryption by the client can be stolen and inferred by attackers. However, FedSNDOE adds symmetric noise during the encryption phase, so the intermediate values after decryption after restoring the secret are fuzzy values that differ greatly from the initial values, and attackers cannot accurately infer the original data. It is not until all intermediate values are decrypted that the positive and negative noises can cancel each other out in an aggregated manner.

[0045] Embodiment 2 Please refer to Figure 10 , a schematic structural diagram of a federated learning system for decentralized orthogonal encryption based on symmetric noise provided by an embodiment of the present invention. The method includes: The SVD decomposition module is used for the central server to perform SVD decomposition on the initial model, generate a row representation matrix and a column representation matrix, and determine row and column sampling index values through the Nystrom method and send them to the client; The encryption module is used for the client to generate a local private orthogonal encryption matrix and a globally shared orthogonal encryption matrix. After using Gram-Schmidt orthogonalization processing, a double orthogonal transformation is used to encrypt the local model matrix; The construction module is used to divide the private encryption matrix into N sub-shares through a threshold secret sharing mechanism, construct a t-1 degree polynomial to implement secret distribution, and form a distribution matrix; The sorting module is used for the central server to perform weight sorting rather than aggregation on the encrypted matrices uploaded by the clients, and generate a set of sorted encrypted matrices; The decryption module is used for the client to gradually remove the encrypted matrices through an iterative decryption process, using the transpose of the orthogonal matrix and secret sharing reconstruction, and finally restore the global aggregation result through a noise cancellation mechanism.

[0046] In this embodiment, the construction module includes: The construction sub-module is used to independently construct polynomials for each element of the matrix, and use the polynomial calculation results as sub-secrets for distribution; The construction sub-module is used to construct a distribution matrix, and the non-diagonal elements in the distribution matrix contain shared sub-secrets among clients.

[0047] In this embodiment, the decryption module includes: The preliminary decryption sub-module is used for preliminary decryption by right-multiplying the transpose of the global orthogonal matrix; The reconstruction sub-module is used to reconstruct the private encryption matrix through Lagrange interpolation; The cancellation sub-module is used to perform left-multiplication decryption operations in rounds, and finally obtain the unencrypted global matrix through a noise cancellation mechanism.

[0048] The foregoing has shown and described the basic principles, main features and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited by the above embodiments, and the above embodiments and the descriptions in the specification are only preferred examples of the present invention, and are not used to limit the present invention. Without departing from the spirit and scope of the present invention, the present invention will have various changes and improvements, and these changes and improvements all fall within the scope of the present invention claimed. The scope of protection of the present invention is defined by the appended claims and their equivalents.

Claims

1. A federated learning method for decentralized orthogonal encryption based on symmetric noise, characterized in that It includes the following steps: S1. The central server performs SVD decomposition on the initial model to generate a row representation matrix and a column representation matrix, and determines row and column sampling index values through the Nystrom method and distributes them to the client; S2. The client generates a local private orthogonal encryption matrix and a global shared orthogonal encryption matrix. After using Gram-Schmidt orthogonalization processing, it encrypts the local model matrix by using double orthogonal transformation; S3. The private encryption matrix is divided into N sub-shares through a threshold secret sharing mechanism, and a t-1 degree polynomial is constructed to realize secret distribution, forming a distribution matrix; S4. The central server performs weight sorting instead of aggregation on the encrypted matrices uploaded by the clients to generate a set of sorted encrypted matrices; S5. The client gradually removes the encrypted matrix through an iterative decryption process by using the transpose of the orthogonal matrix and secret sharing reconstruction, and finally restores the global aggregation result through a noise cancellation mechanism.

2. The federated learning method for decentralized orthogonal encryption based on symmetric noise according to claim 1, characterized in that The global shared orthogonal matrix in step S2 is generated as follows: , ; Among them, and the matrix is generated distributively through secure multi-party computation.

3. A federated learning method for decentralized orthogonal encryption based on symmetric noise as claimed in claim 1, wherein The specific implementation of the secret sharing in step 3 includes: Construct polynomials independently for each element of the matrix, and use the polynomial calculation results as sub-secrets for distribution; Construct a distribution matrix, and the non-diagonal elements in the distribution matrix contain the shared sub-secrets among the clients.

4. The federated learning method for decentralized orthogonal encryption based on symmetric noise according to claim 3, characterized in that, The polynomial construction includes a dynamic threshold adjustment mechanism: Calculate the effective threshold value in real time according to the online status of the clients, and dynamically adjust the number of Lagrange interpolation calculation nodes.

5. A federated learning method for decentralized orthogonal encryption based on symmetric noise as claimed in claim 1, characterized in that, The server sorting process in step 4 includes: Perform lexicographical sorting on the encrypted client matrices according to the client numbers to ensure the discrete state of the encrypted data.

6. The federated learning method for decentralized orthogonal encryption based on symmetric noise according to claim 1, wherein, The server sorting process in step 4 includes: Establish an encrypted data verification structure based on a Merkle tree, generate a root hash value for the set of sorted encrypted matrices, and the client confirms the data integrity and order consistency by verifying the hash chain.

7. The federated learning method for decentralized orthogonal encryption based on symmetric noise according to claim 1, characterized in that, The iterative decryption process in step 5 includes: Perform preliminary decryption by right multiplying the transpose of the global orthogonal matrix; Reconstruct the private encryption matrix through Lagrange interpolation method; Execute the left multiplication decryption operation in rounds, and finally obtain the unencrypted global matrix through a noise cancellation mechanism.

8. A federated learning system for decentralized orthogonal encryption based on symmetric noise, characterized in that, The system includes: An SVD decomposition module, which is used for the central server to perform SVD decomposition on the initial model to generate a row representation matrix and a column representation matrix, and determine row and column sampling index values through the Nystrom method and distribute them to the client; An encryption module, which is used for the client to generate a local private orthogonal encryption matrix and a global shared orthogonal encryption matrix. After using Gram-Schmidt orthogonalization processing, it encrypts the local model matrix by using double orthogonal transformation; A construction module, which is used for dividing the private encryption matrix into N sub-shares through a threshold secret sharing mechanism, constructing a t-1 degree polynomial to realize secret distribution, and forming a distribution matrix; A sorting module, which is used for the central server to perform weight sorting instead of aggregation on the encrypted matrices uploaded by the clients to generate a set of sorted encrypted matrices; A decryption module, which is used for the client to gradually remove the encrypted matrix through an iterative decryption process by using the transpose of the orthogonal matrix and secret sharing reconstruction, and finally restore the global aggregation result through a noise cancellation mechanism.

9. The federated learning system for decentralized orthogonal encryption based on symmetric noise according to claim 8, characterized in that, The construction module includes: Constructor sub-module, which is used to independently construct polynomials for each element of the matrix and distribute the polynomial calculation results as sub-secrets; Builder sub-module, which is used to build a distribution matrix, and the non-diagonal elements in the distribution matrix contain the shared sub-secrets among the clients.

10. A federated learning system for decentralized orthogonal encryption based on symmetric noise as claimed in claim 8, characterized in that, The decryption module includes: Initial decryption sub-module, which is used to perform initial decryption by right-multiplying the transpose of the global orthogonal matrix; Reconstruction sub-module, which is used to reconstruct the private encryption matrix by Lagrange interpolation method; Cancellation sub-module, which is used to perform left-multiplication decryption operations in rounds and finally obtain the unencrypted global matrix through a noise cancellation mechanism.

Citation Information

Patent Citations

  • Cloud computing outsourcing and data dynamic sharing method and system based on proxy re-encryption

    CN116684062A

  • Encryption and deduplication storage method for decentralized data based on coding matrix secret sharing

    CN119759278A

  • System and method of fine-tuning large language models using differential privacy

    WO2024059334A1

Cited By

  • Safety clustering federated learning method and system based on generalization parameters

    CN121257784A