Reasonable entrustment federal learning method and system based on differential privacy

By building a zero-determinal policy and secret sharing technology, the profit relationship between the client and the server is established, and the federated learning training exceptions caused by malicious server operations are solved, and the normal progress of model training and privacy protection are achieved.

CN120389861APending Publication Date: 2025-07-29GUIZHOU UNIV
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510595769.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-09
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

Existing research usually can only verify the aggregation results of the server and does not consider incentivizing the server to perform correct aggregation operations, resulting in the inability to perform model training in federated learning.

Method used

Build a rational computing model based on zero determinant strategy, establish a linear return relationship between the server and the client, and realize the client's revenue control over the server through bounded differential privacy protection mechanism and secret sharing technology, and the aggregation results can verify the correctness.

Benefits of technology

Effectively incentivize the server to perform correct aggregation operations, reduce the long-tail effect of Laplace distribution, tolerate server disconnection and network exceptions, and ensure the normal progress of model training.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389861A_ABST
    Figure CN120389861A_ABST
Patent Text Reader

Abstract

The invention discloses a rational entrustment federated learning method and system based on differential privacy, and the method achieves the purpose that a client controls the expected income of a server through constructing a rational calculation model based on a zero determinant strategy and establishing a linear income relation between the server and the client, and further achieves the purpose that the client controls the expected income of the server through a bounded differential privacy protection mechanism. And finally, whether the servers execute correctness aggregation or not is checked through an aggregation result verifiable algorithm of differential privacy based on secret sharing, meanwhile, offline of a certain number of servers can be tolerated, the influence of network abnormality, power failure and other emergencies on training can be weakened, and the training efficiency can be improved. The technical problem that the normal operation of model training in federated learning still cannot be ensured because only the aggregation result of the server can be checked in the existing research and the correct aggregation operation of the server is not considered is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of federated learning, and particularly to a rational delegated federated learning method and system based on differential privacy. Background Art

[0002] With the rise of technologies such as artificial intelligence and the popularization of 5G networks, a large number of client devices are connected to the network, generating a huge amount of data that grows exponentially. This data not only contains sensitive information of the clients but also is their invaluable assets. Traditional machine learning requires client devices to send all data sets to the server for training, which increases the risk of privacy leakage in the cross-device data circulation. As an emerging distributed machine learning paradigm, federated learning allows multi-source data to stay on the client devices without leaving, and meets the requirements of user privacy protection and government regulations by local training and exchanging model parameters with the server, breaking data silos and achieving cross-device modeling. Unfortunately, existing research shows that the local model parameters still contain sensitive data information, and attackers can launch attacks on these parameters to infer the original data set information of the client devices. To provide lightweight protection for local model parameters, differential privacy technology emerged, which can add carefully calibrated noise to the data and provide strong privacy guarantees through strict mathematical calculations. Therefore, differential privacy has become an increasingly popular choice of privacy protection technology in the federated learning framework.

[0003] Laplace is a common differential privacy mechanism. However, when allocating a small privacy budget value, this mechanism may produce a long-tail effect, generating large noise and reducing the usability of the aggregated model. In addition, most existing research on federated learning security technologies is based on the assumption that the server is honest but curious, that is, it will perform normal aggregation according to the protocol and try to obtain private information. In fact, the server may be malicious, deviate from the protocol, and deliberately manipulate the training process to weaken the model usability and forge verification results. For example, to save computational overhead, return random results to the clients. In response to this situation, it is necessary for the clients to verify the aggregated results of the server. However, existing research usually can only verify the aggregated results of the server, without considering motivating the server to perform correct aggregation operations, and still cannot ensure the normal progress of model training in federated learning. Therefore, how to motivate the server not to perform malicious attacks and complete correct aggregation operations is an urgent challenge. Summary of the Invention

[0004] This application provides a rational delegated federated learning method and system based on differential privacy, which solves the technical problem that existing research usually can only verify the aggregated results of the server, without considering motivating the server to perform correct aggregation operations, and still cannot ensure the normal progress of model training in federated learning.

[0005] In view of this, a first aspect of the present application provides a rational delegated federated learning method based on differential privacy, and the method includes: Step S1, construct a system model including n clients and m servers, and initialize the model parameters of the system model. Among them, each client and the m servers in the system model are in an adversarial relationship, and the servers are in a cooperative relationship with each other; Step S2, construct a rational calculation model of the zero-determinant strategy for each client based on the system model and the model parameters; Step S3, each client calculates the local training gradient according to the local dataset and the global model and updates the local model; Step S4, each client calculates the MAC value based on the differentially private perturbation gradient generated during the local training process, and uses the secret sharing technology to generate the first secret share of the differentially private perturbation gradient and the second secret share of the MAC value respectively, and distributes the first secret share and the second secret share to each server; Step S5, each server aggregates the first secret shares of all the differentially private perturbation gradients and the second secret shares of the MAC values received from each client, and returns the aggregation result to the first client; Step S6, the first client performs a recovery operation on the differentially private perturbation gradient and the MAC value according to the aggregation result returned by each server, and checks whether the aggregation result of the differentially private perturbation gradient after the recovery operation is correct. If it is correct, the differentially private perturbation gradient is passed to other clients to perform the next round of training, otherwise the training is terminated.

[0006] Optionally, the step S1 is specifically: Construct a system model including n clients and m servers, where each client and the m servers in the system model are in an adversarial relationship, and the servers are in a cooperative relationship with each other; The server and the client negotiate to initialize the global model, the privacy budget, and the global key, and generate a negotiation result; The server distributes the negotiation result to each client.

[0007] Optionally, the step S3 specifically includes: Each client receives the global initialization result; Each client calculates the local training gradient according to the local dataset and the global model; Each client updates the local model using the stochastic gradient descent algorithm.

[0008] Optionally, the step S4 specifically includes: During the local training process, each client clips the local training gradient to obtain a local clipped gradient; Each client uses the bounded difference privacy mechanism to perturb the local clipped gradient to obtain the differentially private perturbed gradient; Each client calculates the MAC value based on the differentially private perturbed gradient; Each client calculates the first secret share of the differentially private perturbed gradient for secret sharing and the second secret share of the MAC value based on two randomly generated polynomials, and distributes the first secret share and the second secret share to each server.

[0009] Optionally, the step S5 specifically includes: Each server performs aggregation processing on the first secret share of the received differentially private perturbed gradient and the second secret share of the MAC value to obtain the aggregation result of the first secret share of the differentially private perturbed gradient and the aggregation result of the second secret share of the MAC value respectively; Each server returns the aggregation result to the first client.

[0010] Optionally, the step S6 specifically includes: The first client receives the aggregation result of the first secret share of the differentially private perturbed gradient and the aggregation result of the second secret share of the MAC value sent by all servers; The first client performs secret recovery processing on the aggregation result of the first secret share of the differentially private perturbed gradient and the aggregation result of the second secret share of the MAC value, and checks whether the aggregation result of the first secret share of the differentially private perturbed gradient after the recovery operation multiplied by the global key is identically equal to the aggregation result of the second secret share of the MAC value after the recovery operation; If they are equal, the first client sends the aggregation result of the first secret share of the differentially private perturbed gradient after secret recovery to other clients, and all clients perform the next round of training based on the aggregation result of the first secret share of the differentially private perturbed gradient, otherwise the training is terminated.

[0011] The second aspect of the present application provides a rational entrusted federated learning system based on differential privacy, and the system includes: A system model of n clients and m servers, where each client and the m servers in the system model are in an adversarial relationship, and each server is in a cooperative relationship; Based on the system model and model parameters, a rational calculation model of the zero-determinant strategy of each client is constructed; Each client calculates the local training gradient according to the local dataset and the global model and updates the local model; Each client calculates the MAC value based on the differentially private perturbed gradient generated during the local training process, and uses the secret sharing technology to generate the first secret share of the differentially private perturbed gradient and the second secret share of the MAC value respectively, and distributes the first secret share and the second secret share to each server; Each server aggregates the first secret shares of all differentially private perturbed gradients of each client received and the second secret shares of the MAC values, and returns the aggregation result to the first client; The first client performs a recovery operation on the differentially private perturbed gradients and the MAC values according to the aggregation results returned by each server, and verifies whether the aggregation result of the differentially private perturbed gradients after the recovery operation is correct. If it is correct, the differentially private perturbed gradients are passed to other clients to perform the next round of training; otherwise, the training is terminated.

[0012] As can be seen from the above technical solutions, the embodiments of the present application have the following advantages: In the present application, a rational delegation federated learning method and system based on differential privacy are provided. By constructing a rational calculation model based on zero-determinant strategies, a linear revenue relationship between the server and the client is established to achieve the goal of the client controlling the expected revenue of the server. Further, through a bounded differential privacy protection mechanism, the long-tail effect of the Laplace distribution is reduced. Finally, through an aggregator result verification algorithm for differential privacy based on secret sharing, it is verified whether the server performs correct aggregation, and at the same time, a certain number of server dropouts can be tolerated, weakening the impact of emergencies such as network anomalies and power outages on training, and solving the technical problem that existing research can usually only verify the aggregation results of the server, does not consider motivating the server to perform correct aggregation operations, and still cannot guarantee the normal progress of model training in federated learning. Description of the Drawings

[0013] Figure 1 It is a flowchart of the rational delegation federated learning method based on differential privacy in the embodiments of the present application; Figure 2 It is a schematic structural diagram of the rational delegation federated learning system based on differential privacy in the embodiments of the present application. Detailed Embodiments

[0014] In order to enable those skilled in the art to better understand the solutions of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0015] The present application designs a rational delegation federated learning method and system based on differential privacy, and solves the technical problem that existing research can usually only verify the aggregation results of the server, does not consider motivating the server to perform correct aggregation operations, and still cannot guarantee the normal progress of model training in federated learning.

[0016] For ease of understanding, please refer to Figure 1 , Figure 1 which is the flowchart of the rational delegated federated learning method based on differential privacy in the embodiments of this application, as shown in Figure 1 follows: Step S1: Construct a system model including n clients and m servers, and initialize the model parameters of the system model. Among them, each client and the m servers in the system model are in an adversarial relationship, and the servers are in a cooperative relationship with each other; Specifically, the step S1 is as follows: Construct a system model including n clients and m servers, where each client and the m servers in the system model are in an adversarial relationship, and the servers are in a cooperative relationship with each other; The server and the client negotiate to initialize the global model, privacy budget, and global key, and generate a negotiation result; The server distributes the negotiation result to each client.

[0017] It should be noted that a system model including n clients and m servers is constructed.

[0018] There is an adversarial relationship between the client and the server, that is, the client may not fully trust the server and needs to protect its own data privacy.

[0019] There is a cooperative relationship between the servers, and they need to jointly complete the model training task.

[0020] The model parameters of the system model are initialized, including but not limited to the structure of the model, initial weights, etc.

[0021] The server and the client negotiate to initialize the global model, privacy budget, and global key, generate a negotiation result, and distribute the negotiation result to each client.

[0022] Example: Suppose there is a federated learning scenario for medical data, with 5 hospitals (clients) and 2 cloud service providers (servers). Each hospital has its own patient data, but for privacy protection, it is not willing to directly share the data with the cloud service providers. Therefore, a system model is constructed, where there is an adversarial relationship between the hospital and the cloud service providers, and the cloud service providers need to cooperate to complete the training of the medical model.

[0023] Initialize a simple neural network model as the global model, and its initial weights are randomly generated.

[0024] The hospital and the cloud service provider negotiate a privacy budget of ε = 1.0 (differential privacy parameter), and negotiate to generate a global key for subsequent secure communication.

[0025] The cloud service provider distributes the negotiation results (global model, privacy budget, global key) to each hospital.

[0026] The system model includes clients and servers two types of entities. Specifically, multiple servers accept the commission to collaboratively train the global model, rather than relying solely on a central server.

[0027] denotes the first client, which is responsible for receiving and restoring the aggregated results from multiple servers, verifying the correctness of the aggregated results, and determining whether the model meets the training requirements. If the requirements are met, it sends the global aggregated results to other clients. The client provides data and trains the local model during each global epoch. Any entity with cross-silo computing resources can assume

[0028] We consider the system model as a 1-to- commissioned federated learning, where each client is in an adversarial relationship with servers, and the servers need to cooperate with each other.

[0029] In addition, the servers and clients negotiate to initialize the global model 、privacy budget and global key , and then distribute the negotiation results to all clients.

[0030] Step S2: Based on the system model and model parameters, construct a rational calculation model of the zero-determinant strategy for each client; It should be noted that based on the system model and model parameters, a rational calculation model of the zero-determinant strategy for each client is constructed. The zero-determinant strategy is a strategy in game theory that enables a client to maintain rational behavior in interactions with other participants and avoid adverse consequences caused by malicious operations or irrational behaviors.

[0031] For example In the above medical data scenario, hospitals (clients) and cloud service providers (servers) respectively construct their own zero-determinant rational calculation models according to the negotiated system model and parameters. This model can encourage hospitals and cloud service providers to choose cooperative strategies and ensure that the above entities operate according to the established rules during the training process, such as: ​When the hospital pays the service remuneration to the cloud service provider, it will not deliberately tamper with the amount, because this may cause the cloud service provider to no longer perform correct model aggregation, ultimately affecting its own interests.

[0032] The cloud service provider will perform the correct aggregation operation according to the agreement and will not maliciously tamper with the aggregation result, because its income is unilaterally controlled by the hospital.

[0033] In 1-to- federated learning, the strategies adopted by each entity are cooperation and betrayal . The game result of each entity has possibilities, which are listed as , …, , where represents the strategy adopted by the client , and represents the strategy adopted by the server .

[0034] The probabilities of choosing the cooperation strategy in the next round are , , … .

[0035] Each pair of strategies generates a Markov chain, and the state transition matrix is: .

[0036] The row sum is 1, indicating that it has a unit eigenvalue, so there exists a steady-state vector satisfying , where , is the identity matrix.

[0037] For , using Cramer's rule, we can obtain , , where is the adjoint matrix of , is the determinant of , and it satisfies .

[0038] We assume that is the payoff matrix of , is the payoff matrix of , , then in the steady-state distribution of the Markov chain, there are payoff functions and As follows: .

[0039] For any vector , there exists that holds.

[0040] Observing the above formula, it can be found that there exists a vector that is only related to and is irrelevant to . Therefore, there exists a linear relationship , where is the average revenue of all servers, is the average payment matrix of all servers, When any two rows in the determinant are proportional, the value of the determinant is 0.

[0041] Therefore, can adjust and its own strategy to satisfy , so that the revenues of each entity become a linear relationship. Among them are all determined unilaterally by , that is can individually limit the expected revenues of each entity. We define this kind of strategy as the zero-determinant strategy.

[0042] When adopts the zero-determinant strategy, according to the optimization theory, the total revenue of the cooperative party is defined as follows: .

[0043] Therefore, there is: .

[0044] When , , the above formula constraint conditions are transformed into: .

[0045] When , .

[0046] Among them corresponds to the payment price of the th strategy combination in the payment matrix , corresponds to the average payment price of the server of the th strategy combination in the payment matrix .

[0047] Observing the above formula, it can be obtained that when When there is a feasible solution, that is, the minimum value of can be obtained. Similarly, when is satisfied, there is When, the minimum value of can be found. .

[0048] Therefore, when adopting the zero-determinant strategy , At this time, the overall revenue of the entrusted federated learning system is , and it can unilaterally control the revenues of all other .

[0049] In addition, each server may change its strategy at any time during the federated learning process to maximize its own revenue. Therefore, it is necessary to design its revenue function according to the payoff matrix to encourage to choose the cooperation strategy in repeated learning.

[0050] Since the revenue of the server depends not only on its own behavior but also on the payment price set by the client through the zero-determinant strategy, we define the revenue function of the server as: , where is a positive coefficient .

[0051] Furthermore, define as the revenue obtained when both parties choose the cooperation strategy , as the revenue obtained when both parties choose the cooperation strategy , as the decrease in revenue when chooses the betrayal strategy , as the increase in its revenue when chooses the betrayal strategy, as the decrease in revenue when chooses the betrayal strategy , as the increase in its revenue when chooses the betrayal strategy.

[0052] Then, we discuss in different cases.

[0053] When the client chooses the cooperation strategy, the utility function of the server is:

[0054] To motivate the server at to choose the cooperation strategy, the above formula needs to satisfy

[0055] That is, there is , .

[0056] When the client chooses the betrayal strategy, the utility function of the server is

[0057] To motivate the server at to choose the cooperation strategy, the above formula needs to satisfy: .

[0058] Solving it, there is: , .

[0059] In summary, when the client adopts the zero-determinant strategy, it can adjust so that to motivate the server to choose the cooperation strategy.

[0060] Step S3: Each client calculates the local training gradient according to the local dataset and the global model, and updates the local model; The specific steps of step S3 include: Each client receives the global initialization result; Each client calculates the local training gradient according to the local dataset and the global model; Each client updates the local model using the stochastic gradient descent algorithm.

[0061] It should be noted that each client receives the global initialization result (including the global model, privacy budget, global key, etc.).

[0062] Calculate the local training gradient according to the local dataset and the global model.

[0063] Update the local model using the stochastic gradient descent algorithm.

[0064] For example: In the medical data scenario, after each hospital receives the global initialization result distributed by the cloud service provider, it calculates the local training gradient using its own patient data. Suppose Hospital A has 1000 pieces of patient data and Hospital B has 800 pieces of patient data, and they calculate the gradients using this data respectively.

[0065] Hospitals A and B update their local models using the stochastic gradient descent algorithm.

[0066] All clients calculate the training gradient based on the local dataset and the global model : , where is the loss function.

[0067] Subsequently, the local model is updated using the stochastic gradient descent algorithm, , where is the learning rate.

[0068] Step S4: Each client calculates the MAC value based on the differentially private perturbed gradient generated during the local training process, and uses the secret sharing technology to generate the first secret share of the differentially private perturbed gradient and the second secret share of the MAC value respectively, and distributes the first secret share and the second secret share to each server; The specific steps of step S4 include: During the local training process, each client clips the local training gradient to obtain the local clipped gradient; Each client perturbs the local clipped gradient using the bounded differential privacy mechanism to obtain the differentially private perturbed gradient; Each client calculates the MAC value based on the differentially private perturbed gradient; Each client calculates the first secret share of the differentially private perturbed gradient for secret sharing and the second secret share of the MAC value based on two randomly generated polynomials, and distributes the first secret share and the second secret share to each server.

[0069] It should be noted that during the local training process, each client clips the local training gradient to obtain the local clipped gradient. Clipping is to limit the magnitude of the gradient and avoid adverse effects of overly large gradients on model training.

[0070] The local clipped gradient is perturbed using the bounded differential privacy mechanism to obtain the differentially private perturbed gradient. The differential privacy mechanism protects data privacy by adding noise.

[0071] The MAC value (message authentication code) is calculated based on the differentially private perturbed gradient, which is used to verify the integrity and origin of the data.

[0072] After calculating the first secret share for the differentially private perturbed gradient of the secret sharing and the second secret share of the MAC value based on two randomly generated polynomials, the first secret share and the second secret share are distributed to each server.

[0073] For example Suppose the locally clipped gradients calculated by Hospital A are [g1(A), g2(A)], and the locally clipped gradients calculated by Hospital B are [g1(B), g2(B)].

[0074] Hospitals A and B respectively perturb the clipped gradients using the bounded differential privacy mechanism. For example, after adding noise, Hospital A obtains the differentially private perturbed gradient [g1(A) + noise1, g2(A) + noise2].

[0075] Hospitals A and B respectively calculate the MAC values. Suppose the MAC value of Hospital A is [MAC_1A, MAC_2A], and the MAC value of Hospital B is [MAC_1B, MAC_2B].

[0076] Hospitals A and B respectively calculate the secret shares based on two random polynomials. Suppose Hospital A divides the differentially private perturbed gradient and the MAC value into two secret shares (S1A1, S2A1) and (S1A2, S2A2) respectively, and Hospital B divides the differentially private perturbed gradient and the MAC value into two secret shares (S1B1, S2B1) and (S1B2, S2B2) respectively.

[0077] Hospital A shares (S1A1, S2A1) and (S1A2, S2A2) with two cloud service providers respectively, and Hospital B shares (S1B1, S2B1) and (S1B2, S2B2) with two cloud service providers respectively.

[0078] During the local training process, the gradient satisfies the following after being clipped .

[0079] Since during the training process, the value ranges of the gradients of different layers of the neural network are different, therefore, we define as the privacy parameter, which can be set personalized according to the characteristics of each layer of the neural network. We use the bounded differential privacy mechanism to perturb and after that , where .

[0080] The perturbed clipped gradient has a bounded probability density function for the bounded local differential privacy as follows:

[0081] where 。

[0082] To ensure the applicability of the bounded differential privacy mechanism in federated learning, three conditions need to be met: ①: The bounded differential privacy mechanism needs to satisfy the differential privacy mechanism; ②: The sum of the probability distributions of the bounded differential privacy mechanism is 1; ③: The bounded differential privacy mechanism satisfies unbiasedness, then there is , Among them, there is 。

[0083] Therefore, in the bounded mechanism The sum of the probability cumulative distribution functions at is In other words, with a probability of perturb in the range of

[0084] To verify whether the server has performed the correct aggregation, we use the MAC value to verify the aggregation result. The client generates clipped gradients during the local training process which, after being perturbed by the bounded differential privacy, becomes and calculates the MAC value 。 Generate two random degree polynomials, namely and respectively used for secret sharing and values.

[0085] Subsequently, calculate and distribute the secret shares and and to The server performs the following aggregation operations on the received secret shares of all gradients and MAC values and returns the aggregation result to 。

[0086] Step S5: Each server aggregates the first secret shares of all differentially private perturbed gradients of each client received and the second secret shares of the MAC values, and returns the aggregation result to the first client; The specific steps of step S5 include: Each server performs aggregation processing on the first secret shares of the differentially private perturbed gradients received and the second secret shares of the MAC values, respectively obtaining the aggregation result of the first secret shares of the differentially private perturbed gradients and the aggregation result of the second secret shares of the MAC values; Each server returns the aggregation result to the first client.

[0087] It should be noted that each server performs an aggregation process on the first secret share of the differentially private perturbed gradient and the second secret share of the MAC value received, respectively obtaining the aggregation result of the first secret share of the differentially private perturbed gradient and the aggregation result of the second secret share of the MAC value;

[0088] Each server returns the aggregation result to the first client.

[0089] Example Suppose two cloud service providers respectively receive the secret shares of Hospital A and Hospital B: Cloud service provider 1 receives (S1A1, S2A1) and (S1B1, S2B1), and cloud service provider 2 receives (S1A2, S2A2) and (S1B2, S2B2).

[0090] Cloud service provider 1 aggregates (S1A1, S2A1) and (S1B1, S2B1) to obtain the aggregation result X1 of all the secret shares of the differentially private perturbed gradient and the aggregation result Y1 of the secret shares of the MAC value; cloud service provider 2 aggregates (S1A2, S2A2) and (S1B2, S2B2) to obtain the aggregation result X2 of all the secret shares of the differentially private perturbed gradient and the aggregation result Y2 of the secret shares of the MAC value.

[0091] Cloud service provider 1 and cloud service provider 2 return the aggregation results (X1, Y1) and (X2, Y2) to the first client (assumed to be Hospital A) Step S6: The first client performs a recovery operation on the differentially private perturbed gradient and the MAC value according to the aggregation results returned by each server, and checks whether the aggregation result of the differentially private perturbed gradient after the recovery operation is correct. If it is correct, the differentially private perturbed gradient is transmitted to other clients to perform the next round of training; otherwise, the training is terminated; The specific steps of step S6 include: The first client receives the aggregation result of the first secret share of the differentially private perturbed gradient and the aggregation result of the second secret share of the MAC value sent by all servers; The first client performs a secret recovery process on the aggregation result of the first secret share of the differentially private perturbed gradient and the aggregation result of the second secret share of the MAC value, and checks whether the product of the aggregation result of the first secret share of the differentially private perturbed gradient after the recovery operation and the global key is identically equal to the aggregation result of the second secret share of the MAC value after the recovery operation; If they are equal, the first client sends the aggregation result of the first secret share of the differentially private perturbed gradient after the secret recovery to other clients, and all clients perform the next round of training based on the aggregation result of the first secret share of the differentially private perturbed gradient; otherwise, the training is terminated.

[0092] It should be noted that the first client receives the aggregated result of the first secret shares of the differentially private perturbed gradients sent by all servers and the aggregated result of the second secret shares of the MAC values.

[0093] The first client performs secret recovery processing on the aggregated result of the first secret shares of the differentially private perturbed gradients and the aggregated result of the second secret shares of the MAC values, and checks whether the aggregated result of the differentially private perturbed gradients after the recovery operation is correct; If the aggregated result of the differentially private perturbed gradients is correct, the first client sends the aggregated result of the differentially private perturbed gradients after secret recovery to other clients to perform the next round of training, otherwise the training is terminated.

[0094] Example Hospital A receives the aggregated results (X1, Y1) and (X2, Y2) returned by Cloud Service Provider 1 and Cloud Service Provider 2.

[0095] Hospital A performs secret recovery processing on (X1, Y1) and (X2, Y2) to obtain the recovered differentially private perturbed gradients and MAC values.

[0096] Hospital A checks whether the aggregated result of the differentially private perturbed gradients after the recovery operation is correct. Assume that the recovered MAC value is consistent with the result of multiplying the aggregated result of the differentially private perturbed gradients recovered by Hospital A by the global key, then it indicates that the aggregated result is correct.

[0097] If the aggregated result of the differentially private perturbed gradients is correct, Hospital A sends the recovered differentially private perturbed gradients to other clients (Hospital B), and Hospital A and B perform the next round of training based on this gradient. If the aggregated result of the differentially private perturbed gradients is incorrect, the training is terminated to prevent privacy leakage or model training errors.

[0098] Please refer to Figure 2 , Figure 2 which is the structural schematic diagram of the rational delegated federated learning system based on differential privacy in the embodiments of this application. As Figure 2 shown, specifically: It includes: A system model of n clients 201 and m servers 202, where each client 201 and the m servers in the system model are in an adversarial relationship, and the servers are in a cooperative relationship; Based on the system model and model parameters, construct a rational calculation model with a zero-determinant strategy for each client 201; Each client 201 calculates the local training gradient according to the local dataset and the global model and updates the local model; Each client 201 calculates the MAC value based on the differentially private perturbed gradient generated during the local training process, and uses the secret sharing technology to generate the first secret share of the differentially private perturbed gradient and the second secret share of the MAC value respectively, and distributes the first secret share and the second secret share to each server; Each server aggregates the first secret shares of all the differentially private perturbed gradients and the second secret shares of the MAC values received from each client, and returns the aggregation result to the first client; The first client performs a recovery operation on the differentially private perturbed gradient and the MAC value according to the aggregation result returned by each server, and verifies whether the aggregation result of the differentially private perturbed gradient after the recovery operation is correct. If it is correct, the differentially private perturbed gradient is passed to other clients to perform the next round of training, otherwise the training is terminated.

[0099] In the embodiments of the present application, a rational entrusted federated learning method and system based on differential privacy are provided. By constructing a rational calculation model based on the zero-determinant strategy, a linear revenue relationship between the server and the client is established to achieve the goal of the client controlling the expected revenue of the server. Further, through the bounded differential privacy protection mechanism, the long-tail effect of the Laplace distribution is reduced. Finally, through the aggregator result verification algorithm of differential privacy based on secret sharing, it is verified whether the server performs correct aggregation, and at the same time, a certain number of server disconnections can be tolerated, weakening the impact of emergencies such as network anomalies and power outages on training, and solving the technical problem that existing research can usually only verify the aggregation result of the server, does not consider motivating the server to perform correct aggregation operations, and still cannot ensure the normal progress of model training in federated learning.

[0100] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0101] The terms "first", "second", "third", "fourth", etc. (if any) in the specification of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products, or devices.

[0102] It should be understood that in this application, "at least one (item)" means one or more, and "a plurality" means two or more. "And / or" is used to describe the relationship between associated objects and indicates that there can be three relationships. For example, "A and / or B" can mean: only A exists, only B exists, and both A and B exist at the same time. Here, A and B can be singular or plural. The character " / " generally indicates an "or" relationship between the associated objects before and after. "At least one (item) of the following" or its similar expressions refer to any combination of these items, including any combination of single item (s) or plural items (s). For example, at least one (item) of a, b, or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, and c can be single or multiple.

[0103] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces, and the indirect couplings or communication connections of devices or units can be in electrical, mechanical, or other forms.

[0104] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0105] In addition, in each embodiment of this application, the functional units can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0106] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memories (English full name: Read-Only Memory, English abbreviation: ROM), random access memories (English full name: Random Access Memory, English abbreviation: RAM), magnetic disks, or optical discs.

[0107] As described above, the above embodiments are only used to illustrate the technical solutions of this application, rather than to limit them; although this application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of various embodiments of this application.

Claims

1. A rational entrusted federated learning method based on differential privacy, characterized in that Including: Step S1: Construct a system model including n clients and m servers, and initialize the model parameters of the system model. Among them, each client in the system model is in an adversarial relationship with the m servers, and the servers are in a cooperative relationship with each other; Step S2: Based on the system model and the model parameters, construct a rational calculation model for the zero-determinant strategy of each client; Step S3: Each client calculates the local training gradient according to the local dataset and the global model and updates the local model; Step S4: Each client calculates the MAC value based on the differentially private perturbed gradient generated during the local training process, and uses the secret sharing technology to generate the first secret share of the differentially private perturbed gradient and the second secret share of the MAC value respectively, and distributes the first secret share and the second secret share to each server; Step S5: Each server aggregates the first secret shares of all differentially private perturbed gradients and the second secret shares of the MAC values received from each client, and returns the aggregation result to the first client; Step S6: The first client performs a recovery operation on the differentially private perturbed gradient and the MAC value according to the aggregation result returned by each server, and checks whether the aggregation result of the differentially private perturbed gradient after the recovery operation is correct. If it is correct, the differentially private perturbed gradient is passed to other clients to perform the next round of training, otherwise the training is terminated.

2. The rational delegated federated learning method based on differential privacy according to claim 1, characterized in that, The specific content of step S1 is as follows: Construct a system model including n clients and m servers. Among them, each client in the system model is in an adversarial relationship with the m servers, and the servers are in a cooperative relationship with each other; The server and the client negotiate to initialize the global model, the privacy budget, and the global key, and generate a negotiation result; The server distributes the negotiation result to each client.

3. The rational delegated federated learning method based on differential privacy according to claim 1, wherein The specific content of step S3 includes: Each client receives the global initialization result; Each client calculates the local training gradient according to the local dataset and the global model; Each client updates the local model using the stochastic gradient descent algorithm.

4. The rational entrusted federated learning method based on differential privacy according to claim 1, characterized in that The specific content of step S4 includes: During the local training process, each client clips the local training gradient to obtain a local clipped gradient; Each client perturbs the local clipped gradient using the bounded differential privacy mechanism to obtain a differentially private perturbed gradient; Each client calculates the MAC value based on the differentially private perturbed gradient; Each client calculates the first secret share of the differentially private perturbed gradient for secret sharing and the second secret share of the MAC value based on two randomly generated polynomials, and distributes the first secret share and the second secret share to each server.

5. The rational delegation federated learning method based on differential privacy according to claim 4, wherein, The specific content of step S5 includes: Each server performs an aggregation process on the first secret shares of the differentially private perturbed gradients and the second secret shares of the MAC values received, and obtains the aggregation result of the first secret shares of the differentially private perturbed gradients and the aggregation result of the second secret shares of the MAC values respectively; Each server returns the aggregation result to the first client.

6. The rational delegation federated learning method based on differential privacy according to claim 5, wherein The specific content of step S6 includes: The first client receives the aggregation result of the first secret shares of the differentially private perturbed gradients and the aggregation result of the second secret shares of the MAC values sent by all servers; The first client performs secret recovery processing on the first secret share aggregation result of the differentially private perturbed gradient and the second secret share aggregation result of the MAC value, and checks whether the first secret share aggregation result of the differentially private perturbed gradient after the recovery operation multiplied by the global key is identically equal to the second secret share aggregation result of the MAC value after the recovery operation; If they are equal, the first client sends the first secret share aggregation result of the differentially private perturbed gradient after secret recovery to other clients, and all clients perform the next round of training based on the first secret share aggregation result of the differentially private perturbed gradient, otherwise the training is terminated.

7. A rational delegation federated learning system based on differential privacy, characterized in that, A system model including n clients and m servers, where each client and the m servers in the system model are in an adversarial relationship, and the servers are in a cooperative relationship with each other; Based on the system model and model parameters, a rational calculation model of the zero-determinant strategy for each client is constructed; Each client calculates the local training gradient according to the local dataset and the global model and updates the local model; Each client calculates the MAC value based on the differentially private perturbed gradient generated during the local training process, and uses the secret sharing technology to generate the first secret share of the differentially private perturbed gradient and the second secret share of the MAC value respectively, and distributes the first secret share and the second secret share to each server; Each server aggregates the first secret shares of all differentially private perturbed gradients and the second secret shares of the MAC values received from each client, and returns the aggregation result to the first client; The first client performs recovery operations on the differentially private perturbed gradient and the MAC value according to the aggregation result returned by each server, and checks whether the aggregation result of the differentially private perturbed gradient after the recovery operation is correct. If it is correct, the differentially private perturbed gradient is passed to other clients to perform the next round of training, otherwise the training is terminated.

Citation Information

Cited By

  • Attribute-driven single-encryption multilevel differential privacy output method

    CN121619100A

  • Attribute-driven single-encryption multi-level differential privacy output method

    CN121619100B