A Lightweight Federated Learning Privacy Protection Method Based on Decentralized Secure Aggregation
By adopting decentralized security aggregation and random perturbation security parameter segmentation and recovery algorithms in federated learning, the problem of insufficient privacy protection in traditional federated learning is solved, and a lightweight privacy protection training process is realized, which reduces the risk of privacy leakage and improves the efficiency and security of the model.
Patent Information
- Application Number
- CN202110966055.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-08-23
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2041-08-23
AI Technical Summary
Existing federated learning technologies have shortcomings in privacy protection, traditional central aggregators are vulnerable to attacks, leading to data privacy leakage, and existing methods such as differential privacy, homomorphic encryption and secret sharing technologies are inadequate in efficiency and cost.
A lightweight federated learning privacy protection method based on decentralized security aggregation is adopted to build a decentralized aggregation platform through edge nodes and consortium blockchains, and a randomly perturbed security parameter segmentation and recovery algorithm is used to protect the privacy of local and global models, reduce computing overhead and improve the high availability of the model.
It realizes privacy protection without time-consuming encryption operations in federated learning, ensures a lightweight training process on the user side, mitigates the threat of privacy leakage, and outperforms existing technologies in computing efficiency, model accuracy and privacy protection against member inference attacks.
Smart Images

Figure CN113806768B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a lightweight federated learning privacy protection method based on decentralized secure aggregation, aiming to achieve lightweight training on the user side by using decentralized secure aggregation, reduce the threat of privacy leakage of traditional central aggregators, and belongs to the technical field of data privacy protection. Background Art
[0002] In recent years, Federated Learning (FL) has been widely applied as a new type of distributed learning framework.
[0003] Federated learning allows multiple participants to collaboratively train a unified machine learning model under the premise of privacy protection. In each round of training, participants obtain local models based on their own datasets respectively, and then a central aggregator aggregates them. The aggregator constructs a global model and sends it to the participants for the next round of training. Although the local training data of users is not publicly disclosed during the federated learning process, the frequent parameter sharing between training participants and the aggregator can be exploited by malicious participants, resulting in data privacy leakage.
[0004] In recent years, attacks against federated learning have emerged in an endless stream. Among them, membership inference attack is a relatively typical one. The purpose of the membership inference attack is to train an attack model to infer whether there are data records in the training dataset. According to the prior knowledge obtained by the attacker, these attacks are roughly divided into local attacks and global attacks. By observing the changes in local model updates, malicious participants can launch local attacks on the participating parties. Global attacks are usually launched by a malicious aggregator, which isolates a participant and sends it a carefully constructed global model. Since the victim uses the carefully constructed global model to train the local model, the attacker can infer more privacy information from the local model updates. Thus, it can be seen that the membership inference attack poses a great threat to the privacy of the federated learning participant datasets.
[0005] The prior art generally achieves federated learning privacy protection through the following methods:
[0006] (1) Protect the privacy of the global model by adding differential privacy (DP) noise to the global model.
[0007] The purpose of differential privacy is to hide the contributions of customers during training, which can ensure that the privacy of the global model is not known to the participants.
[0008] However, this method cannot protect local privacy. The aggregator can still obtain all local models, which will lead to the aggregator launching a membership inference attack on local privacy, and the model accuracy will also be damaged.
[0009] (2) Use homomorphic encryption technology to protect the gradients on an honest but curious cloud server.
[0010] However, the encryption and decryption operations in each round of training bring a large amount of encryption and decryption calculations and communication costs. Its application cost in a large-scale environment is high and may affect the efficiency of machine learning models.
[0011] (3) Protect the privacy of local models by using secret sharing technology and adding random perturbations.
[0012] The homomorphic hash function is integrated with the pseudorandom technology as the underlying structure of the verifiable method, allowing participants to verify the correctness of the cloud server's execution at an acceptable overhead.
[0013] However, it is difficult for participants to afford the secret sharing calculations and frequent communication costs, and the global model still faces the risk of privacy leakage.
[0014] In summary, the privacy protection of federated learning still faces numerous challenges. Summary of the Invention
[0015] The purpose of the present invention is to overcome the defects existing in the prior art, to solve the technical problem of privacy protection in federated learning, and creatively propose a lightweight federated learning privacy protection method based on decentralized secure aggregation.
[0016] The innovation of the present invention lies in: on the user side, an edge node and a consortium blockchain are used to construct a secure decentralized aggregation platform. On this platform, the aggregation process is carried out collaboratively. Each user connects to N edge nodes and performs model segmentation locally.
[0017] To protect the privacy of local models and ensure accuracy, the present invention designs a secure parameter segmentation and recovery algorithm based on random perturbations. Each user segments the local model (i.e., parameters) and sends them to each connected edge node respectively. Under the Byzantine assumption, a single edge node or a group of collaborative edge nodes cannot recover the local model. At the same time, to protect the privacy of the global model, each user generates a global random number and segments it, and shares it separately with the edge nodes connected to it. Then, all edge nodes will perform secure decentralized aggregation, and each user will receive the global model perturbed by its custom global random number.
[0018] Thus, the edge nodes participating in the aggregation cannot know the global model, and each user can remove the added perturbation to obtain the original global model. This method can achieve privacy protection without time-consuming encryption operations, thus ensuring a lightweight training process on the user side.
[0019] In this method, each user is a data holder and is responsible for updating the local model in the federated learning process. Each user randomly connects to N edge nodes, and the number of these edge nodes is not less than the total number of Byzantine nodes. The edge nodes provide secure and decentralized local model aggregation for the users. It plays two roles: local model aggregator and blockchain consensus node. The edge nodes are secure aggregation service platforms established at the edge of the user network, provided with storage, computing, and network resources by service providers, responsible for local models and performing partial model aggregation.
[0020] First, each user splits the model parameters, generates a carefully constructed global random number, and splits the global random number through a parameter splitting algorithm.
[0021] Then, the user sends the split model parameters and the global random number to the edge nodes it is connected to.
[0022] After that, the edge nodes perform local model aggregation and upload it to the blockchain. The blockchain ledger, as a data sharing platform, uses a global model aggregation contract to complete global model aggregation, obtaining a global model covered by the global random number. During the operation of the smart contract, each edge node queries the data of other edge nodes from the blockchain shared ledger. At the same time, an access control security policy is adopted, and except for each edge node and each user, other entities cannot obtain the data uploaded to the general ledger.
[0023] Finally, the edge node sends the global model to its corresponding user, and the global random number is completely eliminated by the user, obtaining the final global model. Based on the global model, lightweight training on the user side is realized, thus reducing the threat of privacy leakage.
[0024] Beneficial effects
[0025] The method of the present invention has the following advantages compared with the prior art:
[0026] On the user side, an edge node and a consortium blockchain are used to build a secure decentralized aggregation platform, where the aggregation process is coordinated, and privacy protection is carried out for the global and local models.
[0027] (1) The present invention is applicable to privacy protection in federated learning carried out in a decentralized platform environment.
[0028] (2) The present invention can perform privacy protection training in a lightweight manner without sacrificing the accuracy of the model. Using a secure decentralized aggregation platform instead of a centralized aggregator can avoid data privacy leakage;
[0029] (3) The present invention designs a security parameter partitioning and recovery algorithm based on one-time filling to protect local and global models, reduce the computational overhead on the user side, and ensure the high availability of the model without losing accuracy.
[0030] (4) The present invention has carried out a rigorous security analysis and proved the security of the proposed scheme.
[0031] Through extensive experiments, it is demonstrated that our approach outperforms current techniques in terms of computational efficiency, model accuracy, and privacy protection against member inference attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 It is the cooperation model on which the method of the present invention relies;
[0033] Figure 2 It is the interactive protocol process of the method of the present invention. DETAILED DESCRIPTION
[0034] The present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be noted that the implementation of the present invention is not limited to the following embodiments, and any form of modification or change made to the present invention will fall within the protection scope of the present invention.
[0035] A lightweight federated learning privacy protection method based on decentralized secure aggregation. On the user side, edge nodes and alliance blockchains are used to build a secure decentralized aggregation platform. On this platform, the aggregation process is carried out collaboratively.
[0036] Specifically, the steps include:
[0037] Step 1: Each user in federated learning connects to N edge nodes. Each user splits the model parameters and generates a global random number. The global random number is split by parameter partitioning and sent to each connected edge node separately.
[0038] Specifically, the steps include:
[0039] Step 1.1: Edge nodes establish a consortium blockchain and reach consensus to build a secure decentralized aggregation platform.
[0040] Step 1.2: Each user generates a global random number to mask the global model in each subsequent round of training.
[0041] In federated learning training, selected users train local models on their respective local datasets and then calculate user u i Local model of The following steps are involved:
[0042] Step 1.2.1: Initialize the global model w0 , the number of training rounds T, and the learning rate λ;
[0043] Step 1.2.2: For each training process, select a user U from the user set U s to participate in the training;
[0044] Step 1.2.3: For each user U s , perform local model training through Equation 1;
[0045]
[0046] where, w t-1 represents the model parameter of the previous round of training, η represents the learning rate, represents the gradient, L represents the loss function, w represents the model parameter, and b represents the model parameter.
[0047] Step 1.3: Use the parameter splitting algorithm to split the local model parameters and the global random number i of user u , and send them to each connected edge node respectively, and upload them to the decentralized secure aggregation smart contract.
[0048] Among them, in the parameter splitting algorithm, let v be the parameter and n be the number of splits to be generated after splitting. Among them, seed is the random number seed and PRG is the random number generator, including the following steps:
[0049] Step 1.3.1: Use PRG(seed) to generate a set of pseudo-random numbers to obtain {r 1 , r 2 , …, r n}, representing n pseudo-random numbers.
[0050] Step 1.3.2: Split the parameter v.
[0051] Let v i = v + r i - r i+1 , i ∈ {1, 2, …, n + 1}, and let v n = v + r n - r 0 .
[0052] Among them, v i , v n represent the model parameters, and r i , r i+1 represent the pseudo-random numbers.
[0053] Step 1.3.3: Return a set of v i , i ∈ {1, 2, …, n + 1}.
[0054] Step 2: The aggregator performs decentralized secure aggregation, including the following steps:
[0055] Step 2.1: Edge node Edg j Use the global random numbers of the selected users in the next round of training to aggregate all partitioned local models
[0056] Step 2.2: Upload the aggregated local model from the blockchain to the blockchain ledger. The blockchain ledger, as a data sharing platform, uses the global model aggregation contract for global model aggregation.
[0057] Step 2.3: When all edge node data returns to all sets After that, the edge node calculates and returns the global model covered by the global random number This global model is covered by the global random number i from user u covered.
[0058] Step 3: The user removes the global random number covering the global model to obtain the global model.
[0059] User u i gets After that, remove the globally random number added by itself by Thereby obtaining the global model g t .
[0060] Step 4: Implement user-side lightweight training based on the global model, thereby reducing the threat of privacy leakage.
[0061] Embodiment 1
[0062] This embodiment establishes a cooperation model on which a lightweight privacy protection federated learning method based on decentralized secure aggregation of the present invention depends, as Figure 1 shown.
[0063] Figure 1The following decentralized secure aggregation scenario is described: Each user holds a local dataset and updates the local model in the FL process. Each user randomly connects to multiple edge nodes. The user splits the model parameters, generates a carefully constructed global random number, and splits the global random number through parameter partitioning. The split parameters and global random number are sent to the connected nodes. The edge nodes provide secure and decentralized local model aggregation, receive the split local models, and perform partial model aggregation. The partially aggregated model is uploaded to the blockchain ledger for global aggregation to obtain a global model covered by the global random number. The blockchain ledger serves as a data sharing platform to assist in completing model aggregation. The global model aggregation contract runs on the blockchain. During the operation of the smart contract, each edge node can query the data of other edge nodes from the blockchain shared ledger, complete global aggregation, and send the user the global model covered by its custom random number. The user can finally remove the random number to obtain the final model.
[0064] Relying on Figure 1 the model in, when specifically implementing the method of the present invention, the following steps are taken:
[0065] Step A: Set the number of users to 100, 1000, and 10000, which respectively represent applications with small, medium, and large user scales. The proportion of users selected to participate in training is 5%, 10%, and 15%.
[0066] Using the MNIST dataset (http: / / yann.lecun.com / exdb / mnist / ), train and test on the CNN network according to steps 1 to 3. The MNIST is set to IID by default. Calculate the model accuracy R through Equation 2, where p t n is the number of correctly classified positive instances, and f
[0067] R = t p / (f n + t p ) (2)
[0068] The model accuracies obtained by training instances in different user scale scenarios are shown in Table 1.
[0069] Table 1 Accuracy results for different user scales
[0070]
[0071] From Figure 2It can be seen that at small and medium user scales, the training loss drops rapidly, and it can be concluded that the training loss is almost independent of the selected user percentage. However, in the case of a large user scale, the larger the selected user ratio, the faster the training loss decreases. This is because in the large-scale case, more users participate in training, and each user has fewer data instances. The highest accuracy of the trained model under different user scales has little relation to the percentage of selected users. In all three cases of user scales, this method can train a model with high accuracy.
[0072] Step B: Calculate the training time on the user side and the time on the aggregation side (edge node side).
[0073] Step C: Calculate the blockchain communication time, that is, the latency of invoking smart contracts to share and query data, and the communication time between the user and the edge node.
[0074] The training time overhead of the instance under different user scale scenarios is shown in Table 2.
[0075] Table 2 Training time overhead
[0076]
[0077] As can be seen from Table 2, the percentage of selected users has no impact on the training time on the user side and the aggregation side. This is because the increase in the number of selected users only increases the computational overhead of random number generation, and random number generation is a lightweight operation. Then, in all three cases of user scales, the time cost is very small, which proves that this training is lightweight training on the user side. This is because the operations in this part do not involve encryption and decryption work. The larger the user scale, the less training time is consumed on the user side. The reason is that more users mean fewer data instances. In all cases, the time cost on the aggregator side is very small. This is because the edge node only needs to continue with addition operations and does not need to do other heavy computational work.
[0078] The communication time overhead of the blockchain for each round of training of the instance is shown in Table 3.
[0079] Table 3 Communication time overhead of the blockchain for each round of training
[0080]
[0081]
[0082] As can be seen from Table 3, when the number of blockchains increases, this part of the overhead also increases, which is caused by the characteristics of consortium blockchains. However, since the local aggregation process of each blockchain node is parallel and independent, there will be no obvious change in time. Similarly, when the number of users increases, each user runs independently of each other, so the communication time overhead will not change significantly.
[0083] Example 2
[0084] In this example, the results of the method of the present invention in various scenarios are compared to verify that the privacy protection method of the present invention has high training accuracy and efficiency. This example is compared with existing methods, all of which are for protecting data privacy in the process of federated learning. Federated learning has no privacy protection measures. HEDL uses HE encryption to protect the privacy of local models in distributed deep learning. DPFed ensures the privacy of the ordinary global model that users do not know by adding DP noise to the global model. PSA and VerifyNet protect the privacy of local models by covering random perturbations. The comparison results of the accuracy and time overhead of the trained models obtained by comparing these existing methods with this method are shown in Tables 4 and 5.
[0085] Table 4 Comparison results of accuracy of different methods under different user scales
[0086]
[0087] Table 5 Comparison results of computational time overhead of different methods under different user scales
[0088]
[0089]
[0090] As can be seen from Table 4, this method is superior to DPFed in terms of model accuracy. This method does not add a noise mechanism to the global model, thus avoiding the situation of model damage. At the same time, this method is at the same level as HEDL, VerifyNet and PSA in terms of accuracy. Compared with traditional federated learning methods, these methods do not have an obvious loss in accuracy.
[0091] The results of comparing the communication time with existing methods are given in Table 5. Since there are no time-consuming operations such as encryption and decryption in this method, it has obvious advantages. Compared with the two methods of VerifyNet and PSA that adopt secret sharing, the computational time overhead on the user side is higher than this method. Because in HEDL where a large number of homomorphic operations are required on the client side, the performance of this method is better than HEDL. The time cost on the server side is also comparable to other comparison methods. As the user scale increases, the total time cost of this method increases slightly, while HEFed, VerifyNet, and PSA also increase.
[0092] Example 3
[0093] In this example, the results of the method of the present invention in various scenarios are compared to verify that the privacy protection method of the present invention has a resistance to membership inference attacks. The membership inference attack method is used to attack five different methods: federated learning, HEDL, DPFed, VerifyNet, and PSA. The CIFAR-10 dataset (https: / / www.cs.toronto.edu / ~kriz / cifar.html) is used for the membership inference attack, and the attack comparison results are shown in Table 6.
[0094] Table 6 Comparison results of different methods for resisting membership inference attacks
[0095]
[0096] As can be seen from Table 6, traditional FL, VerifyNet, and PSA cannot defend against membership inference attacks because the central server can still expose the global model. In HEDL, the server can only obtain the encrypted local model and the global model, and the attack accuracy is very low. In this method, the attack accuracy remains at a low level, indicating that the attack model is a guess of the global model because the attacker can only obtain virtual random number model parameters, and other attacks such as attribute inference attacks are carried out under the knowledge conditions of the local model or the global model. On this basis, such attacks cannot achieve a high attack accuracy like the results of membership inference attacks.
[0097] The above describes the implementation manners of the present invention in combination with the drawings and embodiments. However, for those skilled in the art, several improvements can still be made without departing from the principles of this patent, and these also belong to the protection scope of this patent.
Claims
1. A lightweight federated learning privacy protection method based on decentralized secure aggregation, characterized in that, each user is a data holder and is responsible for updating the local model in the federated learning process; each user randomly connects to N edge nodes, and the number of edge nodes is not less than the total number of Byzantine nodes; the edge nodes provide secure and decentralized local model aggregation for users, and it plays two roles: local model aggregator and blockchain consensus node; the edge nodes are secure aggregation service platforms established at the edge of the user network, and the service provider provides storage, computing, and network resources, is responsible for the local model and performs partial model aggregation; firstly, each user splits the model parameters, generates a carefully constructed global random number, and splits the global random number through a parameter splitting algorithm; then, the user sends the split model parameters and the global random number to the edge nodes it is connected to; after that, the edge nodes perform local model aggregation and upload it to the blockchain; the blockchain ledger, as a data sharing platform, uses the global model aggregation contract to complete the global model aggregation and obtains a global model covered by the global random number; during the operation of the smart contract, each edge node queries the data of other edge nodes from the blockchain shared ledger; at the same time, an access control security policy is adopted, and except for each edge node and each user, other entities cannot obtain the data uploaded to the general ledger; finally, the edge nodes send the global model to their corresponding users, and the global random number is completely eliminated by the users to obtain the final global model; lightweight training on the user side is implemented based on the global model, thereby reducing the threat of privacy leakage.
2. The lightweight federated learning privacy protection method based on decentralized secure aggregation according to claim 1, characterized in that, the method for each user to split the model parameters to generate a global random number is as follows: In federated learning training, the selected users train local models on their respective local datasets and then calculate the local models of the users of the local models , including the following steps: First, initialize the global model and the number of training rounds as well as the learning rate ; Then, for each round of the training process, select users from the user set to participate in the training . After that, for each user , local model training is performed through Equation 1; Among them, represents the model parameters of the previous round of training, represents the learning rate, represents the gradient, represents the loss function, w represents the model parameters, and b represents the model parameters.
3. The lightweight federated learning privacy protection method based on decentralized secure aggregation according to claim 1, characterized in that, the method for the aggregator to perform decentralized secure aggregation is as follows: First, the edge node aggregates all the partitioned local models using the global random number of the users selected in the next round of training ; Then, upload the aggregated local models from the blockchain to the blockchain ledger; the blockchain ledger, as a data sharing platform, uses the global model aggregation contract to perform global model aggregation; When all edge node data returns all sets After that, the edge node calculates and returns the global model covered by the global random number , and this global model is from the user 's global random number covered.
4. The lightweight federated learning privacy protection method based on decentralized secure aggregation according to claim 1, characterized in that, User After obtaining the global model remove the randomly generated numbers added by the user through to obtain the global model , indicating the global random number of the user .
Citation Information
Patent Citations
Trusted federated learning method, system and device based on block chain and medium
CN111966698A
Block chain federation learning system and Byzantine attack detection method
CN112100659A