A Federated Learning Method Based on DAG Blockchain

By selecting devices with strong communication and computing capabilities in the fog network for local training, and using the isolated forest detection algorithm, the device difference and malicious model detection problems in federated learning are solved, and the model accuracy is improved and the security of the global model is achieved.

CN113919507BActive Publication Date: 2025-06-24ZHENGZHOU JINZHI TALENT INFORMATION TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111186244.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-12
Publication Date
2025-06-24
Estimated Expiration
2041-10-12

AI Technical Summary

Technical Problem

In federated learning, the differences in equipment lead to differences in model accuracy, and the detection of malicious models is difficult, which endangers the convergence and accuracy of the global model.

Method used

The federated learning method based on DAG blockchain is adopted to select devices with strong communication and computing capabilities in the fog network for local training, and use a fast dual malicious model detection algorithm for isolated forests for model detection.

Benefits of technology

It effectively solves the problem of model accuracy differences caused by device differences, and ensures the convergence and accuracy of the global model through an efficient malicious model detection mechanism.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113919507B_ABST
    Figure CN113919507B_ABST
Patent Text Reader

Abstract

The present invention relates to a federated learning method based on a DAG blockchain, belonging to the field of mobile communication technology. First, devices with relatively high reputation values within a sliding window w are selected from the alternative device set to participate in local training. Secondly, during the local training process of the selected devices, aggregation of local models based on the local DAG blockchain is performed. Finally, the main fog node collects the trained local models and preliminarily detects potential malicious models using a fast detection algorithm based on isolation forest. Then, the main fog node uses the test data set of the task publisher to test the accuracy of the potential malicious models. If the difference between its accuracy and the accuracy of the current global model is greater than β, the model is confirmed as a malicious model; otherwise, it is a normal model. Finally, a new global model is obtained. When the training of the target model is completed, the task publisher obtains the target model and the attribute records of the local models of relevant IoT devices from the main blockchain, and the main fog node updates the reputation values of the IoT devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of mobile communication and relates to a federated learning method based on a DAG blockchain. Background Art

[0002] With the rapid development of the Internet of Things (IoT), various mobile devices need to access the Internet, which poses serious challenges to mobile devices with limited computing power and data resources. To effectively overcome these challenges and well support compute-intensive and latency-sensitive applications with quality-of-service requirements, fog computing (Fog Computing), a new paradigm similar to mobile edge computing (MEC), has been proposed as a promising solution that can distribute resources such as computing, communication, and storage to devices close to users, thereby extending cloud computing to the network edge. Since fog computing has relatively strong computing power, the performance of the system in terms of task processing latency can be greatly improved. However, it also faces many challenges such as user privacy and data security. Federated learning, as a current hot artificial intelligence technology, can solve the problems of private data and "data islands". Applying federated learning in the field of edge computing can effectively handle difficult problems such as private data. Federated learning allows participants to transfer and exchange model parameters without revealing their own privacy to build a machine learning model using the data of the participants.

[0003] Although federated learning is widely regarded as a feasible method to enhance the privacy and security of IoT networks, many challenges still exist during the deployment process. The two main points are as follows: First, in federated learning, there are differences among devices. Different devices have different federated learning resources in terms of computing, communication, caching, battery power, data, and training time. Second, the anomaly detection of the federated learning model. During the federated learning process, malicious participants may provide malicious local models by launching poisoning attacks, which will endanger the convergence and accuracy of the global model. Summary of the Invention

[0004] In view of this, the purpose of the present invention is to provide a federated learning method based on a DAG blockchain.

[0005] To achieve the above purpose, the present invention provides the following technical solutions:

[0006] A federated learning method based on a DAG blockchain, the method comprising the following steps:

[0007] S1: Select a federated learning training device scheme in the fog network;

[0008] S2: A local model training and aggregation scheme based on a directed acyclic graph blockchain;

[0009] S3: Fast Dual Malicious Model Detection Algorithm Based on Isolation Forest;

[0010] S4: Reputation Calculation Scheme Based on Subjective Evaluation;

[0011] In step S1, the master fog node selects devices with stronger communication ability ξ m and computing ability τ m from the alternative devices to form an alternative device set, and then selects devices with higher reputation values within the sliding window w from the alternative device set to participate in the local training task.

[0012] In step S2, the devices participating in local training download the global model from their affiliated fog nodes, perform training and local aggregation. The device randomly selects some unvalidated transactions (tips) on its local DAG for validation, and selects a local model with high precision for local aggregation. Subsequently, the device uses the local dataset to train a new local model. Finally, the device publishes a block containing the newly trained local model. During the local training process of this model, the Stochastic Gradient Descent (SGD) algorithm is used to update the local model, and the Federated Averaging (FedAVG) algorithm is used to obtain the local aggregation model.

[0013] In step S3, the master fog node collects the local models to be aggregated and uses the fast detection algorithm based on isolation forest to preliminarily detect potential malicious models. First, the algorithm constructs multiple isolation trees through multiple samplings and uses the average depth of each model in the tree as the final output depth; second, it calculates the anomaly score of each data point in the leaf nodes through the output depth and selects the models with anomaly scores exceeding the threshold as potential malicious models; third, the master fog node uses the test dataset of the task publisher to test the accuracy of the potential malicious models. If the difference between its accuracy and the accuracy of the current global model is greater than β, the model is confirmed as a malicious model, otherwise it is a normal model; finally, after selecting the normal models, global aggregation is performed to obtain a new global model.

[0014] In step S4, when the training of the target model is completed, the task publisher obtains the target model from the main blockchain, as well as the attribute records (whether it is a malicious model) of the local models of the relevant IoT devices, calculates the reputation values of the corresponding devices, feeds them back to the affiliated fog nodes, and then forwards them to the master fog node for updating the reputation values of the IoT devices. The process of reputation value update is as follows:

[0015] The reputation evaluation of device l by task publisher m' based on the released task y is represented by a vector as:

[0016] where respectively represent trust, distrust, and uncertainty. where Based on the subjective logic model, we get:

[0017]

[0018] Among them, is the number of normal (malicious) models during the execution of task y, represents the successful transmission probability of data packets during the execution of task y, that is, the communication quality affecting the uncertainty of reputation evaluation. η(κ) respectively represent the weights of normal (malicious) models, and η + κ = 1 and κ ≤ η. Based on this, the reputation evaluation of the IoT device l by the task publisher m' based on task y can be expressed as:

[0019]

[0020] Among them, a ∈ [0, 1] represents the degree of influence of uncertainty on reputation.

[0021] The beneficial effects of the present invention are as follows: It solves the differences in model accuracy caused by the differences in computing, communication, caching, battery power, data, and training time between different devices. Secondly, in order to achieve anomaly detection of the model, a malicious model detection algorithm based on isolation forest is adopted. By constructing an isolation forest to calculate the malicious score of the model uploaded by participants, when the malicious score of the model is higher than the threshold, its accuracy will be tested, and the model exceeding the accuracy loss threshold is finally determined as a malicious model.

[0022] Other advantages, objectives, and features of the present invention will be described to some extent in the subsequent specification, and to some extent, will be obvious to those skilled in the art based on the study of the following text, or can be taught from the practice of the present invention. The objectives and other advantages of the present invention can be achieved and obtained through the following specification. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be described in detail preferably with reference to the accompanying drawings, where:

[0024] Figure 1 is the system model diagram;

[0025] Figure 2 is the flow chart of federated learning based on directed acyclic graph blockchain in the fog network;

[0026] Figure 3 is the flow chart of the fast isolation forest malicious model double detection algorithm. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0027] The following specific examples illustrate the implementation manners of the present invention. Those skilled in the art can easily understand other advantages and effects of the present invention from the content disclosed in this specification. The present invention can also be implemented or applied through other different specific implementation manners. Various details in this specification can also be modified or changed based on different viewpoints and applications without departing from the spirit of the present invention. It should be noted that the drawings provided in the following embodiments only illustrate the basic concept of the present invention in a schematic manner. Without conflict, the following embodiments and the features in the embodiments can be combined with each other.

[0028] Among them, the drawings are only for illustrative purposes, showing only schematic diagrams rather than physical diagrams, and should not be construed as a limitation to the present invention; in order to better illustrate the embodiments of the present invention, some components in the drawings will be omitted, enlarged or reduced, which does not represent the size of the actual product; for those skilled in the art, it is understandable that some well-known structures and their descriptions in the drawings may be omitted.

[0029] In the drawings of the embodiments of the present invention, the same or similar reference numerals correspond to the same or similar components; in the description of the present invention, it should be understood that if there are terms such as "upper", "lower", "left", "right", "front", "rear", etc. indicating the orientation or positional relationship, it is based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, the terms describing the positional relationship in the drawings are only for illustrative purposes and should not be construed as a limitation to the present invention. For those of ordinary skill in the art, the specific meanings of the above terms can be understood according to specific circumstances.

[0030] 1. System Model

[0031] In this model, the fog network consists of fog nodes FN (Fog Nodes) and Internet of Things devices. As Figure 1 shown. The fog nodes have large-capacity computing and communication resources. Suppose there are K fog nodes, denoted by . The Internet of Things devices have limited computing and communication resources. Suppose there are M Internet of Things devices, denoted by M = {1,.., m,.., M}. Define the Internet of Things device that requests a task as m', which has a specific request task, such as image recognition, traffic situation prediction, etc. Let the set M of Internet of Things devices have a corresponding training data set D = {D1,.., D m ,.., D M}. The computing task is to train a task model based on the data set D and return the target model required by the task requester.

[0032] This model adopts a DAG-based federated learning structure, which includes the following three steps: device selection, local training and aggregation, and global aggregation. First, in device selection, by screening IoT devices with better performance, the efficiency and accuracy of model training are improved, and the security of the trained model is ensured. Secondly, local models are transmitted between IoT devices through D2D (Device to Device), and the DAG structure is used for model verification and aggregation. Finally, the block producer nodes are selected as aggregators for global aggregation through the DPOS consensus algorithm. The specific implementation steps are as Figure 2 shown. It mainly includes device selection for local model training, DAG-based local model aggregation, global aggregation by fog nodes selected by the DPOS consensus algorithm, double screening of local models, and a subjective reputation calculation model for training devices.

[0033] 2. Federated Learning Model Based on DAG Blockchain

[0034] Federated learning (FL) is to build a machine learning model using distributed training datasets, which are stored and maintained on local devices, and can achieve privacy protection of participants' data. FL updates the global model by collecting local models from different devices to achieve global aggregation. In this model, the task requests of task requesters are completed through FL. Among them, IoT devices perform local training, and the main fog nodes perform global aggregation.

[0035] For the IoT device m with the dataset D m , the loss function of the local model is defined as

[0036]

[0037] where f j (w, x j , y j ) is the loss function of the local model w on the data sample (x j , y j ), and |D m | is the size of the data sample D m . Therefore, the loss function F(w) of the global model is defined as

[0038]

[0039] where |M| is the number of IoT devices. c m is the weight factor of the local model of m.

[0040] During the model training process, the stochastic gradient descent (SGD) algorithm is adopted, and through step-by-step iteration, the minimum global loss function F(w)

[0041] Q(w) = argminF(w) (5)

[0042] 2.1 Device Selection

[0043] To improve the training efficiency and accuracy and ensure the security of the training model, first, select devices with strong communication ability ξ m and computing ability τ m from the alternative devices to form an alternative device set, and then select devices with higher reputation values during the sliding window w period from the alternative device set to participate in the local training task. The specific implementation steps are as follows:

[0044] First, the task publisher initializes the global model and sends the global model, relevant task information, and test data set to the affiliated fog node, which is sent to the main fog node of the fog network through the fog node, and the main fog node broadcasts the task to the entire fog network. Internet of Things devices with training conditions send their available computing and communication capabilities to the corresponding fog nodes. After the main fog node collects all device information, according to the computing and communication capabilities ξ m ·τ m sort the Internet of Things devices in descending order and filter them according to the reputation value, and finally determine the list of alternative devices The main fog node receives the local models of the corresponding devices according to the device list.

[0045] 2.2 Local Model Training and Aggregation Based on DAG Blockchain

[0046] Compared with traditional single-chain blockchains, the DAG blockchain is adopted in this model. Its advantage is that in traditional blockchains, nodes pack multiple collected transactions into a block and connect the blocks in a single-chain manner. The subsequent block must be confirmed by the previous block. The block-packing delay and linear verification method reduce the effectiveness of blockchain transaction verification and hinder the improvement of blockchain throughput.

[0047] Different from the linear connection structure of traditional blockchains, this model adopts a data structure based on DAG. The data stored at the bottom layer is in the form of a directed acyclic graph, and the data is connected and stored through DAG. By adopting the DAG structure in the blockchain, blocks can be added asynchronously. Its structural advantage enables transactions in the entire network to be executed concurrently; moreover, since the DAG structure supports asynchrony, the blockchain based on the DAG structure can omit the block-packing delay, further improving the blockchain efficiency. Therefore, the throughput performance of the blockchain based on the DAG structure has been greatly improved compared with that of traditional blockchain structures.

[0048] In this model, the verification and update processes of the local model are combined. First, in the local blockchain, the device l participating in the local model training maintains a local DAG blockchain, where each block contains the device's authentication information, local model parameters, and block connection relationships. The local DAG blockchain updates the local DAG blockchain through the gossip protocol, so that the new model can be spread throughout the fog network; Second, run the consensus algorithm to update the local DAG blockchain. The consensus of the local DAG blockchain approves the block by verifying the identity information of the tips and the correctness of the local model. The authentication of the tips can be verified through encryption technologies such as RSA in the blockchain field, while the local model can be verified through the test set formed based on local data.

[0049] When the device performs local aggregation, first it runs the consensus algorithm based on the DAG blockchain, selects some tips for verification through the Markov Chain Monte Carlo (MCMC) algorithm on its local DAG blockchain, and selects the local models with high accuracy for aggregation to construct a new local model. Second, the device uses the local dataset to train the new local model. Finally, it publishes the block containing the new local model.

[0050] In this model, the local training adopts the Stochastic Gradient Descent (SGD) algorithm. In the t-th iteration, the device uses the global model w in the (t - 1)-th iteration t-1 through the dataset D l to train and obtain the local model to calculate the descent gradient through formula (6) l packs the local model parameters into a block, sends it to nearby devices through the D2D link, and receives the blocks of nearby devices. Then, l selects some tips (not exceeding α) that meet the time tolerance from the local DAG blockchain using the MCMC algorithm for local aggregation. It first verifies the identity information of the tips, then tests the accuracy of the local model in the block using the local test dataset, and sorts them in descending order of accuracy. Select k (k < α) local models with the highest accuracy, obtain the local aggregation model through the Federated Averaging (FedAVG) algorithm, and then use the local dataset to train the local model.

[0051]

[0052] where η is the learning rate of the distributed gradient descent algorithm.

[0053] 2.3 Global Aggregation

[0054] After local training and aggregation, each fog node collects local model parameters and sends them to the main fog node. After screening malicious models, the main fog node performs global aggregation using formula (7), records the status (normal or malicious) of the local models of the corresponding devices, updates the alternative device list (devices that upload malicious models more than three times will be removed from the alternative device list), packs the relevant model parameters and device status information into blocks, and adds them to the main chain after verification by other fog nodes.

[0055]

[0056] where L is the number of devices participating in local training, and C l is the contribution of device l to the entire training process in iteration t.

[0057] In this model, the main blockchain selects block producers through the DPOS consensus algorithm. Fog nodes vote based on computing power, communication ability, and historical behavior to select a certain number of devices to form a candidate set. The fog nodes in the candidate set take turns as the main fog node, that is, the block producer, and perform global model aggregation and block packaging and publishing. The packaged block is sent to other candidate fog nodes for verification. The verifiers verify the information in the block and return the results to the main fog node. After the main fog node collects all the verification results, it decides whether to submit the block. If the verification passes, the main fog node sends the block to all fog nodes to update the main blockchain.

[0058] 3. Fast Isolation Forest (IForest) Dual Malicious Model Detection Algorithm

[0059] In this model, the Fast Isolation Forest Dual Malicious Model Detection Algorithm is adopted. It is an outlier detection algorithm that constructs multiple isolation trees (iTrees) through multiple samplings and uses the average value of the depths of each node in multiple iTrees as the final output depth. The outlier score of the node is calculated through the final output depth, and the nodes with high outlier scores are selected as candidate malicious models in this model.

[0060] For the selected candidate malicious models, the accuracy of the models is tested using the test dataset provided by the task publisher. When the difference between the accuracy of the candidate model and the accuracy of the global model is less than α, the model is determined to be a normal model; otherwise, it is determined to be a malicious model and cannot participate in global aggregation. Devices that upload malicious models will be marked as sensitive devices and will not be removed from the device list temporarily and can continue with federated learning. When a device is marked as a sensitive device three times, it will be removed from the device list so as to ensure that normal devices will not be determined to be malicious devices due to occasional training errors. The algorithm flow is as Figure 3As shown in the figure, it mainly includes input model parameter dimensionality reduction, constructing an isolation forest for calculating model anomaly scores and thresholds, and detecting malicious models. The specific steps are as follows:

[0061] 3.1 Data Dimensionality Reduction Based on the Unsupervised Feature Selection Algorithm (NMIFS) of Normalized Mutual Information

[0062] Since the parameters of the model are usually high-dimensional matrices, which is not conducive to constructing an isolation forest anomaly detection model, all model parameters need to be flattened into a one-dimensional vector for the following reasons: First, represent the value at each position in the model parameters as the data features of the model. After flattening the model into a one-dimensional vector, the data features of the model can be expressed more intuitively. Second, it is more convenient to apply the IForest algorithm after flattening the model into a one-dimensional vector. After flattening the parameters of the local model i into a one-dimensional vector, it can be represented as a k-dimensional column vector: u i ={x i1 ,x i2 ,..,x ik}, i ∈ (1, L), x ik is the k-th feature data of the i-th model, and the input original data set is: U = {u1, u2, …, u L}, where L is the number of IoT devices participating in local training.

[0063] First, calculate the redundancy based on normalized mutual information:

[0064] Mutual information (MI) is a measure of the mutual dependence between two random variables and is defined as:

[0065] I(x, y) = H(x) + H(y) - H(x, y) (8)

[0066] where H(.) represents the information entropy of the variable. For given discrete random variables x and y, MI can be calculated by the following formula

[0067]

[0068] where p(x i ,x j ) is the joint probability distribution, and p(x i ), p(x j ) are the marginal probability distributions. Thus, the redundancy of a single feature and a feature subset can be calculated by the following formula.

[0069] 1) The normalized mutual information (NMI) between feature x k and feature x k' , that is, the redundancy is:

[0070]

[0071] 2) Feature x k Average redundancy of feature F relative to the feature subset, that is, feature x s is the average of the redundancies of feature x k relative to each feature x k' ∈F s :

[0072]

[0073] 3) Feature subset F s The redundancy of is the average of the average redundancies of each feature x k' ∈F s :

[0074]

[0075] For the data set U, calculate the average redundancy using formula (12) and use it as the threshold for selecting its feature elements. Then calculate the entropy value of each feature in U and sort them in ascending order. Then, for each feature in turn, calculate its average redundancy using formula (11). For features with an average redundancy less than the threshold, use them as the feature elements of the feature subset, and finally obtain the feature subset F s . s .

[0076] Taking F s as the output feature subset after data dimensionality reduction, F s = {x1,…,x s ,…,x S}, S is the total number of features in the feature set, x s is the s-th feature in the feature set, s ∈ (1, S), x s = {y1, y2,…,y l}, y l is the feature value of the l-th model in the s-th feature, l ∈ (1, L).

[0077] 3.2 Malicious model detection based on IForest

[0078] After dimensionality reduction processing of all local models, each feature vector in F s has L parameters respectively. Malicious model detection based on IForest consists of three steps:

[0079] Step 1: Use F s to construct isolation trees and isolation forests respectively.

[0080] Step 2: Calculate the anomaly score of the model to generate a candidate malicious model set.

[0081] Step 3: Based on the test data set, determine the malicious model.

[0082] First, use F s to construct isolation numbers and isolation forests respectively. Randomly select a data feature from F s to construct an iTree, and calculate the anomaly score of the data point x sl in the iTree, which is defined as:

[0083]

[0084] where L represents the total number of data points used to construct the iTree. After traversing the isolation tree iTree, the layer number of the data point x sl , that is, the depth h(x sl ) of the data point, can be obtained:

[0085] h(x sl ) = e + C(L) (14)

[0086] e is the current path length, and C(L) is a correction value, representing the average path depth of constructing a binary tree with L data points. The calculation formula is as follows:

[0087]

[0088] where ξ = 0.5772156649 is the Euler constant. By traversing an isolation tree, the anomaly score SM(x sl ) of the data point can be obtained. Considering the random selection of the sampling subspace and features, the reliability of SM(x sl ) is very low. Therefore, the construction of the isolation forest can obtain the average path depth of each data point in multiple trees, and then obtain the average anomaly score AS(x sl ) of the data point x sl sl )

[0089]

[0090] E(h(x sl )) represents the average value of the path depth of the data point x sl in multiple iTrees.

[0091] Secondly, calculate the model anomaly score to generate a set of alternative malicious models. The traditional isolation forest algorithm obtains its anomaly score by traversing each tree in the forest and calculating the average path length of each data point. When the anomaly score of a data point tends to 1, the point is determined as an outlier; when the anomaly score tends to 0, the point is a normal point; when the anomaly score tends to 0.5, its state cannot be judged. In this solution, the outlier coefficient of the feature is obtained through statistical data feature analysis, and the dispersion degree of the data set is measured based on the outlier coefficient of the feature, and thus the threshold for determining the malicious model is obtained. ​

[0092] Feature x s The outlier coefficient Disp of the feature coe (x s ) is defined as:

[0093]

[0094] where, is the mean of the anomaly scores of feature x s , y l represents the anomaly score of the l-th model in feature x s , Disp coe (x s ) is used to measure the dispersion degree of feature x s . Calculate the outlier coefficients of the features in the feature set F s in turn to obtain the data set feature outlier coefficient vector D x , denoted as:

[0095] D x ={Disp coe (x1), Disp coe (x2), …, Disp coe (x S )} (18)

[0096] Normalize D x according to formula (18) to obtain the normalized data set feature outlier coefficient vector D Norm , as shown in formula (19):

[0097]

[0098] D Norm ={NDisp coe (x1), NDisp coe (x2), …, NDisp coe (x S )} (20)

[0099] The pruning threshold θ D can be calculated through the feature outlier coefficient vector. In formula (21), D Norm -Top(S) means using the Top() algorithm to quickly obtain the S largest values of the feature outlier coefficients in D x , S is the number of features in Fs after dimensionality reduction of D by NMIFS, and the adjustment factor α is a random number in the interval [0.45, 0.55]. Calculate the anomaly scores of each data point through the isolation forest algorithm and sort them in descending order, and classify the first n*θ D data points with larger anomaly scores into the candidate malicious model set.

[0100]

[0101] Finally, using the test dataset of the task publisher, the accuracy of the candidate malicious model is tested. If the difference between the accuracy of its model and the global model accuracy is greater than β, the model is confirmed as a malicious model; otherwise, it is a normal model.

[0102] 3.3 Global Aggregation

[0103] After the malicious model detection by IForest, the detected normal models are globally aggregated according to formula (7). Then the aggregated global model w t is broadcast to all devices.

[0104] 4. Reputation Model Based on Subjective Evaluation

[0105] After the model training is completed, the task publisher obtains the attribute records (whether it is a malicious model) of the target model and the local models of relevant IoT devices from the main blockchain, calculates the corresponding device reputation values, feeds them back to the affiliated fog node, and then forwards them to the main fog node for updating the reputation values of IoT devices. The reputation value update process is as follows:

[0106] The reputation evaluation of device l by task publisher m' based on the released task y is represented by a vector as:

[0107] where represent trust, distrust, and uncertainty respectively. where Based on the subjective logic model, we can get:

[0108]

[0109] where, is the number of normal (malicious) models during the execution of task y, represents the successful transmission probability of data packets during the execution of task y, that is, the communication quality affecting the uncertainty of reputation evaluation. η(κ) represent the weights of normal (malicious) models respectively, and η + κ = 1 and κ ≤ η. Based on this, the reputation evaluation of IoT device l by task publisher m' based on task y can be expressed as:

[0110]

[0111] where, a ∈ [0, 1] represents the influence degree of uncertainty on reputation.

[0112] Figure 2 Figure 51 is the flowchart of federated learning based on DAG in the fog network. The specific implementation steps are as follows:

[0113] Step 201: Algorithm initialization;

[0114] Step 202: Based on the DPOS consensus algorithm in the fog node, select candidate block producers that form the consensus layer;

[0115] Step 203: The task publisher sends the task information and requirements to be trained to its affiliated fog node, which forwards it to the main fog node;

[0116] Step 204: After receiving the task information, the main fog node broadcasts the task information to the devices in the entire fog network. Then, after the devices receive the task information, the devices that meet the requirements send their own resource information (such as the communication ability and computing ability of the device) to the corresponding fog node, and finally summarize it to the main fog node;

[0117] Step 205: The main fog node selects devices with strong comprehensive capabilities and meeting the reputation requirements to participate in local training according to the information returned by the devices;

[0118] Step 206: The devices selected to participate in the training download the global model to be trained from their affiliated fog nodes;

[0119] Step 207: After the device trains the local model, it broadcasts the model to adjacent devices;

[0120] Step 208: The device accepts the local models of adjacent devices, selects a batch of tips through the MCMC algorithm, verifies their accuracy using the test data set, and selects the local model with high accuracy for aggregation;

[0121] Step 209: Before each global aggregation, the fog node collects the local models trained by its affiliated devices and sends them to the main fog node;

[0122] Step 210: The main fog node uses the fast IForest dual malicious model detection algorithm to screen malicious models and selects normal models for global aggregation;

[0123] Step 211: Verify whether the accuracy of the aggregated global model meets the requirements. If not, continue training; otherwise, end the training;

[0124] Step 212: The task publisher obtains the target model it trained and returns the reputation value of the device to the main fog node according to the behavior performance of the participating devices during the training process;

[0125] Step 213: When the main fog node receives the feedback reputation value from the task publisher, it updates the reputation value of the device and adds it to the main blockchain;

[0126] Step 214: End

[0127] Figure 3Flowchart of the double detection algorithm for the fast isolated forest malicious model. The specific implementation steps are as follows:

[0128] Step 301: Algorithm initialization;

[0129] Step 302: Calculate the entropy of the output model parameter matrix;

[0130] Step 303: Calculate the redundancy of the features of the model parameters according to the entropy to obtain the subset of feature vectors with the minimum redundancy;

[0131] Step 304: Use the isolated forest algorithm to construct an isolated forest tree;

[0132] Step 305: Use the constructed isolated forest tree to calculate the anomaly score of each model;

[0133] Step 306: Calculate the threshold of the malicious model using formula (21);

[0134] Step 307: Select candidate malicious models using the threshold;

[0135] Step 308: Test the accuracy of the candidate malicious models;

[0136] Step 309: For candidate malicious models that do not meet the accuracy requirements, determine them as malicious models;

[0137] Step 310: End.

[0138] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the present technical solution, and they should all be covered by the scope of the claims of the present invention.

Claims

1. A federated learning method based on a directed acyclic graph (DAG) blockchain, characterized in that: The method comprises the following steps: S1: Federated learning training device selection in fog network; S2: Local model training and aggregation based on directed acyclic graph blockchain; S3: Conduct a fast dual malicious model detection algorithm based on isolation forest; S4: Reputation calculation based on subjective evaluation; In the S1, the main fog node selects devices with relatively strong communication capabilities ξ m and computing capabilities τ m from the devices that meet the training requirements to form a set of alternative devices, and then selects devices with relatively high reputation values within the sliding window w from the set of alternative devices to participate in the local training task; In S2, after the device participating in the local training obtains the latest global model, it performs local training and aggregation; the device randomly selects some unverified transactions on its local DAG for verification, and selects local models with high precision for local aggregation; then, the device uses the local data set to train a new local model; finally, the block containing the newly trained local model is released; in the local training process of this global model, the stochastic gradient descent SGD algorithm is used to update the local model, and the local aggregation model is obtained by the federated average algorithm; In S3, the main fog node collects the local models to be aggregated, and uses a fast detection algorithm based on isolation forest to preliminarily detect potential malicious models; finally, the main fog node uses the test data set of the task publisher to test the accuracy of the potential malicious model. If the difference between its accuracy and the accuracy of the current global model is greater than β, the model is confirmed as a malicious model, otherwise it is a normal model; finally, after selecting the normal model, global aggregation is performed to obtain a new global model; In S4, the task publisher obtains the required target model from the main blockchain, as well as the attribute records of the local model of the device participating in the local training during the training process, the attribute record is whether it is a malicious model, and calculates the reputation value of the corresponding device, feeds it back to the fog node to which it belongs, and then forwards it to the main fog node to update the reputation value of the IoT device; The reputation evaluation of the task publisher m' on the device l based on the published task y is represented by a vector: wherein respectively represent trust, distrust, and uncertainty; wherein based on the subjective logic model, it is obtained that: Among them, is the number of normal models during the execution of task y, is the number of malicious models during the execution of task y, represents the successful transmission probability of data packets during the execution of task y, that is, the communication quality affecting the uncertainty of reputation evaluation; η represents the weight of the normal model, κ represents the weight of the malicious model, and η+κ=1 and κ≤η; the reputation evaluation of the task publisher m' on the IoT device l based on the task y is expressed as: Among them, a∈[0,1] represents the impact of uncertainty on reputation.

Citation Information

Patent Citations

  • Sensing edge cloud blockchain network trusted offload cooperation node selection system and method

    CN112202928A

  • Marine Internet of Things data security sharing method under edge computing framework based on federated learning and block chain technology

    CN112348204A