Security Protection Method and System for Federated Learning Models Based on Secure Shuffling and Differential Privacy

The federated learning model is subjected to noise processing and encryption through differential privacy Gaussian mechanism and security shuffle algorithm, which solves the privacy and usability problems of the federated learning model when it is released and used, and realizes the secure release of the model and the reliable use of users.

CN113987539BActive Publication Date: 2025-07-22STATE GRID ELECTRIC POWER RES INST +3
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111270844.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-29
Publication Date
2025-07-22
Estimated Expiration
2041-10-29

AI Technical Summary

Technical Problem

Existing federated learning models cannot effectively protect the privacy of the model when they are released and used, and the models obtained by users may not be available.

Method used

The differential privacy Gaussian mechanism is used to perform noise processing on model parameters, and the user authorization key and security shuffling algorithm are used for encryption and decryption to generate and protect the noise-free federated learning model.

Benefits of technology

It protects the privacy of the model owner, ensures the availability and security of the federated learning model obtained by users, and only authorizes users to use the model normally.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113987539B_ABST
    Figure CN113987539B_ABST
Patent Text Reader

Abstract

The present invention discloses a security protection method and system for a federated learning model based on secure shuffling and differential privacy. The federated model owner uses differential privacy technology to add noise to the model parameters of federated learning to generate noisy model parameters, and then uses the user authorization key and the secure shuffling algorithm to encrypt the model parameters, and sends the encrypted federated learning model parameters to the user. When the user uses the federated learning model locally, the user first uses the user authorization key and the secure shuffling algorithm to decrypt the ciphertext of the model parameters to obtain the noisy federated learning model, and the user can obtain the desired output result by using his own data as the input of the model. The present invention not only protects the privacy of the original model, but also can effectively protect the security of the original model and ensure that the user can obtain a usable model usage result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of artificial intelligence, and particularly relates to a method and system for securing a federated learning model based on secure shuffling and differential privacy. Background Art

[0002] Federated learning is an artificial intelligence technology that is being widely studied and used. The goal is to carry out efficient machine learning among multiple participants or computing nodes while ensuring information security during big data exchange, protecting terminal data and personal data privacy, and ensuring legal compliance. Therefore, federated learning can solve machine learning tasks without data leaving the local area, thereby protecting the privacy of training sample data of collaborative participants and solving the data silo problem. However, although current federated learning has solved the data privacy problems such as training samples of each participant, the existing related differential privacy protection technologies focus on sample privacy and parameter privacy during model training and have not been able to solve the security privacy of the locally used federated learning model. As is well known, the federated learning model is the result of multi-party collaborative cooperation, and the original federated learning model is the data asset of the model owner. Ensuring the privacy of the federated learning model during release and use remains an urgent problem to be solved. Therefore, how to securely release the original federated learning model and ensure the usability of the model by users is an important technical difficulty. Summary of the Invention

[0003] Object of the Invention: Aiming at the deficiencies of the prior art, the present invention provides a method and system for securing a federated learning model based on secure shuffling and differential privacy, which can protect the privacy of the federated learning model owner and ensure the usability of the federated model obtained by users.

[0004] Technical Solution: The method for securing a federated learning model based on secure shuffling and differential privacy according to the present invention includes the following steps:

[0005] (1) Adding noise to the model parameters of federated learning based on the differential privacy Gaussian mechanism to generate noisy model parameters;

[0006] (2) Encrypting the differentially private noisy model parameters using the user authorization key and the secure shuffling algorithm, and sending the encrypted federated learning model parameters to the user;

[0007] (3) Decrypting the model parameter ciphertext using the user authorization key and the secure shuffling algorithm to obtain the noisy federated learning model;

[0008] (4) Using the user's data as the input of the noisy federated learning model to obtain the desired output result.

[0009] Further, the implementation process of step (1) is as follows:

[0010] The parameters of the federated learning model Π form an m×n matrix A Π , and the Gaussian mechanism in differential privacy is used to process the noise of each element in the matrix A Π to obtain the parameter matrix A' of the federated learning model Π' with noise Π :

[0011] A' Π (i,j) = A Π (i,j)+α (1)

[0012] Among them, the Gaussian mechanism provides relaxed (ε,δ)-differential privacy, the noise ratio σ≥cΔs / ε, and the constant ε∈(0,1); the sensitivity The Gaussian noise distribution α~N(0,σ 2 ) satisfies (ε,δ)-differential privacy. α is the noise value added to each data in the matrix, and the sensitivity represents the maximum difference in the output of the query function s for adjacent data sets

[0013] Furthermore, step (2) includes the following steps

[0014] (21) Read in the noisy federated learning model parameter matrix A of m×n Π ;

[0015] (22) Initialize the logical mapping control parameters s, d, f, g, where s is the chaos control parameter, d and f are the logical mapping control parameters, and map x n , y n respectively, and g is the coupling term; and initialize the iterative mapping iter = 200, and give the key key = {x, y}, where x and y are the two initial values of the chaotic mapping

[0016] (23) Using the key key as the initial value, through the iterative mapping m×n+iter for the chaotic sequence values, discard the iter pairs of values, obtain m×n pairs of chaotic sequence values, and store them in one-dimensional arrays P and Q of size m×n respectively

[0017]

[0018] (24) Run the following secure shuffling algorithm 1 operation on the elements in P and Q to obtain two one-dimensional matrices P' and Q' of integer values

[0019] (25) Sort through P' and Q' to generate two one-dimensional pseudo-random sequence matrices P” and Q” of length m×n, and their element values are unequal integers within [0,m×n-1]

[0020] (26) Perform the following transformations on each element P”(k) and Q”(k) in the one-dimensional random sequences P” and Q”, and map them to two-dimensional scrambling matrices X and Y of size m×n;

[0021]

[0022] where x(i,j) and y(i,j) are the elements of the two-dimensional scrambling matrices X and Y respectively;

[0023] (27) First, use the scrambling matrix X to scramble the matrix A Π to obtain an intermediate result of scrambled temporary model parameters; then use Y to perform position scrambling on the intermediate result of scrambled temporary model parameters to obtain the final scrambled ciphertext of the federated learning model parameters with noise.

[0024] Furthermore, the implementation process of step (3) is as follows:

[0025] (31) Given the same key key = {x, y} as in the encryption process, generate the scrambling matrices X and Y from the keys x and y;

[0026] (32) First, use the scrambling matrix Y to scramble the scrambled ciphertext of the federated learning model parameters with noise to obtain an intermediate result of scrambled temporary model parameters, and then use X to perform position scrambling on the intermediate result of scrambled temporary model parameters to obtain a parameter model with noise.

[0027] Based on the same inventive concept, the present invention also proposes a security protection system for federated learning models based on secure shuffling and differential privacy, including a parameter processing module, an encryption module, and a decryption module; the parameter processing module adds noise to the model parameters of the federated learning based on the differential privacy Gaussian mechanism to generate model parameters with noise; the encryption module encrypts the differentially private noise-added model parameters using the user authorization key and the secure shuffling algorithm, and sends the encrypted federated learning model parameters to the user; the decryption module decrypts the model parameter ciphertext using the user authorization key and the secure shuffling algorithm to obtain the federated learning model with noise.

[0028] Furthermore, the working process of the parameter processing module is as follows:

[0029] The parameters of the federated learning model Π form a matrix A of size m×n Π , and use the Gaussian mechanism in differential privacy to perform noise processing on each element in the matrix A Π to obtain a parameter matrix A' of the federated learning model Π' with noise Π :

[0030] A' Π (i,j) = A Π (i,j) + α (1)

[0031] Among them, the Gaussian mechanism provides relaxed (ε,δ)-differential privacy, and the noise ratio σ≥cΔs / ε, where the constant ε∈(0,1); the sensitivity The Gaussian noise distribution α~N(0,σ 2 ) satisfies (ε,δ)-differential privacy. α is the noise value added to each data in the matrix, and the sensitivity represents the maximum difference in the output of the query function s for adjacent data sets.

[0032] Furthermore, the working process of the encryption module is as follows:

[0033] (S1) Read in the noisy federated learning model parameter matrix A of m×n Π ;

[0034] (S2) Initialize the logical mapping control parameters s, d, f, g, where s is the chaos control parameter, d and f are the logical mapping control parameters, which map x n and y n respectively, and g is the coupling term; and initialize the iteration mapping iter = 200, and given the key key = {x, y}, where x and y are the two initial values of the chaos mapping;

[0035] (S3) Using the key key as the initial value, through the iteration mapping m×n+iter for the chaos sequence values, discard the iter pairs of values, obtain m×n pairs of chaos sequence values, and store them in one-dimensional arrays P and Q of size m×n respectively:

[0036]

[0037] (S4) Run the following secure shuffling algorithm 1 operation on the elements in P and Q to obtain two one-dimensional matrices P′ and Q′ of integer values;

[0038] (S5) Sort through P′ and Q′ to generate two one-dimensional pseudo-random sequence matrices P” and Q” of length m×n, and the values of their elements are unequal integers within [0,m×n-1];

[0039] (S6) Perform the following transformations on each element P”(k) and Q”(k) in the one-dimensional random sequences P” and Q”, and map them to two-dimensional scrambling matrices X and Y of size m×n;

[0040]

[0041] Among them, x(i,j) and y(i,j) are the elements of the two-dimensional scrambling matrices X and Y respectively;

[0042] (S7) Use the scrambling matrix X to first scramble the matrix A Π to obtain the intermediate result of the scrambled temporary model parameters; then use Y to scramble the intermediate result of the scrambled temporary model parameters to obtain the final encrypted ciphertext of the scrambled federated learning model parameters with noise.

[0043] Furthermore, the working process of the decryption module is as follows:

[0044] (H1) Given the same key key = {x, y} as in the encryption process, generate the scrambling matrices X and Y from the keys x and y;

[0045] (H2) Use the scrambling matrix Y to first scramble the encrypted ciphertext of the scrambled federated learning model parameters with noise to obtain the intermediate result of the scrambled temporary model parameters, and then use X to scramble the intermediate result of the scrambled temporary model parameters to obtain the parameter model with noise.

[0046] Beneficial effects: Compared with the prior art, the beneficial effects of the present invention are as follows: The present invention enables the model owner to protect the privacy of the real federated learning model using differential privacy, and adds noise to the trained model parameters in terms of noise addition, avoiding interference with the neural network training model and ensuring the usability of the federated learning model with noise; the combination of secure shuffling and authorized keys ensures that only authorized users can obtain the federated learning model with noise; thus achieving the secure release of the federated learning model for local use. Description of the Drawings

[0047] Figure 1 is the flow chart of the present invention;

[0048] Figure 2 is the forward shuffling flow chart of the federated learning model;

[0049] Figure 3 is the reverse shuffling flow chart of the federated learning model. Detailed Embodiments

[0050] The present invention will be further described in detail below with reference to the accompanying drawings.

[0051] The present invention provides a secure protection method for local use of the release of a federated learning model based on secure shuffling and differential privacy, which protects the model assets of the model owner and ensures the usability of the federated learning model obtained by users. As Figure 1 shown, it specifically includes the following steps:

[0052] Step 1: The federated model owner uses differential privacy to add noise to the model parameters of the federated learning to generate model parameters with noise. The descriptions of each parameter are shown in Table 1:

[0053] Table 1 Parameter Descriptions

[0054]

[0055]

[0056] Assume that the parameters of the federated learning model Π form an m×n matrix A Π , and use the Gaussian mechanism in differential privacy to add noise to each element in matrix A Π to obtain the parameter matrix A of the noisy federated learning model Π′, and its mathematical formula is as follows: Π

[0057] A′ Π (i,j) = A Π (i,j) + α(1)

[0058] The Gaussian mechanism can provide relaxed (ε,δ)-differential privacy. To ensure that the added Gaussian noise distribution α~N(0,σ 2 ) satisfies (ε,δ)-differential privacy, where α is the noise value added to each data in the matrix, set the noise ratio σ≥cΔs / ∈, where the constant ∈∈(0,1), and the sensitivity Sensitivity represents the maximum difference in the output of the query function s for adjacent data sets.

[0059] Step 2: Encrypt the model parameters using the user authorization key and the secure shuffling algorithm, and send the encrypted federated learning model parameters to the user, as Figure 2 shown.

[0060] 1) Read in the noisy federated learning model parameter matrix A of m×n Π .

[0061] 2) Initialize the logical mapping control parameters s = 4, d = 0.9, f = 0.9, g = 0.1, and initialize the iterative mapping iter = 200. Given the key key = {x, y}, where x and y are the two initial values of the chaotic mapping.

[0062] 3) Using the key key as the initial value, obtain m×n pairs of chaotic sequence values by iterating the chaotic sequence values of m×n + iter, discard iter pairs of values, and store them in one-dimensional arrays P and Q of size m×n respectively, as follows:[[]]

[0063]

[0064] 4) Run the following secure shuffling algorithm operation on the elements in P and Q to obtain two one-dimensional matrices P′ and Q′ of integer values, as shown in Table 2:[[]]

[0065] ​Table 2 Secure Shuffle Algorithm

[0066]

[0067] 5) Sort through P' and Q' to generate two one-dimensional pseudo-random sequence matrices P'' and Q'' of length m×n, with their elements taking on distinct integer values within the range [0, m×n - 1].

[0068] 6) Perform the following transformations on each element P''(k) and Q''(k) in the one-dimensional random sequences P'' and Q'', and map them to two-dimensional scrambling matrices X and Y of size m×n:

[0069]

[0070] where x(i,j) and y(i,j) are the elements of the two-dimensional scrambling matrices X and Y, respectively.

[0071] 7) First, use the scrambling matrix X to scramble matrix A Π to obtain an intermediate result of scrambled temporary model parameters, and then use Y to scramble the positions of the intermediate result of scrambled temporary model parameters to obtain the final encrypted ciphertext of the federated learning model parameters with noise.

[0072] Step 3: When the user uses the federated learning model locally, use the user authorization key and the secure shuffle algorithm to decrypt the encrypted model parameters ciphertext to obtain the federated learning model with noise. As Figure 3 shown, the user takes the data as the input of the federated learning model with noise to obtain the desired output result.

[0073] After receiving the encrypted ciphertext of the federated learning model parameters with noise and the key key = {x, y}, the user needs to perform the inverse operation of the federated learning model owner on the parameter model with noise Π; use this model to process their own data. The specific process is as follows:

[0074] 1) Given the same key key = {x, y} as in the encryption process of the federated learning model owner and the same encryption process, generate the scrambling matrices X and Y from the keys x and y;

[0075] 2) First, use the scrambling matrix Y to scramble the encrypted ciphertext of the federated learning model parameters with noise to obtain an intermediate result of scrambled temporary model parameters, and then use X to scramble the positions of the intermediate result of scrambled temporary model parameters to obtain a usable parameter model with noise.

[0076] Based on the same inventive concept, the present invention also proposes a secure protection system for a federated learning model based on secure shuffling and differential privacy, including a parameter processing module, an encryption module, and a decryption module; the parameter processing module adds noise to the model parameters of the federated learning based on the differential privacy Gaussian mechanism to generate noisy model parameters; the encryption module encrypts the differentially private and noise-added model parameters using the user authorization key and the secure shuffling algorithm, and sends the encrypted federated learning model parameters to the user; the decryption module decrypts the model parameter ciphertext using the user authorization key and the secure shuffling algorithm to obtain the noisy federated learning model.

[0077] Among them, the working process of the parameter processing module is as follows:

[0078] The parameters of the federated learning model Π form an m×n matrix A Π , and the Gaussian mechanism in differential privacy is used to process the noise of each element in the matrix A Π to obtain the parameter matrix A' of the noisy federated learning model Π': Π :

[0079] A' Π (i,j) = A Π (i,j) + α(1)

[0080] Among them, the Gaussian mechanism provides relaxed (ε,δ)-differential privacy, the noise ratio σ ≥ cΔs / ε, and the constant ε ∈ (0,1); the sensitivity The Gaussian noise distribution α ∼ N(0,σ 2 ) satisfies (ε,δ)-differential privacy, α is the noise value added to each data in the matrix, and the sensitivity represents the maximum difference in the output of the query function s for adjacent data sets.

[0081] The working process of the encryption module is as follows:

[0082] (S1) Read in the m×n noisy federated learning model parameter matrix A Π ;

[0083] (S2) Initialize the logical mapping control parameters s, d, f, g, where s is the chaos control parameter, d and f are the logical mapping control parameters, and respectively map x n , y n , g is the coupling term; and initialize the iteration mapping iter = 200, and give the key key = {x, y}, where x and y are the two initial values of the chaos mapping;

[0084] (S3) With the key key as the initial value, iterate the chaotic sequence values through m×n + iter, discard iter pairs of values, obtain m×n pairs of chaotic sequence values, and store them in one-dimensional arrays P and Q of size m×n respectively:

[0085]

[0086] (S4) Run the following Secure Shuffle Algorithm 1 operation on the elements in P and Q to obtain two one-dimensional matrices P' and Q' of integer values;

[0087] (S5) Sort through P' and Q' to generate two one-dimensional pseudo-random sequence matrices P'' and Q'' of length m×n, whose element values are unequal integers within [0, m×n - 1];

[0088] (S6) Perform the following transformation on each element P''(k) and Q''(k) in the one-dimensional random sequences P'' and Q'', and map them to two-dimensional scrambling matrices X and Y of size m×n;

[0089]

[0090] where x(i,j) and y(i,j) are the elements of the two-dimensional scrambling matrices X and Y respectively;

[0091] (S7) First, use the scrambling matrix X to scramble matrix A Π to obtain an intermediate result of the scrambled temporary model parameters; then use Y to perform position scrambling on the intermediate result of the scrambled temporary model parameters to obtain the final scrambled ciphertext of the federated learning model parameters with noise.

[0092] The working process of the decryption module is as follows:

[0093] (H1) Given the same key key = {x, y} as in the encryption process, generate the scrambling matrices X and Y from the keys x and y;

[0094] (H2) First, use the scrambling matrix Y to scramble the scrambled ciphertext of the federated learning model parameters with noise to obtain an intermediate result of the scrambled temporary model parameters, and then use X to perform position scrambling on the intermediate result of the scrambled temporary model parameters to obtain the parameter model with noise.

[0095] Those skilled in the art should understand that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program code.

[0096] This application is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, such that the instructions executed by the processor of the computer or other programmable data processing device generate a means for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or a means for implementing the functions specified in multiple blocks.

[0097] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, such that the instructions stored in the computer-readable memory generate a manufactured article including an instruction means that implements the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or a means for implementing the functions specified in multiple blocks.

[0098] These computer program instructions can also be loaded onto a computer or other programmable data processing device, such that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or a means for implementing the functions specified in multiple blocks.

[0099] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: the specific implementation manners of the present invention can still be modified or equivalently replaced, and any modification or equivalent replacement that does not depart from the spirit and scope of the present invention shall be covered by the protection scope of the claims of the present invention.

Claims

1. A security protection method for a federated learning model based on secure shuffling and differential privacy, characterized in that, It includes the following steps: (1) Add noise to the model parameters of federated learning based on the differential privacy Gaussian mechanism to generate noisy model parameters; (2) Encrypt the differentially private and noise-added model parameters using the user authorization key and the secure shuffle algorithm, and send the encrypted federated learning model parameters to the user; (3) Decrypt the ciphertext of the model parameters using the user authorization key and the secure shuffle algorithm to obtain the noisy federated learning model; (4) Use the user's data as the input of the noisy federated learning model to obtain the desired output result; The step (2) includes the following steps: (21) Read in the noisy federated learning model parameter matrix A of size m×n Π ; (22) Initialize the logical mapping control parameters s, d, f, g, where s is the chaos control parameter, d and f are the logical mapping control parameters, which respectively map the chaos sequence values x n , y n ; g is the coupling term; and initialize the iterative mapping iter = 200, and given the key key = {x, y}, where x and y are the two initial values of the chaos mapping; (23) Using the key key as the initial value, through the iterative mapping m×n+iter for the chaotic sequence values, discard iter pairs of values to obtain m×n pairs of chaotic sequence values x n and y n , and store them respectively in one-dimensional arrays P and Q of size m×n: (24) Run the secure shuffle algorithm on the elements in P and Q, and calculate to obtain two one-dimensional matrices P' and Q' of integer values; (25) Generate two one-dimensional pseudo-random sequence matrices P'' and Q'' of length m×n through sorting by P' and Q', and the values of their elements are unequal integers within [0, m×n - 1]; (26) Perform the following transformations on each element P''(k) and Q''(k) in the one-dimensional random sequences P'' and Q'', and map them to two-dimensional scrambled matrices X and Y of size m×n; where x(i,j) and y(i,j) are the elements of the two-dimensional scrambled matrices X and Y respectively; (27) First, use the scrambling matrix X to scramble matrix A Π to obtain the intermediate result of scrambled temporary model parameters; then use Y to scramble the positions of the intermediate result of scrambled temporary model parameters to obtain the final scrambled ciphertext of the federated learning model parameters with noise.

2. The method for securing a federated learning model based on secure shuffling and differential privacy according to claim 1, wherein The implementation process of the step (1) is as follows: The parameters of the federated learning model Π form an m×n matrix A Π , and the Gaussian mechanism in differential privacy is used to add noise to each element in the matrix A Π to obtain the parameter matrix A' of the noisy federated learning model Π'. Π : A' Π (i,j) = A Π (i,j) + α (1) Among them, the Gaussian mechanism provides relaxed (ε,δ)-differential privacy, and the noise ratio σ ≥ cΔs / ε, where the constant sensitivity The Gaussian noise distribution α ~ N(0,σ 2 ) satisfies (ε,δ)-differential privacy. α is the noise value added to each data in the matrix, D is the dataset, D' represents the neighboring dataset that differs from D by only one record, and the sensitivity represents the maximum difference in the output of the query function s for adjacent datasets.

3. The secure protection method for a federated learning model based on secure shuffling and differential privacy according to claim 1, characterized in that, The implementation process of the step (3) is as follows: (31) Given the same key key = {x, y} as the encryption process of the federated learning model owner, and the same as its encryption process, generate the scrambled matrices X and Y from the keys x and y; (32) First, use the scrambled matrix Y to scramble the ciphertext of the noisy federated learning model parameters to obtain an intermediate result of the scrambled temporary model parameters, and then use X to scramble the position of the intermediate result of the scrambled temporary model parameters to obtain the noisy parameter model.

4. A secure protection system for a federated learning model based on secure shuffle and differential privacy using the method as described in any one of claims 1 to 3, including a parameter processing module, an encryption module, and a decryption module; the parameter processing module adds noise to the model parameters of federated learning based on the differential privacy Gaussian mechanism to generate noisy model parameters; the encryption module encrypts the differentially private and noise-added model parameters using the user authorization key and the secure shuffle algorithm, and sends the encrypted federated learning model parameters to the user; the decryption module decrypts the ciphertext of the model parameters using the user authorization key and the secure shuffle algorithm to obtain the noisy federated learning model.

5. The secure protection system for a federated learning model based on secure shuffling and differential privacy according to claim 4, characterized in that, The working process of the parameter processing module is as follows: The parameters of the federated learning model Π form an m×n matrix A Π , and the Gaussian mechanism in differential privacy is used to add noise to each element in the matrix A Π to obtain the parameter matrix A' of the federated learning model Π' with noise Π : A' Π (i,j) = A Π (i,j) + α (1) Among them, the Gaussian mechanism provides relaxed (ε,δ)-differential privacy, and the noise ratio σ ≥ cΔs / ε, where the constant sensitivity The Gaussian noise distribution α ~ N(0,σ 2 ) satisfies (ε,δ)-differential privacy, α is the noise value added to each data in the matrix, D is the data set, D' represents the neighboring data set that differs from D by only one record, and the sensitivity represents the maximum difference in the output of the query function s for adjacent data sets.

6. The secure protection system for the federated learning model based on secure shuffling and differential privacy according to claim 4, characterized in that, The working process of the encryption module is as follows: (S1) Read in the noisy federated learning model parameter matrix A of size m×n Π ; (S2) Initialize the logical mapping control parameters s, d, f, g, where s is the chaos control parameter, d and f are the logical mapping control parameters, which respectively map x n and y n respectively, and g is the coupling term; and initialize the iterative mapping iter = 200, and given the key key = {x, y}, where x and y are the two initial values of the chaos mapping; (S3) Using the key key as the initial value, iterate through the chaotic sequence values by m×n + iter, discard iter pairs of values, and obtain m×n pairs of chaotic sequence values x n and y n , and store them respectively in one-dimensional arrays P and Q of size m×n: (S4) Run the secure shuffle algorithm on the elements in P and Q, and calculate to obtain two one-dimensional matrices P' and Q' of integer values; (S5) Generate two one-dimensional pseudo-random sequence matrices P'' and Q'' of length m×n through sorting by P' and Q', and the values of their elements are unequal integers within [0, m×n - 1]; (S6) Perform the following transformations on each element P''(k) and Q''(k) in the one-dimensional random sequences P'' and Q'', and map them to two-dimensional scrambled matrices X and Y of size m×n; where x(i,j) and y(i,j) are the elements of the two-dimensional scrambled matrices X and Y respectively; (S7) First, use the scrambling matrix X to scramble matrix A Π to obtain the intermediate result of scrambled temporary model parameters; then use Y to perform position scrambling on the intermediate result of scrambled temporary model parameters to obtain the final scrambled ciphertext of the federated learning model parameters with noise.

7. The secure protection system for a federated learning model based on secure shuffling and differential privacy according to claim 4, characterized in that, The working process of the decryption module is as follows: (H1) Given the same key key = {x, y} as in the encryption process, generate scrambling matrices X and Y from the keys x and y; (H2) First, use the scrambling matrix Y to scramble the encrypted ciphertext of the federated learning model parameters with noise to obtain an intermediate result of the scrambled temporary model parameters, and then use X to perform position scrambling on the intermediate result of the scrambled temporary model parameters to obtain a parameter model with noise.

Citation Information

Patent Citations

  • Self-adaptive image texture region steganography algorithm based on pixel blocks

    CN110166784A

  • Composite privacy protection method and system, computer equipment and storage medium

    CN112966298A