Defense Method Against Privacy Inference Attacks for Federated Learning Based on Parameter Compression
By analyzing the differences in client model parameters in federated learning and performing parameter compression, the global model accuracy reduction caused by privacy reasoning attacks is solved, and the model performance is maintained while protecting client data characteristics.
Patent Information
- Application Number
- CN202111333252.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-11
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2041-11-11
AI Technical Summary
The existing federated learning privacy protection method has the problem of global model accuracy degradation when defending against privacy inference attacks, especially after increasing noise through differential privacy technology, model performance is affected.
By analyzing the differences between the local model parameters of the client before and after training, determining that the parameters with large differences are the target parameters to maintain the state after training, the parameters with small differences are restored to the state before training, and parameter compression is carried out to form compressed model parameters to prevent privacy reasoning attacks.
While ensuring the accuracy of the global model, the possibility of attackers inferring private data information from model parameters is reduced, the local private data characteristics of the client are protected, and effective privacy protection is achieved.
Smart Images

Figure CN114239049B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular, to a defense method against privacy inference attacks for federated learning based on parameter compression. Background Art
[0002] Federated Learning is a machine learning framework that enables private data and shared models. Each participating client (which can be simply referred to as a client) has private data, and multiple clients jointly train a model. In each round of training, each client uploads the model parameters obtained from its local training (which can be called local model parameters), and the global model parameters are obtained through federated averaging by a central server, and then sent to each client for the next round of training.
[0003] With the popularity of federated learning, the attack methods against federated learning are also increasing day by day. Clients use Generative Adversarial Network (GAN) for privacy inference attacks to steal the data of other federated learning clients. Federated learning is based on a background of protecting the privacy of multiple participants, that is, the shared model will not leak local private data. Therefore, the behavior of malicious participants obtaining federated model parameters and using GAN to steal the data of the attacked party needs to be defended.
[0004] Currently, one of the main methods for privacy protection in federated learning is Differential Privacy. Its basic method is to add Gaussian noise or Laplace noise to the dataset, which can effectively prevent the leakage of privacy data. However, in order to effectively protect privacy data, as the noise increases, the accuracy of the global model decreases. Summary of the Invention
[0005] In view of this, this application provides a defense method against privacy inference attacks for federated learning based on parameter compression.
[0006] Specifically, this application is implemented through the following technical solutions:
[0007] According to the first aspect of the embodiments of this application, a defense method against privacy inference attacks for federated learning based on parameter compression is provided, including:
[0008] Based on the differences between the local model parameters of the target client before and after training, determine the target parameters in the local model parameters of the target client; wherein, the differences between the target parameters in the local model parameters of the target client before and after training are greater than the differences between the non-target parameters in the local model parameters of the target client before and after training;
[0009] Determine the compression model parameters of the target client, where the target parameters in the compression model parameters adopt the target parameters in the local model parameters after training of the target client, and the non-target parameters in the compression model parameters adopt the non-target parameters in the local model parameters before training of the target client, so as to defend against privacy inference attacks;
[0010] Determine the global model parameters according to the compression model parameters of the target client.
[0011] According to a second aspect of the embodiments of the present application, there is provided an electronic device, which includes:
[0012] A processor and a machine-readable storage medium, where the machine-readable storage medium stores machine-executable instructions that can be executed by the processor; the processor is used to execute the machine-executable instructions to implement the above method.
[0013] The defense method against privacy inference attacks for federated learning based on parameter compression in the embodiments of the present application, by, when each round of local training is completed, based on the differences in the local model parameters of the client before and after training, determining the parameters with relatively large differences before and after training as the target parameters that need to maintain the post-training state, and the parameters with relatively small differences before and after training as the non-target parameters that need to be restored to the pre-training state. By keeping the target parameters with large differences before and after training in the post-training state, the accuracy of the global model is ensured; by restoring the non-target parameters with relatively small differences before and after training to the pre-training state, part of the parameter information in the complete model parameters is truncated, the sparsification of the local model parameters of the client is realized, and the parameter information leaked to the attacker is reduced, which can effectively defend against the attacker inferring the privacy data information of the attacked party from the model parameters, protect the local private data features of the client, and realize the defense against privacy inference attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 It is a schematic flowchart of a defense method against privacy inference attacks for federated learning based on parameter compression shown in an exemplary embodiment of the present application;
[0015] Figure 2A It is a schematic flowchart of determining the target parameters in the local model parameters of the target client shown in an exemplary embodiment of the present application;
[0016] Figure 2B It is a schematic flowchart of another method for determining the target parameters in the local model parameters of the target client shown in an exemplary embodiment of the present application;
[0017] Figure 3Schematic flowchart of a defense method against privacy inference attacks in federated learning based on parameter compression shown in an exemplary embodiment of the present application;
[0018] Figure 4 Schematic structural diagram of a defense device against privacy inference attacks in federated learning based on parameter compression shown in an exemplary embodiment of the present application;
[0019] Figure 5 Schematic structural diagram of another defense device against privacy inference attacks in federated learning based on parameter compression shown in an exemplary embodiment of the present application;
[0020] Figure 6 Schematic hardware structure diagram of an electronic device shown in an exemplary embodiment of the present application. Detailed implementation manners
[0021] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the present application. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present application as detailed in the appended claims.
[0022] The terms used in the present application are only for the purpose of describing specific embodiments and are not intended to limit the present application. The singular forms "a", "the" and "said" used in the present application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise.
[0023] To enable those skilled in the art to better understand the technical solutions provided in the embodiments of the present application, some terms related to the embodiments of the present application will be briefly described below.
[0024] Federated learning: The federated learning process includes the following steps: (1) Initialization of the local model of the client; (2) Training the local model of the client until the model converges, and uploading the local model parameter values to the central parameter server; (3) The central parameter server aggregates the local model parameters reported by all clients to generate and distribute a new round of initial parameters to all clients.
[0025] GAN Privacy: An attacker downloads the federated model parameters (i.e., global model parameters) from the central parameter server to update the local model parameters of its local model. By creating a new copy of the federated model as the discriminator (D) and running the generator (G) on D, it simulates the samples of the attacked user, mislabels the generated samples to the local model, and thus affects the federated model (i.e., the global model), forcing the attacked user to use more samples for local training to distinguish the fake generated samples.
[0026] Sequence Top k: Given an unordered list L, running the Top k algorithm on it to obtain the sequence of the top k largest list contents of the sequence.
[0027] Non-IID Data (Non-Independent and Identically Distributed Data): In federated learning, the source training data owned by multiple clients exists in a non-independent and identically distributed form. That is, for two clients Mi, M j ∈M, i≠j, there is data with the data label k
[0028] In order to make the above objects, features, and advantages of the embodiments of the present application more obvious and understandable, the technical solutions in the embodiments of the present application will be further described in detail below with reference to the accompanying drawings.
[0029] Please refer to Figure 1 , which is a schematic flowchart of a defense method for privacy inference attacks in federated learning based on parameter compression provided by an embodiment of the present application. As Figure 1 shown, the defense method for privacy inference attacks in federated learning based on parameter compression may include the following steps:
[0030] Step S100: Determine the target parameters in the local model parameters of the target client according to the differences in the local model parameters of the target client before and after training; wherein, the differences in the target parameters in the local model parameters of the target client before and after training are greater than the differences in the non-target parameters in the local model parameters of the target client before and after training.
[0031] In the embodiments of the present application, the target client does not specifically refer to a certain fixed client, but may refer to any client in the federated learning system.
[0032] In the embodiments of the present application, since all the model parameters of the client contain complete information about the private key training data of the client, and the attacker of the privacy inference attack infers the private data information of the attacked party through the model parameters of the attacked party. In order to defend against the privacy inference attack, before determining the global model parameters based on the local model parameters of the client, the local model parameters of the client can be compressed first, the parameters can be sparsified, some parameters are kept in the state after training (that is, the parameters after training are used), and the remaining parameters are restored to the state before training (that is, the parameters before training are used), truncating some parameter information in the complete model parameters, realizing the sparsification of the local model parameters of the client, reducing the parameter information leaked to the attacker, so as to protect the local private data features of each client.
[0033] In addition, considering that the greater the difference between the parameters before and after training, the greater the contribution of the parameter to the optimization of the model performance. Therefore, in order to maintain the accuracy of the global model while defending against the privacy inference attack, when compressing the local model parameters, the parameters with relatively large differences before and after training can be preferentially kept in the state after training, and for the parameters with relatively small differences before and after training, they can be restored to the state before training.
[0034] Correspondingly, for any round of model training, based on the local model parameters of the target client before training and the local model parameters after training, the difference between the local model parameters of the target client before and after training can be determined, and based on the difference between the local model parameters of the target client before and after training, the parameters that need to be kept in the state after training in the local model parameters of the target client (referred to as target parameters in this article) can be determined.
[0035] Exemplarily, among the local model parameters of the target client, the difference between the target parameters before and after training is greater than the difference between the non-target parameters (that is, the remaining parameters other than the target parameters in the local model parameters) before and after training.
[0036] It should be noted that in the embodiments of the present application, unless otherwise specified, the before and after training mentioned refer to one round of training. That is, for any round of training, the local model parameters of the client before training refer to the parameters of the local model at the start of training, and the local model parameters after training refer to the parameters of the local model after this round of training converges to the local model.
[0037] Step S110, determine the compressed model parameters of the target client. The target parameters in the compressed model parameters adopt the target parameters in the local model parameters of the target client after training, and the non-target parameters in the compressed model parameters adopt the non-target parameters in the local model parameters of the target client before training, so as to defend against the privacy inference attack.
[0038] In the embodiments of the present application, when the target parameter in the local model parameters of the target client is determined, for the target parameter in the local model parameters, it can be maintained in the trained state, that is, the parameter value in the trained local model parameters is used; for the non-target parameter in the local model parameters, it can be restored to the state before training, that is, the parameter value in the local model parameters before training is used, so as to maintain the accuracy of the global model while realizing the defense against privacy inference attacks.
[0039] Step S120: Determine the global model parameters according to the compressed model parameters of the target client.
[0040] In the embodiments of the present application, for any client, the compressed model parameters can be determined in the above manner, and when the compressed model parameters of each client are determined, the global model parameters can be determined according to the compressed model parameters of each client.
[0041] It can be seen that in Figure 1 the shown method flow, after each round of local training is completed, according to the difference between the local model parameters of the client before and after training, the parameter with a relatively large difference before and after training is determined as the target parameter that needs to be maintained in the trained state, and the parameter with a relatively small difference before and after training is determined as the non-target parameter that needs to be restored to the state before training. By keeping the target parameter with a large difference before and after training in the trained state, the accuracy of the global model is ensured; by restoring the non-target parameter with a relatively small difference before and after training to the state before training, part of the parameter information in the complete model parameters is truncated, the sparsification of the local model parameters of the client is realized, the parameter information leaked to the attacker is reduced, the attacker can be effectively defended from inferring the privacy data information of the attacked person from the model parameters, the local private data features of the client are protected, and the defense against privacy inference attacks is realized.
[0042] In some embodiments, the above defense method for privacy inference attacks in federated learning based on parameter compression can be applied to a central parameter server.
[0043] As Figure 2A shown, in step S100, to determine the target parameter in the local model parameters of the target client according to the difference between the local model parameters of the target client before and after training, it can be realized through the following steps:
[0044] Step S101a: Send the global model parameters to each client;
[0045] Step S102a: Receive the local model parameters reported by the target client;
[0046] Step S103a: Use the global model parameters as the local model parameters before training for the target client, and use the local model parameters reported by the target client as the local model parameters after training for the target client to determine the difference in the local model parameters of the target client before and after training;
[0047] Step S104a: Determine the target parameters in the local model parameters of the target client based on the difference in the local model parameters of the target client before and after training.
[0048] Exemplarily, take the defense method against privacy inference attacks in federated learning based on parameter compression applied to a central parameter server as an example.
[0049] The central parameter server can determine the global model parameters based on the local model parameters reported by each client and send the determined global model parameters to each client.
[0050] When the target client receives the global model parameters sent by the central parameter server, it can use the received global model parameters as the local model parameters before training, perform a new round of training on the local model until the local model converges, obtain the local model parameters after training, and report the local model parameters after training to the central parameter server.
[0051] In the case where the central parameter server receives the local model parameters (local model parameters after training) reported by the target client, it can use the global model parameters sent to each client (the global model parameters sent to each client in this round of training) as the local model parameters before training for the target client, use the received local model parameters reported by the target client as the local model parameters after training, determine the difference in the local model parameters of the target client before and after training, and determine the target parameters in the local model parameters of the target client based on the difference in the local model parameters of the target client before and after training.
[0052] Exemplarily, the central parameter server can compress the local model parameters reported by the target client based on the determined target parameters in the local model parameters of the target client to obtain compressed model parameters.
[0053] Exemplarily, when the central server determines the compressed model parameters of each client, it can determine the latest global model parameters based on the compressed model parameters of each client.
[0054] For example, the average value of the compressed model parameters of each client can be determined as the latest global model parameters.
[0055] It can be seen that by implementing the compression of the local model parameters of the client on the central parameter server side, the performance requirements for the client are reduced.
[0056] In some embodiments, the above defense method for privacy inference attacks in federated learning based on parameter compression can be applied to the client.
[0057] As Figure 2B shown, in step S100, according to the difference in the local model parameters of the target client before and after training, determining the target parameters in the local model parameters of the target client can be achieved through the following steps:
[0058] Step S101b: Receive the global model parameters sent by the central parameter server;
[0059] Step S102b: Use the global model parameters as the local model parameters before training, train the local model, and obtain the local model parameters after training;
[0060] Step S103b: According to the difference in the local model parameters before and after training, determine the target parameters in the local model parameters.
[0061] Exemplarily, taking the above defense method for privacy inference attacks in federated learning based on parameter compression that can be applied to the client as an example.
[0062] Exemplarily, the central parameter server can determine the global model parameters according to the local model parameters reported by each client, and send the determined global model parameters to each client.
[0063] When the target client receives the global model parameters sent by the central parameter server, it can use the received global model parameters as the local model parameters before training, train the local model for a new round until the local model converges, and obtain the local model parameters after training.
[0064] The target client can determine the difference in the local model parameters before and after training according to the local model parameters before training and the local model parameters after training, and determine the target parameters in the local model parameters according to the difference in the local model parameters before and after training.
[0065] It can be seen that by compressing the local model parameters of each client, the processing load of the central parameter server is reduced.
[0066] In one example, in step S130, according to the compressed model parameters of the target client, determining the global model parameters may include:
[0067] Report the compressed model parameters to the central parameter server, so that the central parameter server determines the latest global model parameters according to the compressed model parameters reported by each received client.
[0068] Exemplarily, when the target client determines the target parameters in the local model parameters, it can compress the trained local model parameters to obtain compressed model parameters and report the compressed model parameters to the central parameter server.
[0069] When the central parameter server receives the compressed model parameters reported by each client, it can determine the latest global model parameters based on the compressed model parameters of each client received.
[0070] In some embodiments, in step S100, determining the target parameters in the local model parameters of the target client according to the difference between the local model parameters of the target client before and after training may include:
[0071] Determine the difference between each parameter in the local model parameters of the target client before and after training;
[0072] According to the absolute value of the difference between each parameter before and after training, determine the top K parameters with the largest absolute value of the difference before and after training as the target parameters, where K is a positive integer.
[0073] Exemplarily, to simplify the processing operation of determining the target parameters, the difference between each parameter in the local model parameters of the target client can be determined respectively, and according to the absolute value of the difference between each parameter before and after training, determine the top K parameters with the largest absolute value of the difference before and after training as the target parameters.
[0074] For example, the top K algorithm can be used to determine the top K parameters with the largest absolute value of the difference from the absolute value of the difference between each parameter before and after training.
[0075] In some embodiments, in step S100, determining the target parameters in the local model parameters of the target client according to the difference between the local model parameters of the target client before and after training may include:
[0076] For any layer of model parameters of the local model of the target client, determine the difference between each parameter in this layer of model parameters before and after training;
[0077] According to the absolute value of the difference between each parameter in this layer of model parameters before and after training, determine the top K parameters with the largest absolute value of the difference before and after training as the target parameters, where K is a positive integer.
[0078] Exemplarily, to refine the granularity of determining the target parameters and optimize the training performance of the compressed model parameters, when determining the target parameters, it can be determined respectively for each layer of model parameters of the local model.
[0079] Exemplarily, for any layer of model parameters of the local model of the target client, the difference between each parameter in this layer of model parameters before and after training can be determined, and based on the absolute value of the difference between each parameter in this layer of model parameters before and after training, the top K parameters with the largest absolute value of the difference before and after training are determined as target parameters.
[0080] In some embodiments, in step S100, determining the target parameters in the local model parameters of the target client according to the difference between the local model parameters of the target client before and after training may include:
[0081] For any model parameter component of any layer of model parameters of the local model of the target client, determine the difference between each parameter in this model parameter component before and after training;
[0082] Based on the absolute value of the difference between each parameter in this model parameter component before and after training, the top K parameters with the largest absolute value of the difference before and after training are determined as target parameters, where K is a positive integer.
[0083] Exemplarily, in order to refine the granularity of target parameter determination and optimize the training performance of compressed model parameters, when determining target parameters, it can be determined respectively for each model parameter component of each layer of model parameters of the local model.
[0084] Exemplarily, any layer of model parameters of the local model can be a two-dimensional matrix, and the model parameter component can be a row or a column of this two-dimensional matrix.
[0085] Exemplarily, for any model parameter component of any layer of model parameters of the local model of the target client, the difference between each parameter in this model parameter component before and after training can be determined, and based on the absolute value of the difference between each parameter in this model parameter component before and after training, the top K parameters with the largest absolute value of the difference before and after training are determined as target parameters.
[0086] Exemplarily, in the above embodiments, K can be determined according to the preset compression rate and the number of parameters participating in the sorting.
[0087] For example, taking all the parameters in the local model parameters participating in the sorting as an example, assuming that the total number of parameters in the local model parameters is N1 and the preset compression rate is R1, then K can be N1*(1 - R1).
[0088] Among them, if N1*(1 - R1) is not an integer, an integer K can be obtained by methods such as rounding up, rounding down, or rounding.
[0089] For another example, taking the parameters in the model parameter component participating in the sorting as an example, assuming that the number of parameters in the model parameter component is N2 and the preset compression rate is R2, then K can be N2*(1 - R2).
[0090] Wherein, if N2*(1 - R2) is not an integer, the integer K can be obtained by methods such as rounding up, rounding down, or rounding to the nearest integer.
[0091] It should be noted that in the embodiments of the present application, in the embodiments of determining the target parameters for the overall local model parameters, for each single-layer model parameter, or for each individual model parameter component respectively, K can be different; in the embodiments of determining the target parameters for the single-layer model parameters, K of the target parameters in the model parameters of different layers can also be different; in the embodiments of determining the target parameters for the individual model parameter components, K of the target parameters in different model parameter components can also be different.
[0092] In addition, the method for determining the target parameters in the local model parameters is not limited to the methods described in the above embodiments, and the target parameters in the local model parameters can also be determined by other methods. For example, according to the absolute value of the difference between each model in the local model parameters before and after training, the parameters whose absolute value of the difference exceeds a preset threshold are determined as the target parameters; or, according to the absolute value of the difference between each parameter in the model parameter components before and after training, the parameters whose absolute value of the difference exceeds a preset threshold are determined as the target parameters; wherein, the values of the preset thresholds for determining the target parameters in different model parameter components can be different.
[0093] In some embodiments, the above defense method for privacy inference attacks in federated learning based on parameter compression can be applied to the central parameter server.
[0094] Before determining the target parameters in the local model parameters of the target client according to the difference between the local model parameters of the target client before and after training in step S100, it can further include:
[0095] Pre-train the global model to obtain the pre-trained global model parameters;
[0096] Send the pre-trained global model parameters to each client as the initial local model parameters of each client.
[0097] Exemplarily, since in one round of training, the central parameter server needs to determine the target parameters in the local model parameters based on the global model parameters sent to the client and the local model parameters (the local model parameters after training) reported by the client, so as to realize model parameter compression. Therefore, before the start of the first round of training, the central parameter server can first pre-train the global model to obtain the pre-trained global model parameters, and send the pre-trained global model parameters to each client as the initial local model parameters of each client.
[0098] When the client completes the local model training based on the initial local model parameters, it can report the trained local model parameters to the central parameter server, and the central parameter server compresses the model parameters based on the local model parameters before and after training.
[0099] To enable those skilled in the art to better understand the technical solutions provided in the embodiments of the present application, the technical solutions provided in the embodiments of the present application will be described below with reference to specific examples.
[0100] The embodiments of the present application provide a defense method against privacy inference attacks for federated learning based on parameter compression. The main method process may include:
[0101] For each round of training, the central parameter server obtains the local model parameters of the client; for any client (such as the above-mentioned target client), the floating situation of the local model parameters of the client before and after training is statistically analyzed, and the part of the parameters with the largest floating change is taken as the parameters to be updated by the client in this round of training (i.e., the above-mentioned target parameters), and participates in the federated average of the central server to determine the global model parameters.
[0102] By selectively updating the parameters according to the changes in the parameters before and after training, the private data features of the client are effectively hidden, and the risk of data leakage is reduced; at the same time, the accuracy of the model for various data sets is greatly guaranteed, and the robustness of the entire federated learning system is more effectively improved.
[0103] In this embodiment, the federated learning system may include Module A to Module D; among them:
[0104] Module A is used to process the original data set, initialize the entire federated learning system and allocate non-independent and identically distributed data.
[0105] Module B is used to implement privacy stealing attacks on the process of federated learning using a generative adversarial network.
[0106] Module C is used to obtain the specific parameter information of each layer of the neural network model of federated learning.
[0107] Model D is used to screen out the part of the parameters with the relatively largest floating, determine this part of the parameters as the parameters to be updated, perform model parameter compression, and determine the latest global model parameters based on the compressed model parameters.
[0108] The following combines Figure 3 The functions of each module will be described in detail.
[0109] Module A: Process the original data set, initialize the entire federated learning system and allocate non-independent and identically distributed data.
[0110] Exemplarily, the MNIST (Mixed National Institute of Standards and Technology database) handwritten digit dataset can be used, which includes a training set of 60,000 instances and a test set of 10,000 instances.
[0111] Exemplarily, 10 clients for federated learning can be created. The clients use the same model, which is a two-layer convolutional neural network. The clients are numbered in sequence, and at the same time, the data with labels corresponding to the client numbers in the dataset are assigned to the corresponding clients.
[0112] For example, the amount of data and label distribution owned by each client can be as shown in Table 1:
[0113] Table 1
[0114]
[0115] Exemplarily, the warmup strategy can be used to pre-train the global model.
[0116] For example, the global model can be pre-trained for 25 rounds to obtain the initial global model parameters, which are used as the initial local model parameters for all clients.
[0117] It should be noted that the data used for pre-training the global model is full-category data, that is, it includes the categories of data of each client.
[0118] Among them, the categories of data of different clients are different.
[0119] Exemplarily, the data that the same client can have can include data of one or more categories.
[0120] Module B: Use a generative adversarial network to implement a privacy stealing attack on the process of federated learning.
[0121] Exemplarily, assume that attacker A is the client numbered 1, and it has data with label 0. A intends to steal the data with label 3 of the victim V, and the client number of the victim V is 4.
[0122] When the test accuracies of the federated model (i.e., the global model) and the local model (i.e., the local model) are both greater than the threshold and the federated learning system is trained for at least one round, that is, when the local models of all clients converge, the privacy inference attack is launched.
[0123] Exemplarily, this threshold can be set to 85%.
[0124] An attacker can build a GAN model locally. By labeling the data generated by the GAN model with incorrect labels, "poisonous data" can be obtained. The attacker uses the poisonous data for local model training to make the victim V provide more data features. Then, the attacker uses the richer data features provided by V to generate more accurate photos using the GAN, and repeats this process to obtain the target category information of the private data of the victim V.
[0125] Module C: Obtain the specific parameter information of each layer of the neural network model for federated learning.
[0126] Exemplarily, before each federated learning participant uploads the local model parameters after client training to the central parameter server, Keras (an open-source artificial neural network library) can be used to obtain the parameters of all layers of the local model and store the parameters of each layer in a list.
[0127] Exemplarily, the parameters can be saved in the format of ndarray (a multi-dimensional array for storing elements of the same type).
[0128] Module D: Screen out the part of the parameters with the largest relative floating, determine this part of the parameters as the parameters to be updated, perform model parameter compression, and determine the latest global model parameters based on the compressed model parameters.
[0129] Exemplarily, calculate the difference between the local model parameters obtained from the client training in this round (i.e., the local model parameters after training) and the local model parameters at the beginning of this round (i.e., the local model parameters before training), and store the difference e in absolute value format. Use the top k algorithm to obtain the sorted list of the top sequences in e.
[0130] For example, assuming the preset compression rate is 99.9%, the top 0.1% (i.e., 1 - 99.9%) of the differences in the difference e sequence can be taken, and the corresponding parameters are determined as the target parameters.
[0131] Exemplarily, for any layer model in the local model, the number of parameters participating in training can be determined by using a deep learning framework to obtain the parameter dimension information and based on the parameter dimension information.
[0132] For any client, the target parameters in the local model parameters remain in the state after training, and the non-target parameters are restored to the state before training.
[0133] Exemplarily, module D can implement model parameter compression through the following process:
[0134] 4.1. For the j-th parameter component w[j] of w, calculate its difference e from w[j] in the previous round;
[0135] Exemplarily, w is the model parameter of any layer of the local model, which can be a two-dimensional matrix, and w[j] can be the j-th row or the j-th column in this two-dimensional matrix.
[0136] 4.2. Determine the k parameters with the largest absolute value of e in w[j] as the target parameters.
[0137] 4.3. Keep the k parameters (i.e., the target parameters) in w[j] in the state after training, and restore the remaining parameters (i.e., the non-target parameters) in w[j] to the state before training.
[0138] 4.4. After all parameter components are compressed, the compressed local model parameters of the client are obtained (i.e., the compressed model parameters, which can be denoted as w compressed ).
[0139] It can be seen that in this embodiment, with a small amount of computation, an effective defense against privacy inference attacks for GANs in federated learning is achieved, while ensuring that the accuracy of the federated model is not affected to the greatest extent.
[0140] The method provided in this application has been described above. Next, the device provided in this application will be described:
[0141] Please refer to Figure 4 , which is a schematic structural diagram of a defense device for privacy inference attacks in federated learning based on parameter compression provided in an embodiment of this application. As Figure 4 shown, the defense device for privacy inference attacks in federated learning based on parameter compression may include:
[0142] The first determination unit 410 is configured to determine the target parameters in the local model parameters of the target client according to the difference between the local model parameters of the target client before and after training; wherein, the difference between the target parameters in the local model parameters of the target client before and after training is greater than the difference between the non-target parameters in the local model parameters of the target client before and after training;
[0143] The second determination unit 420 is configured to determine the compressed model parameters of the target client. The target parameters in the compressed model parameters adopt the target parameters in the local model parameters of the target client after training, and the non-target parameters in the compressed model parameters adopt the non-target parameters in the local model parameters of the target client before training, so as to defend against privacy inference attacks;
[0144] The third determination unit 430 determines the global model parameters according to the compressed model parameters of the target client.
[0145] In some embodiments, when the device is deployed on the central parameter server,
[0146] The first determination unit 410 determines the target parameters in the local model parameters of the target client according to the differences in the local model parameters of the target client before and after training, including:
[0147] Send the global model parameters to each client;
[0148] Receive the local model parameters reported by the target client;
[0149] Use the global model parameters as the local model parameters of the target client before training, and use the received local model parameters reported by the target client as the local model parameters of the target client after training to determine the differences in the local model parameters of the target client before and after training;
[0150] Determine the target parameters in the local model parameters of the target client according to the differences in the local model parameters of the target client before and after training.
[0151] In some embodiments, when the device is deployed on the client side,
[0152] The first determination unit 410 determines the target parameters in the local model parameters of the target client according to the differences in the local model parameters of the target client before and after training, including:
[0153] Receive the global model parameters sent by the central parameter server;
[0154] Use the global model parameters as the local model parameters before training to train the local model to obtain the local model parameters after training;
[0155] Determine the target parameters in the local model parameters according to the differences in the local model parameters before and after training.
[0156] In some embodiments, the third determination unit 430 determines the global model parameters according to the compressed model parameters of the target client, including:
[0157] Report the compressed model parameters to the central parameter server so that the central parameter server determines the latest global model parameters according to the received compressed model parameters reported by each client.
[0158] In some embodiments, the first determination unit 410 determines the target parameters in the local model parameters of the target client according to the differences in the local model parameters of the target client before and after training, including:
[0159] Determine the difference of each parameter in the local model parameters of the target client before and after training;
[0160] Based on the absolute value of the difference between each parameter before and after training, the top K parameters with the largest absolute value of the difference before and after training are determined as target parameters, where K is a positive integer.
[0161] In some embodiments, the first determination unit 410 determines target parameters in the local model parameters of the target client based on the differences in the local model parameters of the target client before and after training, including:
[0162] For any layer of model parameters of the local model of the target client, determine the differences between the parameters in this layer of model parameters before and after training;
[0163] Based on the absolute value of the differences between the parameters in this layer of model parameters before and after training, the top K parameters with the largest absolute value of the difference before and after training are determined as target parameters, where K is a positive integer.
[0164] In some embodiments, the first determination unit 410 determines target parameters in the local model parameters of the target client based on the differences in the local model parameters of the target client before and after training, including:
[0165] For any model parameter component of any layer of model parameters of the local model of the target client, determine the differences between the parameters in this model parameter component before and after training;
[0166] Based on the absolute value of the differences between the parameters in this model parameter component before and after training, the top K parameters with the largest absolute value of the difference before and after training are determined as target parameters, where K is a positive integer.
[0167] In some embodiments, K is determined based on a preset compression rate and the number of parameters participating in the sorting.
[0168] In some embodiments, when the device is deployed on a central parameter server,
[0169] As Figure 5 shown, the device further includes:
[0170] A pre-training unit 440, configured to pre-train the global model to obtain pre-trained global model parameters; and send the pre-trained global model parameters to each client as the initial local model parameters of each client.
[0171] Correspondingly, the present application also provides Figure 4 or Figure 5 shown in the hardware structure of the device. Refer to Figure 6 , the hardware structure may include: a processor and a machine-readable storage medium, where the machine-readable storage medium stores machine-executable instructions that can be executed by the processor; the processor is configured to execute the machine-executable instructions to implement the method disclosed in the above examples of the present application.
[0172] Based on the same application concept as the above method, an embodiment of the present application further provides a machine-readable storage medium, on which a number of machine-executable instructions are stored. When the machine-executable instructions are executed by a processor, the method disclosed in the above examples of the present application can be implemented.
[0173] Exemplarily, the above machine-readable storage medium can be any electronic, magnetic, optical or other physical storage device that can contain or store information, such as executable instructions, data, and so on. For example, the machine-readable storage medium can be: RAM (Random Access Memory), volatile memory, non-volatile memory, flash memory, storage drives (such as hard disk drives), solid state drives, any type of storage disk (such as optical discs, DVDs, etc.), or similar storage media, or a combination thereof.
[0174] It should be noted that, in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the existence of additional identical elements in the process, method, article or device comprising the element.
[0175] The above are only the preferred embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application shall be included within the scope of protection of the present application.
Claims
1. A defense method against privacy inference attacks for federated learning based on parameter compression, characterized in that Including: Determine the target parameters in the local model parameters of the target client according to the differences in the local model parameters of the target client before and after training; wherein, the differences in the target parameters in the local model parameters of the target client before and after training are greater than the differences in the non-target parameters in the local model parameters of the target client before and after training; the local model parameters of the target client before training refer to the global model parameters sent by the central parameter server to the target client in this round of training, and the local model parameters of the target client after training refer to the local model parameters obtained by the target client after training the global model parameters. Determine the compressed model parameters of the target client, where the target parameters in the compressed model parameters adopt the target parameters in the local model parameters of the target client after training, and the non-target parameters in the compressed model parameters adopt the non-target parameters in the local model parameters of the target client before training, so as to defend against privacy inference attacks. Determine the latest global model parameters according to the compressed model parameters of the target client.
2. The method according to claim 1, wherein When the method is applied to the central parameter server, The determining the target parameters in the local model parameters of the target client according to the differences in the local model parameters of the target client before and after training includes: Send the global model parameters to each client. Receive the local model parameters reported by the target client. Taking the global model parameters as the local model parameters of the target client before training, and taking the received local model parameters reported by the target client as the local model parameters of the target client after training, determine the differences in the local model parameters of the target client before and after training. Determine the target parameters in the local model parameters of the target client according to the differences in the local model parameters of the target client before and after training.
3. The method according to claim 1, wherein When the method is applied to the client, The determining the target parameters in the local model parameters of the target client according to the differences in the local model parameters of the target client before and after training includes: Receive the global model parameters sent by the central parameter server. Taking the global model parameters as the local model parameters before training, train the local model to obtain the local model parameters after training. Determine the target parameters in the local model parameters according to the differences in the local model parameters before and after training.
4. The method according to claim 3, characterized in that, The determining the latest global model parameters according to the compressed model parameters of the target client includes: Report the compressed model parameters to the central parameter server, so that the central parameter server determines the latest global model parameters according to the compressed model parameters reported by each received client.
5. The method according to claim 1, characterized in that The determining the target parameters in the local model parameters of the target client according to the differences in the local model parameters of the target client before and after training includes: Determine the differences between each parameter in the local model parameters of the target client before and after training. According to the absolute values of the differences between each parameter before and after training, determine the top K parameters with the largest absolute values of the differences before and after training as the target parameters, where K is a positive integer.
6. The method according to claim 1, characterized in that Determining the target parameter in the local model parameters of the target client according to the differences in the local model parameters of the target client before and after training includes: For any layer of model parameters of the local model of the target client, determining the difference between each parameter in this layer of model parameters before and after training; According to the absolute value of the difference between each parameter in this layer of model parameters before and after training, determining the top K parameters with the largest absolute value of the difference before and after training as the target parameters, where K is a positive integer.
7. The method according to claim 1, characterized in that, Determining the target parameter in the local model parameters of the target client according to the differences in the local model parameters of the target client before and after training includes: For any model parameter component of any layer of model parameters of the local model of the target client, determining the difference between each parameter in this model parameter component before and after training; According to the absolute value of the difference between each parameter in this model parameter component before and after training, determining the top K parameters with the largest absolute value of the difference before and after training as the target parameters, where K is a positive integer.
8. The method according to any one of claims 5-7, characterized in that, K is determined according to a preset compression ratio and the number of parameters participating in the sorting.
9. The method according to claim 1, wherein When the method is applied to the central parameter server, Before determining the target parameter in the local model parameters of the target client according to the differences in the local model parameters of the target client before and after training, it further includes: Pre-training the global model to obtain the global model parameters after pre-training; Sending the global model parameters after pre-training to each client as the initial local model parameters of each client.
Citation Information
Patent Citations
Model parameter updating method and device for federated learning
CN110262819A
Model training method, equipment and computer readable storage medium
CN111784001A