Security Defense Method and Application of Distributed Federated Learning Based on Edge-Cloud Architecture
The edge-cloud architecture in federated learning systems uses cosine similarity checks and digital signatures to filter and aggregate models, addressing the issue of malicious model uploads, ensuring model integrity and accuracy while protecting user privacy.
Patent Information
- Application Number
- CN202210199495.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-01
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2042-03-01
AI Technical Summary
In a distributed federated learning system based on end-edge cloud architecture, there is a problem that malicious terminal devices destroy the accuracy of the global model by uploading malicious models. The existing defense solutions are not suitable for distributed environments and have high computing overhead.
The local model is filtered through the edge server, the malicious model is identified and deleted with cosine similarity, the edge aggregation model is signed and uploaded, and the cloud server verifies the signature to ensure the security of the model.
Effectively identify and eliminate malicious models, protect the accuracy of the global model, reduce computing resource usage, and is suitable for resource-constrained federated learning environments.
Smart Images

Figure CN114448601B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security, and in particular to a security defense method and application of distributed federated learning based on an edge-cloud architecture. Background Art
[0002] The proliferation of smartphones, IoT, and other devices has led to the advent of the big data era. Deep learning provides an effective means for processing large amounts of data, such as managing large amounts of patient data for disease prediction, conducting independent security audits from system logs, etc. However, centralized deep learning often leads to the leakage of user data and a series of privacy issues. Federated learning (FL) has been proposed to solve the dilemma of centralized deep learning. FL allows users to participate in global training without sharing private sample data to protect the privacy of user data. Specifically, each user trains a global model using a private dataset and only uploads the updated parameters (i.e., weights and biases) to a central cloud server for aggregation, and repeats the above process until the model converges. However, as the number of users participating in training increases, the use of deep learning models becomes more and more complex, and the parameters uploaded by users become larger and larger, which inevitably leads to bandwidth contention and communication delays. The asymmetry between the uplink speed and the downlink speed of the network exacerbates this problem. Generally speaking, the uplink speed of the network is much lower than the downlink speed. Some communication compression methods, such as sketch update, reduce communication pressure by compressing uploaded gradients, but this will lead to the loss of gradient information and reduce the accuracy of the model.
[0003] At present, it has become a new trend to combine FL and mobile edge computing to alleviate communication pressure. Specifically, edge servers are deployed for terminal devices with close geographical locations to provide outsourced computing and cache resources to reduce the computing pressure of terminal devices and high concurrent access to cloud servers. However, the mobile edge computing architecture is usually an open wireless channel environment, and there may be a small number of malicious terminal devices or external eavesdroppers who maliciously poison training samples or model parameters to destroy the accuracy of the model. Currently, most of the existing poisoning attack defense solutions are designed for centralized machine learning architectures. These solutions basically clean up sample data before training, which has high computational overhead and requires the server to have the training data of the participants, which is contrary to the protection of user data privacy by federated learning. Therefore, the above research results are not applicable to distributed federated learning environments. How to design a solution with low overhead but can accurately identify malicious models is a key problem that needs to be solved urgently.
[0004] The information disclosed in this background technology section is only intended to enhance the understanding of the overall background of the invention and should not be regarded as an acknowledgment or any form of suggestion that the information constitutes the prior art already known to a person skilled in the art. Summary of the invention
[0005] The object of the present invention is to provide a security defense method and application for distributed federated learning based on an edge-cloud architecture, so as to solve the problem that in a distributed federated learning system based on an edge-cloud architecture, due to the distributed and local training characteristics of federated learning, it is difficult to ensure that all participants are secure and trustworthy, and there are a small number of data holders being maliciously controlled, and the accuracy of the global model is damaged by uploading malicious models.
[0006] To achieve the above object, an embodiment of the present invention provides a security defense method for distributed federated learning based on an edge-cloud architecture.
[0007] In one or more embodiments of the present invention, the method includes: an edge server receives an updated local model uploaded by an edge device, where the updated local model is obtained by the edge device training the global model sent by a cloud server based on private data; the edge server filters the updated local model to obtain a secure local model; and the edge server aggregates the filtered secure local models and uploads the generated edge aggregation model to the cloud server.
[0008] In one or more embodiments of the present invention, the edge server filters the updated local model to obtain a secure local model, including: the edge server performs preliminary aggregation on all local models to generate an aggregation model; calculates the cosine similarity between the local model and the aggregation model; and deletes the model parameters corresponding to the cosine similarity whose difference from the maximum cosine similarity is greater than an adaptive threshold according to the distribution of the cosine similarity.
[0009] In one or more embodiments of the present invention, calculating the cosine similarity between the local model and the aggregation model includes: converting the weight and bias matrices corresponding to the convolutional layer and the fully connected layer of the neural network model into one-dimensional vectors, and concatenating them to form a one-dimensional vector containing all parameters; and calculating the cosine similarity according to the one-dimensional vectors corresponding to the parameters of the local model and the aggregation model.
[0010] In one or more embodiments of the present invention, the method further includes: taking the parameters of the edge aggregation model as a message, signing it according to the schnorr signature algorithm, and uploading the signature and the message to the cloud server.
[0011] To achieve the above object, an embodiment of the present invention provides another security defense method for distributed federated learning based on an edge-cloud architecture.
[0012] In one or more embodiments of the present invention, the method includes: the cloud server initializes a global model and distributes the global model to the edge server; and the cloud server verifies the digital signature of the edge aggregation model uploaded by the edge server and globally aggregates the edge aggregation model to obtain an updated global model.
[0013] In one or more embodiments of the present invention, the cloud server verifies the digital signature of the edge aggregation model uploaded by the edge server and globally aggregates the edge aggregation model to obtain an updated global model, including: verifying whether the digital signature matches the message uploaded by the edge server; if not, deleting the edge aggregation model with failed verification; if so, globally aggregating the edge aggregation model with successful verification to obtain an updated global model.
[0014] In another aspect of the present invention, a security defense device for distributed federated learning based on an edge-cloud-end architecture is provided, which includes a receiving module, a filtering module, and an aggregation module.
[0015] The receiving module is used for the edge server to receive the updated local model uploaded by the end device, where the updated local model is obtained by the end device training the global model distributed by the cloud server based on private data.
[0016] The filtering module is used for the edge server to filter the updated local model to obtain a secure local model.
[0017] The aggregation module is used for the edge server to aggregate the filtered secure local models and upload the generated edge aggregation model to the cloud server.
[0018] In one or more embodiments of the present invention, the filtering module is further used for: the edge server performs preliminary aggregation on all local models to generate an aggregation model; calculates the cosine similarity between the local model and the aggregation model; and deletes the model parameters corresponding to the cosine similarity whose difference from the maximum cosine similarity is greater than the adaptive threshold according to the distribution of the cosine similarity.
[0019] In one or more embodiments of the present invention, the filtering module is further used for: converting the weights and bias matrices corresponding to the convolutional layer and the fully connected layer of the neural network model into one-dimensional vectors, and concatenating them to form a one-dimensional vector containing all parameters; and calculating the cosine similarity according to the one-dimensional vectors corresponding to the parameters of the local model and the aggregation model.
[0020] In one or more embodiments of the present invention, the aggregation module is further configured to: use the parameters of the edge aggregation model as a message, sign it according to the Schnorr signature algorithm, and send the signature and the message to the cloud server.
[0021] In another aspect of the present invention, there is provided another security defense device for distributed federated learning based on an edge-cloud architecture, which includes an initialization module and a verification module.
[0022] The initialization module is used for the cloud server to initialize the global model and send the global model to the edge server.
[0023] The verification module is used for the cloud server to verify the digital signature of the edge aggregation model uploaded by the edge server, and globally aggregate the edge aggregation model to obtain an updated global model.
[0024] In one or more embodiments of the present invention, the verification module is further configured to: verify whether the digital signature matches the message uploaded by the edge server; if not, delete the edge aggregation model with verification failure; if so, globally aggregate the edge aggregation model with verification success to obtain an updated global model.
[0025] In another aspect of the present invention, there is provided an electronic device, including: at least one processor; and a memory, where the memory stores instructions, and when the instructions are executed by the at least one processor, the at least one processor executes the security defense method for distributed federated learning based on the edge-cloud architecture as described above.
[0026] In another aspect of the present invention, there is provided a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the security defense method for distributed federated learning based on the edge-cloud architecture as described are implemented.
[0027] Compared with the prior art, the security defense method and application for distributed federated learning based on the edge-cloud architecture according to the embodiments of the present invention can exclude malicious models through a model filtering algorithm, aggregate them into a secure model, and continuously defend against indirect poisoning attacks (such as label flipping attacks on the dataset) on the global model online.
[0028] The security defense method and application for distributed federated learning based on the edge-cloud architecture according to the embodiments of the present invention can also verify the aggregated model through digital signature to continuously defend against a small part of direct attacks (such as model tampering after channel eavesdropping) on the global model online.
[0029] The security defense method and application of distributed federated learning based on the edge-cloud architecture according to an embodiment of the present invention are different from the poisoning attack defense method for filtering sample data before traditional centralized machine learning training. It filters the model itself rather than the sample data, so that the defense method can be deployed on the server side to continuously resist poisoning attacks during the training process. At the same time, it does not occupy the computing resources of the terminal device and does not require the server to have data samples. Therefore, it is applicable to the federated learning environment with limited resources of end devices and protecting user privacy. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 is a flowchart of an edge server of the security defense method of distributed federated learning based on the edge-cloud architecture according to an embodiment of the present invention;
[0031] Figure 2 is a structural diagram of the security defense method of distributed federated learning based on the edge-cloud architecture according to an embodiment of the present invention;
[0032] Figure 3 is a schematic diagram of filtering and verification of the security defense method of distributed federated learning based on the edge-cloud architecture according to an embodiment of the present invention;
[0033] Figure 4 is a flowchart of a cloud server of the security defense method of distributed federated learning based on the edge-cloud architecture according to an embodiment of the present invention;
[0034] Figure 5 is a structural diagram of an edge server of the security defense device of distributed federated learning based on the edge-cloud architecture according to an embodiment of the present invention;
[0035] Figure 6 is a structural diagram of a cloud server of the security defense device of distributed federated learning based on the edge-cloud architecture according to an embodiment of the present invention;
[0036] Figure 7 is a hardware structural diagram of the security defense computing device of distributed federated learning based on the edge-cloud architecture according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0037] The following will describe in detail the specific embodiments of the present invention with reference to the drawings, but it should be understood that the protection scope of the present invention is not limited by the specific embodiments.
[0038] Unless otherwise clearly stated, the term "comprising" or its variations such as "including" or "having" etc. will be understood to include the stated elements or components throughout the specification and claims, without excluding other elements or other components.
[0039] The following will, in conjunction with the accompanying drawings, elaborate on the technical solutions provided by various embodiments of the present invention in detail.
[0040] Embodiment 1
[0041] As Figures 1 to 3 shown, a security defense method for distributed federated learning based on an edge-cloud architecture in an embodiment of the present invention is introduced. This method includes the following steps.
[0042] In step S101, the edge server receives the updated local model uploaded by the end device.
[0043] As Figure 2 shown, determine the end devices (data centers) under the jurisdiction of each edge server (edge cloud), partition the end devices with similar geographical locations, and deploy edge servers for jurisdiction to provide computing and caching resources. The cloud server (central cloud) initializes the global model and distributes it to each edge server, and then the edge server distributes it to the corresponding underlying end devices. The end device uses private data to train the global model, calculates the updated local model through the stochastic gradient descent method, and uploads the updated local model to the corresponding edge server.
[0044] In step S102, the edge server filters the updated local model.
[0045] The edge server receives the updated local model, aggregates all local models, and calculates the cosine similarity between each local model and the aggregated model. At this time, whether it is a direct or indirect small-scale poisoning attack on the local model can be identified. Even if one-third of the local models are contaminated and become dirty models, the model accuracy loss can be controlled within a certain range.
[0046] Specifically, convert the weight and bias matrices corresponding to the convolutional layer and fully connected layer of the neural network model into one-dimensional vectors, and concatenate them to form a one-dimensional vector containing all parameters. The local model and the aggregated model calculate the cosine similarity based on the one-dimensional vectors corresponding to their respective parameters. Based on the cosine similarity, obtain the similarity distribution of each local model and the overall collaborative convergence trend.
[0047] Distinguish the local models according to the similarity distribution, and judge the deviation degree of each local model. The parameters corresponding to the cosine similarity that is close to the maximum cosine similarity distribution and the distance is less than the adaptive threshold are classified as safe parameters; the parameters corresponding to the cosine similarity that is greater than the adaptive threshold from the maximum cosine similarity are classified as malicious parameters, and the malicious parameters are excluded.
[0048] Since the global model is aggregated from local models, the global model and the local models should be similar. However, direct (tampering with the model) or indirect (tampering with the dataset) poisoning attacks on model parameters often cause small deviations in a small number of normal parameters, deviating from the collaborative convergence trend of the overall training. Therefore, the malicious parameters have a lower similarity to the normal parameters and the edge aggregation parameters, while the similarity distribution of the normal parameters is higher overall and closer to each other. Therefore, the model parameters corresponding to the similarity with a maximum cosine similarity gap greater than the adaptive threshold can be identified as a dirty model.
[0049] Direct poisoning attacks mainly involve tampering with the model after eavesdropping on data through the channel. Here, it is a specific tampering that is not easily distinguishable. Since the normal model training parameter data magnitudes are similar, some large changes can be easily identified and excluded by humans. Indirect poisoning attacks are to train a malicious model by constructing specific sample data, such as label flipping attacks. Whether it is a direct or indirect poisoning attack, the parameters after being attacked are verified to have a large deviation from the normal parameters.
[0050] In step S103, the edge server aggregates the filtered secure local models and uploads the generated edge aggregation model to the cloud server.
[0051] Due to the open wireless channel environment of mobile edge computing, the attacker may not take measures to launch a poisoning attack from the data side, but instead, based on channel eavesdropping technology, construct a specific malicious model to directly replace the original model, thereby completing the direct tampering of the model and launching a poisoning attack. This kind of threat may occur in the communication between the end device and the edge cloud, or in the communication between the edge cloud and the central cloud.
[0052] Therefore, after the edge server excludes the malicious local models through the model filtering algorithm, it aggregates the remaining secure local models and uses the aggregated average model parameters as a message, and signs the model using the schnorr signature algorithm.
[0053] Specifically, generate a public key and a private key using the signature algorithm, and generate a corresponding signature based on the hash encryption function and the aggregated model, and send the signature and the message to the cloud server.
[0054] Embodiment 2
[0055] As Figure 4 shown, this describes a security defense method for distributed federated learning based on an end-edge-cloud architecture in an embodiment of the present invention. The method includes the following steps.
[0056] In step S201, the cloud server initializes the global model and sends the global model to the edge server.
[0057] In step S202, the cloud server verifies the digital signature of the edge aggregation model uploaded by the edge server and globally aggregates the edge aggregation model to obtain an updated global model.
[0058] After the cloud server verifies the signature, it excludes malicious models with failed verification and globally aggregates the edge aggregation models that have passed the verification and are secure to update the global model.
[0059] Through the signature verification algorithm, it is verified whether the signature corresponds to the message. Because the hash encryption algorithm has two basic characteristics: 1. Different messages have different signatures. 2. A small change in the message can cause a large change in the hash value. Therefore, the behavior of attempting to keep the original signature while tampering with the data will result in inconsistent verified signatures. The edge aggregation models with failed signature verification will be excluded, and the edge aggregation models that have passed the verification will be globally aggregated to obtain a new round of iterative global model. The cloud server continues to distribute the global model, and this iteration continues until the model converges.
[0060] The edge aggregation model is uploaded to the central cloud in the form of a schnorr signature as a message. Even if the attacker does not attack the local model but attacks the communication between the edge server and the cloud server, the cloud server can still determine whether the edge aggregation parameters have been tampered with through the signature verification method, and then exclude malicious models from the global aggregation to protect the security of the global model.
[0061] As Figure 5 shown, a security defense device for distributed federated learning based on an edge-cloud-end architecture according to a specific embodiment of the present invention is introduced.
[0062] In an embodiment of the present invention, a security defense device for distributed federated learning based on an edge-cloud-end architecture includes a receiving module 501, a filtering module 502, and an aggregation module 503.
[0063] The receiving module 501 is used for the edge server to receive the updated local model uploaded by the end device, where the updated local model is obtained by the end device training the global model distributed by the cloud server based on private data.
[0064] The filtering module 502 is used for the edge server to filter the updated local model to obtain a secure local model.
[0065] The aggregation module 503 is used for the edge server to aggregate the filtered secure local models and upload the generated edge aggregation model to the cloud server.
[0066] The filtering module 502 is further configured to: perform preliminary aggregation on all local models by the edge server to generate an aggregated model; calculate the cosine similarity between the local model and the aggregated model; and delete the model parameters corresponding to the cosine similarity whose difference from the maximum cosine similarity is greater than the adaptive threshold according to the distribution of the cosine similarity.
[0067] The filtering module 502 is further configured to: convert the weight and bias matrices corresponding to the convolutional layer and the fully connected layer of the neural network model into one-dimensional vectors, and concatenate them to form a one-dimensional vector containing all parameters; and calculate the cosine similarity according to the one-dimensional vectors corresponding to the parameters of the local model and the aggregated model.
[0068] The aggregation module 503 is further configured to: use the parameters of the edge aggregated model as a message, sign it according to the schnorr signature algorithm, and send the signature and the message to the cloud server.
[0069] As Figure 6 shown, a security defense device for distributed federated learning based on an edge-cloud architecture according to a specific embodiment of the present invention is introduced.
[0070] In an embodiment of the present invention, a security defense device for distributed federated learning based on an edge-cloud architecture includes an initialization module 601 and a verification module 602.
[0071] The initialization module 601 is configured to initialize a global model by the cloud server and send the global model to the edge server.
[0072] The verification module 602 is configured to verify the digital signature of the edge aggregated model uploaded by the edge server by the cloud server, and perform global aggregation on the edge aggregated model to obtain an updated global model.
[0073] The verification module 602 is further configured to: verify whether the digital signature matches the message uploaded by the edge server; if not, delete the edge aggregated model that fails the verification; if so, perform global aggregation on the edge aggregated model that passes the verification to obtain an updated global model.
[0074] Figure 7 shows a hardware structure diagram of a security defense computing device 70 for distributed federated learning based on an edge-cloud architecture according to an embodiment of this specification. As Figure 7 shown, the computing device 70 may include at least one processor 701, a memory 702 (such as a non-volatile memory), a memory 703, and a communication interface 704, and at least one processor 701, the memory 702, the memory 703, and the communication interface 704 are connected together via a bus 705. At least one processor 701 executes at least one computer-readable instruction stored or encoded in the memory 702.
[0075] It should be understood that the computer-executable instructions stored in the memory 702, when executed, cause at least one processor 701 to perform the various operations and functions described above in connection with the various embodiments of this specification. Figures 1 - 7 described.
[0076] In an embodiment of this specification, the computing device 70 may include, but is not limited to: a personal computer, a server computer, a workstation, a desktop computer, a laptop computer, a notebook computer, a mobile computing device, a smart phone, a tablet computer, a cellular phone, a personal digital assistant (PDA), a handheld device, a messaging device, a wearable computing device, a consumer electronic device, and the like.
[0077] According to one embodiment, a program product such as a machine-readable medium is provided. The machine-readable medium may have instructions (i.e., the elements implemented in software as described above), which, when executed by the machine, cause the machine to perform the various operations and functions described above in connection with the various embodiments of this specification. Figures 1 - 7 Specifically, a system or device equipped with a readable storage medium may be provided, on which software program code for implementing the functions of any one of the above embodiments is stored, and the computer or processor of the system or device is caused to read and execute the instructions stored in the readable storage medium.
[0078] According to the security defense method and application of distributed federated learning based on the edge-cloud architecture according to an embodiment of the present invention, it can analyze whether the local model parameters conform to the collaborative convergence trend by calculating the cosine similarity between the local model and the edge aggregation model on the edge cloud server, and then distinguish malicious and non-malicious models. After excluding malicious parameters, the remaining secure parameters are aggregated, and the aggregated model is signed using a digital signature method and uploaded to the central cloud. The central cloud verifies the signature to determine whether the aggregated model has been tampered with during the transmission process, thereby excluding malicious aggregated models and continuously defending against a small portion of direct (e.g., model tampering after channel eavesdropping) or indirect poisoning attacks (e.g., label flipping attacks on the dataset) on the global model online, further ensuring the security of the federated learning global model.
[0079] According to the security defense method and application of distributed federated learning based on the edge-cloud architecture according to an embodiment of the present invention, different from the traditional poisoning attack defense method for filtering sample data before centralized machine learning training, it filters the model itself rather than the sample data. In this way, the defense method can be deployed on the server side to continuously resist poisoning attacks during the training process, without occupying the computing resources of the terminal device and without the server needing to have data samples. Therefore, it is suitable for federated learning environments with limited resources on the end device and protecting user privacy.
[0080] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memory, CD-ROM, optical memory, etc.) that contain computer-usable program code.
[0081] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as the combination of flows and / or blocks in the flowcharts and / or block diagrams, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for realizing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of blocks.
[0082] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing devices to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means realizes the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of blocks.
[0083] These computer program instructions can also be loaded onto a computer or other programmable data processing devices, so that a series of operation steps are executed on the computer or other programmable devices to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable devices provide steps for realizing the functions specified in Figure 1 one or more of the flows Figure 1 or blocks or the combination of blocks.
[0084] The foregoing description of specific exemplary embodiments of the invention is for purposes of illustration and exemplification. These descriptions are not intended to limit the invention to the precise forms disclosed, and it is apparent that, according to the above teachings, many modifications and variations are possible. The purpose of selecting and describing the exemplary embodiments is to explain the specific principles of the invention and its practical applications, so that those skilled in the art can implement and utilize the various different exemplary embodiments of the invention, as well as various different selections and modifications. The scope of the invention is intended to be defined by the claims and their equivalents.
Claims
1. A security defense method for distributed federated learning based on an edge-cloud architecture, characterized in that, The method includes: The edge server receives the updated local model uploaded by the end device, where the updated local model is obtained by the end device training the global model sent by the cloud server based on private data; The edge server filters the updated local model to obtain a secure local model, which includes: the edge server initially aggregates all local models to generate an aggregated model; calculates the cosine similarity between the local model and the aggregated model; and deletes the model parameters corresponding to the cosine similarity whose difference from the maximum cosine similarity is greater than the adaptive threshold according to the distribution of the cosine similarity; Calculating the cosine similarity between the local model and the aggregated model includes: converting the weight and bias matrices corresponding to the convolutional layer and the fully connected layer of the neural network model into one-dimensional vectors, and concatenating them to form a one-dimensional vector containing all parameters; and calculating the cosine similarity according to the one-dimensional vectors corresponding to the parameters of the local model and the aggregated model; and The edge server aggregates the filtered secure local models and uploads the generated edge aggregated model to the cloud server.
2. The security defense method for distributed federated learning based on the edge-cloud architecture according to claim 1, wherein The method further includes: Taking the parameters of the edge aggregated model as a message, signing it according to the Schnorr signature algorithm, and uploading the signature and the message to the cloud server.
3. A security defense device for distributed federated learning based on an edge-cloud architecture, characterized in that, The device includes: A receiving module for the edge server to receive the updated local model uploaded by the end device, where the updated local model is obtained by the end device training the global model sent by the cloud server based on private data; A filtering module for the edge server to filter the updated local model to obtain a secure local model, which includes: the edge server initially aggregates all local models to generate an aggregated model; calculates the cosine similarity between the local model and the aggregated model; and deletes the model parameters corresponding to the cosine similarity whose difference from the maximum cosine similarity is greater than the adaptive threshold according to the distribution of the cosine similarity; Calculating the cosine similarity between the local model and the aggregated model includes: converting the weight and bias matrices corresponding to the convolutional layer and the fully connected layer of the neural network model into one-dimensional vectors, and concatenating them to form a one-dimensional vector containing all parameters; and calculating the cosine similarity according to the one-dimensional vectors corresponding to the parameters of the local model and the aggregated model; and An aggregation module for the edge server to aggregate the filtered secure local models and upload the generated edge aggregated model to the cloud server.
4. An electronic device, characterized in that, Includes: At least one processor; And A memory that stores instructions, which when executed by the at least one processor, cause the at least one processor to execute the secure defense method of distributed federated learning based on the end-edge-cloud architecture as described in any one of claims 1 to 2.
5. A computer-readable storage medium, characterized in that A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the secure defense method of distributed federated learning based on the end-edge-cloud architecture as described in any one of claims 1 to 2 are implemented.
Citation Information
Patent Citations
Equipment evaluation and federated learning importance aggregation method, system and equipment based on edge intelligence and readable storage medium
CN112181666A
Edge-based federated learning model cleaning and equipment clustering method, system and equipment and readable storage medium
CN112181971A
Model training method and system based on joint learning
CN112261137A