A Group-Verifiable Chain-Type Privacy-Preserving Federated Learning Method and Device

Through the grouping verifiable chain privacy protection federated learning method, lightweight pseudo-random generators are used to perform chain aggregation and correctness verification of local models, solving the problem of large overhead of federated learning computing and communication in the prior art, and achieving efficient privacy protection and model aggregation under resource constraints.

CN115168902BActive Publication Date: 2025-06-27WUHAN UNIV
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202210882955.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-26
Publication Date
2025-06-27
Estimated Expiration
2042-07-26

AI Technical Summary

Technical Problem

In the prior art, federated learning has a high computing and communication overhead, making it difficult to effectively protect privacy and model aggregation in resource-constrained environments.

Method used

A federated learning method for grouping verifiable chain privacy protection is adopted to reduce computation and communication overhead by dividing users into different groups for model training, and using a lightweight pseudo-random generator to perform chain aggregation and correctness verification of local models.

Benefits of technology

It effectively reduces the computing and communication overhead of traditional federated learning privacy protection solutions, realizes efficient privacy protection and model aggregation under resource constraints, simplifies the architecture and reduces the overhead of security protection measures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115168902B_ABST
    Figure CN115168902B_ABST
Patent Text Reader

Abstract

The present invention discloses a group-verifiable chained privacy-preserving federated learning method and device. First, a grouped chained learning mechanism is proposed to ensure the privacy of users during the training phase, and then a verifiable secure aggregation protocol is proposed to ensure the verifiability of the global model. Specifically, the present invention first divides users into different groups for model training, and each group uploads the training results and verification labels to the aggregation server; then the aggregation server aggregates the training results and verification labels and returns the aggregation result, i.e., the global model; finally, the users verify the aggregated labels and accept the aggregation result after the verification passes. The present invention ensures the privacy of the client through a grouped chained learning mechanism without introducing complex cryptographic primitives, and realizes the verifiability of the aggregation result through a verifiable aggregation protocol, with relatively low computational overhead, and can solve the federated learning requirements in resource-constrained scenarios.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of artificial intelligence, and relates to a security protection method for artificial intelligence, in particular to a group-verifiable chained privacy protection federated learning method and device. Background Art

[0002] With the explosive growth of data, machine learning, as a data mining technology, has shown great development potential and can be applied to scenarios such as autonomous driving, intelligent healthcare, and smart cities. This type of machine learning paradigm requires centralized processing of a large amount of data. However, user data may contain privacy information. For example, in intelligent healthcare, patient data is highly confidential and cannot be directly shared with third parties. Additionally, collecting a large amount of data poses a great challenge in the case of limited network resources.

[0003] To address this defect, Google first proposed the federated learning scheme, which can perform machine learning training without the data leaving the users. Federated learning consists of multiple rounds of training. In each round of training, the aggregation server distributes the global model to selected users according to rules. Then the users train local models on their own local datasets and upload them to the server, and the aggregation server performs model aggregation to obtain a new global model. Although federated learning retains sensitive training data locally, it still faces great security risks. During the training process, an attacker may disrupt the aggregation server and poison the global model, thereby indirectly damaging the user's local model. Moreover, an attacker can also use the received information to infer user privacy information.

[0004] Due to the above various privacy and security issues, many solutions use homomorphic encryption, secure multi-party computation, or differential privacy to implement privacy-protected federated learning. However, these technologies still have deficiencies in practice. For homomorphic encryption, the excessively high computational complexity often leads to a large time overhead, especially when the number of clients is too large. For secure multi-party computation, its communication and computational overheads are too large to support actual usage requirements. For differential privacy, since it introduces noise, it is likely to affect the model accuracy. Additionally, in differential privacy-based solutions, in order to obtain a more accurate model, a larger privacy budget is often required, and in this case, the actual achieved privacy level is debatable.

[0005] Meanwhile, in order to prevent the aggregation server from returning incorrect aggregation results, it is also necessary to verify the correctness of the aggregation results. To alleviate this problem, some researchers have proposed corresponding solutions by combining homomorphic hashing and zero-knowledge proof technologies. However, these solutions still face expensive computational and communication overheads.

[0006] It can be seen that the methods in the prior art have the technical problem of large computational overhead. Summary of the Invention

[0007] The present invention provides a group-verifiable chained privacy-preserving federated learning method and apparatus, which are used to solve or at least partially solve the technical problem of large computational overhead in the prior art.

[0008] To solve the above technical problem, a first aspect of the present invention provides a group-verifiable chained privacy-preserving federated learning method, including:

[0009] S1: The server sends the global model parameters to the federated learning users;

[0010] S2: The federated learning users use the global model parameters sent by the server as the local initial model parameters, and perform training based on the local data to obtain new local model parameters;

[0011] S3: The federated learning users in different groups perform chained aggregation of the local models based on the new local model parameters and the random numbers sent by the server;

[0012] S4: The last federated learning user in each group sends the local model aggregation result and the correctness verification label to the server;

[0013] S5: The server aggregates the local model aggregation results and the correctness verification labels sent by the federated learning users in different groups to obtain new global model parameters and global verification labels, and sends them to the federated learning users;

[0014] S6: The federated learning users verify the correctness of the new global model parameters according to the received global verification labels.

[0015] In one implementation, step S1 includes:

[0016] S1.1: The federated learning users access the federated learning training network in groups, and a chained structure is used to connect the users in each group;

[0017] S1.2: The server sends the global model parameters to each federated learning user, and sends the random number δ generated by using a pseudo-random number generator r to the first and the last federated learning users in each group, where r represents the current r-th iteration.

[0018] In one implementation, step S2 includes:

[0019] S2.1: Each federated learning user uses the received global model parameters as the local initial model parameters, and calculates the gradient by using the local initial model parameters and the local data set. The calculation formula is where D (i) represents the federated learning user Pi local dataset, W r represents the global model parameters, g i represents P i on the dataset D (i) gradient obtained by training, represents calculating the gradient;

[0020] S2.2: Each federated learning user calculates the new local model parameters, w i r = W r - ηg i , where η is the learning rate, w i r is the new local model parameter obtained in the r-th iteration.

[0021] In one implementation, step S3 includes:

[0022] S3.1: The first federated learning user in each group calculates θ1 through the formula r = w1 r + δ r , to obtain the corresponding blinded local model parameter θ1 r , and sends θ1 r to the next user, where δ r is the random number sent by the server to the first and last users in each group, used to protect the privacy of the first user, w1 r is the new local model parameter trained by the first federated learning user in the r-th round;

[0023] S3.2: Other federated learning users in each group except the first and last federated learning users calculate according to the formula θ i r = w i r + θ i-1 r to obtain the corresponding blinded local model parameter θ i r , and passes θ i r to the subsequent user, where r represents the current r-th iteration, θ i-1 r represents the blinded local model parameter obtained by the (i - 1)-th user, w i r is the new local model parameter trained by the i-th user in the r-th iteration;

[0024] S3.3: The last federated learning user in each group calculates according to θ lr = w l r + θ l-1 r Calculate the blinded local aggregation model parameter θ l r , and based on θ g r = θ l r - δ r Calculate the local aggregation model parameter θ of the current user group g r , and use θ g r as the local model aggregation result of the current user group, where g represents the number of the last federated learning user in the chain structure.

[0025] In one implementation, step S4 includes:

[0026] S4.1: The federated learning user calculates through to obtain the aggregation result correctness verification label of user group G i where k and b are random vectors unknown to the server, j represents the current jth group of users, is the local model aggregation result obtained by the jth group of users in the rth iteration;

[0027] S4.2: The federated learning user uploads and to the server together.

[0028] In one implementation, step S5 includes:

[0029]

[0029] S5.1: The server calculates to obtain the global model parameter W after the rth iteration r+1 , where n is the number of users participating in federated learning training, m is the number of user groups, is the local aggregation model parameter of the jth group of users in the rth iteration, and is the local model aggregation result of the jth group of users in the rth iteration;

[0030] S5.2: The aggregation server calculates to obtain the global verification label σ after the rth iteration r+1 , and sends it to the federated learning user.

[0031] In one implementation, step S6 includes:

[0032] The federated learning user judges Whether it holds. If it holds, it indicates that the newly received global model parameters are correct; otherwise, the newly received global model parameters are discarded, where m is the number of user groups.

[0033] Based on the same inventive concept, a second aspect of the present invention provides a group-verifiable chained privacy protection federated learning device, including:

[0034] A global model parameter synchronization module, configured to send global model parameters to federated learning users through a server;

[0035] A local training module, configured to use the global model parameters sent by the server as local initial model parameters by federated learning users, and perform training on the basis of local data to obtain new local model parameters;

[0036] A local aggregation module, configured to perform chained aggregation of local models by federated learning users in different groups based on the new local model parameters and random numbers sent by the server;

[0037] An aggregation result sending module, configured to send the local model aggregation result and the correctness verification label to the server by the last federated learning user in each group;

[0038] A global aggregation module, configured to aggregate the local model aggregation results and the correctness verification labels sent by federated learning users in different groups through the server to obtain new global model parameters and global verification labels, and send them to the federated learning users;

[0039] A verification module, configured to verify the correctness of the new global model parameters by federated learning users according to the received global verification label.

[0040] Based on the same inventive concept, a third aspect of the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed, the method described in the first aspect is implemented.

[0041] Based on the same inventive concept, a fourth aspect of the present invention provides a computer device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the program, the method described in the first aspect is implemented.

[0042] Compared with the prior art, the advantages and beneficial technical effects of the present invention are as follows:

[0043] (1) Different from other federated learning methods, the present invention can complete the federated learning training of privacy protection only by using a grouped chained training structure, and can effectively reduce the computational and communication overhead of the traditional federated learning privacy protection scheme.

[0044] (2) The verifiable secure aggregation scheme adopted by the present invention can verify the correctness of the aggregation result of the server while ensuring privacy and efficiency.

[0045] (3) The present invention can be used for federated learning training under resource-constrained conditions. Its simple and easy-to-use architecture makes it easy to deploy and greatly reduces the overhead of existing security protection measures. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the following drawings are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0047] Figure 1 It is a schematic diagram of the scenario of the group-verifiable chained privacy protection federated learning method in the embodiments of the present invention;

[0048] Figure 2 It is a schematic diagram of the process of the group-verifiable chained privacy protection federated learning method in the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0049] The present invention first proposes a grouped chained learning mechanism to ensure the privacy of users during the training phase, and then proposes a verifiable secure aggregation protocol to ensure the verifiability of the global model. The present invention does not require any complex cryptographic primitives and does not introduce noise. By using a lightweight pseudorandom generator, verifiable privacy-preserving federated learning can be achieved.

[0050] In order to achieve the above technical effects, the main inventive concept of the present invention is as follows:

[0051] The present invention first divides users into different groups for model training, and each group uploads the training results and verification tags to the aggregation server; then the aggregation server aggregates the training results and verification tags and returns the aggregation result, that is, the new global model parameters; finally, the users verify the aggregated tags and accept the aggregation result after passing the verification. The present invention ensures the privacy of the client through a grouped chained learning mechanism without introducing complex cryptographic primitives, and realizes the verifiability of the aggregation result through a verifiable aggregation protocol, with low computational overhead, and can meet the requirements of federated learning in resource-constrained scenarios.

[0052] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0053] Embodiment 1

[0054] The embodiment of the present invention provides a group-verifiable chained privacy-preserving federated learning method, including:

[0055] S1: The server sends the global model parameters to the federated learning users;

[0056] S2: The federated learning users use the global model parameters sent by the server as the local initial model parameters, and perform training based on the local data to obtain new local model parameters;

[0057] S3: The federated learning users in different groups perform chained aggregation of the local models based on the new local model parameters and the random numbers sent by the server;

[0058] S4: The last federated learning user in each group sends the local model aggregation result and the correctness verification label to the server;

[0059] S5: The server aggregates the local model aggregation results and the correctness verification labels sent by the federated learning users in different groups to obtain new global model parameters and global verification labels, and sends them to the federated learning users;

[0060] S6: The federated learning users verify the correctness of the new global model parameters according to the received global verification labels.

[0061] The embodiment of the present invention provides a lightweight and secure privacy-preserving federated learning method for edge computing scenarios, as shown in the specific scenario Figure 1 as follows. The process of this method is as shown in Figure 2 as follows.

[0062] In the specific implementation process, federated learning users access the federated learning training network in groups, and parameter synchronization is performed between the server and the users. Step S2 is local training. Each federated learning user uses the global model parameters sent by the server as local initial model parameters and trains them based on local data to obtain new local model parameters. S3 is the chained aggregation of local model parameters, and the last federated learning user in each group sends the local model aggregation result and the correctness verification label to the server. Step S5 is for the server to globally aggregate the received model aggregation results and corresponding labels in each group to obtain new global model parameters and global verification labels. Finally, the users perform the verification.

[0063] In one implementation, step S1 includes:

[0064] S1.1: Federated learning users access the federated learning training network in groups, and a chained structure is used to connect users in each group;

[0065] S1.2: The server sends the global model parameters to each federated learning user, and sends the random number δ r generated by the pseudorandom number generator to the first and the last federated learning users in each group, where r represents the current r-th iteration.

[0066] Specifically, the federated learning users are the federated learning clients or participants. The server sends the random number δ r generated by the pseudorandom number generator to the first and the last federated learning users in each group for the subsequent parameter blinding and aggregation. Among them, the first user in the group can use the random number sent by the server to blind its own model parameters (specifically see formula θ1 r = w1 r + δ r ), and the last user needs to use this data for deblinding to restore the local aggregation result of this group of users (specifically see formula θ g r = θ l r - δ r ).

[0067] In one implementation, step S2 includes:

[0068] S2.1: Each federated learning user uses the received global model parameters as local initial model parameters and calculates the gradient using the local initial model parameters and the local data set. The calculation formula is where D (i) represents the local data set of the federated learning user P i , and Wr Denote the global model parameters as g i Denote P i On the dataset D (i) The gradient obtained through training Denote the calculation of the gradient;

[0069] S2.2: Each federated learning user calculates the new local model parameters w i r = W r - ηg i , where η is the learning rate, and w i r is the new local model parameter obtained in the r-th round of iteration.

[0070] In the specific implementation process, each time a federated learning user trains, the global model parameters received in this round will be used as the input for the current local model training, that is, as the local initial model parameters.

[0071] In one implementation, step S3 includes:

[0072] S3.1: The first federated learning user in each group calculates θ1 through the formula r = w1 r + δ r , to obtain the corresponding blinded local model parameter θ1 r , and send θ1 r to the next user, where δ r is the random number sent by the server to the first user and the last user in each group, used to protect the privacy of the first user, and w1 r is the new local model parameter trained by the first federated learning user in the r-th round;

[0073] S3.2: For the other federated learning users in each group except the first federated learning user and the last federated learning user, calculate according to the formula θ i r = w i r + θ i-1 r to obtain the corresponding blinded local model parameter θ i r , and pass θ i r to the subsequent user, where r represents the current r-th round of iteration, and θ i-1 r represents the blinded local model parameter obtained by the (i - 1)-th user, and w i r is the new local model parameter trained by the i-th user in the r-th round;

[0074] S3.3: The last federated learning user in each group is based on θ l r =w l r +θ l-1 r Calculate the blinded local aggregation model parameters θ l r , and according to θ g r =θ l r -δ r Calculate the local aggregation model parameter θ for the current user group g r , and θ g r As the local model aggregation result of the current user group, g represents the number of the last federated learning user in the chain structure.

[0075] Specifically, the first federated learning user in each group calculates the corresponding blinded local model parameter θ1 through the formula r , then θ1 r The next user in the group will calculate based on the parameters sent by the previous user and the new local model parameters obtained by the user to obtain the corresponding blinded local model parameters. This continues until the last user in the group. The last user will perform further operations, that is, calculate the obtained blinded local model parameters with the random number sent by the server to obtain the reorganized local model parameter aggregation result.

[0076] In one embodiment, step S4 includes:

[0077] S4.1: Federated learning users pass Calculate the user group G i Aggregation result correctness verification tag Where k and b are random vectors unknown to the server, j represents the current j-th group of users, The local model aggregation result obtained for the j-th group of users in the r-th iteration;

[0078] S4.2: Federated learning users will and Upload them to the server together.

[0079] In one embodiment, step S5 includes:

[0080] S5.1: Server Computing Get the global model parameters W after the rth iterationr+1 , where n is the number of users participating in the federated learning training, m is the number of user groups, is the local aggregation model parameter of the j-th group of users in the r-th iteration, and is the local model aggregation result of the j-th group of users in the r-th iteration;

[0081] S5.2: The aggregation server calculates to obtain the global verification label σ after the r-th iteration r+1 , and sends it to the federated learning users.

[0082] It should be noted that after the calculations of the server in steps S5.1 and S5.2, this round (the r-th round) of training is completed. At this time, the corresponding global model parameters and global verification labels (i.e., the model parameters and labels after iteration) will be obtained. Among them, the global model parameter W after the r-th iteration r+1 will be used as the input for the next round (the r + 1)-th round of training. For example, in the first round of iteration, the initial global model parameter W 1 is sent to each federated learning user, which is used as the input for training. After the end of this round of training, the training result of this round, that is, W 2 will be used as the input (global model parameter) for the next round of training.

[0083] In one implementation, step S6 includes:

[0084] The federated learning user judges whether it holds. If it holds, it means that the newly received global model parameter is correct. Otherwise, the newly received global model parameter is discarded, where m is the number of user groups;

[0085] After the above verification, the federated learning users and the server continue the next round of iterative training until the iteration condition is met.

[0086] A group-verifiable chained privacy protection federated learning method provided by the present invention can verify the correctness of the global model while protecting user privacy, and mitigate the single-point failure risk of the federated learning aggregation server.

[0087] Embodiment 2

[0088] Based on the same inventive concept, this embodiment provides a group-verifiable chained privacy protection federated learning device, including:

[0089] A global model parameter synchronization module, configured to send the global model parameter to the federated learning users through the server;

[0090] A local training module, which is used for a federated learning user to use the global model parameters sent by the server as local initial model parameters and perform training based on local data to obtain new local model parameters;

[0091] A local aggregation module, which is used for different groups of federated learning users to perform chained aggregation of local models based on the new local model parameters and the random numbers sent by the server;

[0092] An aggregation result sending module, which is used for the last federated learning user in each group to send the local model aggregation result and the correctness verification label to the server;

[0093] A global aggregation module, which is used for the server to aggregate the local model aggregation results and the correctness verification labels sent by different groups of federated learning users to obtain new global model parameters and global verification labels, and send them to the federated learning users;

[0094] A verification module, which is used for a federated learning user to verify the correctness of the new global model parameters according to the received global verification label.

[0095] Since the device introduced in the second embodiment of the present invention is the device adopted for the group-verifiable chained privacy protection federated learning method in the first embodiment of the present invention, based on the method introduced in the first embodiment of the present invention, those skilled in the art can understand the specific structure and variations of the device, so it will not be elaborated here. Any device adopted for the method in the first embodiment of the present invention falls within the scope of protection of the present invention.

[0096] Embodiment 3

[0097] Based on the same inventive concept, the present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed, it implements the method described in Embodiment 1.

[0098] Since the computer-readable storage medium introduced in the third embodiment of the present invention is the computer-readable storage medium adopted for the group-verifiable chained privacy protection federated learning method in the first embodiment of the present invention, based on the method introduced in the first embodiment of the present invention, those skilled in the art can understand the specific structure and variations of the computer-readable storage medium, so it will not be elaborated here. Any computer-readable storage medium adopted for the method in the first embodiment of the present invention falls within the scope of protection of the present invention.

[0099] Embodiment 4

[0100] Based on the same inventive concept, the present application also provides a computer device, including a storage, a processor, and a computer program stored on the memory and executable on the processor, and when the processor executes the above program, it implements the method in Embodiment 1.

[0101] Since the computer device introduced in the fourth embodiment of the present invention is the computer device used in the group-verifiable chained privacy protection federated learning method in the first embodiment of the present invention, based on the method introduced in the first embodiment of the present invention, those skilled in the art can understand the specific structure and variations of this computer device, so it will not be elaborated here. Any computer device used in the method of the first embodiment of the present invention falls within the scope of protection of the present invention.

[0102] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0103] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, and the combination of flows and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for realizing the specified functions in one Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0104] Although the preferred embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications once they know the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments and all changes and modifications falling within the scope of the present invention.

[0105] Obviously, those skilled in the art can make various changes and modifications to the embodiments of the present invention without departing from the spirit and scope of the embodiments of the present invention. Thus, if these modifications and variations of the embodiments of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these changes and modifications.

Claims

1. A group-verifiable chained privacy-preserving federated learning method, characterized in that Including: S1: The server sends the global model parameters to the federated learning users; S2: The federated learning users use the global model parameters sent by the server as the local initial model parameters, and perform training based on the local data to obtain new local model parameters; S3: Different groups of federated learning users perform chained aggregation of the local models based on the new local model parameters and the random numbers sent by the server; S4: The last federated learning user in each group sends the local model aggregation result and the correctness verification label to the server; S5: The server aggregates the local model aggregation results and the correctness verification labels sent by different groups of federated learning users to obtain new global model parameters and global verification labels, and sends them to the federated learning users; S6: The federated learning users verify the correctness of the new global model parameters according to the received global verification labels; Among them, step S3 includes: S3.1: The first federated learning user in each group performs calculations through the formula to obtain the corresponding blinded local model parameters , and sends to the next user, where is the random number sent by the server to the first and last users in each group to protect the privacy of the first user, is the new local model parameters trained by the first federated learning user in the r-th round; S3.2: For other federated learning users in each group except the first and the last federated learning users, calculate according to the formula to obtain the blinded local model parameters corresponding to this user , and pass to the subsequent user, where r represents the current r-th iteration, represents the blinded local model parameters obtained by the (i - 1)-th user, is the new local model parameters trained by the i-th user in the r-th iteration; S3.3: The last federated learning user in each group, according to calculate the blinded local aggregated model parameters , and according to calculate the local aggregated model parameters of the current user group , take as the local model aggregation result of the current user group, where g represents the number of the last federated learning user in the chain structure.

2. The group-verifiable chained privacy-preserving federated learning method according to claim 1, wherein Step S1 includes: S1.1: The federated learning users access the federated learning training network in groups, and a chained structure is used for connection between each group of users; S1.2: The server distributes the global model parameters to each federated learning user and sends the random numbers generated by the pseudo-random number generator to the first and the last federated learning users in each group, where r represents the current r-th round of iteration.

3. The group-verifiable chained privacy-preserving federated learning method according to claim 1, wherein Step S2 includes: S2.1: Each federated learning user takes the received global model parameters as the local initial model parameters and calculates the gradient using the local initial model parameters and the local dataset. The calculation formula is , where represents the federated learning user 's local dataset, represents the global model parameters, represents the gradient obtained by training on the dataset , and represents the calculation of the gradient;​ S2.2: Each federated learning user calculates new local model parameters, , where is the learning rate, is the new local model parameter obtained in the r-th iteration.

4. The group-verifiable chained privacy protection federated learning method according to claim 1, wherein Step S4 includes: S4.1: The federated learning user passes through computation to obtain the aggregation result correctness verification label of the user group G i , where and k are random vectors unknown to the server, b j represents the current j group of users, is the aggregated result of the local models obtained by the r th group of users in the j th round of iteration;​ S4.2: The federated learning user uploads and to the server together.

5. The group-verifiable chained privacy protection federated learning method according to claim 1, wherein, Step S5 includes: S5.1: Server calculation , obtain the global model parameters after the r-th iteration , where n is the number of users participating in the federated learning training, m is the number of user groups, is the local aggregation model parameter of the j-th group of users in the r-th iteration, and is the local model aggregation result of the j-th group of users in the r-th iteration; S5.2: Aggregation Server Computation , obtain the global verification tag after the r-th iteration , and send it to the federated learning users.

6. The group-verifiable chained privacy-preserving federated learning method according to claim 1, wherein Step S6 includes: Federated Learning User Judgment to determine whether it holds. If it holds, it means that the newly received global model parameters are correct; otherwise, discard the newly received global model parameters, where m is the number of user groups.

7. A group-verifiable chained privacy-preserving federated learning device, characterized in that Including: A global model parameter synchronization module, which is used to send the global model parameters to the federated learning users through the server; A local training module, which is used to use the global model parameters sent by the server as the local initial model parameters by the federated learning users, and perform training based on the local data to obtain new local model parameters; A local aggregation module, which is used to perform chained aggregation of the local models by different groups of federated learning users based on the new local model parameters and the random numbers sent by the server; An aggregation result sending module, which is used to send the local model aggregation result and the correctness verification label to the server by the last federated learning user in each group; A global aggregation module, which is used to aggregate the local model aggregation results and the correctness verification labels sent by different groups of federated learning users through the server to obtain new global model parameters and global verification labels, and send them to the federated learning users; A verification module, which is used to verify the correctness of the new global model parameters by the federated learning users according to the received global verification labels; Among them, the local aggregation module is specifically used to execute the following steps: S3.1: The first federated learning user in each group performs calculations through the formula to obtain the corresponding blinded local model parameters , and sends to the next user, where is the random number sent by the server to the first and last users in each group to protect the privacy of the first user, is the new local model parameters trained by the first federated learning user in the r-th round; S3.2: For other federated learning users in each group except the first and the last federated learning users, calculate according to the formula to obtain the blinded local model parameters corresponding to this user , and pass to the subsequent user, where r represents the current r-th iteration, represents the blinded local model parameters obtained by the (i - 1)-th user, is the new local model parameters trained by the i-th user in the r-th iteration; S3.3: The last federated learning user in each group, according to calculate the blinded local aggregated model parameters , and according to calculate the local aggregated model parameters of the current user group , take as the local model aggregation result of the current user group, where g represents the number of the last federated learning user in the chain structure.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed, it implements the method described in any one of claims 1 to 6.

9. A computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • Federal learning privacy protection system and method based on hierarchical aggregation and block chain

    CN114254386A

  • Privacy protection federal learning method oriented to edge computing scene

    CN114595830A