Horizontal Federated Model Construction Optimization Method, Electronic Device, Medium and Program Product

The method enhances federated learning by iteratively updating global models and client confidence scores based on local model evaluations, effectively reducing Byzantine attacks while maintaining privacy and accuracy.

CN115311023BActive Publication Date: 2025-07-15WEBANK (CHINA)
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211033101.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-26
Publication Date
2025-07-15
Estimated Expiration
2042-08-26

AI Technical Summary

Technical Problem

In federated learning, it is difficult for the prior art to effectively defend against Byzantine attacks, especially after client model parameters are encrypted, the detection accuracy is not high or the detection cannot be performed.

Method used

By implementing a horizontal federated model construction optimization method between the server and the client, the local model is sampled and aggregated by the client confidence, the model effect is evaluated, the candidate global model is selected and iteratively updated, the client confidence is improved, and the impact of malicious clients is reduced.

Benefits of technology

Effective defense against Byzantine attacks improves the model effect while ensuring the accuracy of client confidence and learning efficiency, and reducing the probability of impact of malicious clients.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115311023B_ABST
    Figure CN115311023B_ABST
Patent Text Reader

Abstract

The present application discloses a method for optimizing the construction of a horizontal federated model, an electronic device, a medium, and a program product, which are applied to a server side and include: sending the current global model to each client for the client to perform local training and update on the current global model according to local data to obtain a local model; receiving the local models sent by each client, sampling and selecting at least one set of local models from the local models according to the confidence levels of each client for aggregation to obtain each aggregated model; respectively feeding back each aggregated model to the corresponding target client for each target client to evaluate the model effect of each aggregated model by using local data; receiving the scores of the effects of each local model, selecting a candidate global model from each aggregated model according to the scores of the effects of each local model, and iteratively updating the current global model and the confidence levels of each client until the horizontal federated learning training ends. The present application solves the technical problem of how to defend against Byzantine attacks during the federated learning process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of artificial intelligence technology in financial technology (Fintech), and particularly to a method for optimizing the construction of a horizontal federated model, an electronic device, a medium, and a program product. Background Art

[0002] With the continuous development of financial technology, especially Internet technology finance, more and more technologies (such as distributed, artificial intelligence, etc.) are applied in the financial field. However, the financial industry also poses higher requirements for technologies, such as higher requirements for the distribution of to-do items corresponding to the financial industry.

[0003] As a distributed machine learning method, federated learning can solve the "data silo" problem. On the premise of protecting data privacy, it uses local data from multiple parties to build a shared federated model. However, federated learning is often vulnerable to malicious attacks, such as Byzantine attacks, that is, malicious clients upload malicious model parameter information to damage the performance of the global model. Therefore, how to defend against Byzantine attacks in federated learning is an important problem that needs to be solved urgently.

[0004] Currently, in order to defend against Byzantine attacks during the federated learning process, it is usually the server that detects the plaintext model parameters uploaded by the clients to detect Byzantine attackers among the clients. However, in order to protect the data privacy of the clients, the clients usually encrypt and protect the plaintext model parameters before uploading them to the server. For example, homomorphic encryption or differential privacy is used for encryption protection. For homomorphic encryption, since the encrypted ciphertext is completely different from the plaintext model parameters, it cannot be used to detect Byzantine attackers; for differential privacy, since noise is added to the plaintext model parameters, using the plaintext model parameters with added noise to detect Byzantine attackers will affect the detection accuracy. Therefore, in the current scenario where the plaintext model parameters uploaded by the clients are encrypted and protected, either Byzantine attack detection cannot be performed, resulting in the inability to defend against Byzantine attacks, or the accuracy of Byzantine attack detection is not high. Summary of the Invention

[0005] The main purpose of this application is to provide a method for optimizing the construction of a horizontal federated model, an electronic device, a medium, and a program product, aiming to solve the technical problem of how to defend against Byzantine attacks during the federated learning process.

[0006] To achieve the above objective, this application provides a method for optimizing the construction of a horizontal federated model, which is applied to the server. The method for optimizing the construction of a horizontal federated model includes:

[0007] Sending the current global model to each client for the client to perform local training and updating on the current global model according to local data to obtain a local model;

[0008] Receive the local models sent by each of the clients, and based on the client confidence levels corresponding to each of the clients, sample and select at least one set of local models from the local models for aggregation to obtain the aggregation models respectively corresponding to each set of local models;

[0009] Feed back each of the aggregation models to the corresponding target client respectively for each of the target clients to use the local data to evaluate the model effect of the received aggregation model to obtain the local model effect score;

[0010] Receive the local model effect scores fed back by each of the target clients, and based on each of the local model effect scores, select candidate global models from each of the aggregation models;

[0011] Iteratively update the current global model and each of the client confidence levels based on the candidate global models until the horizontal federated learning training ends.

[0012] To achieve the above object, the present application also provides a horizontal federated model construction optimization method, which is applied to a client, and the horizontal federated model construction optimization method includes:

[0013] Receive the current global model sent by the server, and based on the local data, perform local training and update on the current global model to obtain a local model;

[0014] Upload the local model to the server for the server to sample and select at least one set of local models from the local models based on the client confidence levels corresponding to each of the clients for aggregation to obtain the aggregation models respectively corresponding to each set of local models;

[0015] If the aggregation model fed back by the server is received, then based on the local data, evaluate the model effect of the aggregation model to obtain the local model effect score;

[0016] Upload the local model effect score to the server for the server to select candidate global models from each of the aggregation models based on each of the local model effect scores, and iteratively update the current global model and each of the client confidence levels based on the candidate global models until the horizontal federated learning training ends.

[0017] To achieve the above object, the present application also provides a horizontal federated model construction optimization method, which is applied to a server, and the horizontal federated model construction optimization method includes:

[0018] Send the current global model to each client for the client to perform local training and update on the current global model based on the local data to obtain a local model;

[0019] Receive the local models sent by each of the clients, and based on the client confidence levels corresponding to each of the clients, sample and select at least one set of local models from the local models for aggregation to obtain aggregation models corresponding to each set of local models;

[0020] Feedback each of the aggregation models to the corresponding target client respectively, so that each of the target clients can use the local data to evaluate the model effect of the received aggregation model to obtain a local model effect score;

[0021] Receive the local model effect scores fed back by each of the target clients, and based on the local model effect scores, select candidate global models from the aggregation models;

[0022] Iteratively update the current global model and each of the client confidence levels based on the candidate global models until the horizontal federated learning training ends.

[0023] This application also provides a horizontal federated model construction optimization device, which is applied to the server. The horizontal federated model construction optimization device includes:

[0024] A model distribution module, configured to distribute the current global model to each client, so that the client can perform local training and update on the current global model according to local data to obtain a local model;

[0025] An aggregation module, configured to receive the local models sent by each of the clients, and based on the client confidence levels corresponding to each of the clients, sample and select at least one set of local models from the local models for aggregation to obtain aggregation models corresponding to each set of local models;

[0026] A feedback module, configured to feedback each of the aggregation models to the corresponding target client respectively, so that each of the target clients can use the local data to evaluate the model effect of the received aggregation model to obtain a local model effect score;

[0027] A candidate global model selection module, configured to receive the local model effect scores fed back by each of the target clients, and based on the local model effect scores, select candidate global models from the aggregation models;

[0028] An iterative update module, configured to iteratively update the current global model and each of the client confidence levels based on the candidate global models until the horizontal federated learning training ends.

[0029] This application also provides a horizontal federated model construction optimization device, which is applied to the client. The horizontal federated model construction optimization device includes:

[0030] A local training update module, configured to receive the current global model sent by the server, and perform local training update on the current global model according to local data to obtain a local model;

[0031] A model upload module, configured to upload the local model to the server, so that the server samples and selects at least one group of local models from the local models according to the client confidence corresponding to each client, and aggregates them to obtain an aggregated model corresponding to each group of local models;

[0032] A model evaluation module, configured to, if receiving the aggregated model fed back by the server, perform model effect evaluation on the aggregated model according to the local data to obtain a local model effect score;

[0033] A score upload module, configured to upload the local model effect score to the server, so that the server selects a candidate global model from the aggregated models according to the local model effect scores, and iteratively updates the current global model and the client confidence of each client according to the candidate global model until the horizontal federated learning training ends.

[0034] The present application also provides an electronic device, where the electronic device includes: a memory, a processor, and a program of the horizontal federated model construction and optimization method stored on the memory and executable on the processor. When the program of the horizontal federated model construction and optimization method is executed by the processor, the steps of the horizontal federated model construction and optimization method as described above can be implemented.

[0035] The present application also provides a computer-readable storage medium, where a program for implementing the horizontal federated model construction and optimization method is stored on the computer-readable storage medium. When the program of the horizontal federated model construction and optimization method is executed by the processor, the steps of the horizontal federated model construction and optimization method as described above are implemented.

[0036] The present application also provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps of the horizontal federated model construction and optimization method as described above are implemented.

[0037] The present application provides a method for optimizing the construction of a horizontal federated model, an electronic device, a medium, and a program product. In the process of horizontal federated learning, the server first distributes the current global model to each client, so that the client can perform local training and update on the current global model according to local data to obtain a local model; receive the local models sent by each client, and sample and select at least one set of local models from the local models for aggregation according to the client confidence corresponding to each client, achieving the purpose of sampling and selecting multiple sets of local models from the local models for aggregation respectively according to the client confidence of each client, thereby obtaining multiple aggregated models; feedback each of the aggregated models to the corresponding target client, so that each target client can use the local data to evaluate the model effect of the received aggregated model to obtain a local model effect score, receive the local model effect scores feedback by each target client, and thus select the aggregated model with the best model effect from the aggregated models as the candidate global model according to the local model effect scores, and perform iterative updates on the current global model and each client confidence according to the candidate global model. In the present application, the aggregated model with the best model effect can be used as the new current global model and distributed to the client, and the client confidence corresponding to the candidate global model can be correspondingly increased to complete this round of iteration. Therefore, in the process of multiple rounds of iteration until the end of horizontal federated learning training, the client confidence of normal clients with good model effects will become higher and higher, while the client confidence of malicious clients with poor model effects will remain at a low level. Therefore, when sampling and selecting multiple sets of local models from the local models for aggregation respectively, the probability of the local models uploaded by malicious clients being selected will become lower and lower, thereby achieving the purpose of defending against Byzantine attacks by malicious clients and solving the technical problem of how to defend against Byzantine attacks in the process of federated learning. Description of the Drawings

[0038] The drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with the present application and used together with the specification to explain the principles of the present application.

[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, other drawings can also be obtained based on these drawings without creative efforts.

[0040] Figure 1 It is a flowchart of the first embodiment of the method for optimizing the construction of the horizontal federated model of the present application;

[0041] Figure 2It is a schematic diagram of the interaction between the server and multiple clients in the horizontal federated model construction optimization method in this application;

[0042] Figure 3 It is a schematic flowchart of the second embodiment of the horizontal federated model construction optimization method in this application;

[0043] Figure 4 It is a schematic diagram of the device structure of an embodiment of the horizontal federated model construction optimization device in this application;

[0044] Figure 5 It is a schematic diagram of the device structure of another embodiment of the horizontal federated model construction optimization device in this application;

[0045] Figure 6 It is a schematic diagram of the device structure of the hardware operating environment involved in the horizontal federated model construction optimization method in the embodiments of this application.

[0046] The realization of the purpose, functional features and advantages of this application will be further described with reference to the embodiments and the accompanying drawings. Detailed Embodiments

[0047] To make the above objects, features and advantages of this application more obvious and understandable, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of this application without creative efforts shall fall within the scope of protection of this application.

[0048] Embodiment 1

[0049] The embodiments of this application provide a horizontal federated model construction optimization method. In the first embodiment of the horizontal federated model construction optimization method in this application, with reference to Figure 1 and Figure 2 , the method of this embodiment is applied to the server, and the horizontal federated model construction optimization method includes:

[0050] Step S10: Send the current global model to each client, so that the client can perform local training and update on the current global model according to local data to obtain a local model;

[0051] Step S20: Receive the local models sent by each client, and sample and select at least one group of local models from the local models according to the client confidence corresponding to each client to obtain an aggregated model corresponding to each group of local models;

[0052] Step S30: Feed each of the aggregation models back to the corresponding target client, so that each target client can use the local data to evaluate the model effect of the received aggregation model and obtain a local model effect score.

[0053] Step S40: Receive the local model effect scores fed back by each target client, and select a candidate global model from each of the aggregation models according to the local model effect scores.

[0054] Step S50: Iteratively update the current global model and the client confidence levels based on the candidate global model until the horizontal federated learning training ends.

[0055] In this embodiment, it should be noted that the client can be a participant in horizontal federated learning, and the server can be a coordinator of horizontal federated learning; the current global model can be an initialized global model or a global model generated during a certain round of iteration in horizontal federated learning; the client confidence level is the credit score of the client. The lower the client confidence level, the more likely the corresponding client is a malicious attacker, that is, a Byzantine attacker. Among them, the initial confidence levels of each client can be set before federated learning, and the initial confidence levels of each client can be set to the same value, such as 1.

[0056] As an example, steps S10 to S50 include: obtaining the current global model, and sending the current global model to each client, so that the client can locally train and update the current global model according to the training sample set extracted from the local data to obtain a local model; receiving the local models sent by each client, and performing multiple rounds of sampling on each local model according to the sampling probability corresponding to the client confidence of each client to obtain at least one set of local models, where one set of local models is obtained in each round of sampling; aggregating each set of local models respectively to obtain an aggregation model corresponding to each set of local models, where one set of local models corresponds to one aggregation model; respectively feedbacking each aggregation model to the corresponding target client, so that the target client can use the test sample set extracted from the local data to evaluate the received aggregation model to obtain a local model effect score, where the target client is the client that uploads the local model used for aggregating to obtain the aggregation model; receiving the local model effect scores feedbacked by each target client, and selecting the aggregation model with the best model effect among each aggregation model according to at least one local model effect score corresponding to each aggregation model as the candidate global model; updating the current global model to the candidate global model, and increasing the client confidence of at least one client corresponding to the candidate global model, that is, increasing the confidence of the client that uploads the local model used for aggregating to obtain the candidate global model, and returning to execute the step: sending the current global model to each client until the horizontal federated learning training ends.

[0057] In addition, the local model sent by the client to the server can be an encrypted local model. For example, it can be a ciphertext local model in the state of homomorphic encryption. Thus, the server can sample and select the ciphertext local models for aggregation to obtain a ciphertext aggregation model in the state of homomorphic encryption. Steps S10 to S50 include: sending the current ciphertext global model to each client for the client to decrypt the current ciphertext global model to obtain the current global model, locally training and updating the current global model according to local data to obtain a local model, and performing homomorphic encryption on the local model to obtain a ciphertext local model; receiving the ciphertext local models sent by each client, and sampling and selecting at least one group of ciphertext local models for aggregation from each local model according to the client confidence corresponding to each client to obtain a ciphertext aggregation model corresponding to each group of ciphertext local models; respectively feeding back each ciphertext aggregation model to the corresponding target client for each target client to decrypt the received ciphertext aggregation model and using the local data to evaluate the model effect of the decrypted aggregation model to obtain a local model effect score; receiving the local model effect scores fed back by each target client, and selecting a candidate ciphertext global model from each ciphertext aggregation model according to each local model effect score; and iteratively updating the current ciphertext global model and each client confidence according to the candidate ciphertext global model until the horizontal federated learning training ends.

[0058] In the embodiment of the present application, the ciphertext aggregation model with the best model effect can be used as the new current ciphertext global model and distributed to the clients, and the client confidence corresponding to the candidate ciphertext global model can be correspondingly improved to complete this round of iteration. Thus, in the process of multiple rounds of iteration until the horizontal federated learning training ends, the client confidence of normal clients with good model effects will be higher and higher, while the client confidence of malicious clients with poor model effects will remain at a low level. Therefore, when sampling and selecting multiple groups of ciphertext local models from each ciphertext local model for aggregation respectively, the probability that the malicious client uploads the ciphertext local model and is selected will be lower and lower. Thus, compared with the scenario where the Byzantine attack of malicious clients can be defended in the case of encrypting the models uploaded by the clients, and since the embodiment of the present application does not directly use the local model itself for Byzantine attack detection, the success rate of defending against the Byzantine attack will not be affected due to the encryption of the local model, and the effectiveness of Byzantine attack defense can be ensured. Among them, the local model uploaded by the client can be the model network parameters of the local model or the gradient information of the local model.

[0059] Among them, the step of selecting a candidate global model from each aggregation model according to each local model effect score includes:

[0060] Step S41: Aggregate the at least one local model effectiveness scores corresponding to each of the aggregation models respectively to obtain the global model effectiveness scores corresponding to each of the aggregation models.

[0061] Step S42: Select the candidate global model from each of the aggregation models according to the global effectiveness scores.

[0062] In this embodiment, it should be noted that the number of local model effectiveness scores corresponding to the aggregation model is the same as the number of local models used for aggregating to obtain the aggregation model. For example, if an aggregation model is obtained by aggregating 10 local models, there will be 10 local model effectiveness scores feedback by clients.

[0063] As an example, steps S41 to S42 include: Aggregate the multiple local model effectiveness scores corresponding to each aggregation model respectively according to a preset aggregation method to obtain the global model effectiveness scores corresponding to each of the aggregation models, where the preset aggregation method can be to find the median or to find the average value; Select the aggregation model with the highest global model effectiveness score as the candidate global model.

[0064] As an example, since malicious clients will upload incorrect local models to affect the performance of the global model, if a malicious client's uploaded local model is sampled and aggregated to obtain a first type of aggregation model, the model effectiveness of this first type of aggregation model will obviously be weaker than that of a second type of aggregation model obtained by sampling and aggregating local models uploaded by normal clients. Therefore, when using the global model effectiveness scores corresponding to multiple local model effectiveness scores to select the candidate global model, the probability that the second type of aggregation model is selected as the candidate global model is much higher than that of the first type of aggregation model. Therefore, when updating the client confidence level, there is a high probability of increasing the client confidence level of normal clients. After multiple rounds of iteration, the client confidence level of normal clients will become higher and higher, while the client confidence level of malicious clients will remain at a low level, and the probability that the local models uploaded by malicious clients are selected will become lower and lower, thus achieving the purpose of defending against the Byzantine attack of malicious clients.

[0065] In the embodiment of the present application, a malicious client may also deliberately upload a relatively high local model effectiveness score when uploading the local model effectiveness score. However, since the median or average value of the multiple local model effectiveness scores corresponding to the aggregation model is used as the global model effectiveness score in the embodiment of the present application, and a single local model effectiveness score is used as the basis for selecting the candidate global model, even if a malicious client maliciously uploads a relatively high local model effectiveness score, it will not affect the accuracy of selecting the candidate global model using the global model effectiveness score, thus improving the success rate of defending against the Byzantine attack.

[0066] Among them, iteratively updating the current global model and each client confidence according to the candidate global model includes:

[0067] Step S51: Determine whether to discard the candidate global model according to the global effect score corresponding to the candidate global model;

[0068] Step S52: If not, update the current global model to the candidate global model, and increase the client confidence of each client corresponding to the candidate global model, and return to execute the step: send the current global model to each client;

[0069] Step S53: If so, discard the candidate global model, and return to execute the step: send the current global model to each client.

[0070] As an example, steps S51 to S53 include: If the global effect score corresponding to the candidate global model is greater than the preset minimum score threshold, it proves that the model effect of the candidate global model is too poor, and then discard the candidate global model, and directly return to execute the step: send the current global model to each client for the next round of iteration; If the global effect score corresponding to the candidate global model is not greater than the preset minimum score threshold, it proves that the model effect of the candidate global model is not bad, and then update the current global model to the candidate global model, and increase the client confidence of each client corresponding to the candidate global model, and return to execute the step: send the current global model to each client for the next round of iteration.

[0071] The embodiment of the present application realizes judging whether the candidate global model has the value of being a real global model according to whether the global model effect score of the candidate global model is too low. Therefore, in the embodiment of the present application, the candidate global model with a higher global model effect score, that is, a better model effect, is always used to update the current global model, so that the current global model will generally be updated in the direction of better model effect, improving the efficiency of horizontal federated learning modeling.

[0072] Among them, the step of determining whether to discard the candidate global model according to the global effect score corresponding to the candidate global model includes:

[0073] Step S511: Determine whether the global effect score is less than the preset score threshold, where the preset score threshold is the maximum global effect score generated before this round of iteration;

[0074] Step S512: If it is less, discard the candidate global model;

[0075] Step S513: If it is not less, do not discard the candidate global model.

[0076] As an example, steps S511 to S513 include: determining whether the global effect score is less than a preset score threshold, where the preset score threshold is the maximum global effect score generated before this round of iteration; if it is less, discarding the candidate global model; if it is not less, not discarding the candidate global model, and updating the preset score threshold to the current global effect score.

[0077] The embodiments of the present application can always use a candidate global model with better model effect to update the current global model, so that the current global model is always updated in the direction of better model effect during each round of iteration, improving the efficiency of horizontal federated learning modeling.

[0078] Among them, the step of sampling and selecting at least one group of local models from each of the local models according to the client confidence levels corresponding to the clients to obtain an aggregation model corresponding to each group of local models includes:

[0079] Step S21, determining the sampling probability corresponding to each local model according to the client confidence levels;

[0080] Step S22, sampling and selecting each group of local models from each of the local models according to the sampling probabilities, where one group of local models consists of a preset number of local models;

[0081] Step S23, aggregating each group of local models respectively to obtain each aggregation model.

[0082] In this embodiment, it should be noted that the higher the client confidence level of the client, the higher the probability that the local model uploaded by the client is sampled and selected.

[0083] As an example, steps S21 to S23 include: normalizing each of the client confidence levels to obtain the sampling probability corresponding to each local model; performing multi-round sampling in each of the local models according to the sampling probabilities to obtain each group of local models, where one group of local models is selected in each round of sampling, and one group of local models consists of a preset number of local models; aggregating each group of local models respectively according to a preset model aggregation method to obtain an aggregation model corresponding to each group of local models, where the preset model aggregation method can be weighted average or weighted summation, etc. For example, assume that there are 3 clients A, B, and C, the client confidence level of A is 10, the client confidence level of B is 10, and the client confidence level of C is 20. After normalization, the sampling probability of the local model uploaded by A is 25%, the sampling probability of the local model uploaded by B is 25%, and the sampling probability of the local model uploaded by C is 50%.

[0084] As an example, the local data may be local multimedia data, such as image data or audio data, etc., the local model may be a local object detection model, such as an image object detection model or an audio object detection model, etc., and the current global model may be a current global object detection model. The method for optimizing the construction of the horizontal federated model is as follows:

[0085] Step A10: Send the current global object detection model to each client, so that the client can perform local training and update on the current global object detection model according to the local multimedia data to obtain a local object detection model;

[0086] Step A20: Receive the local object detection models sent by each client, and sample and select at least one group of local object detection models for aggregation among the local object detection models according to the client confidence corresponding to each client to obtain an aggregated object detection model corresponding to each group of local object detection models;

[0087] Step A30: Feed back each of the aggregated object detection models to the corresponding target client, so that each target client can use the local multimedia data to evaluate the model effect of the received aggregated object detection model to obtain a local model effect score;

[0088] Step A40: Receive the local model effect scores fed back by each target client, and select a candidate global object detection model from the aggregated object detection models according to the local model effect scores;

[0089] Step A50: Iteratively update the current global object detection model and the client confidence according to the candidate global object detection model until the horizontal federated learning training ends.

[0090] An embodiment of the present application provides a method for defending against Byzantine attacks when constructing a global object detection model based on horizontal federated learning. During the process of constructing a global object detection model based on horizontal federated learning, the aggregated object detection model with the best model effect can be used as the new current global object detection model and distributed to the clients, and the confidence levels of the clients corresponding to the candidate global object detection models can be improved accordingly to complete one iteration. Therefore, during multiple iterations until the end of horizontal federated learning training, the client confidence levels of normal clients with good model effects will become higher and higher, while the client confidence levels of malicious clients with poor model effects will remain at a low level. Therefore, when sampling and selecting multiple groups of local object detection models from each of the local object detection models for aggregation respectively, the probability of the local object detection models uploaded by malicious clients being selected will become lower and lower, thereby achieving the purpose of defending against Byzantine attacks by malicious clients and solving the technical problem of how to defend against Byzantine attacks during the process of constructing an object detection model based on horizontal federated learning.

[0091] The embodiment of the present application provides a method for optimizing the construction of a horizontal federated model, an electronic device, a medium, and a program product. In the process of horizontal federated learning, the server first distributes the current global model to each client, so that the client can perform local training and update on the current global model according to local data to obtain a local model; receive the local models sent by each client, and sample and select at least one group of local models from the local models for aggregation according to the client confidence corresponding to each client, achieving the purpose of sampling and selecting multiple groups of local models from the local models for aggregation respectively based on the client confidence of each client, thereby obtaining multiple aggregated models; feedback each aggregated model to the corresponding target client respectively, so that each target client can use the local data to evaluate the model effect of the received aggregated model to obtain a local model effect score, receive the local model effect scores feedback by each target client, and then select the aggregated model with the best model effect from the aggregated models as the candidate global model according to the local model effect scores, and perform iterative updates on the current global model and each client confidence based on the candidate global model. In the embodiment of the present application, the aggregated model with the best model effect can be used as the new current global model and distributed to the client, and the client confidence corresponding to the candidate global model can be correspondingly improved to complete this round of iteration. Thus, in the process of multiple rounds of iteration until the end of horizontal federated learning training, the client confidence of normal clients with good model effects will become higher and higher, while the client confidence of malicious clients with poor model effects will remain at a low level. Therefore, when sampling and selecting multiple groups of local models from the local models for aggregation respectively, the probability of the local models uploaded by malicious clients being selected will become lower and lower, thereby achieving the purpose of defending against the Byzantine attack of malicious clients and solving the technical problem of how to defend against the Byzantine attack in the process of federated learning.

[0092] Embodiment 2

[0093] The embodiment of the present application also provides a method for optimizing the construction of a horizontal federated model. The method of this embodiment is applied to a client. Refer to Figure 2 and Figure 3 , the method for optimizing the construction of the horizontal federated model includes:

[0094] Step B10, receive the current global model distributed by the server, and perform local training and update on the current global model according to local data to obtain a local model;

[0095] Step B20, upload the local model to the server, so that the server samples and selects at least one group of local models from the local models for aggregation according to the client confidence corresponding to each client to obtain aggregated models corresponding to each group of local models;

[0096] Step B30: If the aggregated model feedback from the server is received, evaluate the model effect of the aggregated model based on the local data to obtain a local model effect score.

[0097] Step B40: Upload the local model effect score to the server, so that the server can select a candidate global model from the aggregated models according to each local model effect score, and iteratively update the current global model and each client confidence level based on the candidate global model until the horizontal federated learning training ends.

[0098] As an example, steps B10 to B40 include: receiving the current global model issued by the server, locally training and updating the current global model according to the training sample set extracted from the local data to obtain a local model; uploading the local model to the server for the server to sample and select at least one group of local models from the local models according to the client confidence levels corresponding to each client to perform aggregation to obtain aggregated models corresponding to each group of local models. The specific implementation process of the server aggregating to obtain each aggregated model can refer to the content in the above steps S10 to S50 and their detailed steps, which will not be elaborated here; if the aggregated model feedback from the server is received, evaluate the model effect of the aggregated model according to the test sample set extracted from the local data to obtain a local model effect score; upload the local model effect score to the server for the server to select a candidate global model from the aggregated models according to each local model effect score, and iteratively update the current global model and each client confidence level based on the candidate global model until the horizontal federated learning training ends. The specific implementation process of the server iteratively updating the current global model and each client confidence level until the horizontal federated learning training ends can refer to the content in the above steps S10 to S50 and their detailed steps, which will not be elaborated here.

[0099] Among them, the local data includes at least one local test sample. The step of evaluating the model effect of the aggregated model based on the local data to obtain a local model effect score includes:

[0100] Step B31: Use the aggregated model to perform model prediction on each local test sample to obtain a test output sample label corresponding to each local test sample.

[0101] Step B32: Test the prediction accuracy of the aggregated model according to each test output sample label and the preset true sample label corresponding to each local test sample to obtain the local model effect score.

[0102] As an example, steps B31 to B32 include: using the aggregation model to perform model prediction on each of the local test samples to obtain test output sample labels corresponding to each of the local test samples; calculating the difference between each of the test output sample labels and the preset true sample labels corresponding to each of the local test samples to obtain label losses corresponding to each of the test output samples; screening the proportion of the number of labels of each label loss not greater than the preset label loss threshold among each of the label losses, and determining the local model effect score according to the proportion. For example, assuming that there are 4 label losses of 0.01, 0.1, 0.2, and 0.3, and the preset label loss threshold is 0.2, then the proportion of the number of labels of each label loss not greater than the preset label loss threshold is 75%, so the local model effect score can be obtained as 75 points.

[0103] The embodiment of the present application provides an optimization method for constructing a horizontal federated model. In this horizontal federated learning process, the client first receives the current global model sent by the server, and performs local training and update on the current global model according to local data to obtain a local model; uploads the local model to the server, so that the server samples and selects at least one group of local models from each of the local models for aggregation according to the client confidence corresponding to each client, achieving the purpose of sampling and selecting multiple groups of local models from each of the local models for aggregation respectively according to the client confidence of each client, thereby obtaining multiple aggregation models; if receiving the aggregation model fed back by the server, then performing model effect evaluation on the aggregation model according to the local data to obtain a local model effect score; uploading the local model effect score to the server for the server to select a candidate global model from each of the aggregation models according to each of the local model effect scores, and iteratively updating the current global model and each of the client confidences according to the candidate global model. In the embodiment of the present application, the aggregation model with the best model effect can be used as the new current global model and distributed to the client, and the client confidences corresponding to the candidate global model can be correspondingly improved to complete this round of iteration. Thus, in the process of multiple rounds of iteration until the end of the horizontal federated learning training, the client confidence of the normal client with good model effect will be higher and higher, while the client confidence of the malicious client with poor model effect will remain at a low level. Therefore, when sampling and selecting multiple groups of local models from each of the local models for aggregation, the probability of the local model uploaded by the malicious client being selected will be lower and lower, thereby achieving the purpose of defending against the Byzantine attack of the malicious client and solving the technical problem of how to defend against the Byzantine attack in the process of federated learning.

[0104] Embodiment III

[0105] Refer to Figure 4, an embodiment of the present application further provides a horizontal federated model construction optimization device, which is applied to a server. The horizontal federated model construction optimization device includes:

[0106] A model distribution module, configured to distribute the current global model to each client, so that the client can perform local training and update on the current global model according to local data to obtain a local model;

[0107] An aggregation module, configured to receive the local models sent by each client, and sample and select at least one group of local models from the local models according to the client confidence corresponding to each client, and aggregate them to obtain an aggregation model corresponding to each group of local models;

[0108] A feedback module, configured to feedback each aggregation model to the corresponding target client, so that each target client can use the local data to evaluate the received aggregation model to obtain a local model effect score;

[0109] A candidate global model selection module, configured to receive the local model effect scores feedback by each target client, and select a candidate global model from each aggregation model according to each local model effect score;

[0110] An iterative update module, configured to iteratively update the current global model and each client confidence according to the candidate global model until the horizontal federated learning training ends.

[0111] Optionally, the candidate global model selection module is further configured to:

[0112] Aggregate at least one local model effect score corresponding to each aggregation model respectively to obtain a global model effect score corresponding to each aggregation model;

[0113] Select the candidate global model from each aggregation model according to each global effect score.

[0114] Optionally, the iterative update module is further configured to:

[0115] Judge whether to discard the candidate global model according to the global effect score corresponding to the candidate global model;

[0116] If not, update the current global model to the candidate global model, and increase the client confidence of each client corresponding to the candidate global model, and return to execute the step: distribute the current global model to each client;

[0117] If so, discard the candidate global model, and return to execute the step: distribute the current global model to each client.

[0118] Optionally, the iterative update module is further configured to:

[0119] Determine whether the global effect score is less than a preset score threshold, where the preset score threshold is the maximum global effect score generated before this round of iteration;

[0120] If it is less, discard the candidate global model;

[0121] If it is not less, do not discard the candidate global model.

[0122] Optionally, the aggregation module is further configured to:

[0123] Determine the sampling probability corresponding to each local model according to each client confidence;

[0124] Sample and select each group of local models from each local model according to each sampling probability, where a group of local models consists of a preset number of local models;

[0125] Aggregate each group of local models respectively to obtain each aggregation model.

[0126] The horizontal federated model construction optimization device provided by the embodiments of the present application adopts the horizontal federated model construction optimization method in the above embodiments, and solves the technical problem of how to defend against Byzantine attacks during the federated learning process. Compared with the prior art, the beneficial effects of the horizontal federated model construction optimization device provided by the embodiments of the present application are the same as those of the horizontal federated model construction optimization method provided by the above embodiments, and other technical features in the horizontal federated model construction optimization device are the same as the features disclosed in the above embodiment method, and will not be elaborated here.

[0127] Embodiment 4

[0128] The embodiments of the present application further provide a horizontal federated model construction optimization device, which is applied to a client. The horizontal federated model construction optimization device includes:

[0129] A local training and update module, configured to receive the current global model sent by the server, and perform local training and update on the current global model according to local data to obtain a local model;

[0130] A model upload module, configured to upload the local model to the server, so that the server samples and selects at least one group of local models from each local model according to the client confidence corresponding to each client for aggregation, to obtain an aggregation model corresponding to each group of local models;

[0131] A model evaluation module, configured to, if receiving the aggregated model fed back by the server, evaluate the effect of the aggregated model according to the local data to obtain a local model effect score;

[0132] A score uploading module, configured to upload the local model effect score to the server, so that the server can select a candidate global model from the aggregated models according to the local model effect scores, and iteratively update the current global model and the client confidences according to the candidate global model until the horizontal federated learning training ends.

[0133] Optionally, the local data includes at least one local test sample, and the model evaluation module is further configured to:

[0134] Use the aggregated model to perform model prediction on each local test sample to obtain a test output sample label corresponding to each local test sample;

[0135] According to each test output sample label and the preset true sample label corresponding to each local test sample, test the prediction accuracy of the aggregated model to obtain the local model effect score.

[0136] The horizontal federated model construction optimization device provided by the embodiments of the present application adopts the horizontal federated model construction optimization method in the above embodiments, and solves the technical problem of how to defend against Byzantine attacks in the process of federated learning. Compared with the prior art, the beneficial effects of the horizontal federated model construction optimization device provided by the embodiments of the present application are the same as those of the horizontal federated model construction optimization method provided by the above embodiments, and other technical features in the horizontal federated model construction optimization device are the same as those disclosed in the above embodiment method, and will not be elaborated here.

[0137] Embodiment Five

[0138] The embodiments of the present application provide an electronic device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the horizontal federated model construction optimization method in Embodiment One above.

[0139] Next, refer to Figure 6 , which shows a schematic structural diagram of an electronic device suitable for implementing the embodiments of the present disclosure. The electronic device in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc.Figure 6 The illustrated electronic device is merely an example and should not impose any limitations on the functions and scope of use of the embodiments of the present disclosure.

[0140] As Figure 6 shown, the electronic device may include a processing device (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) or the program loaded from the storage device into the random access memory (RAM). In the RAM, various programs and data required for the operation of the electronic device are also stored. The processing device, ROM, and RAM are interconnected through a bus. The input / output (I / O) interface is also connected to the bus.

[0141] Generally, the following systems may be connected to the I / O interface: input devices including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; output devices including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; storage devices including, for example, magnetic tape, a hard disk, etc.; and a communication device. The communication device may allow the electronic device to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows an electronic device with various systems, it should be understood that it is not required to implement or have all the shown systems. More or fewer systems may be alternatively implemented or had.

[0142] In particular, according to the embodiments of the present disclosure, the processes described above with reference to the flowcharts may be implemented as computer software programs. For example, the embodiments of the present disclosure include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program may be downloaded and installed from the network through the communication device, or installed from the storage device, or installed from the ROM. When the computer program is executed by the processing device, the above-mentioned functions defined in the methods of the embodiments of the present disclosure are executed.

[0143] The electronic device provided in this application adopts the horizontal federated model construction optimization method in the above embodiments, and solves the technical problem of how to defend against Byzantine attacks during the federated learning process. Compared with the prior art, the beneficial effects of the electronic device provided in the embodiments of this application are the same as those of the horizontal federated model construction optimization method provided in the above embodiments, and other technical features in this electronic device are the same as those disclosed in the above embodiment methods, which will not be elaborated here.

[0144] It should be understood that each part of the present disclosure may be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics may be combined in a suitable manner in any one or more embodiments or examples.

[0145] As described above, this is only the specific implementation manner of the present application. However, the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims described above.

[0146] Embodiment Six

[0147] This embodiment provides a computer-readable storage medium having computer-readable program instructions stored thereon, and the computer-readable program instructions are used to execute the method for optimizing the construction of the horizontal federated model in the first embodiment above.

[0148] The computer-readable storage medium provided by the embodiments of the present application may be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium may be any tangible medium that contains or stores a program, and this program can be used by or in conjunction with an instruction execution system, device, or device. The program code contained on the computer-readable storage medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0149] The above computer-readable storage medium may be included in an electronic device; or it may exist separately without being assembled into the electronic device.

[0150] The above computer-readable storage medium stores one or more programs which, when executed by an electronic device, cause the electronic device to: send the current global model to each client for the client to perform local training and update on the current global model according to local data to obtain a local model; receive the local models sent by each client, and sample and select at least one set of local models from the local models for aggregation according to the client confidence levels corresponding to the clients to obtain aggregation models respectively corresponding to the sets of local models; send each aggregation model back to the corresponding target client for each target client to use the local data to evaluate the model effect of the received aggregation model to obtain a local model effect score; receive the local model effect scores fed back by each target client, select a candidate global model from the aggregation models according to the local model effect scores; and iteratively update the current global model and the client confidence levels according to the candidate global model until the horizontal federated learning training ends.

[0151] Alternatively, receive the current global model sent by the server, perform local training and update on the current global model according to local data to obtain a local model; upload the local model to the server for the server to sample and select at least one set of local models from the local models for aggregation according to the client confidence levels corresponding to the clients to obtain aggregation models respectively corresponding to the sets of local models; if receiving the aggregation model fed back by the server, evaluate the model effect of the aggregation model according to the local data to obtain a local model effect score; and upload the local model effect score to the server for the server to select a candidate global model from the aggregation models according to the local model effect scores and iteratively update the current global model and the client confidence levels according to the candidate global model until the horizontal federated learning training ends.

[0152] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., connected through the Internet using an Internet service provider).

[0153] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a part of code, which contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0154] The modules described in the embodiments of the present disclosure can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation to the unit itself in some cases.

[0155] The computer-readable storage medium provided by the present application stores computer-readable program instructions for executing the above-mentioned horizontal federated model construction optimization method, and solves the technical problem of how to defend against Byzantine attacks during the federated learning process. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by the embodiments of the present application are the same as those of the horizontal federated model construction optimization method provided by the above embodiments, and will not be elaborated here.

[0156] Embodiment Seven

[0157] The present application also provides a computer program product, including a computer program, which when executed by a processor implements the steps of the horizontal federated model construction optimization method as described above.

[0158] The computer program product provided by the present application solves the technical problem of how to defend against Byzantine attacks during the federated learning process. Compared with the prior art, the beneficial effects of the computer program product provided by the embodiments of the present application are the same as those of the horizontal federated model construction optimization method provided by the above embodiments, and will not be elaborated here.

[0159] The above are only the preferred embodiments of the present application, and do not limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the specification and drawings of the present application, or directly or indirectly applied in other related technical fields, are similarly included in the patent scope of the present application.

Claims

1. A method for optimizing the construction of a horizontal federated model, characterized in that, Applied to the server, the horizontal federated model construction optimization method includes: Sending the current global model to each client for the client to perform local training and update on the current global model according to local data to obtain a local model; Receiving the local models sent by each client, and sampling and selecting at least one group of local models from the local models for aggregation according to the client confidence corresponding to each client to obtain an aggregation model corresponding to each group of local models; Feeding back each aggregation model to the corresponding target client for each target client to evaluate the model effect of the received aggregation model using the local data to obtain a local model effect score; Receiving the local model effect scores fed back by each target client, and selecting a candidate global model from the aggregation models according to the local model effect scores; Iteratively updating the current global model and each client confidence according to the candidate global model until the horizontal federated learning training ends; The iteratively updating the current global model and each client confidence according to the candidate global model includes: Judging whether the global effect score corresponding to the candidate global model is less than a preset score threshold, where the preset score threshold is the maximum global effect score generated before this round of iteration; If it is not less than, updating the current global model to the candidate global model, and increasing the client confidence of each client corresponding to the candidate global model, and returning to execute the step: sending the current global model to each client; If it is less than, discarding the candidate global model, and returning to execute the step: sending the current global model to each client.

2. The horizontal federated model construction optimization method according to claim 1, wherein The step of selecting a candidate global model from the aggregation models according to the local model effect scores includes: Aggregating at least one local model effect score corresponding to each aggregation model respectively to obtain a global model effect score corresponding to each aggregation model; Selecting the candidate global model from the aggregation models according to the global model effect scores.

3. The horizontal federated model construction optimization method according to claim 1, wherein The step of sampling and selecting at least one group of local models from the local models for aggregation according to the client confidence corresponding to each client to obtain an aggregation model corresponding to each group of local models includes: Determining the sampling probability corresponding to each local model according to each client confidence; Sampling and selecting each group of local models from the local models according to each sampling probability, where a group of local models consists of a preset number of local models; Aggregating each group of local models respectively to obtain each aggregation model.

4. A method for optimizing the construction of a horizontal federated model, characterized in that, Applied to the client, the horizontal federated model construction optimization method includes: Receiving the current global model sent by the server, and performing local training and update on the current global model according to local data to obtain a local model; Uploading the local model to the server for the server to sample and select at least one group of local models from the local models for aggregation according to the client confidence corresponding to each client to obtain an aggregation model corresponding to each group of local models; If the aggregated model fed back by the server is received, then according to the local data, the model effect of the aggregated model is evaluated to obtain a local model effect score; The local model effect score is uploaded to the server for the server to select a candidate global model from the aggregated models according to the local model effect scores, and determine whether the global effect score corresponding to the candidate global model is less than a preset score threshold, where the preset score threshold is the maximum global effect score generated before this round of iteration; if not less than, then update the current global model to the candidate global model, and increase the client confidence of each client corresponding to the candidate global model, and return to execute the step: send the current global model to each client; if less than, then discard the candidate global model, and return to execute the step: send the current global model to each client until the horizontal federated learning training ends.

5. The horizontal federated model construction optimization method according to claim 4, wherein The local data includes at least one local test sample, The step of evaluating the model effect of the aggregated model according to the local data to obtain a local model effect score includes: Using the aggregated model to perform model prediction on each local test sample to obtain a test output sample label corresponding to each local test sample; According to each test output sample label and the preset true sample label corresponding to each local test sample, test the prediction accuracy of the aggregated model to obtain the local model effect score.

6. An electronic device, characterized in that, The electronic device includes: At least one processor; and, A memory communicatively connected to the at least one processor; wherein, The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the steps of the horizontal federated model construction optimization method according to any one of claims 1 to 5.

7. A computer-readable storage medium, characterized in that, A program for implementing the horizontal federated model construction optimization method is stored on the computer-readable storage medium, and the program for implementing the horizontal federated model construction optimization method is executed by a processor to implement the steps of the horizontal federated model construction optimization method according to any one of claims 1 to 5.

8. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the horizontal federated model construction optimization method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Transverse federated learning optimization method and device based on semi-supervision and storage medium

    CN111275207A

  • Transverse federated learning modeling optimization method, equipment, medium and program product

    CN113516254A