Method for risk assessment index based on gradient leakage input of fully connected network model

CN115618404BActive Publication Date: 2026-10-09GUANGZHOU UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211115785.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-14
Publication Date
2026-10-09
Estimated Expiration
2042-09-14

AI Technical Summary

Technical Problem

问题的原因在于方法并没有给出多分类训练任务和多样本输入的输入求解方案

Benefits of technology

1、该基于全连接网络模型梯度泄露输入的风险评估指标的方法,与现有的梯度泄露输入的指标相比,本发明提出的评估方法是高效的且更符合现实的评估需求,本方法不依赖于任何预训练的统计模型,适用于被普遍采用的多分类多输入样本的模型训练任务;本方案提出的指标是准确的,具备严格的理论依据。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115618404B_ABST
    Figure CN115618404B_ABST
Patent Text Reader

Abstract

The present application relates to the field of artificial intelligence, and discloses a risk assessment index method based on gradient leakage input of a full connection network model, comprising the following steps: S1: constructing a gradient and input relationship equation of a multi-classification multi-input task; S2: calculating the rank and condition number of the coefficient matrix under four risk levels to assess the risk of gradient leakage data; S3: starting from the first risk level, until a certain risk level meets the standard, then the risk level of the gradient leakage data of the current model is authenticated. Compared with the existing gradient leakage input index, the evaluation method proposed by the present application is efficient and more in line with the actual evaluation needs. The method provided by the present application does not depend on any pre-trained statistical model and is suitable for model training tasks of multi-classification multi-input samples which are widely used. The index proposed by the present application is accurate and has a strict theoretical basis.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data privacy protection in federated learning within the field of artificial intelligence, specifically a method for risk assessment of gradient leakage input based on fully connected network models. Background Technology

[0002] With the significant improvement in information processing capabilities and computing efficiency, a large number of deep learning-based applications have emerged that process data such as images, text, and speech. Deep learning models and applications rely on large amounts of high-quality data; however, in reality, few single entities possess such vast amounts of data. Insufficient data volume or low data quality makes it difficult to support the construction and application of deep learning models. Collecting the relevant data from various entities raises issues of data copyright and privacy protection. Therefore, federated learning models, designed to aggregate data to achieve economies of scale while protecting data copyright and privacy, have been developed and are gradually being applied. Federated learning is a distributed deep learning framework where multiple participants or computing nodes share aggregated machine learning model gradient parameters without directly exchanging data, thus resolving the contradiction between data sharing and privacy protection.

[0003] Recent research on the effectiveness of privacy protection in federated learning has confirmed that input data can be reconstructed based on model gradients through certain methods. This means that the privacy protection mechanism of sharing model gradients in federated learning still carries the risk of data leakage. Furthermore, different input samples have different feature values, and the risk of leakage varies depending on the input sample. This invention, by constructing gradient and input equations, theoretically designs a set of risk assessment indicators and methods for gradient leakage data.

[0004] Based on the above, the existing solution is as follows: Scheme [1]: The invention includes the following steps: ① Sampling the local dataset used by a participant in federated learning for input to the local model to obtain a local sampled dataset; ② Using the local sampled dataset to train the local model to obtain the parameter gradient of the local sampled data sample; ③ Using a pre-trained statistical model to calculate the mutual information value between the local sampled data sample and the parameter gradient of the sampled sample; ④ When the mutual information value is greater than or equal to a preset threshold, issuing a privacy risk warning for the gradient of the parameter, otherwise uploading the gradient of the parameter to the parameter aggregation server.

[0005] Solution [2]: In binary classification scenarios, the input is solved by constructing the gradient and output relationship equations of a single sample input and the input and output relationship equations.

[0006] In the aforementioned prior art.

[0007] Scheme [1] calculates the mutual information value between the sampled sample and its gradient using a pre-trained statistical model, thereby measuring the risk of gradient privacy leakage of the sample. This technique requires a pre-trained statistical model as a prerequisite, and the model performance affects the accuracy of mutual information calculation; in addition, this technique only issues risk warnings for samples with high mutual information values ​​calculated using its proposed method, and the selection of the threshold for mutual information values ​​lacks a reliable basis. The reasons for the above problems are twofold: first, the reliance on a pre-trained statistical model for mutual information calculation reduces the efficiency of the construction and application of the technique; second, the design of the indicator lacks a certain theoretical basis.

[0008] The application of scheme [2] is limited, and it can only be applied to binary classification training tasks and single-sample input scenarios. The reason for this is that the method does not provide an input solution for multi-class classification training tasks and multi-sample input.

[0009] We propose a method for risk assessment based on gradient leakage input of fully connected network models. Summary of the Invention

[0010] (a) Technical problems to be solved To address the shortcomings of existing technologies, this invention provides a method for risk assessment of gradient leakage input based on fully connected network models, thus solving the aforementioned problems.

[0011] (II) Technical Solution To achieve the above-mentioned objectives, the present invention provides the following technical solution: a method for risk assessment of gradient leakage input based on a fully connected network model, comprising the following steps: S1: Construct the gradient-input relationship equation for a multi-class, multi-input task; S2: Calculate the rank and condition number of the coefficient matrix under the four risk levels to assess the risk of gradient leakage data; S3: Start the assessment from the first risk level until a certain risk level is met, then certify it as the risk level of gradient leakage data in the current model. Preferably, the gradient-input relationship equation in S1 is as follows:

[0012] in This indicates that the activation function ReLU is in The derivative on, i.e. The coefficient matrix of the relational equation is The unknown vector obtained by the equation is derived from Composition, equation output is . Preferably, the if known and Starting from the gradient-input relationship equation of the last layer, the input is obtained layer by layer, resulting in the following formula: . Preferably, the four risk levels in S2 include: structural risk indicators, network layer-level ideal matrix rank and condition number risk indicators, model-level ideal matrix rank and condition number risk indicators, and model-level approximate matrix rank and condition number risk indicators. Preferably, the calculation steps for the structural risk index are as follows: Step 1: Select the classification model of the fully connected network to be evaluated; Step 2: Traverse all network layers of the model from back to front; Step 3: Determine whether all network layers have been traversed. If it is confirmed that all network layers have been traversed, an alert will be issued indicating that the first risk level is not met. If all network layers have not been traversed, the structural risk index of the current network layer needs to be calculated. Step 4: Determine whether the structural risk indicator is greater than or equal to zero. If the structural risk indicator is not greater than or equal to zero, the first risk level is met. If the structural risk indicator is greater than or equal to zero, restart Step 3.

[0013] Preferably, the risk indicators for the ideal matrix rank and condition number at the network layer level are calculated as follows: Step 1: Select the classification model of the fully connected network to be evaluated; Step 2: Select the batch sample to be evaluated; Step 3: Calculate and maintain the output of each layer in the model for the batch samples; Step 4: Traverse all network layers of the model from back to front; Step 5: Determine if all network layers have been traversed. If all network layers have been traversed, issue a warning that the second risk level has not been met. Step 6: After traversing all network layers, it is necessary to obtain the output of a batch of samples at that layer and construct the equation relating the gradient to the input, and calculate the risk indicators of the ideal matrix rank and condition number at the network layer level. Step 7: Determine whether the risk indicators of the ideal matrix rank and condition number at the network layer level meet the second risk level. If not, restart Step 5.

[0014] Preferably, the steps for calculating the risk indicators of the ideal matrix rank and condition number at the model level are as follows: Step 1: Select the classification model of the fully connected network to be evaluated; Step 2: Select the batch sample to be evaluated; Step 3: Calculate and retain the output of the batch sample in the last layer of the model; Step 4: Traverse all network layers of the model from back to front; Step 5: Determine whether all network layers have been traversed. If it is confirmed that all network layers have been traversed, issue a warning that the third risk level has not been met. Step 6: Without traversing all network layers, construct the gradient-input relationship equation based on the output of the batch samples in that layer, and calculate the risk indicators of the ideal matrix rank and condition number at the model level. Step 7: Determine whether the risk indicators of the ideal matrix rank and condition number at the model level meet the third risk level. If not, solve the current relational equation to obtain the output of the previous layer network and restart Step 5.

[0015] The preferred steps for calculating the risk indicators of the approximate matrix rank and condition number at the model level are as follows: Step 1: Select the classification model of the fully connected network to be evaluated; Step 2: Select the batch sample to be evaluated; Step 3: Approximate the output of the batch of samples in the last layer of the model by solving the optimization problem; Step 4: Traverse all network layers of the model from back to front; Step 5: Determine whether all network layers have been traversed. If it is confirmed that all network layers have been traversed, issue a warning that the fourth risk level has not been met. Step 6: Without traversing all network layers, construct the gradient-input relationship equation based on the output of the batch samples in that layer, and calculate the risk indicators of the approximate matrix rank and condition number at the model level. Step 7: Determine whether the risk indicators of the ideal matrix rank and condition number at the model level meet the fourth risk level. If not, solve the current relational equation to obtain the output of the previous layer network and restart Step 5.

[0016] Preferably, the specific steps for solving the output of the last layer of the classification model are as follows: S1: Normal distribution initialization ; S2: Calculate the target loss value = ; S3: Optimize the loss value using the Adam optimization algorithm and update... value; S4: Iterate through S2-S3 until the specified number of iterations is met, then return the final result. .

[0017] (III) Beneficial Effects Compared with existing technologies, the risk assessment index based on gradient leakage input of a fully connected network model provided by this invention has the following advantages: 1. The risk assessment method based on gradient leakage input of a fully connected network model is more efficient and more in line with real-world assessment needs compared with existing gradient leakage input indicators. This method does not rely on any pre-trained statistical model and is applicable to the commonly used multi-classification and multi-input sample model training tasks. The indicators proposed in this scheme are accurate and have a rigorous theoretical basis. Attached Figure Description

[0018] Figure 1 This is a schematic diagram of the structural risk indicator assessment process proposed in this invention; Figure 2 This is a flowchart illustrating the risk indicators of the ideal matrix rank and condition number at the network layer level proposed in this invention. Figure 3 This is a flowchart illustrating the risk indicators of the ideal matrix rank and condition number at the model level proposed in this invention. Figure 4 This is a flowchart illustrating the risk indicators of the approximate matrix rank and condition number at the model level proposed in this invention. Detailed Implementation

[0019] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0020] Please see Figure 1-4 A method for risk assessment of gradient leakage input based on fully connected network models includes the following: Construct the equation relating gradient to input and solve for the input. , , It is If all elements in the equation are flattened, then formula (6) can be converted into the equation relating the input and the gradient, corresponding to formula (8).

[0021] (8) Accordingly, this invention constructs the relationship equations between the corresponding input and gradient through the gradient formulas of each layer, except... The corresponding equation outside the layer is formally expressed as formula (9), where Indicates the first Layer parameters, Indicates the first The output of a layer network after passing through the ReLU activation function can be obtained from the equation relating the input and gradient of the next layer.

[0022] (9) in This indicates that the activation function ReLU is in The derivative on, i.e. The coefficient matrix of the relational equation is The unknown vector obtained by the equation is derived from Composition, equation output is .

[0023] Therefore, to obtain the input of the first layer (i.e., the features of the input samples), given... and Under this premise, it is necessary to start from the gradient-input relationship equation of the last layer and calculate the input layer by layer. The solution method for the input of each layer can be seen in formula (10), where for Generalized inverse matrix.

[0024] (10) Design of risk indicators for gradient leakage data This invention proposes a tiered risk assessment index system for gradient data leakage, with four risk levels sequentially indicating different degrees of data leakage risk. The specific assessment methods employed vary. The assessment method of this invention starts from the first risk level and continues until a certain risk level is met, at which point the risk level is certified as the current model's gradient data leakage risk level. Meeting the first risk level signifies that the model has the lowest gradient data leakage risk.

[0025] This invention expresses the relationship between gradient and input in the form of an equation: The coefficient matrix is (as in the first) Layer relation equation The unknown quantity is (as in the first) Layer relation equation The equation output is (as in the first) Layer relation equation ).

[0026] First risk level: Structural risk indicators In the gradient-input relationship equation, to obtain the correct input, the coefficient matrix of the equation must at least satisfy the condition that "the number of equations is greater than or equal to the number of unknowns." For the th... Solving for the input of the layer, where the coefficient matrix It must at least meet the following requirements. Otherwise, the relational equation is underdetermined, and the input theoretically has infinitely many solutions. The present invention formulates the corresponding structural risk index as shown in formula (11).

[0027] (11) Structural risk indicators This indicates the "degree of overdeterminacy" of the relational equation; a larger value indicates that the input is theoretically easier to obtain through gradient retrieval. The corresponding specific calculation steps can be found [link to calculation]. Figure 1 . Second risk level: Risk indicators of the ideal matrix rank and condition number at the network layer level. The ideal matrix in this metric refers to the fact that the coefficient matrix in the equation relating the gradient to the input in each network layer is known. This assumption simulates a theoretical upper limit of the attacker's capabilities. In this case, to obtain the correct input, the coefficient matrix of the equation must at least satisfy the condition that "the rank of the coefficient matrix is ​​greater than the number of unknowns." The risk metric for the rank of the ideal matrix at the corresponding network layer level is shown in formula (12).

[0028] (12) in This represents the coefficient matrix of the equation relating the gradient to the input. This indicates the number of unknowns to be found. If for the th... Solving for the input of the layer, then , for Risk indicators of the ideal matrix rank at the network layer level. The larger the value, the easier it is to obtain the input through gradient given an ideal coefficient matrix.

[0029] The condition number of the coefficient matrix indicates the numerical stability of the equation. If the condition number of the coefficient matrix is ​​large, a small change in the equation output will cause a large change in the solution. This invention specifies the condition number of the ideal coefficient matrix of each network layer as a risk indicator of the ideal matrix condition number at the network layer level, as shown in formula (13). The specific calculation steps can be found in [the table below]. Figure 2 .

[0030] (13) Third risk level: Risk indicators of the ideal matrix rank and condition number at the model level.

[0031] The difference between the third-risk level metric and the second-risk level metric is that in the calculation of the third-risk level metric, only the coefficient matrix of the gradient-input relationship equation of the last layer is known; the coefficients of the other layers are unknown. This scenario simulates the attacker's further weakened upper bound capability. In this case, except for the last layer, the coefficient matrices of the other layers are composed of the inputs of the next layer. The coefficient matrix of the layer of ,in and All of these are calculated by solving the relational equations of the next layer. This invention specifies the risk indicators of the ideal matrix rank and condition number at the corresponding model level. and The calculation process is the same as that of formulas (12) and (13), respectively. The specific calculation steps can be found in [link to calculation]. Figure 3 .

[0032] Fourth risk level: Risk indicators of the approximate matrix rank and condition number at the model level.

[0033] The approximation matrix in this metric refers to the coefficient matrix of the equation relating the last layer's gradient to the input, which is approximated using a certain algorithm. The coefficient matrices of other layers are obtained from the equations of the subsequent layers. This invention proposes a method for solving the coefficient matrix of the equation relating the last layer's gradient to the input: The gradient matrix of the last fully connected network layer Its parameter matrix Multiply and sum by column to form And sum the column vectors of the matrix to form formula (14), where The classification confidence matrix for a batch of samples. For the label one-hot matrix of the batch samples, This is the output of the last layer of the network.

[0034] (14) To obtain the coefficient matrix of the equation relating the gradient of the last layer to the input. Then we need to find ,in can be The final output of the last layer of the network is obtained from formula (3). This invention will solve... The problem is transformed into an optimization problem, and its optimization objective is expressed as formula (15).

[0035] (15) Operators It is about finding the dot product of the vectors obtained by flattening matrix a and the vectors obtained by flattening matrix b. The object to be fitted by the objective function, due to the confidence level It is obtained from Softmax, and its output corresponds to an infinite number of inputs, therefore a regularization term is introduced. To narrow down the search space for input, it can effectively improve... The accuracy of the solution, This serves as the weight for the regularization term. The output of the last layer of the network. The specific steps to solve the problem are as follows: S1: Normal distribution initialization ; S2: Calculate the target loss value = ; S3: Optimize the loss value using the Adam optimization algorithm and update... value; S4: Iterate through S2-S3 until the specified number of iterations is met, then return the final result. .

[0036] When calculated Then, based on the equation relating gradient to input, the corresponding input is calculated layer by layer. This invention establishes risk indicators for the approximate matrix rank and condition number at the model level. and The calculation process is the same as that of formulas (11) and (12), respectively.

[0037] In summary, different levels of risk indicators signify different levels of risk associated with gradient leakage data. Meeting the first-level risk indicator means the overall risk of gradient leakage data is the lowest, while failing to meet the fourth-level risk indicator means the risk of gradient leakage data is the highest. The overall calculation process can be seen in [link to calculation]. Figure 4 .

[0038] In classification tasks using fully connected network models, each training iteration of the model is based on the currently selected batch of samples. ,in This is called batch size. Features referred to as batch samples This represents the number of features for each sample. This is known as batch sample labeling (one-hot format). To indicate the number of different label categories in the training dataset, superscript letters will be used as a convention below. Indicates the first For a sample, the forward propagation formula for a certain intermediate layer network of the model can be seen in (1), where the superscript letters are in the formula. Indicates the first layer, Indicates the first The first sample Layer input. (Note: parameter deviation) (This is optional, and the scope of application of the present invention is not limited thereto.) (1) After obtaining the output of a certain layer, it needs to undergo nonlinear transformation through an activation function. The activation function commonly used in neural network models is ReLU, which corresponds to formula (2), and the input of the next layer network can be obtained.

[0039] (2) The forward propagation of a fully connected network model from input to output is actually a nesting of formulas (1) and (2) until the last layer is obtained. Output of the layer model (The activation function of the last layer does not use ReLU), and then the output confidence corresponding to the input sample is obtained through the Softmax function, corresponding to formula (3), where Indicates the first The sample at the th Classification confidence (probability) on each label.

[0040] (3) After calculating the confidence level of each sample in the batch, the classification loss of each sample is calculated, corresponding to formula (4).

[0041] (4) Finally, the classification losses of all input samples are summed and averaged to obtain the final single loss value, which is the overall loss value of the corresponding batch of samples, corresponding to formula (5).

[0042] (5) The above section describes the forward propagation process of model training. The following section describes the backpropagation, which involves converting the total loss value... Take the derivative forward and calculate the parameters for each layer. and corresponding gradient , The last layer ( The parameter differentiation process of the (layer) network corresponds to formulas (6) and (7). Wherein... , , , ,in Indicates the first The number of neurons in the layer, therefore .

[0043] (6) (7).

[0044] The risk assessment method based on gradient leakage input of a fully connected network model provided in the above embodiments of the present invention is more efficient and more in line with real-world assessment needs compared with existing gradient leakage input indicators. The method provided by the present invention does not rely on any pre-trained statistical model and is applicable to the commonly used multi-classification multi-input sample model training task. The indicators proposed by the present invention are accurate and have a rigorous theoretical basis.

[0045] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.

Claims

1. A method for risk assessment of gradient leakage input based on a fully connected network model, characterized in that, Includes the following steps: S1: Construct the gradient-input relationship equation for a multi-class, multi-input task; S2: Calculate the rank and condition number of the coefficient matrix under four risk levels to assess the risk of gradient leakage data; the first risk level is the structural risk indicator, the second risk level is the risk indicator of the rank and condition number of the ideal matrix at the network layer level, the third risk level is the risk indicator of the rank and condition number of the ideal matrix at the model level, and the fourth risk level is the risk indicator of the rank and condition number of the approximate matrix at the model level. S3: Start the assessment from the first risk level until a certain risk level is met, then certify it as the risk level of gradient leakage data of the current model; The equation relating the gradient to the input in S1 is as follows: in This indicates that the activation function ReLU is in The derivative on, i.e. The coefficient matrix of the relational equation is The unknown vector obtained by the equation is derived from Composition, equation output is ; The calculation steps for the structural risk indicators are as follows: Step 1: Select the classification model of the fully connected network to be evaluated; Step 2: Traverse all network layers of the model from back to front; Step 3: Determine whether all network layers have been traversed. If it is confirmed that all network layers have been traversed, an alert will be issued indicating that the first risk level is not met. If all network layers have not been traversed, the structural risk index of the current network layer needs to be calculated. Step 4: Determine whether the structural risk indicator is greater than or equal to zero. If the structural risk indicator is not greater than or equal to zero, the first risk level is met. If the structural risk indicator is greater than or equal to zero, restart Step 3. The steps for calculating the risk indicators of the ideal matrix rank and condition number at the network layer level are as follows: Step 1: Select the classification model of the fully connected network to be evaluated; Step 2: Select the batch sample to be evaluated; Step 3: Calculate and maintain the output of each layer in the model for the batch samples; Step 4: Traverse all network layers of the model from back to front; Step 5: Determine whether all network layers have been traversed. If it is confirmed that all network layers have been traversed, issue a warning that the second risk level has not been met. Step 6: After traversing all network layers, it is necessary to obtain the output of a batch of samples at that layer and construct the equation relating the gradient to the input, and calculate the risk indicators of the ideal matrix rank and condition number at the network layer level. Step 7: Determine whether the risk indicators of the ideal matrix rank and condition number at the network layer level meet the second risk level. If not, restart step 5. The steps for calculating the risk indicators of the ideal matrix rank and condition number at the model level are as follows: Step 1: Select the classification model of the fully connected network to be evaluated; Step 2: Select the batch sample to be evaluated; Step 3: Calculate and retain the output of the batch sample in the last layer of the model; Step 4: Traverse all network layers of the model from back to front; Step 5: Determine whether all network layers have been traversed. If it is confirmed that all network layers have been traversed, issue a warning that the third risk level has not been met. Step 6: Without traversing all network layers, construct the gradient-input relationship equation based on the output of the batch samples in that layer, and calculate the risk indicators of the ideal matrix rank and condition number at the model level. Step 7: Determine whether the risk indicators of the ideal matrix rank and condition number at the model level meet the third risk level. If not, solve the current relational equation to obtain the output of the previous layer network and restart Step 5. The steps for calculating the risk indicators of the approximate matrix rank and condition number at the model level are as follows: Step 1: Select the classification model of the fully connected network to be evaluated; Step 2: Select the batch sample to be evaluated; Step 3: Approximate the output of the batch of samples in the last layer of the model by solving the optimization problem; Step 4: Traverse all network layers of the model from back to front; Step 5: Determine whether all network layers have been traversed. If it is confirmed that all network layers have been traversed, issue a warning that the fourth risk level has not been met. Step 6: Without traversing all network layers, construct the gradient-input relationship equation based on the output of the batch samples in that layer, and calculate the risk indicators of the approximate matrix rank and condition number at the model level. Step 7: Determine whether the risk indicators of the approximate matrix rank and condition number at the model level meet the fourth risk level. If not, solve the current relational equation to obtain the output of the previous layer network and restart Step 5.

2. The method for risk assessment index based on gradient leakage input of a fully connected network model according to claim 1, characterized in that: If known and Starting from the gradient-input relationship equation of the last layer, the input is obtained layer by layer, resulting in the following formula: 。 3. The method for risk assessment index based on gradient leakage input of a fully connected network model according to claim 1, characterized in that: The specific steps for solving the output of the last layer of the fully connected network classification model to be evaluated are as follows: S10: Normal distribution initialization ; S20: Calculate the target loss value = ; S30: Optimize the loss value using the Adam optimization algorithm and update... value; S40: Iterate through S20-S30 until the specified number of iterations is met, then return the final result. .

Citation Information

Patent Citations

  • Method and system for training data privacy measurement in machine learning

    CN113051620A

  • Cloud side-end collaborative ubiquitous intelligent federated learning privacy protection system and method

    CN115017541A