A federated learning auditing method, medium, and electronic device

By analyzing the cooperative information of federated learning participants, building a relationship chain of abnormal behaviors and generating an audit report, the problem that independent audit systems cannot meet the complex federated learning environment is solved, risk judgment and response from a global perspective is realized, and the security of federated learning is improved.

CN115809476BActive Publication Date: 2025-08-19CLUSTAR TECH LO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211372525.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-03
Publication Date
2025-08-19
Estimated Expiration
2042-11-03

AI Technical Summary

Technical Problem

In the prior art, independent audit systems cannot meet the audit requirements of the increasingly complex and changeable federated learning environment, and cannot judge and respond to the associated risks of abnormal behavior from a global perspective.

Method used

By obtaining cooperation information between the first participant and other participants, analyzing their relationships, discovering abnormal behaviors and building a relationship chain, generating an audit report specific to the chain, and performing corresponding responses.

Benefits of technology

It realizes the judgment and response of various risks associated with abnormal behavior from a global perspective, meets the audit requirements of complex federated learning environments, and improves the security and reliability of federated learning.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115809476B_ABST
    Figure CN115809476B_ABST
Patent Text Reader

Abstract

The present invention relates to a federated learning audit method, comprising: obtaining cooperation information between a first participant and other participants, and obtaining association relationship information between the first participant and other participants based on the cooperation information analysis; when the first participant discovers abnormal behavior based on the data packets received and / or sent by it during audit, determining the abnormal cooperation node directly associated with the abnormal behavior, and tracing back other cooperation nodes that have an association relationship with the abnormal cooperation node based on the association relationship information, thereby constructing a relationship chain that has an association relationship with the abnormal cooperation node; generating an audit report specific to the relationship chain based on the abnormal behavior, and performing corresponding response and disposal on each cooperation node in the relationship chain based on the audit report. The implementation of the embodiments of the present invention can judge and respond to various risks associated with abnormal behavior from a global perspective, thereby meeting the audit requirements of increasingly complex federated learning cooperation environments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the fields of privacy computing, privacy data and federated learning technology, specifically to the field of data processing technology, and in particular to a federated learning auditing method, medium and electronic device. Background Art

[0002] Privacy-preserving computing refers to a collection of technologies that enable data analysis and computation while protecting private data from external disclosure. This approach aims to make data "available but invisible," transforming and unlocking its value while fully protecting data and privacy. Federated learning is a key implementation of privacy-preserving computing. It involves data-owning parties exchanging model-related information through encrypted means, without sharing protected private data or transmitting their own data externally, to collaboratively optimize federated learning models. To ensure the privacy of participants, during the training process of a federated learning model, each participant's training data never leaves the local machine. Instead, model-related information, such as the model architecture and parameter gradients, is encrypted and shared with the server, reducing the risk of data leakage. However, multi-party federated learning processes present security risks and vulnerabilities. Since it's impossible to guarantee the bona fides of every participant in a federated learning process, critical nodes in the training or operational process could be compromised by malicious actors.

[0003] Existing techniques for auditing anomalous federated learning participants primarily rely on a single, independent, and segmented security system to verify whether each participant's operations are abnormal. Specifically, an audit system can be deployed for each participant, but the auditing work of each audit system is independent and independent of each other. Each audit system monitors the behavior or actions of its corresponding participant by obtaining its logs, or checks whether the participant is abnormal by auditing the data packets it receives or sends. However, as the number of federated learning participants increases and its application scenarios expand, auditing anomalies in federated learning is becoming increasingly complex. Independent and segmented audit systems are no longer able to meet the increasingly complex and diverse federated learning application scenarios or environments. Specifically, while independent and segmented audit systems can audit their corresponding participants for anomalies, they cannot identify and respond to anomalies or risks associated with the anomalies, either already occurring or potentially occurring. Consequently, they lack a holistic perspective for assessing and responding to the various risks associated with the anomalies. In other words, independent and separate audit systems can only audit single-point anomalies. However, in the increasingly complex and changeable federated learning environment, audit systems that can only audit single-point anomalies can no longer meet audit requirements. Summary of the Invention

[0004] In order to solve the technical problem that independent and separate audit systems can only audit single-point anomalies and cannot meet the audit requirements of the increasingly complex and changeable federated learning environment, the present invention provides a federated learning audit method, medium and electronic equipment, so as to achieve the ability to judge and respond to various risks associated with abnormal behavior from a global perspective, thereby meeting the audit requirements of the increasingly complex federated learning cooperation environment.

[0005] In a first aspect, a federated learning audit method is provided, which is executed on a first participant, comprising: obtaining cooperation information between the first participant and other participants, and obtaining association relationship information between the first participant and the other participants based on the cooperation information analysis; wherein the association relationship information includes the connection relationship of multiple cooperation nodes between the first participant and the other participants; when the first participant discovers abnormal behavior based on the data packets it receives and / or sends through auditing, determining the abnormal cooperation node directly associated with the abnormal behavior, and tracing back other cooperation nodes that have an association relationship with the abnormal cooperation node based on the association relationship information, thereby constructing a relationship chain that has an association relationship with the abnormal cooperation node; wherein the abnormal cooperation node and the other cooperation nodes are nodes among the multiple cooperation nodes; generating an audit report specific to the relationship chain based on the abnormal behavior, and performing corresponding response and disposal on each cooperation node in the relationship chain based on the audit report.

[0006] According to the embodiment described in the first aspect, in one implementation, other cooperation nodes that have an association relationship with the abnormal cooperation node are traced based on the association relationship information, thereby constructing a relationship chain that has an association relationship with the abnormal cooperation node, including: determining the maximum association level that needs to be traced for the abnormal behavior, and screening out other cooperation nodes that have an association relationship with the abnormal cooperation node and meet the maximum association level based on the association relationship information, thereby constructing a relationship chain that has an association relationship with the abnormal cooperation node and meets the maximum association level.

[0007] According to the embodiment described in the first aspect, in one implementation, determining the maximum association level that the abnormal behavior needs to be traced includes: comprehensively determining the maximum association level that the abnormal behavior needs to be traced based on any one or any combination of factors including the audit level of the first participant, the risk level of the abnormal behavior, the computing resources of the first participant, and the network resources of the first participant.

[0008] According to the embodiment described in the first aspect, in one implementation, corresponding response disposal is performed on each cooperation node in the relationship chain according to the audit report, including: reviewing and auditing each cooperation node in the relationship chain that is upstream of the abnormal cooperation node according to the audit report; and monitoring and warning each cooperation node in the relationship chain that is downstream of the abnormal cooperation node according to the audit report.

[0009] According to the embodiment described in the first aspect, in one implementation, each cooperation node located upstream of the abnormal cooperation node in the relationship chain is reviewed and audited according to the audit report, including: determining whether each cooperation node located upstream of the abnormal cooperation node in the relationship chain triggers the alarm rules set in the audit report; and performing behavioral analysis on the cooperation nodes that trigger the alarm rules, so as to determine the cooperation nodes with abnormal behavior among the cooperation nodes located upstream of the abnormal cooperation node.

[0010] According to the embodiment described in the first aspect, in one implementation, the audit report indicates the deadline for each cooperative node in the relationship chain to respond and handle, and the deadline is determined based on the association level between each cooperative node in the relationship chain and the abnormal cooperative node and / or the risk level of the abnormal behavior.

[0011] According to the embodiment described in the first aspect, in one implementation, the multiple cooperation nodes include any number of data source nodes, application nodes, participant nodes, data set nodes, project nodes, service nodes, process nodes and model nodes.

[0012] According to the embodiment described in the first aspect, in one implementation, when the first participant discovers abnormal behavior based on the data packets it receives and / or sends through an audit, determining the abnormal cooperation node directly associated with the abnormal behavior, including: when the first participant discovers abnormal behavior based on the data packets it receives and / or sends through a process audit, determining the abnormal process node directly associated with the abnormal behavior; wherein the process audit includes a control flow audit and / or an algorithm flow audit, the control flow audit is for verifying the control flow information of the data packet, and the control flow information is related to the federated learning task in which the participant participates, and the algorithm flow audit is for verifying the algorithm flow information of the data packet, and the algorithm flow information is related to the federated learning algorithm.

[0013] In a second aspect, a non-transitory computer-readable storage medium is provided, which stores computer instructions. When the computer instructions are executed by a processing device, the processing device executes the federated learning audit method described in any embodiment of the first aspect.

[0014] According to a third aspect, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the federated learning audit method described in any embodiment of the first aspect.

[0015] This embodiment of the present invention not only audits and discovers abnormal cooperation nodes directly associated with abnormal behavior, but also constructs a relationship chain associated with the abnormal cooperation node through association analysis. This allows for the generation of an audit report specific to the relationship chain based on the abnormal behavior, and for each cooperation node in the relationship chain to respond accordingly based on the audit report. This embodiment of the present invention enables a global perspective on the various risks associated with abnormal behavior and responds accordingly, thereby meeting the audit requirements of increasingly complex federated learning collaboration environments. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] In order to more clearly illustrate the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without inventive efforts. In the drawings:

[0017] Figure 1 This is a flow chart of a federated learning audit method provided by an embodiment of the present invention;

[0018] Figure 2 This is a schematic diagram of a cooperation node connection between a first participant and other participants provided by an embodiment of the present invention;

[0019] Figure 3 This is a schematic diagram of the hardware structure of the first federated learning audit electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0020] The present invention aims to address the technical problem that independent and separate audit systems can only audit single-point anomalies and cannot meet the audit requirements of the increasingly complex and changing federated learning environment. The present invention provides a federated learning audit method, medium, and electronic device. The federated learning audit method includes: obtaining cooperation information between a first participant and other participants, and analyzing the cooperation information to obtain association relationship information between the first participant and the other participants; wherein the association relationship information includes the connection relationship between multiple cooperation nodes between the first participant and the other participants; when the first participant discovers abnormal behavior based on the data packets it receives and / or sends, determining the abnormal cooperation node directly associated with the abnormal behavior, and tracing other cooperation nodes associated with the abnormal cooperation node based on the association relationship information, thereby constructing a relationship chain associated with the abnormal cooperation node; wherein the abnormal cooperation node and the other cooperation nodes are nodes among the multiple cooperation nodes; generating an audit report specific to the relationship chain based on the abnormal behavior, and performing corresponding response and disposal on each cooperation node in the relationship chain based on the audit report. Implementing the embodiments of the present invention not only enables audits to identify abnormal collaboration nodes directly associated with abnormal behavior, but also enables the construction of a relationship chain associated with the abnormal collaboration node through association analysis. This allows the generation of an audit report specific to the relationship chain based on the abnormal behavior, and the implementation of a corresponding response and disposal for each collaboration node in the relationship chain based on the audit report. Through the embodiments of the present invention, various risks associated with abnormal behavior can be assessed and responded to from a global perspective, thereby meeting the audit requirements of increasingly complex federated learning collaboration environments.

[0021] The embodiments of the present application can be used in the following application scenarios, including but not limited to multi-party secure computing, machine learning model training related to federated learning, data security, privacy protection, or other application scenarios that apply privacy computing frameworks or algorithms.

[0022] The embodiments of the present application can be adjusted and improved according to the specific application environment and are not specifically limited here.

[0023] In order to enable people skilled in the art to better understand the present application, the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0024] See also Figure 1 , Figure 1 This is a flow chart of a federated learning audit method provided by an embodiment of the present invention. The federated learning audit method is executed in the first participant in federated learning and specifically includes:

[0025] S102: Acquire cooperation information between the first participant and other participants, and obtain association relationship information between the first participant and other participants based on analysis of the cooperation information.

[0026] The first participant can be a data source that provides data for federated learning model training, a data application that requests data to be applied in federated learning model training, or a participant that provides or requests other federated learning services. The present invention does not specifically limit this. Other participants are other participants other than the first participant in the same federated learning organization or the same federated learning alliance based on specific constraints or specific cooperative relationships. The first participant and other participants can be participants participating in the same model training in the same federated learning organization or the same federated learning alliance, or participants participating in different model training in the same federated learning organization or the same federated learning alliance.

[0027] The federated learning in which the first participant and other participants participate can be based on the FATE federated learning framework. The cooperation information between the first participant and other participants can be obtained based on the analysis of behavioral data reported by the tracking service of the FATE federated learning framework, or can be obtained through interaction and collaboration between the first participant and other participants. After the first participant obtains the cooperation information between itself and other participants, the first participant can analyze the obtained cooperation information to obtain the association relationship information between the first participant and other participants, where the association relationship information includes the connection relationship between multiple cooperation nodes between the first participant and other participants, and the multiple cooperation nodes include any of data source nodes, application nodes, participant nodes, dataset nodes, project nodes, service nodes, process nodes, and model nodes. The first and other participants are configured as data source nodes, application nodes, or participant nodes based on their respective roles in federated learning. The collaborative relationship between the first and other participants can be clearly depicted through dataset nodes, project nodes, process nodes, and model nodes. Specifically, dataset nodes represent collaborative datasets between participants, project nodes represent projects jointly participated in by participants, service nodes represent services provided by participants, process nodes represent federated learning processes involving participants, and model nodes represent models jointly trained by participants. Through the division of these nodes, the collaborative relationship between the first and other participants can be more clearly represented.

[0028] Specific as Figure 2As shown, the first participant can be represented by the data source node, and there are three participant nodes that have a cooperative relationship with the data source node, that is, the other participants can be represented by participant node 1, participant node 2, and participant node 3 respectively. Each participant node is connected to the corresponding dataset node, for example, participant node 1 is connected to dataset node 1, participant node 2 is connected to dataset node 2, and participant node 3 is connected to dataset node 3, where the dataset in the dataset node comes from the data source node; dataset node 1 is also connected to project node 1 and project node 2 respectively below, dataset node 2 is connected to project node 3 and service node 1 respectively, and dataset node 3 is connected to project node 4, project node 5, and service node 2 respectively; project node 1 is connected to process node 1 below, project node 2 is connected to data node 2 above, project node 2 is connected to process node 2 below, project node 3 is connected to process node 3 below, and project node 4 is connected to process node 4 below; process node 1 is connected to model node 1 below, process node 2 is connected to model node 2 below, process node 3 is connected to model node 3 below, and process node 4 is connected to model node 4 below.

[0029] S104. When the first participant discovers abnormal behavior based on the audit of the data packets it receives and / or sends, the first participant determines the abnormal cooperation node directly associated with the abnormal behavior, and traces other cooperation nodes that have an associated relationship with the abnormal cooperation node based on the association relationship information, thereby constructing a relationship chain that has an associated relationship with the abnormal cooperation node.

[0030] The first participant can capture the data packets received and / or sent by the first participant at the communication entrance and exit between itself and other participants for auditing. According to the different audit contents, it can be divided into control flow audit and algorithm flow audit, corresponding to the control flow information and algorithm flow information in the audit data packet respectively. Among them, the control flow information refers to the control flow information in the data packet, which is related to the federated learning task in which the participant participates, including data or indicators indicating the status of the federated learning task, such as status information (such as database service status, network connection status, etc.) and module call order. Algorithm flow information refers to the algorithm flow information in the data packet, which is related to the federated learning algorithm, including data or indicators indicating whether the execution process of the federated learning algorithm meets the requirements, such as determining whether the execution process of a specific algorithm such as the RSA intersection algorithm for finding sample intersection is consistent with the reference process or standard process. In some implementation methods, the process audit, that is, the control flow audit and algorithm flow review can be conducted in a real-time audit manner or in a post-audit manner.

[0031] When the first participant discovers abnormal behavior based on the audit of the data packets it receives and / or sends, for example, the first participant discovers through control flow audit that the execution order of the federated learning task does not conform to the preset execution order of the federated learning task, or the first participant discovers through algorithm flow audit that the execution order of the federated learning algorithm does not conform to the preset execution order of the federated learning algorithm, the first participant will first determine the abnormal cooperation node directly associated with the abnormal behavior among the multiple cooperation nodes between the first participant and other participants described in the above step S102, and then trace back other cooperation nodes that have an association relationship with the abnormal cooperation node according to the association relationship information described in the above step S102, thereby constructing a relationship chain that has an association relationship with the abnormal cooperation node, wherein the abnormal cooperation node and the other cooperation nodes are nodes among the multiple cooperation nodes. The following continues with Figure 2 For example, when the data source node in the figure, that is, the first participant, conducts an audit of the data packets it receives and / or sends, such as control flow audit or algorithm flow audit, and finds abnormal behavior, it will be found in the process nodes directly related to the federated learning process, such as Figure 2 The first abnormal information is found at process node 2 in the process. If only the abnormality processing is performed on process node 2, such as warning or response to the abnormal behavior, it cannot completely prevent other risks associated with the abnormal behavior. For example, the abnormal behavior of process node 2 may cause its downstream cooperation nodes such as Figure 2 The model training of model node 2 in the example above may be offset, which may also indicate that its upstream cooperation node is Figure 2 There are other potential unidentified associated risks in the project node 2, dataset node 1 and participant node 1, the cooperative project, the adopted dataset, and the cooperative participants. Figure 2 For abnormal behavior found by process node 2, the embodiment of the present invention will also filter out other cooperation nodes that have an association relationship with the abnormal cooperation node, such as Figure 2 In this example, participant node 1, dataset node 1, project node 2, and model node 2 form a relationship chain associated with the abnormal cooperation node, process node 2. This relationship chain enables the federated learning audit method provided by this invention to go beyond single-point auditing of abnormal behavior and examine the relationship chain of abnormal behavior in the entire federated learning cooperation network from a global perspective, thereby more comprehensively reflecting the associated risks of abnormal behavior and further ensuring the security and reliability of federated learning.

[0032] In some embodiments of the present invention, when the first participant discovers abnormal behavior based on the audit of the data packets it receives and / or sends, the first participant will also determine the maximum association level to which the abnormal behavior needs to be traced, and filter out other cooperation nodes that have an association relationship with the abnormal cooperation node and meet the maximum association level based on the above association relationship information, thereby constructing a relationship chain that has an association relationship with the abnormal cooperation node and meets the maximum association level. Figure 2 , if the first participant discovers abnormal behavior during the audit and determines that the abnormal behavior is directly related to process node 2, if the maximum correlation level determined by the first participant is 1, then the cooperation nodes with a correlation level of 1 will be screened out from the upstream and downstream cooperation nodes of process node 2, that is, Figure 2 Project node 2 and model node 2 in the process node; if the maximum association level determined by the first participant is 2, then the cooperation nodes with an association level of less than 2 will be screened out from the upstream and downstream cooperation nodes of process node 2, that is, Figure 2 In some implementations, the first participant can comprehensively determine the maximum level of relevance for the abnormal behavior that needs to be traced based on any one or more factors: the first participant's audit level, the risk level of the abnormal behavior, the first participant's computing resources, and the first participant's network resources. For example, the audit level can be set to strong, medium, or weak, and the maximum level of relevance can be set based on the strength of the audit level. The stronger the audit level, the larger the maximum level of relevance can be set. For another example, the risk level of the abnormal behavior can be set to high, medium, or low, and the maximum level of relevance can be set based on the risk level of the abnormal behavior. The higher the risk level of the abnormal behavior, the larger the maximum level of relevance can be set. For another example, the maximum level of relevance can be adjusted based on the computing resources and network resources of the first participant. Generally, the more abundant the computing resources and network resources of the first participant, the larger the maximum level of relevance can be set. By setting the maximum level of relevance on the first participant, federated learning participants can flexibly adjust based on their own needs while also meeting the complex and changing audit requirements of different participants.

[0033] S106. Generate an audit report specific to the relationship chain based on the abnormal behavior, and perform corresponding response and disposal on each cooperation node in the relationship chain based on the audit report.

[0034] Specifically, the first participant can review and audit each cooperation node located upstream of the abnormal cooperation node in the relationship chain based on the audit report; and can also monitor and warn each cooperation node located downstream of the abnormal cooperation node in the relationship chain based on the audit report. Figure 2 Take this as an example to illustrate: Figure 2The relationship chain identified in the example consists of participant node 1, dataset node 1, project node 2, process node 2, and model node 2, with process node 2 being an abnormal cooperation node. A review and audit of participant node 1, dataset node 1, and project node 2 upstream of process node 2 is conducted to identify other potential risks. Monitoring and early warning are performed on model node 2 downstream of process node 2 to monitor in real time whether the model trained by model node 2 is drifting and whether the degree of drift exceeds a preset value. If the degree of drift exceeds the preset value, the first participant can take model node 2 offline.

[0035] The above-mentioned review and audit are described in detail below. The first participant, based on the audit report, conducts a review and audit of each cooperative node upstream of the abnormal cooperative node in the relationship chain. This can include: the first participant determines whether each cooperative node upstream of the abnormal cooperative node in the relationship chain triggers the alarm rules set in the audit report; and performs behavioral analysis on the cooperative nodes that trigger the alarm rules, thereby determining which cooperative nodes upstream of the abnormal cooperative node have abnormal behavior. For example, the alarm rules in the audit report may include: login event alarm rules, such as when a participant logs in to the same account with multiple IP addresses more than a preset number of times within a preset time; prediction request event alarm rules, such as when a participant holding a tag performs a federated learning prediction task request more than a preset number of times within a preset time; and intersection task event alarm rules, such as when a participant holding a tag performs a federated learning intersection task more than a preset number of times within a preset time. As the application scenarios of federated learning become increasingly complex, the alarm rules can screen out cooperative nodes suspected of maliciously sabotaging federated learning, but cannot determine whether the cooperative node is an abnormal cooperative node. Therefore, for cooperative nodes that trigger alarm rules, further behavioral analysis is required. This involves collecting monitoring logs related to the events that triggered the alarm rules and performing log analysis. For example, these logs can be compared with the monitoring logs of benevolent federated learning users. If the monitoring logs related to the events that triggered the alarm rules differ from those of benevolent federated learning users in key metrics that exceed preset limits, the cooperative node, suspected of maliciously disrupting federated learning, is identified as an anomalous cooperative node. Key metrics can include the time it takes for a user to click on an event, the amount of data intersection in federated learning, or any other appropriate indicator that can reflect whether the federated learning user is genuine and benevolent.

[0036] In some specific embodiments, the audit report indicates the deadline for each cooperative node in the relationship chain to respond and handle, which limits the deadline for the first participant to respond and handle each cooperative node in the relationship chain. The deadline can be determined based on the association level of each cooperative node in the relationship chain and the abnormal cooperative node and / or the risk level of abnormal behavior.

[0037] Implementing the embodiments of the present invention not only enables audits to identify abnormal collaboration nodes directly associated with abnormal behavior, but also enables the construction of a relationship chain associated with the abnormal collaboration node through association analysis. This allows the generation of an audit report specific to the relationship chain based on the abnormal behavior, and the implementation of a corresponding response and disposal for each collaboration node in the relationship chain based on the audit report. Through the embodiments of the present invention, various risks associated with abnormal behavior can be assessed and responded to from a global perspective, thereby meeting the audit requirements of increasingly complex federated learning collaboration environments.

[0038] Figure 3 FIG1 shows a block diagram of an electronic device for a federated learning audit method provided by an embodiment of the present application. Figure 3 As shown, the electronic device 300 includes a main processor 302, an internal bus 304, a network interface 306, a main memory 308, an auxiliary processor 310 and an auxiliary memory 312, and an auxiliary processor 320 and an auxiliary memory 322. The main processor 302 is connected to the main memory 308, and the main memory 308 can be used to store computer instructions executable by the main processor 302, so as to realize Figure 1 The illustrated federated learning auditing method 100 includes some or all of the steps, as well as any possible combination or conjunction, replacement, or variation of the steps. Network interface 306 is used to provide network connectivity and transmit and receive data over the network. Internal bus 304 is used to provide internal data exchange between main processor 302, network interface 306, auxiliary processor 310, and auxiliary processor 320. Auxiliary processor 310 is connected to auxiliary memory 312 and together provides auxiliary computing capabilities, while auxiliary processor 320 is connected to auxiliary memory 322 and together provides auxiliary computing capabilities. Auxiliary processor 310 and auxiliary processor 320 can provide the same or different auxiliary computing capabilities, including, but not limited to, computing capabilities optimized for specific computing requirements, such as parallel processing capabilities or tensor computing capabilities, and computing capabilities optimized for specific algorithms or logical structures, such as iterative computing capabilities or graph computing capabilities. Auxiliary processor 310 and auxiliary processor 320 can include one or more processors of a specific type, such as a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), etc., to provide customized functions and structures. In some exemplary embodiments, the electronic device 300 may not include an auxiliary processor, may include only one auxiliary processor, or may include any number of auxiliary processors each having corresponding customized functions and structures, which are not specifically limited herein. Figure 3The architecture of the two auxiliary processors shown in is illustrative only and should not be construed as limiting. In addition, the main processor 302 may include a single-core or multi-core computing unit for providing the functions and operations necessary for the embodiments of the present application. In addition, the main processor 302 and the auxiliary processor (such as Figure 3 The auxiliary processors 310 and 320 in the electronic device 300 may have different architectures, that is, the electronic device 300 may be a system based on a heterogeneous architecture. For example, the main processor 302 may be a general-purpose processor such as a CPU based on an instruction set operating system, while the auxiliary processor may be a graphics processor GPU suitable for parallel computing or a dedicated accelerator suitable for neural network model-related operations. Auxiliary memory (e.g. Figure 3 The auxiliary memory 312 and auxiliary memory 322 shown can be used to cooperate with their respective auxiliary processors to implement customized functions and structures. The main memory 308 is used to store necessary instructions, software, configurations, data, etc. so as to cooperate with the main processor 302 to provide the functions and operations required by the embodiments of the present application. In some exemplary embodiments, the electronic device 300 may not include auxiliary memory, may include only one auxiliary memory, or may include any number of auxiliary memories, without specific limitation herein. Figure 3 The architecture of the two secondary memories shown in is illustrative only and should not be construed as limiting. The main memory 308, and possibly the secondary memory, may include one or more of the following characteristics: volatile, non-volatile, dynamic, static, readable / writable, read-only, random access, sequential access, location addressable, file addressable, and content addressable, and may include random access memory (RAM), flash memory, read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, a hard disk, a removable disk, a recordable and / or rewritable compact disk (CD), a digital versatile disk (DVD), a mass storage media device, or any other form of suitable storage medium. The internal bus 304 may include any one or a combination of different bus structures, such as a memory bus or memory controller, a peripheral bus, a universal serial bus, and / or a processor or local bus utilizing any one of a variety of bus architectures. It should be understood that Figure 3 The structure of the electronic device 300 shown does not constitute a specific limitation on the relevant device or system. In some exemplary embodiments, the electronic device 300 may include more or fewer components than the specific embodiments and drawings, or combine certain components, or split certain components, or have a different component arrangement.

[0039] The specific embodiments provided in this application may include or be combined with a computer-readable storage medium, such as one or more storage devices capable of providing non-transitory data storage. The computer-readable storage medium / storage device may be configured to store data, programmers and / or instructions that, when executed by a processor of the device or apparatus provided in the specific embodiments of this application, enable these devices or apparatuses to perform relevant operations. The computer-readable storage medium / storage device may include one or more of the following features: volatility, non-volatility, dynamic, static, readable / writable, read-only, random access, sequential access, location addressability, file addressability, and content addressability. In one or more exemplary embodiments, the computer-readable storage medium / storage device may be integrated into the device or apparatus provided in the specific embodiments of this application or belong to a common system. Computer-readable storage media / storage devices may include optical storage devices, semiconductor storage devices and / or magnetic storage devices, etc., and may also include random access memory (RAM), flash memory, read-only memory (ROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), registers, hard disks, removable disks, recordable and / or rewritable compact disks (CDs), digital versatile disks (DVDs), mass storage media devices or any other form of suitable storage media.

[0040] The above is an implementation method of the embodiment of the present application. It should be noted that the steps in the method described in the specific embodiment of the present application can be adjusted in order, combined and deleted according to actual needs. In the above embodiments, the description of each embodiment has its own focus. For parts that are not described in detail in a certain embodiment, please refer to the relevant description of other embodiments. It is understandable that the structures shown in the embodiments of the present application and the drawings do not constitute specific limitations on the relevant devices or systems. In other embodiments of the present application, the relevant devices or systems may include more or fewer components than the specific embodiments and drawings, or combine certain components, or split certain components, or have different component arrangements. Those skilled in the art will understand that, without departing from the spirit and scope of the specific embodiments of the present application, various modifications or changes can be made to the arrangement, operation and details of the methods and equipment recorded in the specific embodiments; without departing from the principles of the embodiments of the present application, several improvements and modifications can be made, and these improvements and modifications are also considered to be within the scope of protection of the present application.

Claims

1. A federated learning audit method, characterized in that: The federated learning audit method is executed by a first participant, including: Acquiring cooperation information between the first participant and other participants, and analyzing the cooperation information to obtain association relationship information between the first participant and the other participants; wherein the association relationship information includes connection relationships between multiple cooperation nodes between the first participant and the other participants; In the case where the first participant discovers abnormal behavior through auditing of the data packets received and / or sent by the first participant, an abnormal cooperation node directly associated with the abnormal behavior is determined, and other cooperation nodes associated with the abnormal cooperation node are traced back according to the association relationship information, thereby constructing a relationship chain associated with the abnormal cooperation node; wherein the abnormal cooperation node and the other cooperation nodes are nodes among the multiple cooperation nodes; An audit report specific to the relationship chain is generated based on the abnormal behavior, and corresponding response processing is performed on each cooperation node in the relationship chain based on the audit report.

2. The federated learning audit method according to claim 1, characterized in that: Tracing back other cooperation nodes that have an association relationship with the abnormal cooperation node according to the association relationship information, thereby constructing a relationship chain that has an association relationship with the abnormal cooperation node, including: Determine the maximum association level that needs to be traced for the abnormal behavior, and screen out other cooperation nodes that have an association relationship with the abnormal cooperation node and meet the maximum association level based on the association relationship information, thereby constructing a relationship chain that has an association relationship with the abnormal cooperation node and meets the maximum association level.

3. The federated learning audit method according to claim 2, characterized in that: Determine the maximum level of relevance that needs to be traced back to the abnormal behavior, including: The maximum association level for tracing the abnormal behavior is comprehensively determined based on any one or more factors including the audit level of the first participant, the risk level of the abnormal behavior, the computing resources of the first participant, and the network resources of the first participant.

4. The federated learning auditing method according to claim 1, characterized in that: According to the audit report, each cooperation node in the relationship chain is responded to and handled accordingly, including: Conduct a review and audit of each cooperation node upstream of the abnormal cooperation node in the relationship chain according to the audit report; According to the audit report, each cooperation node in the relationship chain that is located downstream of the abnormal cooperation node is monitored and warned.

5. The federated learning auditing method according to claim 4, characterized in that: Conducting a review and audit on each cooperation node upstream of the abnormal cooperation node in the relationship chain according to the audit report, including: respectively determining whether each cooperation node upstream of the abnormal cooperation node in the relationship chain triggers an alarm rule set in the audit report; A behavior analysis is performed on the cooperation node that triggers the alarm rule, so as to determine a cooperation node with abnormal behavior among each cooperation node located upstream of the abnormal cooperation node.

6. The federated learning auditing method according to claim 1, characterized in that: The audit report indicates a deadline for each cooperation node in the relationship chain to respond and handle the situation, and the deadline is determined based on the association level between each cooperation node in the relationship chain and the abnormal cooperation node and / or the risk level of the abnormal behavior.

7. The federated learning auditing method according to claim 1, characterized in that: The multiple cooperation nodes include any of data source nodes, application nodes, participant nodes, data set nodes, project nodes, service nodes, process nodes and model nodes.

8. The federated learning auditing method according to claim 7, characterized in that: When the first participant discovers abnormal behavior through auditing of data packets received and / or sent by the first participant, determining an abnormal cooperation node directly associated with the abnormal behavior includes: In the case where the first participant discovers abnormal behavior through process auditing based on the data packets received and / or sent by it, determine the abnormal process node directly associated with the abnormal behavior; wherein the process audit includes control flow auditing and / or algorithm flow auditing, the control flow audit is for verifying the control flow information of the data packet, and the control flow information is related to the federated learning task in which the participant participates, and the algorithm flow audit is for verifying the algorithm flow information of the data packet, and the algorithm flow information is related to the federated learning algorithm.

9. A non-transitory computer-readable storage medium storing computer instructions, characterized in that: When the computer instruction is executed by a processing device, the processing device is caused to perform the federated learning audit method according to any one of claims 1 to 8.

10. An electronic device, characterized in that: The electronic device comprises: at least one processor; and, a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the federated learning auditing method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Flow auditing method and device based on federated learning, and storage medium

    CN113434474A

  • Multi-party security computing method and apparatus, and electronic device

    WO2020034751A1