A method, system, medium, device and terminal for protecting privacy in federated learning

By adopting a combination of full dynamic secret sharing and elliptic curve cryptography algorithm in federated learning, the problems of large time overhead and privacy data leakage in the existing technology are solved, and efficient and secure federated learning privacy protection is achieved.

CN115883076BActive Publication Date: 2025-05-16XIAN UNIV OF POSTS & TELECOMM
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211483881.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-16
Publication Date
2025-05-16
Estimated Expiration
2042-11-16

AI Technical Summary

Technical Problem

In the existing federated learning algorithm, attackers can inversely eject private data through local model parameters uploaded by the participants, and the time overhead is too high to be applicable to large-scale federated learning; at the same time, the information interaction between the server and the participants in the public network may lead to the influx of unfamiliar information affecting federated learning.

Method used

The full dynamic secret sharing scheme is adopted to improve the efficiency of federated learning, and through an authentication scheme based on the elliptic curve cryptography algorithm, the system is safe under the interference of strange participants. Specifically, it includes the initialization stage, the key distribution stage, the mask generation, the client authentication stage and the model aggregation stage.

Benefits of technology

It effectively reduces the time overhead of key distribution, improves the efficiency of federated learning, ensures the privacy of client data, and prevents malicious interference from unfamiliar clients, ensuring the accuracy of federated learning results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115883076B_ABST
    Figure CN115883076B_ABST
Patent Text Reader

Abstract

The present invention belongs to the technical field of privacy protection for federated learning, and discloses a method, system, medium, device and terminal for privacy protection for federated learning. In the initialization phase, the server and the client complete the initialization of the authentication key pair, the secret sharing auxiliary function and the secret sharing key pair; in the key distribution phase, based on the Diffie-Hellman key exchange of the elliptic curve, a homogeneous linear recursive sequence is constructed and the public parameters of the mask are calculated, and the parameters are sent to the server; in the mask generation and client authentication phase, the mask is calculated and added to the local model parameters; the client generates the authentication parameters, the server authenticates the client, the server aggregates the model parameters and broadcasts the list; in the model aggregation phase, the client calculates the secret sharing parameters, the server recovers the offline client mask and the online client random number mask, and the server completes the aggregation and broadcasts the parameters. The present invention realizes the rapid distribution of keys while ensuring the privacy of the keys.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of federated learning privacy protection, and in particular, relates to a method, system, medium, device and terminal for federated learning privacy protection. Background Art

[0002] At present, the rapid progress of machine learning technology has benefited from the powerful computing power and massive available data provided by technologies such as cloud computing and big data. However, these massive amounts of available data, especially data containing personal privacy, such as medical records, personal location, consumption records, etc., may lead to personal privacy leakage during the data sharing process. At present, in order to protect personal data security, countries around the world have introduced relevant laws to protect user privacy, such as the European Union passed the General Data Protection Regulation (GDPR), the United States passed the Consumer Privacy Rights Act, and my country passed the Personal Information Protection Law, Data Security Law and many other laws. As countries around the world begin to pay attention to data privacy and security, solving the problem of privacy protection in the process of data sharing has become a difficult problem that needs to be solved urgently.

[0003] In response to the above problems, the federated learning algorithm technology has been proposed. Federated learning is a distributed privacy-preserving machine learning technology. In the process of machine learning training models, each participant does not need to share local data. They only need to use local data to train the model separately. The data joint training is completed only by uploading the updated parameters of the local model to achieve joint modeling. However, studies have shown that attackers can infer the privacy data contained in the local model parameters uploaded by the participants. In order to solve this problem, Google proposed a double-mask scheme using Shamir secret sharing to protect the local model update parameters, which can not only protect the privacy of the participants, but also ensure that the mask of the offline participant will not affect the data. In addition, there are also federated learning privacy protection algorithms using technologies such as homomorphic encryption or differential privacy. These algorithms are based on preventing privacy leakage and ensuring data security.

[0004] However, existing methods all have the problem of high time overhead and cannot be applied to large-scale federated learning scenarios. In addition, each time a joint model is performed, the server needs to distribute a new signing key to each participant. Each client needs to send a sub-secret of the mask key to the other clients through the server, and frequent communication greatly increases the time overhead. In addition to the above, most of the information interaction between the server and the participants is in the public network. Failure to verify the identity of the participants may lead to a large influx of unfamiliar information and affect federated learning. Existing federated learning privacy protection methods have not considered related issues.

[0005] Through the above analysis, the problems and defects of the prior art are as follows:

[0006] (1) In traditional federated learning algorithm technology, attackers can infer the private data contained in the local model parameters uploaded by the participants, which cannot solve the privacy protection problem in the data sharing process.

[0007] (2) The existing method of using Shamir secret sharing and double mask scheme to protect local model parameter updates has too high a time cost and cannot be applied to large-scale federated learning scenarios.

[0008] (3) In the existing double-mask scheme, most of the information interactions between the server and the participants are in the public network. Failure to verify the identity of the participants may lead to a large influx of unfamiliar information and affect federated learning. Summary of the invention

[0009] In response to the problems existing in the prior art, the present invention provides a method, system, medium, device and terminal for privacy protection in federated learning, and in particular, relates to a system, method, medium, device and terminal for security situation awareness and analysis of a numerical control system based on full dynamic secret sharing and elliptic curve cryptography algorithm.

[0010] During the training process of federated learning, the present invention uses a fully dynamic secret sharing scheme to improve the efficiency of federated learning, and proposes an authentication scheme based on elliptic curve cryptography to ensure the security of the system under interference from unfamiliar participants.

[0011] The present invention is implemented as follows: a method for protecting privacy in federated learning, the method comprising: a fully dynamic secret sharing scheme is used in the present invention to improve the efficiency of federated learning, and an authentication scheme based on elliptic curve cryptography is proposed to ensure the security of the system under interference from unfamiliar participants. The scheme includes four stages: initialization stage, key distribution stage, mask generation and client authentication stage, and model aggregation stage; the server and the client complete the initialization of the authentication key pair, secret sharing auxiliary function, and secret sharing key pair in sequence; the client completes the Diffie-Hellman key exchange based on the elliptic curve, and uses the key obtained after the exchange to construct a homogeneous linear recursive sequence, and after obtaining the sequence, calculates the public parameters of the mask private key and the random number mask, and sends them to each server; the client uses the mask private key to calculate the mask, and adds the mask and random number mask to the local model parameters, and uses the authentication key pair to generate authentication parameters; the client uploads the masked local model parameters and authentication parameters to the server, and the server authenticates the client according to the authentication parameters. After successful authentication, the client's model parameters are aggregated and a list of offline clients is broadcast;

[0012] The online client calculates the secret sharing parameters of each offline client based on the public parameters of the corresponding offline client and uploads them to the server; after the server aggregates the secret sharing parameters of each offline client, it recovers the mask key of the offline client and calculates the mask of the offline client and the random number mask of the online client; the server adds the mask of the offline client and the random number mask of the online client to the model parameters aggregated by the server, eliminates the influence of the mask and the random number mask, completes the aggregation and broadcasts the model parameters.

[0013] Furthermore, the privacy protection method of federated learning includes the following steps:

[0014] Step 1, initialization phase: The server and client complete the initialization of various parameters for use in subsequent steps in the solution; including initializing the authentication key pair, secret sharing auxiliary function, and secret sharing key pair;

[0015] Step 2, key distribution phase: The client constructs the key and public parameters required for masking; constructs a homogeneous linear recursive sequence and calculates the public parameters of the mask based on the parameters obtained by Diffie-Hellman key exchange based on the elliptic curve, and sends the parameters to the server;

[0016] Step 3, mask generation and client authentication phase: In the scheme, the client uses the mask to encrypt local data to protect the security of private data. At the same time, the server uses the authentication parameters to verify the client to prevent intrusion from unfamiliar clients. The mask is calculated and added to the local model parameters. The client generates the authentication parameters, the server authenticates the client, and the server aggregates the model parameters and broadcasts the list.

[0017] Step 4, model aggregation phase: In this scheme, it is used to securely aggregate data on the server and eliminate the masks of offline users; the client calculates the secret shared parameters, the server recovers the offline client mask and the online client random number mask, and the server completes the aggregation and broadcasts the parameters.

[0018] Furthermore, during the initialization phase, the server uses an elliptic curve-based cryptographic algorithm with a generator g s Generate a pair of public and private keys for each client i ,P i}, each client obtains its own public and private key pair, private key s i Keep it yourself, public key P i Public; Each client constructs an auxiliary function for full dynamic secret sharing and generates a generator g using an elliptic curve-based cryptographic algorithm u , and then the auxiliary function parameters and generator g uThe server sends the auxiliary function parameters and generators to each client. After receiving the generators from other clients, each client generates a pair of public and private keys based on the generators. u,v ,Q u,v}, public key Q u,v The server packages all parameters uploaded by the client and broadcasts them to other clients. The initialization phase is only run once in the first round of a complete federated learning training.

[0019] Furthermore, the initialization phase in step one specifically includes:

[0020] (1) Initialization of the authentication key pair

[0021] 1) The server determines the number of clients as n, and uses an integer of 1,…,n as the client identifier; at the same time, it determines the secret sharing threshold as t, and broadcasts it to the client;

[0022] 2) The server randomly selects an elliptic curve E and a point g on it s As a generator, g s The order of is λ;

[0023] 3) The server is in Z λ Randomly select s for each client i , and calculate P i =s i g s Generate a public-private key pair for each client for authentication i ,P i}; where Z λ represents a finite field, which represents the remainder obtained by dividing the selected integer by λ;

[0024] 4) The server sends the private key s i The secret is sent to the corresponding client, and the public key P i , g s and λ public broadcasts are sent to clients.

[0025] (2) Initialization of secret sharing auxiliary function

[0026] The client constructs a secret sharing auxiliary function and sends the relevant parameters to the server. After the server collects enough client messages to meet the threshold, it broadcasts the parameters, including:

[0027] 1) Each client randomly selects a constant φ>0 and constructs a secret sharing auxiliary function (x-φ) based on the known secret sharing threshold t. t =x t +δ 1 x t-1 +δ2 x t-2 +...+δ t =0;

[0028] 2) The client randomly selects a large prime number ε>δ i , 1≤i≤t, and randomly select an elliptic curve E and a point g on it u As a generator, g u The order of is μ;

[0029] 3) Each client sets the parameters {μ,φ,ε,g u}Package and send to the server;

[0030] 4) After confirming that it has received information from at least t clients, the server broadcasts the parameters uploaded by each client. If the number of clients is less than t, this round of federated learning is terminated.

[0031] (3) Initialization of secret shared key pair

[0032] 1) Each client receives the parameters μ and g from other clients. v , in the finite field Z μ Randomly select an integer s from u,v , calculate Q u,v =s u,v g v Generate a secret shared key pair with the corresponding client {s u,v ,Q u,v}, private key s u,v Keep it yourself, public key Q u,v Sent to the server; u represents the current client, v represents the set of other clients; u and v represent the parameters generated by the current client and other clients in a one-to-one correspondence;

[0033] 2) After the server has received information from at least t clients, it will send the public key q uploaded by each client to u,v Broadcast, if the number of clients is less than t, terminate this round of federated learning.

[0034] 3) The server selects an elliptic curve E and a point g on the elliptic curve E as a generator, the order of g is ι, and broadcasts {g, ι}.

[0035] Furthermore, in the key distribution phase, in each round of training, each client generates a key according to its own generator g. u Generate a private key u , use s u and other clients' Q u,v Complete key exchange and generate W u,vAt the same time, each client obtains a generator g through an elliptic curve-based cryptographic algorithm and uses g to generate a pair of public and private keys {s u ',R u}; Each client uses the obtained W u,v and random numbers r, r', using a two-parameter one-way function to calculate I u,v ,I u,v ', use I u,v ,I u,v 'Establish homogeneous linear recursive series to calculate m n-1 , m' n-1 ; Each client uses m n-1 , m' n-1 Calculate s' u and random number mask b u The public parameters T and T' are sent to the server; the server packages all the parameters uploaded by each client and broadcasts them to other clients.

[0036] Furthermore, the key distribution phase in step 2 specifically includes:

[0037] (1) Diffie-Hellman key exchange based on elliptic curve

[0038] 1) The client is in the finite domain Z ι , Z μ Randomly select an integer s' u 、s u , calculate R u =s' u g;

[0039] 2) Based on the public key Q of other clients u,v Calculate W u,v =s u Q u,v .

[0040] (2) Construct a homogeneous linear recursive sequence and calculate the common parameters of the mask

[0041] Randomly select two integers and use a two-parameter one-way function to calculate the results. Use the obtained results to construct a homogeneous linear recursive sequence, and then use the values ​​of the sequence to calculate the public parameters T, T' of the mask, including:

[0042] 1) Randomly select integers r and r' and use the two-parameter one-way function f to calculate I u,v =f(r,W u,v ), I' u,v =f(r,W u,v ),1≤v≤n;

[0043] 2) Calculation

[0044] 3) Calculate m v 、m' v , where t≤v≤n-1;

[0045] 4) Calculate y v =I u,v -m v-1 ,y' v =I' u,v -m' v-1 , where t <v≤n;

[0046] 5) Calculate T = s' u -m n-1 and T' = b u -m' n-1 , where s' u is the masked private key, T is the public parameter of the masked private key; bu 为 Random number mask, T' is the public parameter of the random number mask.

[0047] (3) Send parameters to the server

[0048] 1) The client will {R u ,y v ,y' b ,r,r',T,T'} parameters are packaged and sent to the server;

[0049] 2) After the server determines that it has received information from at least t clients, it records the identity of the client that uploaded the message in the list U 0 and {R u ,y v ,y' v ,r,r',T,T'} parameters are broadcast to the clients. If the number of clients is less than t, this round of federated learning is terminated.

[0050] Furthermore, in the mask generation and client authentication phase, in each round of training, each client uses the existing model parameters to train the model locally and calculates the model update parameters; each client uses its own private key s' u and the public key R of the other client u Complete key exchange to generate mask z u,v , each client uses mask z u,v and random number mask b u Encrypt model update parameters; each client uses its own s i Calculate and generate parameters for verifying the client's identity and send them to the server. After receiving the model update parameters and verification parameters, the server uses g s The P corresponding to the clientu Authenticate the client identity using the uploaded verification parameters; after confirming that the client belongs to the server, the server aggregates the encrypted model update parameters uploaded by the client, identifies the offline clients, and then sends the list of offline clients to the online clients.

[0051] Furthermore, the mask generation and client authentication phase in step three includes:

[0052] (1) Calculate the mask

[0053] The client calculates z according to the publicly available parameters R v , g and its own mask private key s' u Calculate z u,v = s' u R v .

[0054] (2) Add the mask to the local model parameters

[0055] The client calculates ρ = x u + Δ u,v z u,v + b u , where u > v and u < v indicate the coefficients of z u,v determined according to the size of the client's identification value; where x u represents the client's local model parameters, z u,v is the calculated mask, and b u is the random number mask selected by the client;

[0056] (3) The client generates authentication parameters

[0057] The client calculates and generates the authentication parameters of this client using the random number and the authentication private key, and packs and sends the parameters to the server, specifically including:

[0058] 1) The client uses the random numbers η, θ and the authentication private key s i to calculate k = (ηs i + θ);

[0059] 2) Use k and the generator g publicly available on the server s to calculate a point kg on the elliptic curve s = (x 1 , y 1 );

[0060] 3) Calculate

[0061] 4) Calculate e=H(G), where G is the initial global model parameter or the global model parameter updated by the server in the previous round; H is a hash function that maps any length of message into a fixed-length summary;

[0062] 5) Calculate the client's authentication parameters

[0063] (4) Server authentication client

[0064] 1) After the server has received information from at least t clients, it authenticates the client. If the number of clients is less than t, this round of federated learning is terminated.

[0065] 2) The server calculates e = H(G) and calculates it based on the parameters uploaded by each client.

[0066] 3) Continue to calculate ψ = x 2 modλ and verify the client If the authentication is successful, the client's identity is recorded in the list U 1 If the verification fails, the client message will be rejected;

[0067] (5) The server aggregates model parameters and broadcasts the list

[0068] 1) The server aggregates the model parameters uploaded by the client and calculates ∑ u ρ,u∈U 1 ;

[0069] 2) The server will be in the list U 0 But not in the list U 1 The client identity is regarded as a disconnected client, denoted as U 0 / U 1 , and broadcast the disconnected client list to U 1 Clients in the list.

[0070] Furthermore, in the model aggregation stage, the online client calculates the m of the offline client based on T uploaded by the offline client, and calculates m' based on T' uploaded by other online clients, and sends them to the server; the server recovers s' of the offline client based on m and m' sent by the client. u and the random number mask b of the online client u , and according to s' u Restore the mask z of the offline client u,v,Finally, the server subtracts the mask and random number mask from the aggregated model update parameters, and recovers the model update parameters; after using the parameters to update the model, the updated model parameters are sent to each client, and the client updates the model; if the number of disconnected clients does not exceed the threshold, the server generates a new g,ι parameter and sends it to the client, and the training continues, otherwise the training terminates.

[0071] Furthermore, the model aggregation phase in step 4 specifically includes:

[0072] (1) The client calculates the secret sharing parameters

[0073] After the online client receives the offline client list broadcast by the server, it uses the public parameters of the corresponding client to calculate m v-1 and m' v-1 , and m v-1 、m' v-1 Upload to the server, including:

[0074] 1) The online client receives the offline client list broadcast by the server;

[0075] 2) Calculate using the public parameters of the corresponding offline client and

[0076] 3) m v-1 、m' v-1 Upload to the server.

[0077] (2) The server recovers the offline client mask and the online client random number mask

[0078] After collecting the number of client messages that meet the threshold, the parameter m uploaded by the client is v-1 、m' v-1 and other public parameters to recover the mask key and random number mask, including:

[0079] 1) The server will proceed to the next step after confirming that it has received information from at least t clients. If the number of clients is less than t, this round of federated learning will be terminated;

[0080] 2) The server collects the parameters uploaded by the online client and uses Constructing a function

[0081] 3) Calculate m according to the function i =p(i)φ i , we can calculate the m of the disconnected client n-1 ;

[0082] 4) Use the masked private key public parameters T and m of the offline client n-1 Calculate s'u =T+m v-1 ;

[0083] 5) Use Constructor

[0084] 6) Calculate m' according to the function i =p(i)φ i , we can calculate the m' of the disconnected client n-1 ;

[0085] 7) Use the masked private key public parameters T' and m' of the offline client n-1 calculate b u=T+m' n-1 .

[0086] (3) The server completes aggregation and broadcasts parameters

[0087] 1) The server uses the masked private key s' of the offline client u and the public key R of the other client v Calculate

[0088] 2) The server adds the mask of the offline client and the random number mask of the online client to the aggregation parameters and calculates Complete aggregation;

[0089] 3) The server generates a new pair of {g, ι} parameters and broadcasts them and aggregates the model parameters The updated global model parameters are sent to each client, and the client uses the global model parameters to update its local model. After the update is completed, the next round of joint learning begins until the model parameters meet the conditions or the set number of rounds is reached.

[0090] Another object of the present invention is to provide a federated learning privacy protection system applying the federated learning privacy protection method, the federated learning privacy protection system comprising:

[0091] The initialization module is used to initialize various parameters through the server and the client, including the authentication key pair, the secret sharing auxiliary function, and the secret sharing key pair;

[0092] The key distribution module is used for Diffie-Hellman key exchange based on elliptic curves, constructs homogeneous linear recursive sequence and calculates the public parameters of the mask, and sends the parameters to the server;

[0093] The mask generation and client authentication module is used to calculate the mask and add it to the local model parameters; the client generates the authentication parameters, the server authenticates the client, and the server aggregates the model parameters and broadcasts the list;

[0094] The model aggregation module is used to calculate the secret shared parameters through the client, the server recovers the offline client mask and the online client random number mask, and the server completes the aggregation and broadcasts the parameters.

[0095] Another object of the present invention is to provide a computer device, the computer device comprising a memory and a processor, the memory storing a computer program, and when the computer program is executed by the processor, the processor executes the steps of the federated learning privacy protection method.

[0096] Another object of the present invention is to provide a computer-readable storage medium storing a computer program, which, when executed by a processor, enables the processor to perform the steps of the federated learning privacy protection method.

[0097] Another object of the present invention is to provide an information data processing terminal, which is used to implement the federated learning privacy protection system.

[0098] In combination with the above technical solutions and the technical problems solved, the advantages and positive effects of the technical solutions to be protected by the present invention are as follows:

[0099] First, in view of the technical problems existing in the above-mentioned prior art and the difficulty of solving the problems, the technical solutions to be protected by the present invention and the results and data during the research and development process are closely combined to analyze in detail and deeply how the technical solutions of the present invention solve the technical problems, and some creative technical effects brought about after solving the problems. The specific description is as follows:

[0100] The method for protecting the privacy of federated learning based on full dynamic secret sharing and elliptic curve cryptography provided by the present invention includes two parts: a key distribution method based on full dynamic secret sharing and a client authentication method based on elliptic curve cryptography, which mainly targets four stages: initialization stage, key distribution stage, mask generation and client authentication stage, and model aggregation stage. The present invention realizes the rapid distribution of keys by adopting a key distribution method based on full dynamic secret sharing, while ensuring the privacy of keys, which effectively improves the efficiency of federated learning and ensures the security of keys; through a client authentication method based on elliptic curve cryptography, the identity of the client is authenticated, while ensuring that the accuracy of the model will not be interfered with by forged or malicious data, which can effectively protect the accuracy of federated learning results.

[0101] In view of the problems in existing federated learning such as excessive key distribution time overhead and the possibility that the server may receive data from unfamiliar clients, the present invention provides a federated learning privacy protection method based on full dynamic secret sharing and elliptic curve cryptography algorithm. The key distribution method based on full dynamic secret sharing and the client authentication method based on elliptic curve cryptography algorithm are applied to ensure the security of the privacy data of the participants, improve the efficiency of the joint training model, and prevent the server from receiving data from unfamiliar clients.

[0102] Second, considering the technical solution as a whole or from the perspective of the product, the technical effects and advantages of the technical solution to be protected by the present invention are described in detail as follows:

[0103] The federated learning privacy protection method based on full dynamic secret sharing and elliptic curve cryptography algorithm provided by the present invention protects the security of client privacy data in federated learning; reduces the time overhead of federated learning, improves the efficiency of training and saves resources.

[0104] Compared with the prior art, the present invention has the following advantages:

[0105] (1) In the secret sharing scheme used by existing federated learning to generate mask keys, a large amount of communication time is required to encrypt and send the subkey to the corresponding client. In practice, such communication time overhead is unbearable and affects the efficiency of federated learning.

[0106] (2) The present invention can identify the client deployed by the server itself in the case of a public network, and can also reject data uploaded by unfamiliar clients that may contain forged or malicious data, thereby protecting the accuracy of federated learning from being affected.

[0107] Third, as auxiliary evidence of the inventiveness of the claims of the present invention, it is also reflected in the following important aspects:

[0108] (1) The technical solution of the present invention fills the technical gap in the industry at home and abroad:

[0109] For the first time, a federated learning scheme based on fully dynamic secret sharing is proposed, which is suitable for federated learning in multi-client scenarios. It can effectively train machine learning models through federated learning and ensure the privacy of client data during the training process, thus improving the efficiency of federated learning. At the same time, combined with the cryptographic algorithm based on elliptic curves, an authentication scheme is proposed to prevent intrusion and attacks from unfamiliar clients, thus ensuring the security of the system.

[0110] (2) The technical solution of the present invention solves a technical problem that people have been eager to solve but have never been able to solve successfully:

[0111] At present, the privacy protection methods for federated learning at home and abroad focus on how to improve concurrency and authentication, but lack consideration of reducing communication time overhead and improving training efficiency. In actual application scenarios, a large amount of communication between clients in each round of federated learning requires forwarding by the server, which has a huge communication time overhead and consumes a lot of computing resources. Therefore, reducing the communication overhead of the client and improving the efficiency of federated learning have always been technical problems that have been eager to be solved but have never been successfully solved. The present invention solves the problem of excessive communication time overhead that has always existed, can achieve safe and efficient federated learning, and is more suitable for actual application scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0112] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments of the present invention. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0113] Figure 1 is a flow chart of a method for protecting privacy in federated learning provided by an embodiment of the present invention;

[0114] Figure 2 is an interactive diagram of a federated learning privacy protection method provided by an embodiment of the present invention;

[0115] Figure 3 is a schematic diagram of a privacy protection method for federated learning provided by an embodiment of the present invention;

[0116] Figure 4 Schematic diagram of a key distribution method based on full dynamic secret sharing provided by an embodiment of the present invention;

[0117] Figure 5 is a diagram of a client authentication method based on an elliptic curve cryptographic algorithm provided by an embodiment of the present invention;

[0118] Figure 6 It is a schematic diagram of the training time of the existing federated learning scheme (Secagg, Secure aggregation) provided by the embodiment of the present invention and the scheme of the present invention (EfficiencySecagg, Efficiency Secure aggregation) under different numbers of training rounds;

[0119] Figure 7It is a schematic diagram of training time under different numbers of training rounds for the existing federated learning solution (Secagg, Secure aggregation) provided by an embodiment of the present invention and the solution of the present invention (EfficiencySecagg, Efficiency Secure aggregation) under the premise that 30% of the clients are offline. DETAILED DESCRIPTION

[0120] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0121] In view of the problems existing in the prior art, the present invention provides a method, system, medium, device and terminal for privacy protection in federated learning. The present invention is described in detail below with reference to the accompanying drawings.

[0122] 1. Explanatory Examples In order to enable those skilled in the art to fully understand how to implement the present invention, this section provides an illustrative example that expands and describes the technical solution of the claims.

[0123] like Figure 1 As shown, the federated learning privacy protection method provided by the embodiment of the present invention includes the following steps:

[0124] S101, initialization phase: the server and the client complete the initialization of various parameters, including the authentication key pair, the secret sharing auxiliary function, and the secret sharing key pair;

[0125] S102, key distribution phase: based on the Diffie-Hellman key exchange of the elliptic curve, a homogeneous linear recursive sequence is constructed and the public parameters of the mask are calculated, and the parameters are sent to the server;

[0126] S103, mask generation and client authentication phase: calculate the mask and add the mask to the local model parameters; the client generates authentication parameters, the server authenticates the client, and the server aggregates the model parameters and broadcasts the list;

[0127] S104, model aggregation phase: the client calculates secret shared parameters, the server recovers the offline client mask and the online client random number mask, and the server completes the aggregation and broadcasts the parameters.

[0128] The privacy protection method of the present invention is aimed at the typical scenario of the interaction between the participants and the aggregation server: the client-server scenario, where their interaction mode is as follows: Figure 2As shown. The method of the present invention mainly targets four stages: initialization stage, key distribution stage, mask generation and client authentication stage, and model aggregation stage. The operation mode of the federated learning scheme described in the present invention is: the first round of joint training includes the above four stages, and each subsequent round of joint training only runs the key distribution stage, mask generation and client authentication stage, and model aggregation stage. In short, the initialization stage is only run in the first round of joint training. In the present invention, u is used to represent the current client, and c is used to represent a set of other clients except the current client.

[0129] During the initialization phase, the server uses an elliptic curve-based cryptographic algorithm with a generator g s Generate a pair of public and private keys for each client i ,P i}, each client obtains its own public and private key pair, private key s i Keep it yourself, public key P i Public; Each client constructs an auxiliary function for full dynamic secret sharing and generates a generator g using an elliptic curve-based cryptographic algorithm u , then the auxiliary function parameters and generator g u The server sends the auxiliary function parameters and generators to each client. After receiving the generators from other clients, each client generates a pair of public and private keys based on the generators. u,v ,Q u,v}, public key Q u,v Sent to the server; the server generates parameters based on the elliptic curve cryptography algorithm and packages them with all the parameters uploaded by the client, and broadcasts them to other clients; the initialization phase only needs to be run once in the first round of a complete federated learning training.

[0130] In the key distribution phase, in each round of training, each client generates a key according to its own generator g. u Generate a private key u , use s u and other clients' Q u,v Complete key exchange and generate W u,v At the same time, each client generates a pair of public and private keys through the parameters generated by the server based on the elliptic curve cryptographic algorithm {s u ',R u}; Each client uses the obtained W u,v and random numbers r, r', using a two-parameter one-way function to calculate I u,v ,I u,v ', use I u,v ,I u,v 'Establish homogeneous linear recursive series to calculate m n-1 , m'n-1 ; Afterwards, each client uses m n-1 , m′ n-1 Calculate s′ u and random number mask b u The public parameters T and T′ are obtained and sent to the server; the server packages all the parameters uploaded by each client and broadcasts them to other clients.

[0131] In the mask generation and client authentication phase, in each round of training, each client uses the existing model parameters to train the model locally and calculates the model update parameters. Each client uses its own private key s′ u and the public key R of the other client v Complete key exchange to generate mask z u,v , each client uses mask zu, v and random number mask b u Encrypt the parameters of the model update; then, each client uses its own s i Calculate and generate parameters for verifying the client's identity and send them to the server. After receiving the model update parameters and verification parameters, the server uses g s The P corresponding to the client u After confirming that the client belongs to the server, the server aggregates the encrypted model update parameters uploaded by the client, confirms the offline client, and then sends the offline client list to the online client.

[0132] In the model aggregation stage, the online client calculates the m of the offline client based on T uploaded by the offline client, and calculates m′ based on T′ uploaded by other online clients, and sends them to the server; the server recovers s′ of the offline client based on m and m′ sent by the client. u and the random number mask b of the online client u , then according to s′ u Restore the mask z of the offline client u,v ,Finally, the server subtracts the mask and random number mask from the aggregated model update parameters, and recovers the model update parameters; after using the parameters to update the model, the updated model parameters are sent to each client, and the client updates the model. If the number of disconnected clients does not exceed the threshold, the server generates a new g,ι parameter and sends it to the client, and the training continues, otherwise the training terminates.

[0133] As a preferred embodiment, Figure 3 As shown, the federated learning privacy protection method based on full dynamic secret sharing and elliptic curve cryptography algorithm provided in the embodiment of the present invention specifically includes the following steps:

[0134] Step 1: Initialization phase.

[0135] The server and client complete the initialization of various parameters, including authentication key pair, secret sharing auxiliary function, and secret sharing key pair.

[0136] Step 1.1: Initialization of authentication key pair.

[0137] (1) The server determines the number of clients as n, and uses integers from 1, …, n as the client identifiers for easy understanding and representation; it also determines the secret sharing threshold as t, and broadcasts it to the clients;

[0138] (2) The server randomly selects an elliptic curve E and a point g on it s As a generator, g s The order of is λ;

[0139] (3) The server is in Z λ Randomly select s for each client i , and calculate P i =s i g s Generate a public-private key pair for each client for authentication i ,P i}; where Z λ represents a finite field, which represents the remainder obtained by dividing the selected integer by λ;

[0140] (4) The server sends the private key s i The secret is sent to the corresponding client, and the public key P i , g s and λ is publicly broadcasted to the client;

[0141] Step 1.2: Initialization of secret sharing helper function.

[0142] (1) The client constructs a secret-sharing auxiliary function and sends the relevant parameters to the server. After the server collects enough client messages to meet the threshold, it broadcasts the parameters.

[0143] Step 1.3: Initialization of secret shared key pair.

[0144] (1) Each client receives the parameters μ and g from other clients. v , in the finite field Z μ Randomly select an integer s from u,v , calculate Q u,v =s u,v g v Generate a secret shared key pair with the corresponding client {s u,v ,Q u,v}, private key s u,v Keep it yourself, public key Q u,vSent to the server; u represents the current client, v represents the set of other clients; u and v here represent the parameters generated by the current client and other clients in a one-to-one correspondence;

[0145] (2) After the server has received information from at least t clients, it will send the public key Q uploaded by each client to u,v Broadcast, if the number of clients is less than t, terminate this round of federated learning.

[0146] (3) The server selects an elliptic curve E and a point g on the elliptic curve E as a generator, the order of g is ι, and broadcasts {g, ι}.

[0147] Step 2: Key distribution phase.

[0148] The client completes the Diffie-Hellman key exchange based on the elliptic curve, uses the key obtained after the exchange to construct a homogeneous linear recursive sequence, calculates the public parameters of the masked private key and the random number mask after obtaining the sequence, and sends them to the server.

[0149] Step 2.1: Elliptic Curve Diffie-Hellman Key Exchange.

[0150] (1) The client is in the finite field Z ι , Z μ Randomly select an integer s′ from u 、s u , calculate R u =s′ u g.

[0151] (2) Based on the public key Q of other clients u,v Calculate W u,v =s u Q u,v .

[0152] Step 2.2: Construct a homogeneous linear recursive sequence and calculate the common parameters of the mask.

[0153] (1) Randomly select two integers, use a two-parameter one-way function to calculate the results, then use the obtained results to construct a homogeneous linear recursive sequence, and then use the numerical values ​​of the sequence to calculate the common parameters T, T′ of the mask.

[0154] Step 2.3: Send parameters to the server.

[0155] (1) The client will {R u ,y v ,y′ v ,r,r′,T,T′} parameters are packaged and sent to the server.

[0156] (2) After the server determines that it has received information from at least t clients, it records the identities of the clients that uploaded the messages in list U 0 and broadcasts the parameters {R u , y u , y′ v , r, r′, T, T′} to the clients. If the number of clients is less than t, this round of federated learning is aborted.

[0157] Step 3: Mask generation and client authentication phase.

[0158] The client calculates the mask using the mask private key and adds the mask and the random number mask to the local model parameters, and then generates the authentication parameters. The client uploads the masked local model parameters and the authentication parameters to the server. The server authenticates the client. After successful authentication, the server aggregates the model parameters of the clients and broadcasts the list of disconnected clients.

[0159] Step 3.1: Calculate the mask.

[0160] (1) The client calculates z v according to the public parameters R u , g and its own mask private key s′ u,v = s′ u R v .

[0161] Step 3.2: Add the mask to the local model parameters.

[0162] (1) The client calculates where u > v and u < v indicate the coefficients of z u,v determined according to the size of the client's identification value; where x u represents the local model parameters of the client, z u,v is the calculated mask, and b u is the random number mask selected by the client;

[0163] Step 3.3: The client generates the authentication parameters.

[0164] (1) The client calculates and generates the authentication parameters of this client using the random number and the authentication private key, and packs and sends the parameters to the server.

[0165] Step 3.4: The server authenticates the client.

[0166] (1) After the server determines that it has received information from at least t clients, it authenticates the clients. If the number of clients is less than t, this round of federated learning is aborted;

[0167] (2) The server calculates e = H(G) and calculates respectively according to the parameters uploaded by each client where x 2 ,y 2 ) represents the calculated elliptic curve coordinates;

[0168] (3) Continue to calculate ψ = x 2 modλ and verify the client If the authentication is successful, the client's identity is recorded in the list U 1 If the verification fails, the client message will be rejected;

[0169] Step 3.5: The server aggregates the model parameters and broadcasts the list.

[0170] (1) The server aggregates the model parameters uploaded by the client and calculates ∑ u ρ,u∈U 1 .

[0171] (2) The server will be in the list U 0 But not in the list U 1 The client identity is regarded as a disconnected client, denoted as U 0 / U 1 , and broadcast the disconnected client list to U 1 Clients in the list.

[0172] Step 4: Model aggregation phase.

[0173] The online client calculates the secret shared parameters of each offline client based on the public parameters of the corresponding offline client and uploads them to the server. After the server aggregates the secret shared parameters of each offline client, it recovers the mask key of the offline client and calculates the mask of the offline client and the random number mask of the online client. The server adds the mask of the offline client and the random number mask of the online client to the model parameters aggregated by the server, eliminates the influence of the mask and the random number mask, completes the aggregation, and broadcasts the model parameters.

[0174] Step 4.1: The client calculates the secret sharing parameters.

[0175] (1) After the online client receives the offline client list broadcast by the server, it uses the public parameters of the corresponding client to calculate m v-1 and m′ v-1 , and m v-1 , m′ v-1 Upload to the server.

[0176] Step 4.2: The server recovers the offline client mask and the online client random number mask.

[0177] (1) After collecting enough client messages that meet the threshold, the client uploads the parameter m. v-1 , m′v-1 and other public parameters to recover the mask key and random number mask.

[0178] Step 4.3: The server completes the aggregation and broadcasts the parameters.

[0179] (1) The server uses the masked private key s′ of the disconnected client u and the public key R of the other client v Calculate

[0180] (2) The server adds the mask of the offline client and the random number mask of the online client to the aggregation parameter and calculates Complete aggregation.

[0181] (3) The server aggregates the model parameters As the updated global model parameters, it is sent to each client. At the same time, the server also generates new g,ι parameters and sends them to the client. The client updates its local model with the global model parameters. After the update is completed, the next round of joint learning begins until the model parameters meet the conditions or the set number of rounds is reached.

[0182] Step 1.2 The initialization process of the secret sharing auxiliary function is as follows Figure 4 As shown in (a) and (b), the following steps are included:

[0183] (1) Each client randomly selects a constant φ>0 and constructs a secret sharing auxiliary function (x-φ) based on the known secret sharing threshold value t. t =x t +δ 1 x t-1 +δ 2 x t-2 +...+δ t =0.

[0184] (2) The client randomly selects a large prime number ε>δ i , 1≤i≤t, and randomly select an elliptic curve E and a point g on it u As a generator, g u The order of is μ.

[0185] (3) Each client sets the parameters {μ,φ,ε,g u}Package and send to the server.

[0186] (4) After confirming that it has received information from at least t clients, the server broadcasts the parameters uploaded by each client. If the number of clients is less than t, this round of federated learning is terminated.

[0187] Step 2.2: Construct a homogeneous linear recursive sequence and calculate the common parameters of the mask. Figure 4 (c), comprising the following steps:

[0188] (1) Randomly select integers r and r′ and use the two-parameter one-way function f to calculate I u,v =f(r,W u,v ), I′ u,v =f(r,W u,v ),1≤v≤n.

[0189] (2) Calculation

[0190]

[0191] (3) Calculate m v , m′ v , where t≤v≤n-1.

[0192] (4) Calculate y v =I u,v -m v-1 , y′ v =I′ u,v -m′ v-1 , where t <v≤n。

[0193] (5) Calculate T = s′ u -m n-1 and T′ = b u -m' n-1 , where s' u is the masked private key, and T is the public parameter of the masked private key. u is the random number mask, and T' is the public parameter of the random number mask.

[0194] Step 3.3 and step 3.4 complete the client authentication process as follows Figure 5 As shown in (a) and (b), the following steps are included:

[0195] Step 3.3: The client generates authentication parameters.

[0196] (1) The client uses random numbers η, θ and authentication private key s i Calculate k = (ηs i +θ).

[0197] (2) Use k and the generator g published by the server s Calculate a point kg on the elliptic curve s =(x 1 ,y 1 ), where (x 1 ,y 1 ) represents the calculated elliptic curve coordinates.

[0198] (3) Calculation

[0199] (4) Calculate e = H(G), where G is the initial global model parameter or the global model parameter updated by the server in the previous round. H is a hash function that can map any length of message into a fixed length summary.

[0200] (5) Calculate the client's authentication parameters

[0201] (6) Set the parameters Package and send to the server.

[0202] Step 3.4: The server authenticates the client.

[0203] (1) After the server has received information from at least t clients, it authenticates the client. If the number of clients is less than t, this round of federated learning is terminated.

[0204] (2) The server calculates e = H(G) and calculates where x 2 ,y 2 ) represents the calculated elliptic curve coordinates.

[0205] (3) Continue to calculate ψ = x 2 modλ and verify the client If the authentication is successful, the client's identity is recorded in the list U 1 If the verification fails, the client message will be rejected;

[0206] Step 4.1 The client calculates the secret sharing parameters and step 4.2 The server recovers the mask of the offline client and the random number mask of the online client. Figure 4 (d) and (e) include the following steps:

[0207] Step 4.1: The client calculates the secret sharing parameters.

[0208] (1) The online client receives the offline client list broadcast by the server.

[0209] (2) Calculation using the public parameters of the corresponding client and

[0210] (3) m v-1 、m' v-1 Upload to the server.

[0211] Step 4.2: The server recovers the offline client mask and the online client random number mask.

[0212] (1) The server proceeds to the next step only after it has received information from at least t clients. If the number of clients is less than t, this round of federated learning is terminated.

[0213] (2) The server collects the parameters uploaded by the online client and uses Constructing a function

[0214] (3) Calculate m based on the function i =p(i)φ i , we can calculate the m of the disconnected client n-1 .

[0215] (4) Use the masked private key public parameters T and m of the disconnected client n-1 Calculate s' u =T+m v-1 .

[0216] (5) Use Constructor

[0217] (6) Calculate m' based on the function i =p(i)φ i , we can calculate the m' of the disconnected client n-1 .

[0218] (7) Use the masked private key public parameters T' and m' of the offline client n-1 calculate b u=T+m' n-1 .

[0219] The federated learning privacy protection system provided by the embodiment of the present invention includes:

[0220] The initialization module is used to initialize various parameters through the server and the client, including the authentication key pair, the secret sharing auxiliary function, and the secret sharing key pair;

[0221] The key distribution module is used for Diffie-Hellman key exchange based on elliptic curves, constructs homogeneous linear recursive sequence and calculates the public parameters of the mask, and sends the parameters to the server;

[0222] The mask generation and client authentication module is used to calculate the mask and add it to the local model parameters; the client generates the authentication parameters, the server authenticates the client, and the server aggregates the model parameters and broadcasts the list;

[0223] The model aggregation module is used to calculate the secret shared parameters through the client, the server recovers the offline client mask and the online client random number mask, and the server completes the aggregation and broadcasts the parameters.

[0224] 2. Application Examples: In order to prove the creativity and technical value of the technical solution of the present invention, this section provides application examples of the technical solution of the claims on specific products or related technologies.

[0225] According to the actual application scenario, the fully dynamic secret sharing technology is used to implement the federated learning privacy protection scheme. At the same time, a client authentication scheme is proposed based on the cryptographic algorithm based on the elliptic curve to prevent intrusion from unfamiliar clients and ensure the accuracy and correctness of federated learning. The efficient and secure federated learning privacy protection scheme formed by the present invention has certain practical value for the construction of actual scenarios.

[0226] In the smart medical system, the client can deploy an Internet of Things device or a wearable device to collect health data, and after training the data locally, send the trained parameters to the server for federated learning. After federated learning, the server obtains better model parameters and trains a better model. In this process, the clients participating in federated learning need to communicate separately through the server all the time, which will greatly increase the communication time overhead, resulting in reduced training efficiency and a large amount of resource occupation during the federated learning process. When combined with the present invention, it can be ensured that the client does not need to perform a large amount of separate communications through the server when performing federated learning, thereby reducing the communication time overhead and resource occupation, and improving the efficiency of federated learning training.

[0227] In this scenario, since the client's local data may contain private information, such as blood oxygen saturation or abnormal heart rate information, the client does not want this private information to be disclosed, which puts forward the requirement of privacy protection for the federated learning solution. When combined with the present invention, the privacy of client data can be guaranteed during the training process of federated learning. The server can only obtain the aggregated model parameter results, and cannot obtain the private data of any client.

[0228] In addition, in actual application scenarios, most of the communication processes between the client and the server are completed in the public network, so there is a possibility that clients not deployed on the server may maliciously upload model parameters, interfere with the server to obtain normal aggregation results, and thus affect the accuracy and correctness of federated learning. The present invention uses an elliptic curve-based cryptographic algorithm to implement client authentication, ensuring that during the federated learning process, the server will not receive false model parameters maliciously uploaded by unfamiliar clients. This solution is performed before the server aggregates the client model parameters. If there are model parameters uploaded by unfamiliar clients, they can be filtered out before aggregation to ensure that there will be no impact on aggregation.

[0229] In summary, the present invention proposes for the first time federated learning based on fully dynamic secret sharing, and proposes a secure and efficient federated learning privacy protection scheme in combination with a cryptographic algorithm based on elliptic curves, which can meet certain social needs and has practical value.

[0230] 3. Evidence of the effects of the embodiments. The embodiments of the present invention have achieved some positive effects during the development or use process, and indeed have great advantages over the prior art. The following content is described in conjunction with the data, charts, etc. of the test process.

[0231] like Figure 2 As shown, the framework of federated learning is shown. The federated learning framework adopted in this solution is consistent with the prior art, that is, the client generates model parameters, and the server performs aggregation after collecting enough client model parameters, and sends the optimized model parameters to all clients. The present invention optimizes and updates the existing federated learning framework, making it more efficient and less time-consuming than the existing federated learning.

[0232] like Figure 6 As shown, the comparison of the federated learning training time between the scheme proposed in the present invention and the existing federated learning scheme is shown. It is obvious that the existing federated learning scheme (Secagg, Secure aggregation) has a higher time overhead than the scheme of the present invention (EfficiencySecagg, Efficiency Secure aggregation), and the gap becomes larger as the number of federated learning rounds increases.

[0233] like Figure 7 As shown in the figure, the time overhead of the existing federated learning solution (Secagg, Secure aggregation) and the solution of the present invention (EfficiencySecagg, Efficiency Secureaggregation) is compared when there are clients offline. Even when 30% of the clients are offline, the time overhead of the solution of the present invention is still less than that of the existing federated learning solution. This proves that the efficiency of federated learning in the solution of the present invention is the best regardless of whether there are clients offline.

[0234] It should be noted that the embodiments of the present invention can be implemented by hardware, software, or a combination of software and hardware. The hardware part can be implemented using dedicated logic; the software part can be stored in a memory and executed by an appropriate instruction execution system, such as a microprocessor or dedicated design hardware. It can be understood by a person of ordinary skill in the art that the above-mentioned devices and methods can be implemented using computer executable instructions and / or contained in a processor control code, such as a carrier medium such as a disk, CD or DVD-ROM, a programmable memory such as a read-only memory (firmware), or a data carrier such as an optical or electronic signal carrier. Such code is provided on the carrier medium. The device and its modules of the present invention can be implemented by hardware circuits such as very large-scale integrated circuits or gate arrays, semiconductors such as logic chips, transistors, etc., or programmable hardware devices such as field programmable gate arrays, programmable logic devices, etc., can also be implemented by software executed by various types of processors, and can also be implemented by a combination of the above-mentioned hardware circuits and software, such as firmware.

[0235] The above description is only a specific implementation mode of the present invention, but the protection scope of the present invention is not limited thereto. Any modification, equivalent substitution and improvement made by any technician familiar with the technical field within the technical scope disclosed by the present invention and within the spirit and principle of the present invention should be covered by the protection scope of the present invention.

Claims

1. A method for protecting privacy in federated learning, characterized in that: The privacy protection method of federated learning includes four stages: initialization stage, key distribution stage, mask generation and client authentication stage, and model aggregation stage; the server and client complete the initialization of the authentication key pair, secret sharing auxiliary function, and secret sharing key pair in turn; The client completes the Diffie-Hellman key exchange based on the elliptic curve, uses the key obtained after the exchange to construct a homogeneous linear recursive sequence, calculates the public parameters of the masked private key and the random number mask after obtaining the sequence, and sends them to each server; The client uses the masked private key to calculate the mask, and adds the mask and random number mask to the local model parameters to generate authentication parameters; The client uploads the masked local model parameters and authentication parameters to the server. The server authenticates the client. After successful authentication, it aggregates the client's model parameters and broadcasts a list of offline clients. The online client calculates the secret shared parameters of each offline client based on the public parameters of the corresponding offline client and uploads them to the server; After the server aggregates the secret shared parameters of each offline client, it recovers the mask key of the offline client and calculates the mask of the offline client and the random number mask of the online client; The server adds the mask of the offline client and the random number mask of the online client to the model parameters aggregated by the server, eliminates the influence of the mask and the random number mask, completes the aggregation and broadcasts the model parameters.

2. The method for protecting privacy in federated learning as claimed in claim 1, characterized in that: The privacy-preserving approach to federated learning includes the following steps: Step 1, initialization phase: The server and client complete the initialization of various parameters, including authentication key pair, secret sharing auxiliary function and secret sharing key pair; Step 2, key distribution phase: Based on the Diffie-Hellman key exchange of the elliptic curve, a homogeneous linear recursive sequence is constructed and the public parameters of the mask are calculated, and the parameters are sent to the server; Step 3, mask generation and client authentication phase: calculate the mask and add it to the local model parameters; the client generates authentication parameters, the server authenticates the client, the server aggregates the model parameters and broadcasts the list; Step 4, model aggregation phase: the client calculates the secret shared parameters, the server recovers the offline client mask and the online client random number mask, and the server completes the aggregation and broadcasts the parameters.

3. The method for protecting privacy in federated learning as claimed in claim 2, characterized in that: In the initialization phase of step 1, the server uses an elliptic curve-based cryptographic algorithm with a generator g s Generate a pair of public and private keys for each client i , P i }, each client obtains its own public and private key pair, private key s i Keep it yourself, public key P i Public; Each client constructs an auxiliary function for full dynamic secret sharing and generates a generator g using an elliptic curve-based cryptographic algorithm u , and then the auxiliary function parameters and generator g u The server sends the auxiliary function parameters and generators to each client. After receiving the generators from other clients, each client generates a pair of public and private keys based on the generators. u,v , Q u,v }, public key Q u,v Send to the server; the server packages all parameters uploaded by the client and broadcasts them to other clients; The initialization phase is only run once in the first round of a complete federated learning training; The initialization phase specifically includes: (1) Initialization of authentication key pair 1) The server determines the number of clients as n, and uses integers from 1, ..., n as the client identifiers; at the same time, it determines the secret sharing threshold as t, and broadcasts it to the client; 2) The server randomly selects an elliptic curve E and a point g on it s As a generator, g s The order of is λ; 3) The server is in Z λ Randomly select s for each client i , and calculate P i =s i g s Generate a public-private key pair for each client for authentication i , P i }; where Z λ represents a finite field, which represents the remainder obtained by dividing the selected integer by λ; 4) The server sends the private key s i The secret is sent to the corresponding client, and the public key P i , g s and λ is publicly broadcasted to the client; (2) Initialization of secret sharing auxiliary function The client constructs a secret sharing auxiliary function and sends the relevant parameters to the server. After the server collects enough client messages to meet the threshold, it broadcasts the parameters, including: 1) Each client randomly selects a constant φ>0 and constructs a secret sharing auxiliary function (x-φ) based on the known secret sharing threshold t t =x t +δ1x t-1 +δ2x t-2 +...+δ t =0; 2) The client randomly selects a large prime number ε>δ i , 1≤i≤t, and randomly select an elliptic curve E and a point g on it u As a generator, g u The order of is μ; 3) Each client sets the parameters {μ, φ, ε, g u }Package and send to the server; 4) After confirming that it has received information from at least t clients, the server broadcasts the parameters uploaded by each client. If the number of clients is less than t, this round of federated learning is terminated; (3) Initialization of secret shared key pair 1) Each client receives the parameters μ and g from other clients. v , in the finite field Z μ Randomly select an integer s from u,v , calculate Q u,v =s u,v g v Generate a secret shared key pair with the corresponding client {s u,v , Q u,v }, private key s u,v Keep it yourself, public key Q u,v Sent to the server; u represents the current client, v represents the set of other clients; u and v represent the parameters generated by the current client and other clients in a one-to-one correspondence; 2) After the server has received information from at least t clients, it will send the public key Q uploaded by each client to u,v Broadcast. If the number of clients is less than t, terminate this round of federated learning. 3) The server randomly selects an elliptic curve E and a point g on the elliptic curve E as a generator, the order of g is ι, and broadcasts {g, ι}.

4. The method for protecting privacy in federated learning as claimed in claim 2, characterized in that: In the key distribution phase of step 2, in each round of training, each client generates a key according to its own generator g. u Generate a private key u , use s u and other clients' Q u,v Complete key exchange and generate W u,v At the same time, each client generates a pair of public and private keys through the parameters generated by the server based on the elliptic curve cryptographic algorithm {s u ′,R u }; Each client uses the obtained W u,v and random numbers r, r′, and use a two-parameter one-way function to calculate I u,v ,I u,v ′, use I u,v ,I u,v ′ respectively establish homogeneous linear recursive series to calculate m n-1 , m′ n-1 ; Each client uses m n-1 , m′ n-1 Calculate s′ u and random number mask b u The public parameters T and T′ are sent to the server; The server packages all parameters uploaded by each client and broadcasts them to other clients; The key distribution phase specifically includes: (1) Diffie-Hellman key exchange based on elliptic curve 1) The client is in the finite domain Z l , Z μ Randomly select an integer s′ from u 、s u , calculate R u =s′ u g; 2) Based on the public key Q of other clients u,v Calculate W u,v =s u Q u,v ; (2) Construct a homogeneous linear recursive sequence and calculate the common parameters of the mask Randomly select two integers and use a two-parameter one-way function to calculate the results. Use the obtained results to construct a homogeneous linear recursive sequence, and then use the values ​​of the sequence to calculate the public parameters T and T' of the mask, including: 1) Randomly select integers r and r′ and use the two-parameter one-way function f to calculate I u,v =f(r,W u,v ), I′ u,v =f(r′,W u,v ), 1≤v≤n; 2) Calculation 3) Calculate m v , m′ v , where t≤v≤n-1; 4) Calculate y v =I u,v -m v-1 , y′ v =I′ u,v -m′ v-1 , where t<v≤n; 5) Calculate T = s′ u -m n-1 and T′ = b u -m′ n-1 , where s′ u is the masked private key, T is the public parameter of the masked private key; b u is the random number mask, T′ is the public parameter of the random number mask; (3) Send parameters to the server 1) The client will {R u ,y v , y′ v , r, r′, T, T′} parameters are packaged and sent to the server; 2) After the server has received information from at least t clients, it records the identity of the client that uploaded the message in list U0 and adds {R u ,y v , y′ v , r, r′, T, T′} parameters are broadcast to the clients. If the number of clients is less than t, this round of federated learning is terminated.

5. The method for protecting privacy in federated learning as claimed in claim 2, characterized in that: In the mask generation and client authentication phase in step 3, in each round of training, each client uses the existing model parameters to train the model locally and calculates the model update parameters; each client uses its own private key s′ u and the public key R of the other client u Complete key exchange to generate mask z u,v , each client uses mask z u,v and random number mask b u Encrypt model update parameters; each client uses its own s i Calculate and generate parameters for verifying the client's identity and send them to the server; After receiving the model update parameters and verification parameters, the server uses g s The P corresponding to the client u After confirming that the client belongs to the server, the server aggregates the encrypted model update parameters uploaded by the client, confirms the offline client, and then sends the offline client list to the online client; The mask generation and client authentication phase includes: (1) Calculate the mask The client uses the public parameter R v , g and its own masked private key s′ u Calculate z u,v =s′ u R v ; (2) Add the mask to the local model parameters The client calculates ρ = x u +Δ u,v z u,v +b u , Among them, u>v and u<v indicate that z is determined according to the size of the client's identification value. u,v The coefficient of u Represents the local model parameters of the client, z u,v is the calculated mask, b u The random number mask selected for the client; (3) The client generates authentication parameters The client uses the random number and the authentication private key to calculate the authentication parameters of the client and packages the parameters to send to the server, including: 1) The client uses random numbers η, θ and authentication private key s i Calculate k = (ηs i +θ); 2) Use k and the generator g published by the server s Calculate a point kg on the elliptic curve s =(x1, y1), where (x1, y1) represents the calculated elliptic curve coordinates; 3) Calculation 4) Calculate e = H (G), where G is the initial global model parameter or the global model parameter updated by the server in the previous round; H is a hash function that maps any length of message into a fixed-length summary; 5) Calculate the client's authentication parameters (4) Server authentication client 1) After the server has received information from at least t clients, it authenticates the client. If the number of clients is less than t, this round of federated learning is terminated. 2) The server calculates e = H(G) and calculates it based on the parameters uploaded by each client. Where (x2, y2) represents the calculated elliptic curve coordinates; 3) Continue to calculate ψ = x2 mod λ and verify the client If the verification is successful, the client's identity is recorded in the list U1. If the verification fails, the client's message is rejected; (5) The server aggregates model parameters and broadcasts the list 1) The server aggregates the model parameters uploaded by the client and calculates ∑ u ρ,u∈U1; 2) The server regards the client identities that are not in the list U0 but not in the list U1 as disconnected clients, expressed as U0 / U1, and broadcasts the disconnected client list to the clients in the U1 list.

6. The method for protecting privacy in federated learning as claimed in claim 2, characterized in that: In the model aggregation phase in step 4, the online client calculates m of the offline client based on T uploaded by the offline client, and calculates m′ based on T′ uploaded by other online clients, and sends it to the server; The server recovers the offline client's s' based on the m and m' sent by the client. u and the random number mask b of the online client u , according to s′ u Restore the mask z of the offline client u,v ,Finally, the server subtracts the mask and random number mask from the aggregated model update parameters to restore the model update parameters; After updating the model with the parameters, the updated model parameters are sent to each client, and the client updates the model; If the number of disconnected clients does not exceed the threshold, the server generates a new g,ι parameter and sends it to the client, and the training continues, otherwise the training terminates; The model aggregation stage specifically includes: (1) The client calculates the secret sharing parameters After the online client receives the offline client list broadcast by the server, it uses the public parameters of the corresponding client to calculate m v-1 and m′ v-1 , and m v-1 , m′ v-1 Upload to the server, including: 1) The online client receives the offline client list broadcast by the server; 2) Calculate using the public parameters of the corresponding offline client and 3) m v-1 , m′ v-1 Upload to the server; (2) The server recovers the offline client mask and the online client random number mask After collecting the number of client messages that meet the threshold, the parameter m uploaded by the client is v-1 , m′ v-1 and other public parameters to recover the mask key and random number mask, including: 1) The server will proceed to the next step after confirming that it has received information from at least t clients. If the number of clients is less than t, this round of federated learning will be terminated; 2) The server collects the parameters uploaded by the online client and uses Constructing a function 3) Calculate m according to the function i =p(i)φ i , we can calculate the m of the disconnected client n-1 ; 4) Use the masked private key public parameters T and m of the disconnected client n-1 Calculate s′ u =T+m v-1 ; 5) Use Constructor 6) Calculate m′ according to the function i =p(i)φ i , we can calculate the m′ of the disconnected client n-1 ; 7) Use the masked private key public parameters T' and m' of the disconnected client u-1 Calculate b u =T+m′ n-1 ; (3) The server completes aggregation and broadcasts parameters 1) The server uses the masked private key s′ of the disconnected client u and the public key R of the other client v Calculate 2) The server adds the mask of the offline client and the random number mask of the online client to the aggregation parameters and calculates Complete aggregation; 3) The server aggregates the model parameters The updated global model parameters are sent to each client. At the same time, the server also generates new g,ι parameters and sends them to the client. The client updates its local model with the global model parameters. After the update is completed, the next round of joint learning begins until the model parameters meet the conditions or the set number of rounds is reached.

7. A federated learning privacy protection system using the federated learning privacy protection method according to any one of claims 1 to 6, characterized in that: The federated learning privacy protection system includes: The initialization module is used to complete the initialization of various parameters through the server and the client, including the authentication key pair, the secret sharing auxiliary function and the secret sharing key pair; The key distribution module is used for Diffie-Hellman key exchange based on elliptic curves, constructs a homogeneous linear recursive sequence and calculates the public parameters of the mask, and sends the parameters to the server; The mask generation and client authentication module is used to calculate the mask and add it to the local model parameters; the client generates the authentication parameters, the server authenticates the client, and the server aggregates the model parameters and broadcasts the list; The model aggregation module is used to calculate the secret shared parameters through the client, the server recovers the offline client mask and the online client random number mask, and the server completes the aggregation and broadcasts the parameters.

8. A computer device, characterized in that: The computer device includes a memory and a processor, the memory stores a computer program, and when the computer program is executed by the processor, the processor executes the steps of the federated learning privacy protection method as described in any one of claims 1 to 6.

9. A computer-readable storage medium storing a computer program, which, when executed by a processor, enables the processor to perform the steps of the federated learning privacy protection method as described in any one of claims 1 to 6.

10. An information data processing terminal, characterized in that: The information data processing terminal is used to implement the federated learning privacy protection system as described in claim 7.

Citation Information

Patent Citations

  • Verifiable security aggregation method based on weighted hierarchical asynchronous federated learning

    CN114978533A

  • Federal learning local model parameter aggregation method

    CN115021905A