A federated learning system and method based on differential privacy against poisoning attacks
Through symmetric encryption and differential privacy technology, the key center is used to generate symmetric keys and noise difference matrices, combined with Euclidean distance and clustering algorithms, to solve the problem of detecting poisoning attacks in privacy-preserving federated learning, and achieve efficient model parameter verification and overhead reduction.
Patent Information
- Application Number
- CN202310247834.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-15
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2043-03-15
AI Technical Summary
Existing privacy-preserving federated learning frameworks have high computational and communication overheads when preventing poisoning attacks, and attackers can infer users' sensitive information through model parameters.
Symmetric encryption and differential privacy technologies are used. A symmetric key is generated by the key center, and the server generates noise and calculates the difference matrix. Euclidean distance and clustering algorithm are used to separate normal and toxic parameters, reducing computing and communication overhead.
It is possible to detect whether model parameters are poisoned without violating user privacy, and effectively reduce computing and communication overhead.
Smart Images

Figure CN116402167B_ABST
Abstract
Claims
1. A federated learning method based on differential privacy to prevent poisoning attacks, characterized by: The steps include: Step 1: User U i and server S1 to obtain the symmetric key k i ; Step 2: Server S1 generates N groups of noise User U i Using the symmetric key k i Get noise Step 3: Server S1 uses the symmetric key k i Encrypted global model parameter w (t) , sent to user, user U i Using the symmetric key k i For the received global model parameter w (t) Decryption to obtain the global model parameter w (t) ; Step 4: Server S1 calculates N groups of noise The difference between any noise and the rest of the noise Get the difference matrix V (t) And send it to server S2; Step 5: Server S2 receives the parameters uploaded by the user and the difference matrix Add to get the parameters to be verified Step 6: Server S2 calculates the parameters to be verified With all parameters to be verified Euclidean distance between Using clustering algorithm to transform Euclidean distance Classification, into normal parameters and toxic parameters; Step 7: Server S2 aggregates the normal parameters to obtain the parameters And send it to server S1; server S1 will send the parameter Subtract the mean μ to get the global model parameter w (t+1) , and use the symmetric key k i After encryption, it is sent to user U i , user U i Using the symmetric key k i Decryption to obtain the global model parameter w (t+1) ; Step 8: Repeat steps 2 to 7 until the model converges.
2. The federated learning method according to claim 1, wherein: The specific content of step 1 is: set up the key center KC to enable user U i and server S1 to obtain the symmetric key k i ,include , server S1 and user U i Generate a set of asymmetric keys respectively, send the public key to the key center KC, and the key center generates N sets of symmetric keys k i , the key center KC uses server S1 and user U i The public key encrypts N groups of symmetric keys k i , and sent to server S1 and user U respectively i , server S1 and user U i Decrypt with the private key to obtain the symmetric key k i .
3. The federated learning method according to claim 1, wherein: The specific content of step 2 is: in the tth round of iteration, server S1 generates N groups of noise in It obeys a Gaussian distribution with a mean of μ and a standard deviation of σ, that is, Server S1 uses the symmetric key k i encryption And send it to the corresponding user U i , user U i Using the symmetric key k i Decryption, get noise 4. The federated learning method according to claim 1, wherein: The specific content of step 3 is: in the tth iteration, server S1 uses the symmetric key k i Encrypted global model parameter w (t) And send it to the corresponding user U i , user U i Using the symmetric key k i Decryption to obtain the global model parameter w (t) , the global model parameter w (t) It is the aggregation result of servers S1 and S2 in the t-1th round of iteration. When t=1, server S1 will send an initial parameter to user U. i , the initial parameter defaults to 0.
5. The federated learning method according to claim 1, wherein: The specific content of step 4 is: In the tth round of iteration, server S1 calculates any noise The difference from the rest of the noise is calculated as follows: Among them A (t) is the coefficient matrix, G (t) Is the noise matrix; Server S1 will be the difference matrix V (t) Send to server S2.
6. The federated learning method according to claim 1, wherein: The specific content of step 5 is: Server S2 takes the parameters uploaded by the user Plus Get the parameters to be verified The calculation formula is as follows:
7. The federated learning method according to claim 1, wherein: The specific content of step 6 is: Server S2 calculates the parameters to be verified With all parameters to be verified Euclidean distance between The calculation formula is as follows: Server S2 uses clustering algorithm to convert Euclidean distance Divided into two categories α and β, and satisfying |α|>|β|, where |α| and |β| are the number of samples in class α and class β respectively, and the Euclidean distance in class α The corresponding model parameters are normal parameters, and the Euclidean distance in the β class The corresponding model parameters are toxic parameters.
8. The federated learning method according to claim 1, wherein: The specific content of step 7 is: in the tth iteration, server S2 aggregates the normal parameters and obtains the parameters And sent to server S1, the calculation formula is as follows: Among them, B is the set of normal users; Server S1 will Subtract the mean μ to get the global model parameter w (t+1) , the calculation formula is as follows: in, The value is approximately equal to The value of Server S1 sets the global model parameters w (t+1) With the symmetric key k i After encryption, it is sent to user U i , user U i Using the symmetric key k i Decryption to obtain the global model parameter w (t+1) .
9. The federated learning method according to claim 1, wherein: The specific content of step 8 is: repeat steps 2 to 7 until the model converges. The convergence conditions of the model are as follows: |A (t+1) -A (t) |<0.001 Among them, A (t+1) and A (t) are the global model parameters w (t+1) and w (t) Prediction accuracy on the training dataset.
10. A federated learning system based on differential privacy against poisoning attacks, characterized by: include: Key center KC is used to enable user U i and server S1 to obtain the symmetric key k i ; Server S1, used to generate noise Calculate the difference matrix V (t) , with server S2 and user U i making a communication connection; and, Server S2, used to calculate the parameters to be verified Calculate the parameters to be verified With all parameters to be verified Euclidean distance between Using clustering algorithm to transform Euclidean distance Classify, aggregate normal parameters, and obtain parameters With server S1 and user U i Make a communication connection.
Citation Information
Patent Citations
Privacy protection-oriented regular bus customization method based on federal analysis
CN115048590A
Federal learning method for privacy protection based on SM9 algorithm
CN115442050A