A Privacy-Preserving Ensemble Learning Method Based on Secret Sharing

By adopting a privacy protection integrated learning method based on secret sharing in the edge computing environment, the problem of excessive computing load on edge servers is solved, efficient privacy protection and model prediction accuracy are achieved, and low-latency intelligent services are supported.

CN116405204BActive Publication Date: 2025-05-30JIANGSU OCEAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202310373189.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-04-10
Publication Date
2025-05-30
Estimated Expiration
2043-04-10

AI Technical Summary

Technical Problem

In an edge computing environment, existing privacy protection methods such as differential privacy and secure multi-party computing technologies improve model prediction accuracy and privacy protection, while causing excessive computing load on edge servers, affecting the provision of low-latency services.

Method used

The privacy protection integrated learning method based on secret sharing is adopted, and the user data is divided into sharing shares that can be processed by each edge server through secret sharing technology, which is used for the training and deployment of the Adaboost algorithm, and the calculation results are finally reconstructed by the user.

Benefits of technology

In an edge computing environment, it effectively reduces the computing load of edge servers, improves the efficiency of privacy protection and the accuracy of model prediction, and supports the provision of low-latency intelligent services.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116405204B_ABST
    Figure CN116405204B_ABST
Patent Text Reader

Abstract

The present invention discloses a privacy-preserving ensemble learning method based on secret sharing. The specific steps include: S1: Users submit their privacy data; S2: Each edge server obtains the sharing shares of the user data for the training process of Adaboost and outputs the sharing shares of the calculation results; S3: The user reconstructs the final calculation result through the obtained sharing shares of the calculation results. The privacy-preserving ensemble learning method provided by the present invention can train and deploy the Adaboost algorithm in an edge computing environment and support user privacy protection in the algorithm implementation; the present method uses the Adaboost algorithm to provide services for users in an edge computing environment and supports user privacy protection during the service provision process. At the same time, the present method uses the lightweight cryptographic primitive "secret sharing" to construct the scheme, effectively reducing the computational load of the edge server and improving the usability of the method.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information technology, and specifically to a privacy protection integrated learning method based on secret sharing. Background Technique

[0002] With the advent of the fourth industrial revolution, artificial intelligence technology has made great progress. All kinds of emerging intelligent algorithms have penetrated into all aspects of society and played a positive role. However, a single artificial intelligence model often suffers from overfitting, which affects the normal use of the model. Therefore, integrated learning has emerged. Integrated learning algorithms such as Adaboost focus the attention of weak classifiers on misclassified data by adding weights to the training set. In this way, integrated learning not only improves the prediction accuracy of the model, but also effectively alleviates the overfitting problem, and has strong practical value.

[0003] Today, with the continuous maturity of 5G technology and the continuous popularization of personal mobile terminals, communication infrastructure has been continuously improved. In recent years, edge computing has gradually moved from theory to reality. It is foreseeable that in the future, real-time intelligent services will be provided to users by utilizing the low-latency characteristics of edge computing. Using the above services often requires users' private data, and at this time, the privacy protection of user data becomes particularly important.

[0004] When using the Adaboost algorithm deployed on the edge server to provide services to users, in order to protect users' privacy, the currently common solution is to achieve it by introducing differential privacy. However, this method will introduce random noise to protect users' privacy during the implementation process, but this operation will affect the prediction accuracy of the model; another idea is to adopt the security multi-party computing technology mechanism to protect users' privacy and security. Methods for training and deploying artificial intelligence models using security multi-party computing technology for privacy protection include homomorphic encryption, secret sharing, garbled circuits, etc. At the same time, the computing load capacity of the edge server is small and cannot complete a large number of encryption and decryption calculations under the condition of ensuring low latency. Therefore, a privacy protection integrated learning method based on secret sharing is provided. Summary of the Invention

[0005] The purpose of the present invention is to address the deficiencies of the prior art and provide a privacy protection integrated learning method based on secret sharing to solve the problems raised in the above background technique.

[0006] To achieve the above objective, the present invention provides the following technical solution: A privacy protection integrated learning method based on secret sharing, which can realize the training and deployment of the Adaboost algorithm in the edge computing environment. The specific steps are as follows:

[0007] S1: The user submits their own private data;

[0008] S2: Each edge server obtains the sharing shares of the user data and uses them in the training process of Adaboost, and finally outputs the sharing shares of the calculation results.

[0009] S3: The user reconstructs the calculation result through the obtained sharing shares of the calculation result.

[0010] As a preferred technical solution of the present invention, in S2, each edge server obtains the sharing shares of the user data for the training process of Adaboost and outputs the sharing shares of the calculation result. The method further includes the following steps:

[0011] S21: Initialize the weight coefficients of the training set by secret sharing.

[0012] S22: Each edge server calculates the sharing share of the error rate.

[0013] S23: Each edge server calculates the sharing share of the classifier weight coefficient.

[0014] S24: Update the weight coefficients of the training set.

[0015] S25: Each edge server outputs the sharing shares of the calculation result.

[0016] As a preferred technical solution of the present invention, the method for each edge server in S2 to obtain the sharing shares of the user data further includes: A trusted third party divides the privacy data submitted by the user according to the rules of additive secret sharing and sends it to each edge server.

[0017] As a preferred technical solution of the present invention, the reconstruction of the calculation result by the user through the obtained sharing shares of the calculation result in S2 further includes: The output results of each edge server are denoted as f i ; The reconstruction process is simply adding the output results. Specifically, f out = f 1 + f 2 +,..., + f n .

[0018] As a preferred technical solution of the present invention, in S23, each edge server calculates the sharing share of the classifier weight coefficient, and uses a multi-party secure calculation logarithm protocol to calculate the sharing of the logarithmic function result. The specific steps are as follows:

[0019] S231: The additive sharing shares obtained by each participant are denoted as <x> i , and the multiplicative sharing shares are denoted as [x] i ; First, each edge server jointly runs the additive-multiplicative resharing protocol to reshare the received additive sharing shares <x>i Convert to multiplicative sharing share [x] i ;

[0020] S232: Each participant selects a multiplicative sharing share of a random number, denoted as [ρ] i , and at the same time calculates [x] i ×[ρ] i =[x×ρ] i ;

[0021] S233: Each participant recovers x×ρ through mutual sharing;

[0022] S234: Each participant runs the multiplication-addition resharing protocol to convert [x×ρ] i and [ρ] i into additive sharing shares, denoted as <λ> i and <ρ> i , and calculate

[0023] S235: Each participant runs the addition-multiplication resharing protocol to obtain [c] i and calculate Denote it as <y> i .

[0024] As a preferred technical solution of the present invention, in S24, the weight coefficient of the training set is updated, and a multi-party secure computing exponent protocol is used to calculate the sharing share of the exponential function result. The specific steps are as follows:

[0025] S241: Each participant selects the multiplicative sharing share [ρ] i , and then jointly runs the multiplication-addition resharing protocol according to the input [ρ -1 i , to obtain <ρ -1 > i ;

[0026] S242: Each participant locally calculates All parties jointly recover e x ×ρ;

[0027] S243: Each participant calculates <y> i =e x ×ρ×<ρ -1 > i .

[0028] ​The beneficial effects of the present invention are as follows: This method can train and deploy the Adaboost algorithm in an edge computing environment and support user privacy protection in the algorithm implementation; This method provides a solution for using the Adaboost algorithm to provide services for users in an edge computing environment and supports user privacy protection during the service provision process. At the same time, this method uses the lightweight cryptographic primitive "secret sharing" to construct the solution, effectively reducing the computational load of the edge server and improving the usability of the method. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] Figure 1 It is a schematic diagram of the system model of the present invention;

[0030] Figure 2 It is a protocol flowchart of the multi-party secure computing logarithmic function;

[0031] Figure 3 It is a protocol flowchart of the multi-party secure computing exponential function;

[0032] Figure 4 It is a flowchart for training the Adaboost algorithm in an edge computing environment;

[0033] Figure 5 It is a schematic diagram of data movement after deploying the Adaboost algorithm on the edge server. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0034] The following elaborates on the preferred embodiments of the present invention in conjunction with the accompanying drawings, so that the advantages and features of the present invention can be more easily understood by those skilled in the art, thereby making the protection scope of the present invention more clearly defined.

[0035] Embodiment: Please refer to Figure 1 , the present invention provides a technical solution: A privacy-preserving ensemble learning method based on secret sharing. The solution that can be implemented by the present invention is divided into three entities, namely the user, the edge server (B i ), and the trusted third party (Γ). The user provides data as the training set during the Adaboost algorithm training process, provides historical data as input during the prediction process, and receives and reconstructs the sharing shares of the calculation results after the algorithm runs. The edge server is a device close to the user side and has certain computing and storage functions. Introducing edge computing can not only improve the speed of data acquisition and transmission of users, but also improve the utilization rate of computing resources of surrounding idle devices. The trusted third party is responsible for generating the necessary random parameters required in the implementation of the solution, and can also allocate the sharing shares of user data to the edge server.

[0036] Combined with Figure 2 and Figure 3 , the method of the present invention for multi-party secure computing of logarithms and exponential functions.

[0037] In this section, three basic multi-party security protocols are introduced first, denoted as the secure multiplication protocol, the addition-multiplication resharing protocol, and the multiplication-addition resharing protocol respectively.

[0038] 1. Secure multiplication protocol, the specific steps are as follows:

[0039] S1: Γ generates a random triple (a, b, c) that satisfies c = a × b;

[0040] S2: Γ shares (a, b, c) with B i , and each B i obtains a share;

[0041] S3: The share of the user data obtained by B i is denoted as <x> i and <y> i , and uses the shares of the random triple to calculate <e> i = <x> i - i and <f> i = <y> i - i ;

[0042] S4: Through mutual sharing, B i recovers e and f;

[0043] S5: B i calculates <xy> 1 = f × i + e × i + <c> i + e × f,

[0044] <xy> i = f × i + e × i + <c> i (i ≠ 1).

[0045] 2. Multiplication-addition resharing protocol, the specific steps are as follows:

[0046] S1: B i obtains the multiplication share [x] i , Γ generates a random non-zero number c, and distributes the addition share <c> i and the multiplication share [c] i of c to B i ;

[0047] S2: B i calculates Through mutual sharing, B iRestore α;

[0048] S3: B i Calculate the additive sharing share <x> i = α × <c> i .

[0049] 3. Additive-Multiplicative Resharing Protocol, the specific steps are as follows:

[0050] S1: B i Obtain the additive sharing share <x> i , Γ generates a random non-zero number c, and sends to B i The additive sharing share <c> of c i and the multiplicative sharing share [c] i ;

[0051] S2: B i Input <x> i and <c> i Run the secure multiplication protocol to obtain <x × c> i ;

[0052] S3: B i Send <x × c> i to B 1 , B 1 Restore x × c;

[0053] S4: B 1 Calculate the multiplicative sharing share [x] 1 = x × c × [c -1 1 , B i Calculate [x] i = [c -1 i , where i ≠ 1.

[0054] As Figure 2 shown, the protocol for multi-party secure calculation of logarithms in the present invention is as follows:

[0055] S1: B i The obtained additive sharing share is denoted as <x> i , and the multiplicative sharing share is denoted as [x] i . First, B i Jointly run the additive-multiplicative resharing protocol to convert the received additive sharing <x> i into the multiplicative sharing share [x] i ;

[0056] S2: B i Select a multiplicative sharing share of a random number denoted as [ρ] i , and at the same time calculate [x] i × [ρ]​​i = [x × ρ] i ;

[0057] S3: B i Recover x × ρ by sharing mutually;

[0058] S4: B i Run the multiplication-addition resharing protocol to transform [x × ρ] i and [ρ] i into additive sharing shares, denoted as <λ> i and <ρ> i , and then calculate

[0059] S5: Each participant calculates , denoted as <y> i .

[0060] As Figure 3 shown, the multi-party secure logarithm calculation protocol of the present invention is as follows:

[0061] S1: B i Select the multiplicative sharing share [ρ] i , and then jointly run the multiplication-addition resharing protocol according to the input [ρ -1 i to obtain <ρ -1 > i ;

[0062] S2: B i Calculate All parties mutually share according to the input and jointly recover e x × ρ;

[0063] S3: B i Calculate <y> i = e x × ρ × <ρ -1 > i .

[0064] Combined with Figure 4 , the process of training the Adaboost algorithm in the edge computing environment of the present invention is introduced below, and the specific steps are as follows:

[0065] During the whole process of Adaboost algorithm training. The weak classifier is denoted as C(x), and K is the number of iterations. The K-th iteration of C(x) is denoted as C K (x). The final model output result is denoted as O(x). The training set is denoted as D, where D = {(x 1 , y 1 ), ···, (x n , y n ​)}. The weights of the training set are denoted as ω. The output result of a single iteration is denoted as P.

[0066] Step 1: Initialize the weight coefficients of the training set in a secret sharing manner;

[0067] In the first round of iteration, the weight coefficients of the training set are ω = {ω 1,1 , ω 1,2 , ···, ω 1,n}), where The trusted third party divides the weight coefficients according to the additive secret sharing rule and sends them to each edge server B i . Each edge server only obtains one share, denoted as . Among them, the weight coefficients satisfy the condition

[0068] Step 2: Each edge server calculates the share of the error rate;

[0069] Here, the situation of the weak classifier C K (x) in the K-th round of iteration is discussed. In the initialization stage, the training set D is secretly shared by the trusted third party to each participating party, and each B i can only obtain one share, that is Each party calculates where is denoted as S i . If S i = 0, then I(S i ) = 0; otherwise I(S i ) = 1.

[0070] Step 3: Each edge server calculates the share of the classifier weight coefficients;

[0071] Taking the error rate as the input, each edge server B i executes the multi-party secure logarithm protocol to obtain the share of the weight coefficients Here

[0072] Step 4: Update the weight coefficients of the training set;

[0073] To ensure that the sum of the weights of the training set is 1, before updating the weight coefficient ω k , it is necessary to calculate the normalization factor σ k . Here B i obtains the additive share of by inputting and executing the multi-party secure exponential protocol. Then, using the homomorphic property of secret sharing, locally calculates its own σk The additive sharing share. Then B i Local calculation As the training set weights for the next round of training.

[0074] Step 5: Each edge server outputs the sharing share of the calculation result;

[0075] Since during the training process, all intermediate results are the additive secret sharing shares of each edge server B i So the final result is the simple linear addition of the sharing shares of the final calculation result of B i The final calculation result is denoted as O(x i ), that is Among them,

[0076] Such as Figure 5 As shown, in a privacy-preserving ensemble learning method based on secret sharing provided by the present invention, data is moved from User 1 to edge servers in the form of additive secret sharing, and each edge server obtains a sharing share. Each edge server will calculate the sharing share of the final result. Then User 2 receives all the sharing of the calculation results and reconstructs them to obtain the final calculation result.

[0077] The above embodiments only represent several implementation manners of the present invention, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention.

Claims

1. A privacy - protected ensemble learning method based on secret sharing, characterized in that: The specific steps are as follows: S1: The user submits their own private data; S2: Each edge server obtains the sharing shares of the user data and uses them in the training process of Adaboost, and finally outputs the sharing shares of the calculation results; It also includes the following steps: S21: Initialize the weight coefficients of the training set with secret sharing; S22: Each edge server calculates the sharing share of the error rate; S23: Each edge server calculates the sharing share of the classifier weight coefficients, and uses a multi - party secure logarithm - calculating protocol to calculate the sharing of the logarithmic function result. The specific steps are as follows: S231: The additive sharing shares obtained by each participant are denoted as <x> i , and the multiplicative sharing shares are denoted as [x] i ; First, all edge servers jointly run the additive-multiplicative resharing protocol to convert the received additive sharing shares <x> i into multiplicative sharing shares [x] i ; S232: Each participant selects a multiplicative sharing share of a random number, denoted as [ρ]. i , and simultaneously calculates [x]. i × [ρ] i = [x × ρ] i ; S233: Each participant recovers x×ρ through mutual sharing; S234: Each participant runs the multiplication-addition resharing protocol to get [x × ρ] i and [ρ] i converted into additive sharing shares, denoted as <λ> i and <ρ> i , and calculate S235: Each participant runs the addition-multiplication resharing protocol to obtain [c] i and calculate Denote it as <y> i ; S24: Update the weight coefficients of the training set; S25: Each edge server outputs the sharing share of the calculation result; S3: The user reconstructs the calculation result through the obtained sharing shares of the calculation result.

2. The privacy - protected ensemble learning method based on secret sharing according to claim 1, characterized in that: The method for each edge server in S2 to obtain the sharing shares of the user data further includes: The trusted third party divides the private data submitted by the user according to the rules of additive secret sharing and sends it to each edge server.

3. The privacy - protected ensemble learning method based on secret sharing according to claim 1, characterized in that: In step S2, the user reconstructs the calculation result through the sharing ratio of the obtained calculation result, which also includes: the output results of each edge server are denoted as f i ; the reconstruction process is simply adding the output results, specifically f out = f 1 + f 2 +,..., + f n .

4. The privacy - protected ensemble learning method based on secret sharing according to claim 1, characterized in that: When updating the weight coefficients of the training set in S24, a multi - party secure exponent - calculating protocol is used to calculate the sharing share of the exponential function result. The specific steps are as follows: S241: Each participant selects the multiplication sharing share [ρ] i , and then jointly runs the multiplication-addition resharing protocol based on the input [ρ -1 i to obtain <ρ -1 > i ;​ S242: Each participant locally calculates e <x>i ×[ρ] i =[e x ×ρ] i , and each party jointly recovers e x ×ρ according to the input; S243: Each participating party calculates <y> separately i = e x × ρ × <ρ -1 > i .