Method and apparatus for determining model training participants

By using the index public key and verification identifier of the target evaluation indicator in the task management platform of federated learning, encrypted verification information is generated, which solves the problem of random selection of participants, resulting in poor model training results, and achieves more reasonable participant selection and higher model training effects.

CN116822650BActive Publication Date: 2025-07-01UNIV OF SCI & TECH OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310774862.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-06-27
Publication Date
2025-07-01
Estimated Expiration
2043-06-27

AI Technical Summary

Technical Problem

In federated learning, when randomly selecting participants for model training, the model training effect is easily poor due to the different data distribution, data volume and computing power of different participants.

Method used

In the task management platform, encrypted verification information is generated based on the indicator public key and verification identifier of the target evaluation indicator, and sent it to candidate participants. The candidate participant determines whether the conditions for participating in training are met by decrypting the verification mark in the verification information, thereby selecting the appropriate participant.

Benefits of technology

It realizes the rational selection of participants according to model training needs, improves the model training effect, and reduces the risk of index data leakage of participants.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116822650B_ABST
    Figure CN116822650B_ABST
Patent Text Reader

Abstract

The present application provides a method and apparatus for determining model training participants. The present application is applied to a task management platform based on federated learning. The task management platform obtains a model training task published by a task publisher of model training, and obtains the index public key of each target evaluation index from an authoritative management server based on the index characteristics that at least one target evaluation index in the model training task needs to meet; generates encrypted verification information based on the index public key of each target evaluation index and a determined first verification identifier; sends the encrypted verification information and the information of each target evaluation index to multiple candidate participants; if the second verification identifier decrypted by the candidate participant is the same as the first verification identifier, determines the candidate participant as the target participant for training the target model. The solution of the present application can more reasonably determine the participants participating in model training in the scenario of training a model based on federated learning, and improve the model training effect.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of machine learning, and particularly to a method and device for determining model training participants. Background Art

[0002] Federated learning is a distributed machine learning framework in which a machine model can be jointly trained by different participants located in different places using their respective local data. During the model training process, there is no need to transfer the training data, and only the intermediate parameters of the model are exchanged to achieve joint training.

[0003] In the scenario of training a model based on federated learning, it is necessary to determine the participants involved in model training. Currently, generally, the required number of participants is randomly selected from multiple candidate participants. However, due to the differences in data distribution, data volume, and device computing power among different participants, each participant has a high degree of specificity. Based on this, randomly selecting participants to participate in model training is likely to affect the model training effect due to the inappropriate attributes of the selected participants. Summary of the Invention

[0004] In view of this, the present application provides a method and device for determining model training participants, so as to more reasonably determine the participants involved in model training and improve the model training effect in the scenario of training a model based on federated learning.

[0005] To achieve the above object, on the one hand, the present application provides a method for determining model training participants, which is applied to a task management platform based on federated learning and includes:

[0006] Obtain a model training task issued by a task publisher of model training, where the model training task includes: a target model to be trained and target conditions that participants required to participate in training the target model need to meet, and the target conditions include: index characteristics that at least one target evaluation index needs to meet;

[0007] For each target evaluation index, based on the index characteristics that the target evaluation index needs to meet, obtain the index public key of the target evaluation index from an authoritative management server;

[0008] Determine a first verification identifier;

[0009] Generate encrypted verification information based on the index public keys of the at least one target evaluation index and the first verification identifier;

[0010] Send the encrypted verification information and the information of the at least one target evaluation index to multiple candidate participants;

[0011] Obtain the second verification identifier decrypted by the candidate participant from the encrypted verification information. If the second verification identifier is the same as the first verification identifier, determine the candidate participant as the target participant for training the target model, where the second verification identifier is decrypted from the encrypted verification information by using the respective index private keys of the at least one target evaluation index corresponding to the candidate participant; the index private key of the target evaluation index is the index private key of the target evaluation index obtained by the candidate participant from the authoritative management server based on the index data of the target evaluation index in the candidate participant.

[0012] In a possible implementation manner, before generating the encrypted verification information, it further includes:

[0013] Construct a linear secret sharing scheme matrix based on the respective index characteristics that the at least one target evaluation index needs to satisfy, where different rows of the linear secret sharing scheme matrix represent the index characteristics of different target evaluation indexes;

[0014] The step of sending the encrypted verification information and the information of the at least one target evaluation index to multiple candidate participants includes:

[0015] Send the encrypted verification information and the linear secret sharing scheme matrix to multiple candidate participants;

[0016] Wherein, the second verification identifier is decrypted from the encrypted verification information by the candidate participant by using the respective index private keys of the at least one target evaluation index after the candidate participant determines the at least one target evaluation index by using the linear secret sharing scheme matrix.

[0017] In another possible implementation manner, the index public key of the target evaluation index is: generated by the authoritative management server based on a hash mapping function and the index characteristics of the target evaluation index, where the hash mapping function is used to map the input parameters to elements in the first multiplicative group corresponding to the bilinear mapping, and the bilinear mapping is a mapping from two first multiplicative groups to a second multiplicative group;

[0018] Before generating the encrypted verification information, it further includes:

[0019] Obtain the bilinear mapping stored in the authoritative management server;

[0020] The step of generating the encrypted verification information based on the respective index public keys of the at least one target evaluation index and the first verification identifier includes:

[0021] Generate the encrypted verification information based on the bilinear mapping, the respective index public keys of the at least one target evaluation index, and the first verification identifier;

[0022] Wherein, the second verification identifier is decrypted from the encrypted verification information by using the bilinear mapping and the index private key of each of the at least one target evaluation index corresponding to the candidate participant;

[0023] The index private key of the target evaluation index corresponding to the candidate participant is generated based on the hash mapping function and the index data of the target evaluation index in the candidate participant.

[0024] In another possible implementation, a hash mapping function and a master key parameter are stored in the authoritative management server, and the master key parameter includes a first master key parameter τ;

[0025] Wherein, the index public key PK of the target evaluation index x x includes: a first index public key PK 1,x and a second index public key PK 2,x , and the index public key PK of the target evaluation index x x is obtained by the authoritative management server through the following formula:

[0026]

[0027] Wherein, x b is the index feature corresponding to the target evaluation index x; v x is the version number of the target evaluation index x, τ is the first master key parameter, and H() is the hash mapping function.

[0028] On the other hand, the present application also provides a device for determining model training participants, which is applied to a task management platform based on federated learning, and includes:

[0029] A task acquisition unit, configured to acquire a model training task issued by a task publisher of model training, where the model training task includes: a target model to be trained and target conditions that participants participating in training the target model need to meet, and the target conditions include: index features that at least one target evaluation index needs to meet respectively;

[0030] A public key acquisition unit, configured to, for each target evaluation index, obtain the index public key of the target evaluation index from an authoritative management server based on the index feature that the target evaluation index needs to meet;

[0031] An identifier determination unit, configured to determine a first verification identifier;

[0032] An encryption generation unit, configured to generate encrypted verification information based on the index public keys of the at least one target evaluation index respectively and the first verification identifier;

[0033] An information sending unit, configured to send the encrypted verification information and information of the at least one target evaluation metric to a plurality of candidate participants;

[0034] A participant determination unit, configured to obtain a second verification identifier decrypted by the candidate participant from the encrypted verification information. If the second verification identifier is the same as the first verification identifier, the candidate participant is determined as a target participant for training the target model, where the second verification identifier is decrypted from the encrypted verification information by using respective index private keys of the at least one target evaluation metric corresponding to the candidate participant; the index private key of the target evaluation metric is the index private key of the target evaluation metric obtained by the candidate participant from the authoritative management server based on index data of the target evaluation metric in the candidate participant.

[0035] As can be seen from the above, in the model training task issued by the task publisher in the present application for federated learning, in addition to including index characteristics that at least one target evaluation metric of the participants participating in training the target model needs to meet. The task management platform for federated learning can respectively obtain the index public key of the target evaluation metric from the authoritative management server based on the index characteristics required for each target evaluation metric, and generate encrypted verification information by using the index public key of each target evaluation metric and a verification identifier determined by the task management platform, and send it to each candidate participant. On this basis, if the candidate participant meets the corresponding index characteristics based on the index data of its own respective target evaluation metrics, then after the candidate participant obtains the index private keys of the respective target evaluation metrics from the authoritative server based on the index data of its respective target evaluation metrics, it can decrypt the verification identifier from the encrypted verification information by using the index private keys of the respective target evaluation metrics. Therefore, the task management platform determines the candidate participant that decrypts the verification identifier as the target participant participating in the training of the target model, so as to select the participant that can meet the requirements of the task publisher for at least one target evaluation metric, realizes the selection of appropriate participants according to the model training requirements, and further can more reasonably select the participants for model training, and naturally can improve the model training effect. Description of the Drawings

[0036] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.

[0037] Figure 1 Shows a schematic flowchart of a method for determining model training participants provided by an embodiment of the present application;

[0038] Figure 2 shows a schematic diagram of a composition architecture of a federated learning system in an embodiment of the present application;

[0039] Figure 3 shows a schematic diagram of a process interaction of a method for determining model training participants provided in an embodiment of the present application;

[0040] Figure 4 shows a schematic diagram of a composition structure of a device for determining model training participants provided in an embodiment of the present application. Detailed implementation manners

[0041] The solution of the present application is applicable to the scenario of model training based on federated learning, to more reasonably determine the participants in model training and improve the model training effect.

[0042] Among them, federated learning is a distributed machine learning framework with privacy protection and security encryption technologies, aiming to enable scattered participants to collaborate in model training of machine learning on the premise of not disclosing private data to other participants.

[0043] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0044] As Figure 1 shown, it shows a method for determining model training participants in the present application, which is applied to a task management platform based on federated learning. The method of this embodiment includes the following steps:

[0045] S101, obtain a model training task published by a task publisher for model training.

[0046] The task publisher refers to the device of a unit, institution or individual that needs to publish a model training task.

[0047] Among them, the model training task includes: a target model to be trained. For example, the structure and initial internal parameters of the target model to be trained are not limited thereto.

[0048] In the present application, the model training task further includes: target conditions that the participants participating in training the target model need to meet, and the target conditions include: index characteristics that at least one target evaluation index needs to meet respectively.

[0049] Among them, the evaluation index refers to the index used to evaluate the influence of the participating party (or candidate participating party) on the model training effect. The evaluation index can be various features in the participating party that can affect model training, and there is no restriction on this. For example, the evaluation indexes for evaluating the participating party may include but are not limited to: the computing power of the participating party, the memory space of the participating party, the willingness to participate in model training, the amount of training data that can be used for training the model in the participating party, and the number of data types, etc.

[0050] The target evaluation index refers to the evaluation index set or selected by the task participating party and that needs to be concerned about in the training of the target model. Therefore, the target evaluation index belongs to the multiple evaluation indexes of the participating party.

[0051] The index characteristics that the target evaluation index needs to meet are the specific values that the target evaluation index needs to reach or meet. Among them, since different task publishers have different training requirements for different models, the number, specific types of the target evaluation index in the target conditions, and the specific index characteristics that the target evaluation index needs to meet can all be set by the task publisher according to needs, and there is no restriction on this.

[0052] For example: If the task publisher hopes to train a model with higher accuracy, then at least the number of data types of the participating party can be specified in the target conditions not to be lower than the set number. That is, the index characteristic that the target evaluation index of the data type needs to meet is the set number. This set number can be set according to needs, such as the set number can be eight.

[0053] Another example: If the task publisher hopes to complete model training more efficiently, then the participation conditions can at least include that the computing power of the participating party is higher than the set computing power value, and can also include that the bandwidth of the participating party is higher than the target bandwidth value, etc. Then the index characteristic that the target evaluation index of the bandwidth needs to meet is the target bandwidth value.

[0054] Of course, in practical applications, the target conditions can include the index characteristics corresponding to multiple target evaluation indexes at the same time, and there is no restriction on this.

[0055] S102. For each target evaluation index, based on the index characteristics that the target evaluation index needs to meet, obtain the index public key of the target evaluation index from the authoritative management server.

[0056] Among them, the authoritative management server is a device in the federated learning system used to generate the index private key or index public key based on the index data of the evaluation index or the set index characteristics that need to be met.

[0057] In this application, the generation rules of the metric private key and the metric public key can be preset in the authoritative management server. On this basis, when the specific values of the metric characteristics required for the target evaluation metric are different, the metric public key generated by the authoritative management server for the target evaluation metric will also be different.

[0058] In this application, there can be multiple possible specific implementations for the authoritative management server to generate the metric public key, and no restrictions are imposed on this.

[0059] In one possible implementation, the authoritative management server can generate the metric public key of the target evaluation metric based on a hash mapping function and the metric characteristics of the target evaluation metric. Among them, the hash mapping function is used to map the input parameters to elements in the first multiplicative group corresponding to the bilinear mapping, and this bilinear mapping is a mapping from two first multiplicative groups to the second multiplicative group.

[0060] For example, the authoritative management server can use the hash mapping function to determine the first element value in the first multiplicative group to which the metric characteristics of the target evaluation metric are mapped, and generate the metric public key based on the first element value.

[0061] In one possible case, the authoritative server can generate the metric public key of the target evaluation metric based on the metric characteristics of the target evaluation metric after obtaining the metric characteristics of the target evaluation metric sent by the task management platform.

[0062] In yet another possible case, for each evaluation metric, the authoritative server can also pre - combine the possible metric characteristics set for the evaluation metric with the metric public keys of the evaluation metric under different metric characteristics. On this basis, the task management platform can obtain the metric public key corresponding to the metric characteristics of the target evaluation metric from the authoritative server.

[0063] S103, determine the first verification identifier.

[0064] Among them, the first verification identifier is generated by the task management platform and is used to verify whether the participant has the identifier to participate in the training of the target model. There can be multiple ways to generate the first verification identifier, and no restrictions are imposed on this.

[0065] For example, the task management platform can select a verification identifier from multiple pre - configured verification identifiers as the first verification identifier. Among them, the verification identifier can be randomly selected as the first verification identifier to improve the security of the first verification identifier.

[0066] For another example, the task management platform can also randomly generate a first verification identifier. For example, randomly generate a number or a symbol as the first verification identifier.

[0067] S104. Generate encrypted verification information based on the index public key and the first verification identifier of each of at least one target evaluation index.

[0068] Among them, the encrypted verification information at least includes the encrypted first verification identifier. Of course, it may also include other relevant information for assisting in decrypting the first verification identifier, and there is no limitation on this.

[0069] S105. Send the encrypted verification information and the information of at least one target evaluation index to multiple candidate participating parties.

[0070] Among them, the information of at least one target evaluation index may include the names of at least one target evaluation index, so that the candidate participating parties can determine the target evaluation index required for decryption.

[0071] In a possible implementation manner, in order to represent at least one target evaluation index more conveniently and easily. In this application, a linear secret sharing scheme (LSSS) matrix can be constructed based on the index characteristics that each of at least one target evaluation index needs to satisfy. Among them, different rows of the LSSS matrix represent the index characteristics of different target evaluation indexes. That is, different rows of the LSSS matrix correspond to different target evaluation indexes, and the values of each row in the LSSS matrix represent the index characteristics of the target evaluation index.

[0072] For example, the LSSS matrix can be an n×l matrix M, where n is the number of target evaluation indexes in the target conditions, and l can be set as needed. Generally, a relatively large number can be selected.

[0073] On this basis, the task management platform can also send the encrypted verification information and the linear secret sharing scheme matrix to multiple candidate participating parties.

[0074] S106. Obtain the second verification identifier decrypted by the candidate participating party from the encrypted verification information. If the second verification identifier is the same as the first verification identifier, determine the candidate participating party as the target participating party for training the target model.

[0075] In this application, for the convenience of distinction, the verification identifier decrypted by the candidate participating party from the encrypted verification information is called the second verification identifier.

[0076] The second verification identifier is decrypted by the candidate participating party from the encrypted verification information by using the index private key of each of at least one target evaluation index corresponding to the candidate participating party.

[0077] Among them, the index private key of the target evaluation index is the index private key of the target evaluation index obtained by the candidate participant from the authoritative management server based on the index data of the target evaluation index in the candidate participant. The index data of the target evaluation index in the candidate participant refers to the specific value of this evaluation index in the candidate participant.

[0078] For example, the index data of the target evaluation index of computing power is a specific computing power value, and the index data of the index of participation willingness can be a participation willingness level or a participation willingness value, etc. The number of data types is the specific number of data types of the training data possessed by the candidate participant.

[0079] In this application, if the second verification identifier that the candidate participant can decrypt from the encrypted verification information based on the obtained index private keys of at least one target evaluation index is the same as the first verification identifier generated by the task management platform, it indicates that the index data of each target evaluation index in this candidate participant respectively meet the index characteristics required by each target evaluation index.

[0080] In this application, the process of the authoritative management server generating the index private key of the target evaluation index based on the index data of the target evaluation index can be set as needed, as long as the index private key of the target evaluation index generated can decrypt the data encrypted with the index public key of the target evaluation index on the premise that the index data of the target evaluation index meets the index characteristics of the target evaluation index.

[0081] In a possible implementation manner, when the index public key of the target evaluation index is generated by using a hash mapping function, the index private key of the target evaluation index corresponding to the candidate participant is generated by the authoritative management server based on this hash mapping function and the index data of this target evaluation index in this candidate participant. For example, the authoritative management server can use the hash mapping function to determine the value of the second element in the first multiplicative group of the bilinear mapping to which the index data of the target evaluation index is mapped, and determine the index private key of the target evaluation index based on this second element value.

[0082] Correspondingly, the second verification identifier is decrypted from the encrypted verification information by the candidate participant by using this bilinear mapping and the index private keys of at least one target evaluation index corresponding to the candidate participant respectively. Among them, the candidate participant can also obtain this bilinear mapping from the authoritative management server.

[0083] Particularly, when the task management platform sends the linear secret sharing scheme (LSSS) matrix to the candidate participant, after the candidate participant determines the at least one target evaluation index by using the linear secret sharing scheme matrix, the candidate participant then decrypts the second verification identifier from the encrypted verification information by using the index private keys of the at least one target evaluation index corresponding to the candidate participant respectively.

[0084] It is understandable that for the index private key of any target evaluation index corresponding to any candidate participant, the index private key of the target evaluation index can be pre-generated by the authoritative server, or when the candidate participant needs to decrypt the encrypted verification information, after sending the index data of the target evaluation index to the authoritative server, the authoritative server generates the index private key based on the index data of the target evaluation index, and there is no restriction on this.

[0085] As can be seen from the above, in the model training task issued by the task publisher of federated learning in this application, in addition to including the index characteristics that at least one target evaluation index among the participants participating in the training of the target model needs to meet. The task management platform of federated learning can respectively obtain the index public key of the target evaluation index from the authoritative management server based on the index characteristics required by each target evaluation index, and use the index public key of each target evaluation index and a verification identifier determined by the task management platform to generate encrypted verification information and send it to each candidate participant. On this basis, if the candidate participant meets the corresponding index characteristics based on the index data of its own target evaluation indexes, then after the candidate participant obtains the index private keys of each target evaluation index from the authoritative server based on the index data of its own target evaluation indexes, it can decrypt the verification identifier from the encrypted verification information by using the index private keys of each target evaluation index. Therefore, the task management platform determines the candidate participant that decrypts the verification identifier as the target participant participating in the training of the target model, thereby realizing the selection of participants who can meet the requirements of the task publisher for at least one target evaluation index, realizing the selection of appropriate participants according to the model training requirements, and then being able to more reasonably select the participants in the model training, and naturally improving the model training effect.

[0086] Moreover, in this application, in the process of the task management platform determining the target participant, it is not necessary for each candidate participant to transmit the index data of each evaluation index in the candidate participant to the task publisher or the task management platform, thereby reducing the risk of leakage of the index data in the candidate participant.

[0087] In the embodiment of this application, there can be various specific implementations for the authoritative management server to generate the index public key based on the index characteristics of the target evaluation index and generate the index private key based on the index data of the target evaluation index.

[0088] In an alternative manner, in this application, the index public key of the target evaluation index can be generated by the authoritative management server based on the hash mapping function and the index characteristics of the target evaluation index, where the hash mapping function is used to map the input parameters to elements in the first multiplicative group corresponding to the bilinear mapping. The bilinear mapping is a mapping from two first multiplicative groups to the second multiplicative group.

[0089] Before generating the encrypted verification information, the task management platform also needs to obtain the bilinear mapping stored in the authoritative management server. On this basis, the task management platform can generate the encrypted verification information based on the bilinear mapping, the index public key of each of the at least one target evaluation index, and the first verification identifier.

[0090] Correspondingly, the candidate participant can use the bilinear mapping obtained from the authoritative server and the index private key of each of the at least one target evaluation index corresponding to the candidate participant to decrypt the second verification identifier from the encrypted verification information.

[0091] It can be understood that considering the properties of the bilinear mapping in encryption and decryption, on the premise that the authoritative management server uses the hash mapping function related to the bilinear mapping to generate the index public key of the target evaluation index and the index private key of the target evaluation index by combining the index characteristics of the target evaluation index and the index data in the candidate participants respectively, after the task management platform encrypts the verification identifier using the bilinear mapping and the index public key of the target evaluation index, if the index data of the target evaluation index of the candidate participant conforms to the index characteristics required by the target evaluation index, then the candidate participant can decrypt the verification identifier from the encrypted verification information using the index private key of each target evaluation index and the bilinear mapping.

[0092] It can be understood that in practical applications, after determining the target participants, the target model can be continuously trained by the determined target participants until the training of the target model is completed.

[0093] In practical applications, during the process of training the target model, it may also be necessary to re-determine the target participants every few training rounds or at regular intervals. In this case, considering that the index data of the candidate participants may change dynamically, such as the load of the candidate participants at different times may be different, on this basis, in order to reasonably select the target participants for training the target model each time, the authoritative management server can also generate a version number for each evaluation index. If the index data of this evaluation index of a candidate participant changes, the authoritative management server will update the version number.

[0094] On this basis, the index public key of the target evaluation index can be generated by the authoritative management server based on the hash mapping function, the version number of the target evaluation index, and the index characteristics of the target evaluation index. Similarly, the index private key of the target evaluation index corresponding to the candidate participant is generated by the authoritative management server based on the hash mapping function, the version number of the target evaluation index, and the index data of the target evaluation index in the candidate participant.

[0095] Of course, if the metric public key and metric private key of the evaluation metric are pre-generated, then after the authoritative management server updates the version number of a certain evaluation metric, it is also necessary to update the corresponding metric public key of the evaluation metric and the metric private keys of each candidate participant corresponding to the evaluation metric.

[0096] To facilitate the understanding of the solution of this application, the system architecture involved in the federated learning of this application will be described below, taking an implementation manner of determining the metric public key, metric private key, and encryption / decryption verification information as an example.

[0097] As Figure 2 , it shows a schematic diagram of an architecture of the federated learning system provided by this application.

[0098] From Figure 2 it can be seen that the federated learning system may include: a central authoritative server 201, an attribute authoritative server 202, a task management platform 203, a publisher device 204 of the task publisher, and participant devices 205 of multiple candidate participants.

[0099] The central authoritative server is used to determine the main key parameters, public parameters, hash mapping functions, etc. required for encryption and decryption.

[0100] The authoritative management server is used to determine the metric public key, metric private key, and participant keys of the evaluation metric based on the main key parameters, public parameters, and hash mapping functions determined by the central authoritative server.

[0101] Both the central authoritative server and the authoritative management server can be servers of trusted institutions in the federated learning architecture. Therefore, they have relatively high security.

[0102] It should be noted that Figure 2 only one authoritative management server is shown in . In actual applications, in order to avoid affecting the stability of the federated learning system due to reasons such as a single authoritative management server malfunctioning, multiple authoritative management servers can also be set in this application. Different authoritative management servers can be responsible for the relevant processing of the metric public keys and metric private keys of different evaluation metrics.

[0103] Correspondingly, in actual applications, the central authoritative server can also be the same as the authoritative management server. However, as an optional method, in order to avoid the risk of single-point failure, a central authoritative server for generating the global parameters required for encryption and decryption can also be deployed separately.

[0104] Among them, the task management platform can be used to obtain the model training task sent by the task publisher through the publisher device, determine the target participants who can participate in the model training from multiple participants, and distribute the model training task to the participant devices of the determined target participants.

[0105] Among them, the task management platform can be a single server or a system composed of multiple servers. For example, the task management platform can be a cloud service platform, etc., without limitation.

[0106] The candidate participating parties can be various units or enterprises that hope to participate in model training. The participating party devices of the candidate participating parties can be personal computers or servers, etc., which are computer devices that can support model training, without limitation.

[0107] In this application, in order to reasonably determine the participating parties required for model training, the task publisher can send to the task management platform the target conditions that the participating parties set to be able to participate in model training. The task management platform will generate a verification identifier, and based on the index characteristics of each target evaluation index indicated in the target conditions, obtain the index public key from the authoritative management server, and encrypt the verification identifier using the obtained index public key.

[0108] Correspondingly, the candidate participating parties will, based on the index data of their respective evaluation indexes, use the authoritative management server to generate the index private keys of each evaluation index and the participating party private key of this participating party. On this basis, only when the index data of the evaluation indexes of the candidate participating parties meet the target conditions can the candidate participating parties use the corresponding index private keys and their participating party keys to decrypt the encrypted verification identifier to obtain the verification identifier. And only the candidate participating parties that can decrypt the verification identifier will be determined by the task management platform as the target participating parties that can participate in the model training task, so that it is possible to reasonably select participating parties without leaking the index data to the task management platform corresponding to the task publisher.

[0109] In Figure 2 Based on the system composition architecture of, the following is described in combination with an implementation method.

[0110] Such as Figure 3 , which shows a schematic diagram of a process interaction of a method for determining model training participating parties provided by an embodiment of this application. The method of this embodiment may include:

[0111] S301, the central authoritative server determines a bilinear mapping that maps two identical first multiplicative groups to a second multiplicative group, determines a hash mapping function, a master key parameter, and a public parameter, and sends the bilinear mapping, the hash mapping function, the master key parameter, and the public parameter to the authoritative management server.

[0112] Among them, each multiplicative group can include multiple element values.

[0113] For example, the central authority server selects a security parameter, determines a prime number p with a relatively large value (e.g., a value greater than a set value) based on this security parameter, uses this prime number p as the order of the multiplicative group, and determines the first multiplicative group and the second multiplicative group. In this application, the process of specifically constructing or determining the multiplicative group is not restricted.

[0114] Among them, the bilinear mapping is also called a bilinear pair. In this application, the bilinear mapping from two first multiplicative groups G to the second multiplicative group G T can be expressed as the following formula (1):

[0115] e:G×G→G T (Formula (1));

[0116] Among them, the hash mapping function is used to map the parameter to be mapped (such as the name of the evaluation index or the index data of the evaluation index mentioned later) to an element in the first multiplicative group.

[0117] For example, the hash mapping function can be expressed as the following formula (2):

[0118] H:{0,1} * →G (Formula (2));

[0119] Since the name of the evaluation index and the index data are both represented as binary elements, {0,1} * represents a binary number composed of 0 and 1.

[0120] Among them, the master key parameter may include a first master key parameter τ, a second master key parameter a, and a third master key parameter α. These three master key parameters can be randomly determined by the central authority server. These three master key parameters all belong to integers of the scale of the prime number p.

[0121] Among them, the public parameter can be constituted based on a generator in the first multiplicative group.

[0122] For example, let g be the generator of the first multiplicative group G. Then, the public parameter PP=(g,g a ). Among them, the generator of the multiplicative group is an element in the multiplicative group, and in the multiplicative group, all other elements can be generated by multiplying this element.

[0123] It can be seen that the public parameter may include a first public parameter g and a second public parameter g a , the first public parameter is the generator in the first multiplicative group, the second public parameter is the first power of the generator, and the first power is the second master key parameter a.

[0124] S302, the authoritative management server determines at least one evaluation metric that can be used to evaluate candidate participants. For any one evaluation metric, it determines the current version number of this evaluation metric, and based on the version number of this evaluation metric, it calculates the metric public keys of this evaluation metric under different candidate metric features respectively.

[0125] For each evaluation metric, the authoritative management server can pre-configure the metric features that can be selected and set for this evaluation metric in the authoritative management server. For the sake of easy distinction, the metric features available for selection of the evaluation metric are called candidate metric features. On this basis, for each candidate metric feature of the evaluation metric, the authoritative management server can determine the metric public key corresponding to this evaluation metric under this candidate metric feature based on the current version number of this evaluation metric, the candidate metric feature of this evaluation metric, and the hash mapping function.

[0126] In this application, the version number of the evaluation metric is a random number determined by the authoritative management server. Moreover, every time the metric data of this evaluation metric in the candidate participants in the federated learning system changes, the authoritative management server will update the version number of this evaluation metric.

[0127] For example, in one implementation, assume that the current version number of the evaluation metric x is the random number v x , v x belongs to the integers of the scale of the prime number p. Then, the metric public key PK x of the evaluation metric x can include the first metric public key PK 1,x and the second metric public key PK 2,x , and the authoritative management server can calculate the metric public key PK x of the evaluation metric x through the following formula three

[0128] It is expressed as the following formula three:

[0129]

[0130] where, x b is the metric feature corresponding to the evaluation metric (here it can also be called the candidate metric feature); v x is the version number of the target evaluation metric, τ is the second master key parameter, and H() represents the hash mapping function mentioned above.

[0131] It can be seen that the first metric public key is to map the metric feature x b of the evaluation metric x to the first element in the first multiplicative group based on the hash mapping function, and calculate the v x (the current version number of the evaluation metric x) power corresponding to this first element. And the second metric public key is to map the metric feature x bMap it to the second element in the first multiplicative group, and calculate the second power of the second element, where the second number is the current version number v of the evaluation metric x x The product with the first master key parameter τ.

[0132] It can be understood that if the metric data of the evaluation metric x of the candidate participants in the federated learning system changes, then the authoritative management server needs to regenerate another random number As the version number of the evaluation metric x. At the same time, the authoritative management server needs to replace the version number in Formula 3 above with the latest updated version number, and update the metric public key corresponding to the evaluation metric x under the metric feature x b The updated metric public key Can be expressed as Formula 4 below:

[0133]

[0134] Correspondingly, the updated metric public key also includes the updated first metric public key And the updated second metric public key For the specific meaning, please refer to the relevant introduction in Formula 3 and will not be elaborated here.

[0135] S303. The candidate participant sends the metric data of each evaluation metric in the candidate participant to the authoritative management server.

[0136] S304. For each candidate participant, the authoritative management server generates a unique participant private key for the candidate participant based on the master key parameter and the public parameter.

[0137] In one implementation, the participant private key of the candidate participant may include a first participant private key and a second participant private key. The first participant private key is determined based on the first public parameter, the second public parameter, and the unique random number corresponding to the candidate participant. The unique random number corresponding to the candidate participant may be a unique random number randomly generated by the authoritative management server for the candidate participant. The second participant private key is determined based on the first public parameter and the random number corresponding to the candidate participant.

[0138] For example, the first participant private key K can be expressed as Formula 5 below:

[0139] K = g α ·g at (Formula 5);

[0140] The second participant private key L can be expressed as Formula 6 below:

[0141] L = g t (Formula 6);

[0142] Among them, t is the random number uniquely corresponding to the candidate participant.

[0143] S305. For each evaluation index of the candidate participant, the authoritative management server generates an index private key for the candidate participant based on the index data of the evaluation index in the candidate participant, the current version number of the evaluation index, and the hash mapping function.

[0144] In a possible implementation, the index private key can be obtained by mapping the index data of the evaluation index to the third element in the first multiplicative group using the hash mapping function, and then calculating the third power of the third element. The third quantity is the product of the current version number of the evaluation index and the dynamic random number uniquely corresponding to the candidate participant.

[0145] For example, the index private key K corresponding to the evaluation index x of the candidate participant x can be expressed as the following formula seven:

[0146]

[0147] where x o is the index data of the target evaluation index x in the candidate participant. Other parameters are as described above.

[0148] It can be understood that, as described above, in the federated learning system, if the index data of the evaluation index x of any candidate participant changes, the authoritative management server will re-determine the version number of the evaluation index x. At the same time, for each candidate participant whose index data of the evaluation index x has not changed, the authoritative management server will re-generate the index private key corresponding to the evaluation index x for the candidate participant based on the updated version number of the evaluation index, the random number uniquely corresponding to the candidate participant, and the hash mapping function, so as to obtain the updated index private key corresponding to the evaluation index x in the candidate participant.

[0149] Among them, the process of generating the updated index private key is similar to the above formula seven, except that the version number in formula seven needs to be replaced with the updated version number of the evaluation index. For example, assuming that the updated version number of the evaluation index x is then the updated index private key corresponding to the evaluation index x in the candidate participant can be expressed as the following formula eight:

[0150]

[0151] It can be understood that if the index data of the evaluation index of the candidate participant changes, by updating the version number of the evaluation index and updating the index public key and index private key related to the evaluation index, then if the index data of the evaluation index of the candidate participant after the change does not meet the index characteristics of the evaluation index, then the candidate participant cannot use the index private key of its corresponding evaluation index to decrypt the data encrypted with the index public key based on the updated evaluation index, thus avoiding the possibility that the subsequent first verification identifier is cracked by a candidate participant who does not meet the requirements for participating in model training.

[0152] S306. The authority management server sends the set of participant private keys of the candidate participant to the candidate participant.

[0153] Among them, the set of participant private keys of the candidate participant may include: the first participant private key, the second participant private key of the candidate participant, and the index private keys of each evaluation index corresponding to the candidate participant.

[0154] For example, the set of participant private keys SK of the candidate participant can be expressed as follows:

[0155]

[0156] Among them, R represents the set of evaluation indexes composed of all evaluation indexes; indicates that the evaluation index x belongs to the evaluation indexes in the set of evaluation indexes.

[0157] Of course, if the key control party updates the index private key of a certain evaluation index among the participants, then the index private key of this evaluation index in the set of participant private keys will also change accordingly.

[0158] The above steps S301 to S306 can be executed before the task publisher publishes the task, and it is not necessarily executed every time before the model training task published by the task publisher. This embodiment is only for facilitating the understanding of the subsequent encryption and verification processes of the task management platform, and the above processes are introduced.

[0159] S307. The task management platform obtains the model training task published by the task publisher.

[0160] Among them, the model training task includes the target model to be trained and the target conditions that the participants participating in the training of the target model need to meet. The target conditions include: the index characteristics that at least one target evaluation index needs to meet respectively.

[0161] S308. The task management platform constructs a linear secret sharing scheme matrix based on the index characteristics that at least one target evaluation index needs to meet respectively.

[0162] Among them, different rows of the linear secret sharing scheme matrix represent the index characteristics of different target evaluation indexes. Correspondingly, the number of rows of the linear secret sharing scheme matrix is the same as the number of types of target evaluation indexes in the target conditions, while the number of columns of the index characteristic matrix can be set as needed without limitation.

[0163] For example, the linear secret sharing scheme matrix M can be an n×l matrix M, where n is the number of target evaluation indexes and l is the number of columns of the linear secret sharing scheme matrix M. l can be set as needed and generally a relatively large number can be selected.

[0164] S309. For the target evaluation index represented by each row in the linear secret sharing scheme matrix, based on the index characteristics represented by the row where the target evaluation index is located in the linear secret sharing scheme matrix, the task management platform obtains the index public key of the target evaluation index from the authoritative management server.

[0165] As described above, the authoritative management server can calculate the index public keys of each evaluation index under different candidate index characteristics, and these index public keys are public. Moreover, the values of the row where the target evaluation index is located in the linear secret sharing scheme matrix actually represent the index characteristics of the target evaluation index. Therefore, the task management platform can obtain the index public key corresponding to the index characteristics of the target evaluation index from the authoritative management server.

[0166] It should be noted that in this embodiment, it is illustrated by taking the authoritative management server as an example to calculate the index public keys of different evaluation indexes in advance under different index characteristics. Of course, if the task management server sends the index characteristics of the target evaluation index or the values of the corresponding row of the target evaluation index in the LSSS matrix to the authoritative management server, and then the authoritative management server calculates the index public key of the target evaluation index in real time, it is also applicable to this embodiment. The specific process of calculating the index public key is the same as before and will not be elaborated here.

[0167] S310. The task management platform determines the first verification identifier and generates encrypted verification information based on the bilinear mapping, the index public keys of the at least one target evaluation index, and the first verification identifier.

[0168] Among them, the method of generating the first verification identifier can refer to the relevant introduction in the previous embodiment and will not be elaborated here.

[0169] In a possible implementation manner, the task management platform can first generate a random vector ξ, and the dimension of the random vector ξ is the same as the number of columns l in the linear secret sharing scheme matrix. The random vector can be randomly generated as needed, and the values of the elements in the random vector can belong to integers of the scale of the prime number p.

[0170] Based on this, encrypted verification information can be generated based on the random vector ξ, the bilinear mapping, the index public key of each at least one target evaluation index, the first verification identifier, the public parameters, and the third master key parameter α. Among them, the encrypted verification information includes: the first encrypted information C, the second encrypted information C′, the third encrypted information C 0,i 、the fourth encrypted information C 1,i and the fifth encrypted information C 2,i , where:

[0171] C = fe(g, g) αs ;

[0172] C′ = g s ;

[0173]

[0174]

[0175]

[0176] Among them, f is the first verification identifier, e() represents the bilinear mapping, g is the first public parameter, and α is the third master key parameter; s is the first element in the random vector ξ; g a is the second public parameter;

[0177] λ i = M i ·ξ, M i is the vector composed of the i-th row of the linear secret sharing scheme matrix M, i ∈ [1, n], and n is the total number of rows of the linear secret sharing scheme matrix M;

[0178] is the first index public key of the target evaluation index corresponding to the i-th row in the linear secret sharing scheme matrix M, ρ(i) is the index feature represented by the target evaluation index corresponding to the i-th row in the linear secret sharing scheme matrix M, and v ρ(i) is the current version number of the target evaluation index corresponding to ρ(i);

[0179] r i is the random number generated by the task management platform for the i-th row of the linear secret sharing scheme matrix M. Since r i is a randomly generated random number, therefore, for different rows in the linear secret sharing scheme matrix M, the value of r i is different.

[0180] is the second index public key of the target evaluation index corresponding to the i-th row in the linear secret sharing scheme matrix M.

[0181] and It can be specifically calculated by the authoritative management server through the previous formula. For the specific calculation process, please refer to Formula 4 above and will not be elaborated here.

[0182] S311. The task management platform sends the encrypted verification information and the linear secret sharing scheme matrix to multiple candidate participants.

[0183] For example, the task management platform can send the following information CT to each candidate participant:

[0184]

[0185] The meanings of the various parameters in CT are as described above and will not be elaborated here.

[0186] S312. Based on the linear secret sharing scheme matrix, the participant device of the candidate participant determines each target evaluation index, and uses the bilinear mapping, the index private key of each of the at least one target evaluation index corresponding to the candidate participant, and the first participant private key and the second participant private key of the candidate participant to decrypt the encrypted verification information, and sends the decrypted second verification identifier to the task management platform.

[0187] The bilinear mapping is obtained by the candidate participant from the authoritative management server.

[0188] Among them, the first participant private key and the second participant private key are the uniquely corresponding private keys of the candidate participant obtained by the candidate participant from the authoritative management server. For example, as described above, the authoritative management server can pre-generate the first participant private key and the second participant private key for the candidate participant and send them to the candidate participant.

[0189] The index private key of at least one target evaluation index corresponding to the candidate participant can be obtained by the candidate participant from the authoritative management server side before the task publisher publishes the model training task.

[0190] Of course, in practical applications, the candidate participant can also send the index data of each target evaluation index in the candidate participant to the authoritative management server after obtaining the encrypted verification information, and obtain the index private key corresponding to each target evaluation index in the candidate participant returned by the authoritative management server. In this case, the specific implementation manner for the authoritative management server to generate the index private key of the target evaluation index for the candidate participant is the same as above and will not be elaborated here.

[0191] In this application, the process for the candidate participant to decrypt the encrypted verification information can be unrestricted, and can be specifically decrypted in combination with the properties of the bilinear mapping.

[0192] For ease of understanding, a simple example is given as follows:

[0193] After the candidate participant obtains the encrypted verification information, it can first verify the integrity of the encrypted verification information. If the encrypted verification information is verified to be complete, the following operations can be performed:

[0194] For M in the i-th row of the linear secret sharing scheme matrix M i , select a suitable constant ω with polynomial time complexity i , ω i belongs to an integer of the scale of prime number p (i.e., ), so that the equation ∑ ρ(i)∈R' ω i M i =(1, 0,..., 0) holds. R' represents the set of index data corresponding to each target evaluation index among the candidate participants.

[0195] If for each row in M, such a set of constants {ω i} can finally be found, where I is the set of rows where each target evaluation index in M is located. On this basis, through the following derivation and calculation:

[0196]

[0197] After deriving and solving the value of e(g, g) αs , substitute it into the following formula, and finally the verification identifier f can be decrypted:

[0198]

[0199] Among them, the specific parameters involved in the above calculations can be referred to the relevant introductions before, and will not be elaborated here. This is just a simple calculation example, and the specific calculation process can be unrestricted.

[0200] S313, if the task management platform determines that the second verification identifier is the same as the first verification identifier, the candidate participant is determined as the target participant participating in the training of the target model.

[0201] It can be understood that after the task management platform determines the target participant, it can send the training task of the target model to the target participant so that the target participant can train the target model. The specific process will not be elaborated here.

[0202] In order to more intuitively reflect the performance of determining the target participant based on the solution of the present application, the image dataset FashionMNIST and the color image dataset CIFAR10 (this dataset includes: a label subset of 80 million tiny images) are used for simple illustration respectively.

[0203] Some partitions were made for 500 participants to simulate the differences in the quantity and quality of data among participants in a real scenario. Taking whether the data owned by participants is independently and identically distributed as an example. IID means that the data is partitioned among all participants with a consistent distribution, and Non-IID means that some participants only have a few limited data set categories, and the Dirichlet distribution is used to generate imbalanced data.

[0204] In terms of model construction, a convolutional neural network is used. Specifically, 4 convolutional layers of 3×3 are set, and each layer uses the ReLu activation function and batch normalization. After every two layers, there is a max pooling layer of 2*2 and two fully connected layers. Only a small number of clients are selected to participate in training in each round of the simulation algorithm, and we set the participation factor PF to 0.1. The learning rate, batch local epoch are set to 0.01, 64 and 5 respectively. Epoch represents the number of updates when all training data has been used once in learning.

[0205] In this embodiment, three algorithms are used. Algorithm 1 is the Federated Averaging (FedAvg) algorithm, Algorithm 2 is the FedProx algorithm (this algorithm is an optimization aggregation algorithm for solving system and statistical heterogeneity in federated networks), and Algorithm 3 is the Attribute-Based Encryption Federated (ABEFed) algorithm. After running 200 and 500 rounds respectively on the two data sets mentioned above, the results can be seen in Table 1 and Table 2. Among them, Table 1 lists the number of communication rounds required for these three algorithms to reach the target accuracy on the FashionMNIST data set respectively. Table 1 lists the number of communication rounds required for these three algorithms to reach the target accuracy on the CIFAR10 data set respectively.

[0206] Table 1

[0207]

[0208]

[0209] Table 2

[0210]

[0211] Among them, in the above Table 1 and Table 2, ToA@Q represents the number of iterations required for the accuracy on the test set to reach Q for the first time. For example, the row where ToA@0.6 is located in Table 2 is the number of iterations required for the accuracy on the test set to reach 0.6 for the first time under different parameters.

[0212] Combining Table 1 and Table 2 above, it can be obtained that:

[0213] In the settings of α = 0.5 and α = 0.1, compared with other baseline algorithms, the proposed ABEFed accelerates convergence and improves the stability of the global model.

[0214] In an ideal environment where α = 1, the training effects of ABEFed and FedAvg are indistinguishable. The reason is that when the participant data distribution is IID, both randomly selected clients and clients meeting the policy have almost the same data distribution.

[0215] However, we can see that when using α = 0.5 with a non - IID setting, the accuracy of the CNN model using ABEFed is higher than that of FedAvg with randomly selected clients, increasing by 0.67% and 3.34% for the FashionMNIST and CIFAR - 10 datasets respectively. If we look at the more extreme case of α = 0.1, the performance improvement is even more obvious, exceeding 3.11% and 18.7% respectively. The reason is predictable because our scheme adaptively selects the participants matching the access policy in each round of training, which enables us to control the data distribution of the participants within a better range, thus achieving better training performance.

[0216] Corresponding to a method for determining model training participants in this application, this application also provides a device for determining model training participants.

[0217] As Figure 4 shown, it shows a schematic diagram of a composition structure of the device for determining model training participants provided by an embodiment of this application. The method of this embodiment is applied to a task management platform based on federated learning and includes:

[0218] A task acquisition unit 401, configured to acquire a model training task issued by a task publisher for model training, where the model training task includes: a target model to be trained and target conditions that participants participating in training the target model need to meet, and the target conditions include: index characteristics that at least one target evaluation index needs to meet;

[0219] A public key acquisition unit 402, configured to, for each target evaluation index, based on the index characteristics that the target evaluation index needs to meet, acquire the index public key of the target evaluation index from an authoritative management server;

[0220] An identification determination unit 403, configured to determine a first verification identification;

[0221] An encryption generation unit 404, configured to generate encrypted verification information based on the index public keys of the at least one target evaluation index and the first verification identification;

[0222] An information sending unit 405, configured to send the encrypted verification information and the information of the at least one target evaluation index to multiple candidate participants;

[0223] A participant determination unit 406, configured to obtain a second verification identifier decrypted by the candidate participant from the encrypted verification information, and if the second verification identifier is the same as the first verification identifier, determine the candidate participant as the target participant for training the target model, where the second verification identifier is decrypted from the encrypted verification information by using the respective index private keys of the at least one target evaluation index corresponding to the candidate participant; the index private key of the target evaluation index is the index private key of the target evaluation index obtained by the candidate participant from the authoritative management server based on the index data of the target evaluation index in the candidate participant.

[0224] In a possible implementation manner, the apparatus further includes:

[0225] A matrix construction unit, configured to construct a linear secret sharing scheme matrix based on the index characteristics that each of the at least one target evaluation index needs to satisfy before the encryption generation unit generates the encrypted verification information, where different rows of the linear secret sharing scheme matrix represent the index characteristics of different target evaluation indexes;

[0226] The information sending unit includes:

[0227] An information sending subunit, configured to send the encrypted verification information and the linear secret sharing scheme matrix to multiple candidate participants;

[0228] Wherein, the second verification identifier obtained by the participant determination unit is decrypted from the encrypted verification information by the candidate participant by using the respective index private keys of the at least one target evaluation index after the candidate participant determines the at least one target evaluation index by using the linear secret sharing scheme matrix.

[0229] In yet another possible implementation manner, the index public key of the target evaluation index obtained by the public key acquisition unit is: generated by the authoritative management server based on a hash mapping function and the index characteristics of the target evaluation index, where the hash mapping function is used to map the input parameters to elements in the first multiplicative group corresponding to the bilinear mapping, and the bilinear mapping is a mapping from two first multiplicative groups to a second multiplicative group;

[0230] The apparatus further includes:

[0231] A mapping acquisition unit, configured to obtain the bilinear mapping stored in the authoritative management server before generating the encrypted verification information;

[0232] The encryption generation unit includes:

[0233] An encryption generation subunit, configured to generate encrypted verification information based on the bilinear mapping, the index public key of each of the at least one target evaluation index, and the first verification identifier;

[0234] Wherein, the second verification identifier obtained by the participant determination unit is decrypted from the encrypted verification information by using the bilinear mapping and the index private key of each of the at least one target evaluation index corresponding to the candidate participant; the index private key of the target evaluation index corresponding to the candidate participant is generated based on the hash mapping function and the index data of the target evaluation index in the candidate participant.

[0235] In another possible implementation manner, the index public key of the target evaluation index obtained by the public key acquisition unit is: generated by the authoritative management server based on the hash mapping function, the version number of the target evaluation index, and the index characteristics of the target evaluation index, wherein, if there is a change in the index data of the target evaluation index in the candidate participant, the authoritative management server updates the version number of the target evaluation index;

[0236] Wherein, the index private key of the target evaluation index corresponding to the candidate participant is generated based on the hash mapping function, the version number of the target evaluation index, and the index data of the target evaluation index in the candidate participant.

[0237] It should be noted that the embodiments in this specification are all described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. At the same time, the features described in each embodiment in this specification can be replaced or combined with each other, enabling those skilled in the art to implement or use this application. For the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can refer to the partial description of the method embodiments.

[0238] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations.

[0239] The above description of the disclosed embodiments enables those skilled in the art to implement or use this application. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of this application. Therefore, this application will not be limited to the embodiments shown herein, but will be accorded the widest scope consistent with the principles and novel features disclosed herein.

[0240] The above are only the preferred embodiments of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.

Claims

1. A method for determining model training participants, characterized in that, Applied to a task management platform based on federated learning, including: Obtain a model training task released by a task publisher for model training, where the model training task includes: a target model to be trained and target conditions that participating parties need to meet for training the target model, and the target conditions include: index characteristics that at least one target evaluation index needs to meet respectively; For each target evaluation index, based on the index characteristics that the target evaluation index needs to meet, obtain the index public key of the target evaluation index from an authoritative management server; Determine a first verification identifier; Generate encrypted verification information based on the index public keys of the at least one target evaluation index and the first verification identifier; Send the encrypted verification information and the information of the at least one target evaluation index to multiple candidate participating parties; Obtain a second verification identifier decrypted by the candidate participating party from the encrypted verification information. If the second verification identifier is the same as the first verification identifier, determine the candidate participating party as the target participating party for training the target model, where the second verification identifier is decrypted from the encrypted verification information by using the index private keys of the at least one target evaluation index corresponding to the candidate participating party; the index private key of the target evaluation index is the index private key of the target evaluation index obtained by the candidate participating party from the authoritative management server based on the index data of the target evaluation index in the candidate participating party.

2. The method according to claim 1, wherein Before generating the encrypted verification information, it further includes: Construct a linear secret sharing scheme matrix based on the index characteristics that the at least one target evaluation index needs to meet respectively, and different rows of the linear secret sharing scheme matrix represent the index characteristics of different target evaluation indexes; The step of sending the encrypted verification information and the information of the at least one target evaluation index to multiple candidate participating parties includes: Send the encrypted verification information and the linear secret sharing scheme matrix to multiple candidate participating parties; Wherein, the second verification identifier is decrypted from the encrypted verification information by the candidate participating party by using the index private keys of the at least one target evaluation index corresponding to the candidate participating party after the candidate participating party determines the at least one target evaluation index by using the linear secret sharing scheme matrix.

3. The method according to claim 2, characterized in that, The index public key of the target evaluation index is: generated by the authoritative management server based on a hash mapping function and the index characteristics of the target evaluation index, where the hash mapping function is used to map the input parameters to elements in the first multiplicative group corresponding to the bilinear mapping, and the bilinear mapping is a mapping from two first multiplicative groups to a second multiplicative group; Before generating the encrypted verification information, it further includes: Obtain the bilinear mapping stored in the authoritative management server; The step of generating encrypted verification information based on the index public keys of the at least one target evaluation index and the first verification identifier includes: Generate encrypted verification information based on the bilinear mapping, the index public keys of the at least one target evaluation index and the first verification identifier; Among them, the second verification identifier is decrypted from the encrypted verification information by using the bilinear mapping and the index private key of each of the at least one target evaluation index corresponding to the candidate participant; The index private key of the target evaluation index corresponding to the candidate participant is generated based on the hash mapping function and the index data of the target evaluation index in the candidate participant.

4. The method according to claim 3, wherein The index public key of the target evaluation index is: generated by the authoritative management server based on the hash mapping function, the version number of the target evaluation index, and the index characteristics of the target evaluation index, where if the index data of the target evaluation index in the candidate participant changes, the authoritative management server updates the version number of the target evaluation index; The index private key of the target evaluation index corresponding to the candidate participant is generated based on the hash mapping function, the version number of the target evaluation index, and the index data of the target evaluation index in the candidate participant.

5. The method according to claim 4, wherein The authoritative management server stores a hash mapping function and a master key parameter, and the master key parameter includes a first master key parameter τ; Among them, the index public key PK of the target evaluation index x x includes: the first index public key PK 1,x and the second index public key PK 2,x , and the index public key PK of the target evaluation index x x is obtained by the authoritative management server through the following formula: Among them, x b is the index feature corresponding to the target evaluation index x; v x is the version number of the target evaluation index x, τ is the first master key parameter, and H() is the hash mapping function.

6. The method according to claim 5, characterized in that The master key parameter further includes: a second master key parameter a and a third master key parameter α; The authoritative management server also stores public parameters, and the public parameters include: a first public parameter and a second public parameter, the first public parameter is the generator of the first multiplicative group, and the second public parameter is the second master key parameter a power of the generator; For each target evaluation index, obtaining the index public key of the target evaluation index from the authoritative management server based on the index characteristics that the target evaluation index needs to satisfy includes: For the target evaluation index represented by each row in the linear secret sharing scheme matrix, obtaining the index public key of the target evaluation index from the authoritative management server based on the index characteristics represented by the row where the target evaluation index is located in the linear secret sharing scheme matrix; Before generating the encrypted verification information, it further includes: Obtaining the public parameter and the third master key parameter from the authoritative management server; Generating the encrypted verification information based on the bilinear mapping, the index public key of each of the at least one target evaluation index, and the first verification identifier includes: Generating a random vector ξ, and the dimension of the random vector ξ is the same as the number of columns in the linear secret sharing scheme matrix; Generating the encrypted verification information based on the random vector ξ, the bilinear mapping, the index public key of each of the at least one target evaluation index, the first verification identifier, the public parameter, and the third master key parameter; Among them, the encrypted verification information includes: first encrypted information C, second encrypted information C′, third encrypted information C 0,i , fourth encrypted information C 1,i and fifth encrypted information C 2,i , where C = fe(g, g) αs ; C′ = g s ; Among them, f is the first verification identifier, e() represents a bilinear mapping, g is the first public parameter, α is the third master key parameter; s is the first element in the random vector ξ; g a is the second public parameter; λ i = M i · ξ, M i is the vector formed by the i-th row of the linear secret sharing scheme matrix M, where i ∈ [1, n] and n is the total number of rows of the linear secret sharing scheme matrix M; is the first index public key of the target evaluation index corresponding to the i-th row in the linear secret sharing scheme matrix M, ρ(i) is the index feature represented by the target evaluation index corresponding to the i-th row in the linear secret sharing scheme matrix M, v ρ(i) is the version number of the target evaluation index corresponding to ρ(i); r i is a random number generated by the task management platform for the i-th row of the matrix M in the linear secret sharing scheme; It is the second index public key of the target evaluation index corresponding to the i-th row in the matrix M of the linear secret sharing scheme.

7. The method according to claim 6, characterized in that, The second verification identifier is decrypted from the encrypted verification information by the candidate participant using the bilinear mapping, the index private key of each of the at least one target evaluation index corresponding to the candidate participant, and the first participant private key and the second participant private key of the candidate participant; Among them, the first participant private key and the second participant private key are the private keys corresponding to the candidate participant obtained by the candidate participant from the authoritative management server; Among them, the first participant private key K is calculated by the authoritative management server through the following formula: K = g α ·g at ; The second participating party private key L is calculated by the authoritative management server through the following formula: L = g t where t is a random number uniquely corresponding to the candidate participating party generated by the authoritative management server; Among them, the index private key K of the target evaluation index x x is calculated by the authoritative management server through the following formula: where x o is the index data of the target evaluation index x among the candidate participants.

8. The method according to claim 1, wherein The determination of the first verification identifier includes any one of the following: Select one verification identifier from a plurality of pre-configured verification identifiers as the first verification identifier; Randomly generate a first verification identifier.

9. An apparatus for determining model training participants, characterized in that, Applied to a task management platform based on federated learning, including: A task acquisition unit, configured to acquire a model training task published by a task publisher for model training, where the model training task includes: a target model to be trained and target conditions that participating parties required to meet for training the target model, and the target conditions include: index characteristics that at least one target evaluation index needs to meet; A public key acquisition unit, configured to, for each target evaluation index, based on the index characteristics required to be met by the target evaluation index, acquire the index public key of the target evaluation index from the authoritative management server; An identifier determination unit, configured to determine a first verification identifier; An encryption generation unit, configured to generate encrypted verification information based on the index public keys of the at least one target evaluation index and the first verification identifier; An information sending unit, configured to send the encrypted verification information and the information of the at least one target evaluation index to a plurality of candidate participating parties; A participating party determination unit, configured to acquire a second verification identifier decrypted by the candidate participating party from the encrypted verification information. If the second verification identifier is the same as the first verification identifier, determine the candidate participating party as the target participating party for training the target model, where the second verification identifier is decrypted from the encrypted verification information by using the index private keys of the at least one target evaluation index corresponding to the candidate participating party; the index private key of the target evaluation index is the index private key of the target evaluation index obtained by the candidate participating party from the authoritative management server based on the index data of the target evaluation index in the candidate participating party.

10. The device according to claim 9, characterized in that, It further includes: A matrix construction unit, configured to construct a linear secret sharing scheme matrix based on the index characteristics that at least one target evaluation index needs to meet before the encryption generation unit generates the encrypted verification information. Different rows of the linear secret sharing scheme matrix represent the index characteristics of different target evaluation indexes; The information sending unit includes: An information sending subunit, configured to send the encrypted verification information and the linear secret sharing scheme matrix to a plurality of candidate participating parties; where the second verification identifier acquired by the participating party determination unit is decrypted from the encrypted verification information by the candidate participating party by using the index private keys of the at least one target evaluation index after the candidate participating party determines the at least one target evaluation index by using the linear secret sharing scheme matrix.

Citation Information

Patent Citations

  • Federated learning training data privacy enhancement method and system

    CN110572253A

  • Model training method, use method and system, trusted node and equipment

    CN113033828A