Blockchain-based federated learning method and learning system thereof
By using a decentralized blockchain system and a Bayesian game theory incentive mechanism, malicious nodes are identified and punished while honest participants are rewarded. This solves the problems of malicious nodes and insufficient incentives in federated learning, and improves model training accuracy and device participation.
Patent Information
- Application Number
- CN202311030077.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-08-14
- Publication Date
- 2025-11-21
- Estimated Expiration
- 2043-08-14
AI Technical Summary
Existing federated learning suffers from poor malicious node detection and a lack of effective incentive mechanisms, resulting in malicious clients affecting the overall model training performance and insufficient participation from honest devices.
It adopts a decentralized system based on blockchain, introduces the roles of learner, verifier and evaluator, and uses an incomplete information static Bayesian game theory incentive mechanism to identify and punish malicious nodes and reward honest participants, so as to ensure the effectiveness of the model and high participation.
It effectively resists interference from malicious clients, improves the training accuracy of the global model, encourages more devices to participate in federated learning, and reduces communication and time costs.
Smart Images

Figure CN117114129B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of artificial intelligence model training, and more particularly relates to a blockchain-based federated learning method and a learning system thereof. BACKGROUND
[0002] With the rapid development of communication technology and the extensive application of the Internet, millions of heterogeneous devices from different environments are connected to wireless networks to provide real-time intelligent services, which produces an exponentially growing amount of data. When it is necessary to train an artificial intelligence model using data on different devices, the traditional way requires devices in the network to upload local data to a central agency for centralized processing. However, due to high communication costs, network security and privacy issues, this method is not suitable for the current wireless network environment. Therefore, federated learning, as a new paradigm of artificial intelligence with privacy protection features, has been deployed in wireless networks to jointly train artificial intelligence models in heterogeneous devices in the network without exchanging private data.
[0003] However, the current federated learning faces a serious security challenge.
[0004] First, some devices connected to the wireless network are malicious, and these malicious devices can manipulate the prediction of the global model by uploading a corrupted local model (e.g., adding noise to the gradient parameters or training local updates using toxic data). The current solution to this problem is mainly to resist malicious nodes by reducing the impact of outliers on client update parameters. Patent CN202211394660.3 “A malicious node detection method in federated learning” uses cosine similarity to calculate the similarity of the gradient vector uploaded each time to determine the quality of this gradient, and calculates a reputation value to select high-quality nodes, while determining whether the model is malicious through cosine similarity to achieve malicious node detection. However, designing only a malicious node detection scheme cannot effectively prevent malicious clients from continuously uploading corrupted models, nor can it eliminate the adverse effects of corrupted parameters on global model aggregation.
[0005] Second, another challenge faced by federated learning is the lack of an effective incentive mechanism. The incentive schemes currently proposed for federated learning mostly focus on the design of pricing mechanisms. Patent CN202111647692.5 “A fair and trustworthy federated learning incentive method” takes the amount of data owned by federated learning participants as the bid, and uses a posteriori price mechanism to give participants a fair income, thereby achieving maximum income by implementing a reverse Vickrey auction to encourage participants to honestly submit their bid information. However, incentive mechanisms based on pricing methods may not be able to consistently motivate heterogeneous federated learning participants to actively participate in federated learning and contribute local resources in model training. SUMMARY
[0006] In view of the above defects or improvement needs of the prior art, the present application provides a blockchain-based federated learning method and a learning system thereof, which aims to effectively integrate malicious node detection and incentive mechanism, effectively resist malicious clients during federated learning, reduce the adverse effects of damaged parameters on global model aggregation, continuously encourage more honest devices to participate in federated learning, prevent participants from turning into malicious clients, and provide the effect of federated learning.
[0007] To achieve the above-mentioned purpose, according to one aspect of the present application, a blockchain-based federated learning method is provided, comprising:
[0008] Step S1: The federated learning task publisher divides the participants in the blockchain federated learning into learners, verifiers and evaluators;
[0009] Step S2: The first learner locally trains the global model obtained in the round to obtain a local model in the round and sends it to the verifier; Step S3: The first verifier verifies the local model selected by it, verifies whether the local model is valid, and sends the verification result to the evaluator; Step S4: The first evaluator counts the verification results of the local model selected by all the verifiers, evaluates the local model that meets the expected statistical result as a usable model and adds it to the set; calculates the probability of the learner being a malicious client according to the verification results of the local model selected by all the verifiers, and provides a reference for the action strategy of all participants in the next round; Step S5: The evaluator calculates the income of each participant in the federated learning based on the incentive mechanism of incomplete information static Bayesian game theory, wherein the incentive mechanism is: for the learner, rewards or punishments are given according to whether the local model is a usable model; for the verifier, rewards or punishments are given according to whether the local model is a usable model.
[0010] Step S6: The evaluator sends the income of each participant to the participant. Step S7: Each participant adjusts the action strategy in the next round according to the income. Step S8: The federated learning task publisher sends the next round of learning task to the participants.
[0011] Step S9: Repeat steps S1-S8 until the learning task is completed. The present application has the advantages that the present application effectively integrates malicious node detection and incentive mechanism, effectively resists malicious clients during federated learning, reduces the adverse effects of damaged parameters on global model aggregation, continuously encourages more honest devices to participate in federated learning, prevents participants from turning into malicious clients, and provides the effect of federated learning. The present application has the advantages that the present application effectively integrates malicious node detection and incentive mechanism, effectively resists malicious clients during federated learning, reduces the adverse effects of damaged parameters on global model aggregation, continuously encourages more honest devices to participate in federated learning, prevents participants from turning into malicious clients, and provides the effect of federated learning. The present application has the advantages that the present application effectively integrates malicious node detection and incentive mechanism, effectively resists malicious clients during federated learning, reduces the adverse effects of damaged parameters on global model aggregation, continuously encourages more honest devices to participate in federated learning, prevents participants from turning into malicious clients, and provides the effect of federated learning. The present application has the advantages that the present application effectively integrates malicious node detection and incentive mechanism, effectively resists malicious clients during federated learning, reduces the adverse effects of damaged parameters on global model aggregation, continuously encourages more honest devices to participate in federated learning, prevents participants from turning into malicious clients, and provides the effect of federated learning.
[0012] The present application has the advantages that the present application effectively integrates malicious node detection and incentive mechanism, effectively resists malicious clients during federated learning, reduces the adverse effects of damaged parameters on global model aggregation, continuously encourages more honest devices to participate in federated learning, prevents participants from turning into malicious clients, and provides the effect of federated learning. The present application has the advantages that the present application effectively integrates malicious node detection and incentive mechanism, effectively resists malicious clients during federated learning, reduces the adverse effects of damaged parameters on global model aggregation, continuously encourages more honest devices to participate in federated learning, prevents participants from turning into malicious clients, and provides the effect of federated learning. The present application has the advantages that the present application effectively integrates malicious node detection and incentive mechanism, effectively resists malicious clients during federated learning, reduces the adverse effects of damaged parameters on global model aggregation, continuously encourages more honest devices to participate in federated learning, prevents participants from turning into malicious clients, and provides the effect of federated learning. and evaluators Rewards and penalties will be based on the amount of verification or evaluation work they participate in.
[0013] Step S6: Evaluator set probability ,income Recorded in the block In the process, the payouts of all evaluators are compared, and the block of the evaluator with the highest payout is selected as the trusted block. ;
[0014] Step S7: Participants Trusted blocks Included in the set Available local models Perform aggregation to determine the global model for this round. ;
[0015] Step S8: Determine whether the federated learning has met the end requirements. If not, proceed to step S1; if yes, end the federated learning and output the final global model.
[0016] In one embodiment, in step S4, the evaluator The statistical selection of all validators on the local model The verification results show that the statistical results conform to the expected local model. The model was evaluated as usable, including
[0017] evaluator Several validators were selected to form the evaluation set. ;
[0018] Obtain the evaluation set All validators in the local model The verification results, combined with the overall verification results, if the local model The validation rate of effective models exceeds that of locally-based models. If the validation percentage is the invalid model, then evaluate the local model. This is a usable model.
[0019] In one embodiment, each participant is assigned a trusted weight;
[0020] In step S3, with Record as a verifier For local models The verification results, for local models Verified When the model is verified as valid, record Otherwise, remember ,in, It is a positive number;
[0021] In step S4, the local model is calculated based on the comprehensive verification results. Assessment score ,like Then evaluate the local model. For the available model, where the evaluation score The calculation formula is:
[0022] In the formula, This represents the trusted block determined in the previous round. Validator in The credibility weight.
[0023] In one embodiment, in each round of federated learning, the evaluator According to the local model Is this a valid model update block? Middle school learners Credibility weights:
[0024] If local model If it is not an effective model, then the learner Credibility weight Updated to: ;
[0025] If local model For an effective model, the learner Credibility weight Updated to:
[0026]
[0027] In the formula, the adjustable coefficient To set parameters and , For trusted blocks Learners recorded The benefits, For the collection of participants, Trusted blocks for participants Participants recorded The benefits.
[0028] In one embodiment, the evaluator In China, learners Probability of being a malicious client The calculation formula is:
[0029] .
[0030] In one embodiment, in step S3, the first One verifier For its chosen local model Verification includes:
[0031] Validator For the global model Perform local identically distributed training to obtain the corresponding local model. benchmark model According to the local model and benchmark model Accuracy gap validates local model Is it effective?
[0032] Among them, the One verifier According to the local model and benchmark model Accuracy gap validates local model Whether it is valid includes:
[0033] Calculate the local model separately accuracy and benchmark models accuracy ;
[0034] Calculate the difference in accuracy ;
[0035] Determine if it satisfies If so, then verify the local model. If the model is valid, then validate the local model; otherwise, validate the local model. This is an invalid model. The threshold value is set.
[0036] In one embodiment, in step S5, the evaluator Calculate each participant Benefits of federal learning The calculation formula is:
[0037]
[0038] In the formula, , Participants Execution Action Strategy The reward function and cost function at that time, Participant The fixed costs of joining federated learning;
[0039] Among them, the reward function for the participant based on the function generated by the incentive mechanism includes a penalty variable and a reward variable :
[0040] for the participant for the learner , the penalty variable takes the value 0 if the evaluator decides that the local model is the available model, and the reward variable , where is a positive coefficient set to 1, is the amount of data in the local dataset of the learner , and is an increasing function of the variable; otherwise, the penalty variable takes the value -1 , and the reward variable takes the value 0;
[0041] for the participant for the verifier , the penalty variable takes the value -1 if the verifier has not performed a verification action, and the reward variable takes the value 0; otherwise, the penalty variable takes the value 0, and the reward variable , where is a positive coefficient set to 1, is the number of local models selected by the verifier to perform a verification, and is an increasing function of the variable;
[0042] for the participant for the evaluator , the penalty variable takes the value -1 if the evaluator has not performed an evaluation action, and the reward variable takes the value 0; otherwise, the penalty variable takes the value 0, and the reward variable , where is a positive coefficient set to 1, is the number of verifiers selected by the evaluator to perform an evaluation, and is an increasing function of the variable.
[0043] In one embodiment, the expression of the reward function is:
[0044]
[0045] In the formula, The reward coefficient is adjustable. For the set unit rewards, According to the assessor Additional bonuses for the accuracy settings of the generated global model:
[0046] when If the accuracy of the generated global model reaches the target threshold, then the penalty variable is applied. Participants Additional rewards Take positive value For other participants Additional rewards ;
[0047] Otherwise, additional rewards for all participants .
[0048] In one embodiment, step S7 includes;
[0049] Each participant Trusted blocks Included in the set Available local models Aggregate to generate a global model ;
[0050] global model The accuracy is the same as the highest accuracy global model determined in the previous rounds. The accuracy of the two models is compared, and if the difference between the two meets the set requirements, the generated global model is used. Use the global model for this round; otherwise, use the global model with the highest accuracy. This serves as the global model for this round.
[0051] According to another aspect of the present invention, a blockchain-based federated learning system is provided, including a blockchain and communication nodes connected to the blockchain. The communication nodes include federated learning task publishers and participants in blockchain-based federated learning. When the federated learning task publisher publishes a federated learning task on the blockchain, the federated learning system is used to implement the steps of the above-described method.
[0052] In summary, compared with the prior art, the above-described technical solutions conceived by this invention can achieve the following beneficial effects:
[0053] The present application provides security for model aggregation and high participation rate of federated learning by deploying a blockchain to establish a decentralized federated learning system. When performing federated learning, three roles are coordinated for blockchain-based participants, in which learners are used to train local models, validators are used to verify the validity of local models, and evaluators are used to aggregate the verification results of different validators to determine whether the model is available, and then calculate the income of each evaluator based on the incentive mechanism of incomplete information static Bayesian game theory, and select the evaluator with the highest income to mine the block as a trusted block to update the blockchain. Finally, the available local modules recorded in the updated blockchain are aggregated to obtain a global module.
[0054] In the above method, two levels of judgment nodes, validators and evaluators, are set, and the validity of the local model generated by the learner can be verified in a decentralized manner by the validators and evaluators, which can effectively identify whether the local model provided by the learner is available. When aggregating to generate a global model, only the available local model is selected, and the malicious model evaluated as unavailable is directly discarded, thereby weakening the interference of malicious participants on the global model. At the same time, the present application analyzes the strategic behavior of learners, validators and evaluators in the federated learning system and models it as a Bayesian game. For learners, rewards and punishments are given according to whether their local model is available, encouraging learners to provide real and reliable data. For validators and evaluators, rewards and punishments are given according to their workload, motivating them to work actively and verify and evaluate more data to improve the accuracy of verification and evaluation work. Based on Bayesian game theory, under the aforementioned reward and punishment incentive mechanism, each participant will review the key information recorded on the blockchain and select an appropriate action strategy. Therefore, the incentive mechanism can encourage more honest participants to participate in federated learning and prevent participants from becoming malicious clients. BRIEF DESCRIPTION OF DRAWINGS
[0055] Figure 1 A step flowchart of the federated learning method based on a blockchain in an embodiment;
[0056] Figure 2 A framework diagram corresponding to the federated learning method in an embodiment. DETAILED DESCRIPTION
[0057] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and do not limit the present application. In addition, the technical features involved in each embodiment of the present application described below can be combined with each other as long as they do not conflict with each other.
[0058] As Figure 1Fig. 1 shows a step flowchart of a blockchain-based federated learning method in an embodiment, as Figure 2 Fig. 2 shows a framework diagram corresponding to the federated learning method.
[0059] The federated learning method mainly includes the following steps:
[0060] Step S1: The federated learning task publisher divides the participants in the blockchain federated learning into learners, validators and evaluators.
[0061] The present application implements federated learning based on blockchain, and the federated learning task publisher and the participants are both on the blockchain. When the federated learning task publisher publishes a federated learning task, other clients on the blockchain who want to participate in federated learning will respond to the federated learning task publisher and become participants in federated learning.
[0062] Define the set of federated learning participants The federated learning task publisher assigns roles to the participants, which are learners, validators and evaluators:
[0063] Define the set of learners ;
[0064] Define the set of validators ;
[0065] Define the set of evaluators .
[0066] Wherein, .
[0067] These participants are heterogeneous devices accessing the wireless network and each participant has a different number of local data sets, which are represented as , and these data sets can be non-identically distributed. Each participant will maintain a local blockchain to store key information in the federated learning process in a decentralized manner to ensure traceability of the model and malicious clients. The goal of all participants is to train a high-precision artificial intelligence model through multiple rounds of interactive communication to meet user needs. Different types of participants undertake different federated learning tasks: learners complete the training of local models; validators verify the effectiveness of the local model according to the data distribution of the learners; evaluators aggregate the validation results of the validators and update the equity information based on the game theory-based incentive mechanism. Subsequently, the evaluators run a proof-of-stake-based consensus algorithm to generate a trusted block to update the blockchain.
[0068] It can be understood that the learners, as the main body providing data, have the largest proportion. In an embodiment, the size relationship of the number satisfies: learner > validator > evaluator.
[0069] Since verifiers and evaluators, as decision nodes, should possess high integrity, it is preferable to select honest participants as verifiers and evaluators, with the remaining participants serving as learners.
[0070] Step S2: individual learners For the The global model that gets the turn Conduct local training to obtain this round Local model And send it to the verifier.
[0071] First, learners train their local models using local data. Due to the privacy of the data, clients do not directly provide their local data; instead, they upload their locally trained models to the blockchain for sharing, ensuring the security of the original local data. The risk here is that the local model uploaded by the learner may not be the actual model trained, but rather a corrupted model trained with added noise or toxic data. Participants uploading corrupted models are considered malicious clients. Therefore, to ensure the accuracy of the AI models trained through federated learning, corrupted models need to be identified and removed before aggregating local models. Simultaneously, it's crucial to incentivize participants to honestly contribute their local resources to prevent them from becoming malicious clients.
[0072] It should be noted that in each iteration of federated learning, it is expected that all participants will honestly and actively perform their respective tasks. However, in reality, each participant's action strategy is made based on their own specific state considerations and is uncontrollable. For example, in the current round, a learner may not provide any data, a verifier may not perform the verification of the learner's learning task, or may only verify the learning tasks of some learners, and an evaluator may not perform the evaluation of the verifier's verification task, or may only select to evaluate a comprehensive portion of the verification task. In this invention, an incentive mechanism based on incomplete information static Bayesian game theory is used to incentivize all participants to perform their respective tasks as honestly and actively as possible.
[0073] In one embodiment, each participant in the federated learning system joins the first... ( Pay a deposit before the round of communication This method of increasing participation costs can effectively prevent customers from creating a large number of malicious accounts to gain control of the system.
[0074] In step S2, learners who are willing to provide data Download the global model determined in the previous round of aggregation. Using its local data for training, the results of this round were obtained. Local model And send it to the verifier. Learner Whether a learner is willing to provide data, and whether the data provided is malicious, depends on the learner. Action strategy The incentive mechanism based on incomplete information static Bayesian game theory designed in this invention can motivate learners. Actively participate in learning and provide real data.
[0075] In the initial stage of federated learning (i.e. ),learner Download the initial model .if ,learner Extract from the previous round from trusted blocks The global model is determined by the aggregation of communication data. .learner Using local datasets and model Perform multiple rounds of training to obtain local model updates Specifically, you can refer to existing methods to train a local model.
[0076] In one embodiment, the model The loss function is expressed by the following formula:
[0077]
[0078] in, Representative dataset Size, Each data sample The loss function. Learner The goal is to obtain the optimal parameters to minimize In training samples The above is about its tags The prediction error. By using the stochastic gradient descent algorithm, the learner... With a constant learning rate implement Rounds of iterations to compute the local model The calculation formula is as follows:
[0079]
[0080] In one embodiment, the learner Will Encapsulated in Learning transactions using private key signing Lieutenant General Upload to randomly associated validators In one embodiment, when the local datasets of different participants are not independently identically distributed (i.e., one participant's dataset corresponds to category 1, category 2, and category 3, while the other participant's dataset corresponds to category 2, category 3, and category 4), then the datasets of the two participants are not identically distributed. In this case, the learner... It also analyzes its local dataset. Distribution And package them together into learning trading If all local datasets are independent and identically distributed, then there is no need to provide the distribution. Therefore, whether or not to provide a distribution can be decided based on the specific circumstances. .
[0081] Step S3: One verifier For its chosen local model Perform validation, validate the local model. Determine if it is effective and send the verification results to the evaluator.
[0082] Validator The received learning transactions are broadcast to all other validators in the system. That is, as long as validators are not disconnected, they communicate with each other, and each validator receives the same set of learning transactions. Define the set of learning transactions. If learners If no data is provided, then the learning transactions in the learning transaction set can be... It is considered empty.
[0083] When the verifier When the verifier is willing to perform the verification work, From learning transaction set Extracting local model sets For each non-empty learning trade , Verify its signature and from Extract If the local datasets of different participants are not independent and identically distributed, from Also extracted .
[0084] Even the verifier They may be willing to perform verification work, but not necessarily willing to learn about sets of transactions. The validation process involves verifying all non-empty learning trades, or possibly selecting only a subset of them. (Validator) The number of learning transactions that are validated depends on the validator. Action strategy The incentive mechanism based on incomplete information static Bayesian game theory designed in this invention can incentivize verifiers. Actively implement verification efforts to improve the accuracy of malicious model identification.
[0085] Specifically, the verification process of the verifier on the learner's learning task can refer to existing methods. In this embodiment, the verifier... For learners Provided local model Taking verification as an example, the verification steps include:
[0086] Step S31: Verifier For the global model Perform local identically distributed training to obtain the corresponding local model. benchmark model .
[0087] Locally identically distributed training ensures the baseline model Classification and Local Models They are classified in the same way, such as local models. If the classification results are divided into category 1, category 2, and category 3, then the baseline model... The classification results also need to be divided into Category 1, Category 2, and Category 3. If the verifier... and learners The local dataset is identically distributed, so its validators can be used directly. The baseline model was obtained by training on the local dataset. In most cases, because different participants use heterogeneous devices, their private datasets are not independent and identically distributed, and directly using their validators... Local datasets cannot achieve local identically distributed training. To ensure the feasibility of model evaluation, validators... A public dataset containing classifications of all participants can be downloaded from a specific server. By merging public and local datasets, a merged dataset is formed. Then from the merged dataset Choose with learners Distribution The same data forms training samples Verifier Using training samples For the global model Perform local identically distributed training to obtain the baseline model. Specifically, the number of training epochs for obtaining the baseline model can be controlled within [number]. Within the wheel.
[0088] Step S32: Calculate the local models separately. accuracy and benchmark models accuracy .
[0089] Step S33: Calculate the accuracy difference .
[0090] Step S34: Determine if the condition is met. If so, then verify the local model. If the model is valid, then validate the local model; otherwise, validate the local model. This is an invalid model. The threshold value is set.
[0091] In this embodiment, the accuracy of the baseline model is used as the benchmark. If the accuracy of the local model is too low compared to the baseline, the local model is considered to be an invalid model; otherwise, it is considered to be a valid model.
[0092] In one embodiment, with Record as a verifier For local models Verification results:
[0093] When local model Verified When the model is verified as valid, record ;
[0094] When local model Verified When the model is verified as invalid, record .
[0095] in, It is a positive number, for example, 1.
[0096] In one embodiment, the verification result set is utilized. Record Verifier The validation results for each learning task. For example, when the local model... Verified When a model is validated as valid, in the validation result set Marking in the local model; Verified The corresponding set of validation results when the model is validated as invalid is: It should be noted that the local model... If empty, then the corresponding verification result It is also empty.
[0097] Finally, the validator Will and Encapsulated in a verification transaction It is then signed using a private key and uploaded to the associated evaluator. .
[0098] Step S4: Individual evaluators The statistics of all selected validators on the local model The verification results show that the statistical results conform to the expected local model. The model was evaluated as usable and included in the set. Based on the selected group of validators, the local model... The verification results are used to calculate the learners' scores. Probability of being a malicious client .
[0099] evaluator The received learning transactions are broadcast to all other evaluators in the system; that is, as long as the evaluators are not disconnected, they communicate with each other, and each evaluator receives the same set of verification transactions. Define the set of verification transactions. If the verifier If no data is provided, then the verification transactions in the verification transaction set can be... It is considered empty.
[0100] When the evaluator Willing to verify the set of transactions Multiple non-empty verification transactions in When performing the evaluation work, the evaluator Multiple non-empty verification transactions can be performed. Perform statistical analysis and evaluate the local model based on the statistical results. Whether a model is usable is usually determined by whether a certain number of validators consider the local model to be usable. If a model is considered effective, then the local model can be considered as such. This is a usable model.
[0101] In one embodiment, the evaluator For local models The evaluation process includes:
[0102] Step S41: Evaluator Several validators were selected to form the evaluation set. .
[0103] When the evaluator Willing to perform the evaluation work, but also may not be willing to verify the transaction set Statistical evaluation of all non-empty verification transactions, because the more data, the higher the cost of its evaluation. It is possible to just select some of the non-empty verification transactions for statistical evaluation, each empty verification transaction from a verifier, that is, select several verifiers to be evaluated, forming an evaluation set The evaluator The number of verification transactions for statistical evaluation depends on the action strategy of the evaluator The incentive mechanism based on incomplete information static Bayesian game theory designed by the present application can encourage evaluators To actively perform evaluation work to improve the accuracy of malicious model identification.
[0104] It should be noted that the evaluation set selected by different evaluators may be different, so the evaluation results of each evaluator may be different, and the best one will be selected later.
[0105] Step S42: Obtain the evaluation set All verifiers verify the results of the local model , integrate the verification results, if the verification proportion of the local model as an effective model exceeds the verification proportion of the local model as an invalid model, then evaluate the local model as a usable model.
[0106] In this embodiment, the verification proportion in the statistical data is used as the evaluation basis. Verify each verifier corresponding verification transaction in the evaluation set , sign and extract , generate a set , wherein the verification result set of the unselected verification node is empty (if the verifier is not selected, then is empty).
[0107] In an embodiment, the evaluator quantifies the performance of each local model by calculating the evaluation score according to the following formula:
[0108]
[0109] In the formula, represents the trusted weight of the verifier in the trusted block determined in the last round.
[0110] The above formula reflects the evaluation set China believes For an effective model ( ) and believe Invalid model ( The proportion of validators:
[0111] like This indicates the evaluation set In China, it is believed that If more than half of the validators are validators of an effective model, then the local model is evaluated. For usable models, Record it in a set middle;
[0112] like This indicates the evaluation set In China, it is believed that If the proportion of validators for an effective model does not meet the standard, then evaluate the local model. This is an unusable model and should be discarded during subsequent aggregation. In this case, you can also upload a partial model. Learners were identified as potential malicious clients and placed into a set. In the next round of learning, participants can refer to the set. The recording and selection of action strategies.
[0113] The above steps involve trust weights. In one embodiment, the trust weights of each participant can be set to be equal, for example, all of them. In one embodiment, to better identify unusable local models based on prior knowledge, the learning process can be based on the local model in each round of learning. Is it an effective model for learners? The credibility weights are updated and recorded in the evaluator's records. corresponding blocks In the middle, and the block The credibility weights of the verifiers and evaluators are the same as in the previous round of communication, i.e. , .learner The formula for updating the trusted weights is:
[0114] If local model Not an effective model ( , ), then learners Credibility weight Updated to: ;
[0115] If local model For an effective model, the learner Credibility weight Updated to:
[0116]
[0117] Adjustable coefficient To set parameters and , For trusted blocks Learners recorded The benefits, For the collection of participants, Trusted blocks for participants Participants recorded The benefits. In particular, if ,but .
[0118] To be based on the evaluation set All validators on the local model The verification results are used to calculate the learners' scores. The probability of an entity acting as a malicious client is generally evaluated as a set of parameters. All validators validate the local model Invalid model ( The proportion of ) is calculated using the following formula:
[0119]
[0120] evaluator probability Recorded in a collection of shared beliefs This is for all participants to refer to when choosing action strategies in the next round. However, if learners are not included... The probability of it being a malicious client is then Empty.
[0121] Step S5: Evaluator Incentive mechanisms based on incomplete information static Bayesian game theory are used to calculate the incentive mechanism for each participant. Benefits of federal learning .
[0122] The incentive mechanism is as follows: for learners According to the local model Whether to reward or punish based on the usability of the model; for validators and evaluators Rewards and penalties will be based on the amount of work they participate in for verification or evaluation.
[0123] evaluator Calculating a set of benefits according to an incentive mechanism based on game theory wherein is a set of participants obtained in the first round of federated learning.
[0124] Defining an incomplete information static Bayesian game constructed by a set of participants in federated learning as .
[0125] wherein is a set of rational but self-interested participants; is the type of participants. Specifically, represents the type space of participants . represents is an honest participant, represents is a malicious client; is the action set of participants, wherein is the action space that participants can choose when making decisions; is the probability set of each participant as a malicious client, which is equivalent to the common belief set in step 3 , without which the data is empty, which records the probability of the maliciousness of participants and is taken as the common belief of all participants; is a set of benefit functions to record the interests of each participant, which is calculated from the difference between the reward function and the cost function.
[0126] Using to represent the strategy set of all participants in the current communication round, wherein represents the strategy of participant .
[0127] Each participant will select an action from the action space to formulate a strategy based on the common belief .
[0128] Specifically, when participant is a learner , the action space is , represents whether the learner is honest, is the local database of the learner for training a local model, and the action strategy of the learner whether to choose as an honest participant and the amount of data of the local database that the participant is willing to contribute.
[0129] when the participant is a verifier , the action space of the participant is wherein, is the network connection state of the participant , and is the number of learning transactions processed by the participant. The action strategy of the participant is essentially whether the participant is willing to perform verification work and verify how many learning transactions of the learners.
[0130] when the participant is an assessor , the action space of the participant is wherein, is the network connection state of the participant , and is the number of verification transactions processed by the participant. The action strategy of the participant is essentially whether the participant is willing to perform assessment work and assess how many verification transactions of the verifiers.
[0131] In the present application, the incentive mechanism is: for the learners , rewards or punishments are given according to whether the local model is an available model; for the verifiers and the assessors , rewards or punishments are given according to the amount of verification or assessment work performed by the participants, based on the incentive mechanism, the learners can be encouraged to provide real and reliable data and the work enthusiasm of the verifiers and the assessors can be improved.
[0132] In an embodiment, the assessor calculates the benefit obtained by each participant in the federated learning , and the calculation formula is:
[0133]
[0134] In the formula, , are the reward function and the cost function of the participant when the participant performs the action strategy , and is the fixed cost of the participant joining the federated learning.
[0135] wherein, the participant performs the action strategy Cost function of the moment It can be set according to actual situation.
[0136] Wherein, the reward function is a function generated based on the incentive mechanism, containing a penalty variable and a reward variable for the participant :
[0137] 1. For the participant is a learner :
[0138] When the evaluator determines that the local model is a usable model, the penalty variable takes 0, and the reward variable , wherein is a positive coefficient set, is an incremental function of the data volume of the local data set of the learner ; otherwise, the penalty variable takes a negative value ; the reward variable takes 0.
[0139] Specifically, the indicators for measuring the learner are the effectiveness of generating the local model and the size of the data set . If the local model is a non-usable model, i.e. , the learner needs to be punished, and if the local model is a usable model, i.e. , the learner needs to be rewarded.
[0140] To simplify the calculation, a judgment function can be introduced, if the condition in the parentheses is true, , otherwise, .
[0141] Let , .
[0142] At this time, if the local model is a non-usable model, , then , ; if the local model is a usable model, , then , . In the formula, and denote the size of the smallest and largest local dataset in all local datasets, respectively. At this point, , .
[0143] It is worth noting that if a learner fails to upload local updates , it will still be penalized because will not be recorded in the set .
[0144] 2. For participants , the verifier :
[0145] When the verifier does not perform the verification action, the penalty variable takes a negative value , and the reward variable takes 0; otherwise, the penalty variable takes 0, and the reward variable , where is a positive coefficient set, is the number of local models selected by the verifier to perform verification is an increasing function of the variable.
[0146] Specifically, the indicator of the verifier is the ability to handle learning transactions. The action space of the verifier is , where is the network connection state of , indicates connection, indicates disconnection, is the number of learning transactions handled by . Similarly, to simplify the calculation, the above judgment function
[0147] is continued to be introduced.
[0148] Let , .
[0149] At this point, if the verifier does not perform the verification action, , , ;
[0150] If the verifier performs the verification action, , , .
[0151] At this time, , .
[0152] 3. For the participant To the assessor :
[0153] When the assessor does not perform the assessment action, the penalty variable takes a negative value , the reward variable takes 0; otherwise, the penalty variable takes 0, and the reward variable , in which, is a positive coefficient set, is the number of verifiers selected by the assessor to perform the assessment, is an increasing function of the variable.
[0154] Specifically, the indicator of the assessor is the ability to handle verification transactions, and specifically, the action space of the assessor is , where is the network connection state of , represents connection, represents disconnection, is the number of verification transactions handled by .
[0155] Similarly, to simplify the calculation, the above judgment function is continued to be introduced.
[0156] Let , .
[0157] At this time, if the assessor does not perform the assessment action, , , ;
[0158] If the assessor performs the assessment action, , , .
[0159] At this time, , .
[0160] In a specific embodiment, the expression of the reward function is:
[0161]
[0162] wherein, is an adjustable reward coefficient, is a set unit reward, is an additional reward set according to the accuracy of the generated global model by the evaluator: When
[0163] the accuracy of the generated global model reaches a target threshold, the additional reward of the participant is positive , , , , , , , , , ,
[0164] In an embodiment, for simplicity, the cost function may be directly set as:
[0165]
[0166] wherein and are limited constants. According to the above definition, the revenue obtained by the participant after performing a round of federated learning is calculated by the following formula:
[0167]
[0168] At this time, the reward coefficient may be adjusted in each round to make the federated learning reach the Bayesian Nash equilibrium as soon as possible. Specifically, the reward coefficient satisfies the following conditions:
[0169] (1) ,
[0170] (2) and
[0171] (3)
[0172] wherein, Total budget for federated learning.
[0173] Step S6: evaluator Set , probability , income Recorded in block , compare the income of all evaluators, and take the block of the evaluator with the highest income as the trusted block ;
[0174] Since the evaluation results of each evaluator are different, the present application selects the evaluator with the highest income based on the size of the evaluator's income, and takes the evaluation result as the final evaluation result. In other words, since there are multiple candidate blocks in the system after the end of this round of communication, it is necessary to select a trusted block according to consistent consensus. Inspired by the proof-of-stake algorithm, the block mined by the evaluator with the highest cumulative stake will be unanimously considered as the trusted block . Each evaluator appends the trusted block to the locally maintained blockchain and requests its related participants (i.e. learners and verifiers) to download .
[0175] In an embodiment, the cumulative income of the evaluator from the first round to the current round can be calculated, and the block of the evaluator with the highest cumulative income is taken as the trusted block .
[0176] The calculation formula of the cumulative income up to the Rth round of communication is:
[0177]
[0178] Step S7: participant Aggregate the available local models recorded in the trusted block to determine the global model of this round. .
[0179] Specifically, the available local models in the trusted block may be aggregated according to conventional methods to generate the global model .
[0180] In an embodiment,
[0181] The global loss function of the honest learner on the distributed data set is calculated by the following formula:
[0182]
[0183] In one embodiment, considering that in some rounds, it is possible that not all invalid local models are identified, which may lead to lower accuracy of the aggregated global model. In this case, the global model can be verified. The validity of the generated global model is used to determine its effectiveness. Is it available? Specifically, calculate Accuracy on the public test set And Stored in trusted block In the middle. Global model The effectiveness can be achieved through To evaluate, among which From The most accurate global model traced back within the maintained local blockchain. A positive threshold is set. ,if Then the global model Valid, otherwise It is invalid because it may have been injected with a large number of corrupted local models. use replace As the first The initial model of round-robin communication is used for local training or model evaluation.
[0184] In one embodiment, participants Records are tracked from the blockchain in the collection before the next round of federated learning is executed. Potential malicious clients in the collection. If certain clients are in the collection Multiple records in the middle, then These clients are identified as malicious and will never be communicated with or interacted with. Once all honest participants cease communication with malicious clients, it signifies that the malicious user has been removed from the federated learning system within the wireless network.
[0185] Step S8: Determine whether the federated learning has met the end requirements. If not, proceed to step S1; if yes, end the federated learning and output the final global model.
[0186] Specifically, repeat steps S1 through S8 until the federated learning task ends. In each round, step S1 reassigns roles. The termination condition can be set to reaching the required number of communication rounds; or obtaining a global model that meets high accuracy requirements. .
[0187] The example realizes a security blockchain federated learning driven by a game-based incentive mechanism, uses a blockchain to identify malicious clients in a decentralized manner, designs a Bayesian game-based incentive mechanism, and realizes that the federated learning can train a high-precision global model under the attack of a malicious client, while maintaining a high collaboration probability of honest clients and reducing the time cost and communication cost of the convergence of the federated learning in a wireless network.
[0188] Correspondingly, the application also relates to a blockchain-based federated learning system, which comprises a blockchain and a communication node connected to the blockchain, the communication node comprising a federated learning task publisher and a participant participating in the blockchain federated learning, and the federated learning system is used to realize the steps of the learning method above after the federated learning task publisher publishes a federated learning task on the blockchain.
[0189] Those skilled in the art will easily understand that the above description is only the preferred embodiment of the application, and is not used to limit the application, and any modification, equivalent replacement and improvement made within the spirit and principle of the application shall be included in the protection scope of the application.
Claims
1. A blockchain-based federated learning method, characterized in that, include: Step S1: The federated learning task issuer divides the participants in the blockchain federated learning into learners, validators, and evaluators; Step S2: individual learners For the The global model that gets the turn Conduct local training to obtain this round Local model And send it to the verifier; Step S3: One verifier For its chosen local model Perform validation, validate the local model. Determine if it is effective and send the verification results to the evaluator; Step S4: Individual evaluators The statistics of all selected validators on the local model The verification results show that the statistical results conform to the expected local model. The model was evaluated as usable and included in the set. Based on the selected group of validators, the local model... The verification results are used to calculate the learners' scores. Probability of being a malicious client This serves as a reference for all participants in choosing action strategies for the next round. Step S5: Evaluator Incentive mechanisms based on incomplete information static Bayesian game theory are used to calculate the incentive mechanism for each participant. Benefits of federal learning The incentive mechanism is as follows: [This refers to the incentive mechanism for learners.] According to the local model Whether to reward or punish based on the usability of the model; for validators and evaluators Rewards and penalties will be based on the amount of verification or evaluation work they participate in. Step S6: Evaluator set probability ,income Recorded in the block In the process, the payouts of all evaluators are compared, and the block of the evaluator with the highest payout is selected as the trusted block. ; Step S7: Participants Trusted blocks Included in the set Available local models Perform aggregation to determine the global model for this round. ; Step S8: Determine whether the federated learning has met the end requirements. If not, proceed to step S1; if yes, end the federated learning and output the final global model.
2. The blockchain-based federated learning method as described in claim 1, characterized in that, In step S4, the evaluator The statistical selection of all validators on the local model The verification results show that the statistical results conform to the expected local model. The model was evaluated as usable, including evaluator Several validators were selected to form the evaluation set. ; Obtain the evaluation set All validators in the local model The verification results, combined with the overall verification results, if the local model The validation rate of effective models exceeds that of locally-based models. If the validation percentage is the invalid model, then evaluate the local model. This is a usable model.
3. The blockchain-based federated learning method as described in claim 2, characterized in that, Each participant is assigned a credibility weight; In step S3, with Record as a verifier For local models The verification results, for local models Verified When the model is verified as valid, record Otherwise, remember ,in, It is a positive number; In step S4, the local model is calculated based on the comprehensive verification results. Assessment score ,like Then evaluate the local model. For the available model, where the evaluation score The calculation formula is: In the formula, This represents the trusted block determined in the previous round. Validator in The credibility weight.
4. The blockchain-based federated learning method as described in claim 3, characterized in that, In each round of federated learning, the evaluators According to the local model Is this a valid model update block? Middle school learners Credibility weights: If local model If it is not an effective model, then the learner Credibility weight Updated to: ; If local model For an effective model, the learner Credibility weight Updated to: In the formula, the adjustable coefficient To set parameters and , For trusted blocks Learners recorded The benefits, For the collection of participants, Trusted blocks for participants Participants recorded The benefits.
5. The blockchain-based federated learning method as described in claim 3, characterized in that, evaluator In China, learners Probability of being a malicious client The calculation formula is: 。 6. The blockchain-based federated learning method as described in claim 1, characterized in that, In step S3, the first One verifier For its chosen local model Verification includes: Validator For the global model Perform local identically distributed training to obtain the corresponding local model. benchmark model According to the local model and benchmark model Accuracy gap validates local model Is it effective? Among them, the One verifier According to the local model and benchmark model Accuracy gap validates local model Whether it is valid includes: Calculate the local model separately accuracy and benchmark models accuracy ; Calculate the difference in accuracy ; Determine if it satisfies If so, then verify the local model. If the model is valid, then validate the local model; otherwise, validate the local model. This is an invalid model. The threshold value is set.
7. The blockchain-based federated learning method as described in claim 1, characterized in that, In step S5, the evaluator Calculate each participant Benefits of federal learning The calculation formula is: In the formula, , Participants Execution Action Strategy The reward function and cost function at that time, Participant The fixed costs of joining federated learning; Among them, the reward function The function generated based on the incentive mechanism includes features for participants. penalty variable and reward variables : For participants For learners When the evaluator Determine its local model For a usable model, the penalty variable Set to 0, reward variable In the formula, For the set positive coefficient, For learners The amount of data in the local dataset If the variable is an increasing function, then the variable is penalized; otherwise, the variable is penalized. Take negative value Reward variables Set to 0; For participants For the verifier When the verifier If the verification action is not performed, a penalty variable is applied. Take negative value Reward variable Set to 0; otherwise, penalize the variable. Set to 0, reward variable In the formula, For the set positive coefficient, As a verifier The number of local models selected for validation It is an increasing function of the variable; For participants For the evaluator When the evaluator If the evaluation action is not performed, the penalty variable is applied. Take negative value Reward variable Set to 0; otherwise, penalize the variable. Set to 0, reward variable In the formula, For the set positive coefficient, For the evaluator Number of validators selected for evaluation It is an increasing function of the variable.
8. The blockchain-based federated learning method as described in claim 7, characterized in that, reward function The expression is: In the formula, The reward coefficient is adjustable. For the set unit rewards, According to the assessor Additional bonuses for the accuracy settings of the generated global model: when If the accuracy of the generated global model reaches the target threshold, then the penalty variable is applied. Participants Additional rewards Take positive value For other participants Additional rewards ; Otherwise, additional rewards for all participants .
9. The blockchain-based federated learning method as described in claim 1, characterized in that, Step S7 includes: Each participant Trusted blocks Included in the set Available local models Perform aggregation to generate a global model ; global model The accuracy is the same as the highest accuracy global model determined in the previous rounds. The accuracy of the two models is compared, and if the difference between the two meets the set requirements, the generated global model is used. Use this as the global model for this round; otherwise, use the global model with the highest accuracy. This serves as the global model for this round.
10. A blockchain-based federated learning system, comprising a blockchain and communication nodes connected to the blockchain, wherein the communication nodes include federated learning task publishers and participants in blockchain-based federated learning, characterized in that, After the federated learning task publisher publishes the federated learning task on the blockchain, the federated learning system is used to implement the steps of the method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Fair and credible federal learning excitation method
CN114330747A
Malicious node detection method in federated learning
CN115766169A