Data processing method and related device

By applying federated learning methods in blockchain networks, the terminal trains the target model based on local data and performs gradient fusion, solving the contradiction between data leakage risk and multi-party collaboration security in data-sensitive industries, and achieving the balance between data security and multi-party collaboration.

CN117371027BActive Publication Date: 2025-05-09PEKING UNIV SHENZHEN GRADUATE SCHOOL
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311231610.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-09-21
Publication Date
2025-05-09
Estimated Expiration
2043-09-21

AI Technical Summary

Technical Problem

In the data-sensitive industry, how to achieve multi-party collaboration while protecting data security, solve the contradiction between data leakage risks and multi-party collaboration security while protecting data security.

Method used

By applying federated learning methods in the blockchain network, the terminal trains the target model based on local data, acquires gradient data and puts it on the chain, and the blockchain network performs checksum gradient fusion on the chain application, updates the model, and broadcasts updates the gradient.

Benefits of technology

It effectively avoids the risk of data leakage in transmitting raw data, improves the security of multiple terminals when collaborating, and further enhances the security of data processing through decentralized blockchain networks and smart contracts.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117371027B_ABST
    Figure CN117371027B_ABST
Patent Text Reader

Abstract

The present application provides a data processing method and related devices, which are applied to a blockchain network, including: obtaining an on-chain application issued by at least two terminals, any on-chain application including: the terminal sending the on-chain application performs federated learning training on the target model based on local data to obtain gradient data; verifies the on-chain application; performs gradient fusion on the gradient data in the verified on-chain application to obtain an updated gradient of the target model; broadcasts the updated gradient, and the updated gradient is obtained by any terminal and used to update the local target model. When using this solution for data processing, the terminal performs federated learning training on the target model based on local data to obtain gradient data, avoiding the risk of data leakage in the transmission of original data, and improving the security of multiple terminals when collaborating. Since a decentralized blockchain network is used to process data and verify the on-chain application, the security of data processing is further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of data processing technology, and in particular, to a data processing method and related devices. Background Art

[0002] With the development of Internet applications, there is an obvious contradiction between data protection and data utilization in applications in data-sensitive industries such as medical care, finance, and insurance.

[0003] On the one hand, from the perspective of data security, the data cannot leave the local server. For example, some data involves privacy and cannot be transmitted in plain text to terminals that do not belong to the data. On the other hand, from the perspective of making full use of the data, it is hoped that data from rich data sources can be utilized.

[0004] Therefore, when processing data, how to protect data security while achieving multi-party collaboration and making full use of existing data is a technical problem that needs to be solved urgently. Summary of the invention

[0005] The embodiments of the present application provide a data processing method and related equipment, which can protect data security and achieve multi-party collaboration.

[0006] In a first aspect, a data processing method is provided, which is applied to a blockchain network including multiple blockchain nodes, the method comprising: obtaining on-chain applications issued by at least two terminals, any of the on-chain applications comprising: gradient data obtained by the terminal sending the on-chain application through federated learning training of a target model based on local data; verifying the on-chain applications to exclude on-chain applications with attacking nature; performing gradient fusion on the gradient data in the on-chain applications that pass the verification to obtain an updated gradient of the target model; broadcasting the updated gradient, and the updated gradient is used to update the local target model after being obtained by any of the terminals.

[0007] When this embodiment performs data processing, the terminal performs federated learning on the target model based on local data to obtain gradient data, thereby avoiding the risk of data leakage in transmitting the original data and improving the security of collaboration among multiple terminals. In addition, the use of a decentralized blockchain network to process data and the use of smart contracts to review chain applications further improves the security of data processing.

[0008] In combination with the first aspect, in certain implementations of the first aspect, the gradient fusion of the gradient data in the verified on-chain application includes: using gradient aggregation to perform weighted aggregation on the gradient data in the verified on-chain application according to a preset algorithm. The preset algorithm may include a federated learning FedAvg algorithm.

[0009] In combination with the first aspect, in certain implementations of the first aspect, the verification of the on-chain application includes: determining whether the on-chain application is an on-chain application of an attacking nature; when it is determined that the on-chain application is not an on-chain application of an attacking nature, the on-chain application passes the verification.

[0010] By verifying whether the on-chain application is an on-chain application of an attack nature, and determining that the on-chain application verification has passed when the on-chain application is not an on-chain application of an attack nature, in this way, the on-chain application of an attack nature issued by a malicious terminal can be filtered out, which is conducive to improving the accuracy of data processing.

[0011] In combination with the first aspect, in some implementations of the first aspect, the on-chain application includes timestamp information, and the timestamp information is used to identify the duration of time consumed by the terminal for federated learning training; the verification of the on-chain application includes: determining whether the timestamp information included in the on-chain application is true, and determining whether the on-chain application is an attacking on-chain application based on whether the timestamp information is true. For example, when the duration corresponding to the timestamp information is less than a preset value, it can be determined that the timestamp information is not true.

[0012] In combination with the first aspect, in certain implementations of the first aspect, it also includes: determining a target blockchain node; performing gradient fusion on the gradient data in the verified on-chain application, including: performing gradient fusion on the gradient data in the verified on-chain application by the target blockchain node.

[0013] In combination with the first aspect, in certain implementations of the first aspect, it also includes: the target blockchain node determines reward information for rewarding each of the at least two terminals based on the smart contract; and broadcasts the reward information.

[0014] In a second aspect, a data processing method is provided, which is applied to a terminal communicating with a blockchain network; the terminal obtains the update gradient broadcast in the first aspect or any possible implementation of the first aspect, and updates the local target model according to the update gradient.

[0015] In combination with the second aspect, in some implementations of the second aspect, it also includes: obtaining reward information broadcast by the blockchain network; the reward information is determined by the blockchain network based on the reward mechanism in the smart contract.

[0016] In a third aspect, a blockchain network is provided, comprising at least two blockchain nodes, and wherein the blockchain network executes the data processing method as described in the first aspect or any possible implementation manner of the first aspect.

[0017] In a fourth aspect, a terminal is provided, comprising: a processor and a memory; the memory is coupled to the processor, the memory is used to store computer program code, the computer program code comprises computer instructions, and the processor calls the computer instructions so that the terminal executes the data processing method as described in the second aspect or any possible implementation of the second aspect.

[0018] It can be understood that the technical solutions provided in the above-mentioned second to fourth aspects can respectively correspond to any solution provided in the first aspect and its possible implementation, and the beneficial effects that can be achieved are similar, which will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0020] Figure 1 It is a schematic diagram of an application scenario using the data processing method of the present application;

[0021] Figure 2 It is a schematic diagram of the interactive flow of a data processing method in an embodiment of the present application;

[0022] Figure 3 It is a schematic diagram of the interactive flow of a data processing method in another embodiment of the present application. DETAILED DESCRIPTION

[0023] In the following description, specific details such as specific structures and technologies are provided for the purpose of illustration rather than limitation, so as to provide a thorough understanding of the embodiments of the present application. However, it should be clear to those skilled in the art that the present application can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, devices, circuits, and methods are omitted to prevent unnecessary details from obstructing the description of the present application.

[0024] In the medical, financial, insurance and other industries, users' health data, financial data, insurance data and other data usually cannot leave the local area because they involve user privacy. In practical applications, users are not limited to individuals, but can also be companies, organizations and other entities. With the development of big data, a lot of data is stored in different terminals. This application can effectively utilize the data existing in different terminals under the premise of ensuring data security. Specifically, when the technical solution provided by this application performs data processing, the terminal performs federated learning training on the target model based on the locally stored data to obtain gradient data, and then sends a chain request including the gradient data to the blockchain network. After excluding the aggressive chain requests, the blockchain network combines the gradient data uploaded by different terminals to obtain updated data, and the updated data can further improve the target model.

[0025] Figure 1 This is a schematic diagram of an application scenario of the data processing method of this application, such as Figure 1 As shown, in this embodiment, the terminal side includes five terminals: a first terminal 101, a second terminal 102, a third terminal 103, a fourth terminal 104 and a fifth terminal 105. Each terminal communicates with the blockchain network respectively, and the blockchain network includes eight blockchain nodes. Figure 1 The terminal in the term "blockchain node" may be a computer, a mobile phone, etc. The blockchain node may be a computer, a server, etc. This application does not limit the specific types of terminals and blockchain nodes.

[0026] In one embodiment, when performing data processing, such as Figure 2 As shown, it includes steps 201 to 207.

[0027] 201. The terminal side device performs federated learning training on the target model based on local data to obtain gradient data.

[0028] Among them, the target model can be obtained by the terminal side device from the blockchain.

[0029] 202. The terminal sends a link-up application to the blockchain network.

[0030] 203. Blockchain network obtains on-chain application.

[0031] In actual applications, the blockchain network can obtain on-chain applications issued by at least two terminals. Any on-chain application includes: the gradient data obtained by the terminal sending the on-chain application through federated learning training of the target model based on local data.

[0032] 204. The blockchain network verifies the application for on-chain access.

[0033] In some possible implementations, verifying the on-chain application includes: determining whether the on-chain application is an on-chain application of an attacking nature; when it is determined that the on-chain application is not an on-chain application of an attacking nature, the on-chain application passes the verification.

[0034] In some possible implementations, the on-chain application includes timestamp information, and the timestamp information is used to identify the time consumed by the terminal for federated learning training; the on-chain application is verified, including: determining whether the timestamp information included in the on-chain application is true, and determining whether the on-chain application is an attack-type on-chain application based on whether the timestamp information is true.

[0035] Specifically, the trusted timestamp technology in the Intel Software Guard Extensions (SGX) trusted execution environment can be used to generate accurate time consumption data for this round of training. Intel SGX can create a secure area called the "secure encryption zone" in the CPU. This area is protected at the hardware level, and external programs or operating systems cannot access or modify it. The code running in the SGX secure encryption zone can obtain real and reliable time information. Through the trusted timestamp verification method, it can be guaranteed that the amount of computing consumed in each round of training is proved, effectively preventing attacks. For example, a normal client trains a model on a local data set, and each round of iteration actually takes about 10 minutes. In order to quickly complete the training process, a malicious client may directly generate some random noise data as a gradient submission, and complete a round of "training" in just 1 second. The attack behavior can be discovered by simply judging the timestamp.

[0036] 205. The blockchain network performs gradient fusion on the gradient data in the verified on-chain application to obtain the updated gradient of the target model.

[0037] In some possible implementations, the step of determining a target blockchain node is also included, and gradient fusion is performed on the gradient data in the verified on-chain application, including: the target blockchain node performs gradient fusion on the gradient data in the verified on-chain application.

[0038] In some possible embodiments, gradient aggregation can be used to perform weighted aggregation on the gradient data in the verified on-chain application according to a preset algorithm to obtain an updated gradient of the target model.

[0039] For example, in one embodiment, if the update gradient is g, the preset algorithm includes:

[0040] g=w1g1+w2g2+...+wn*gn,

[0041] Among them, w1, w2, ..., wn are the weights of each terminal, and g1, g2, ..., gn are the gradient data uploaded by each terminal.

[0042] The wi calculation method includes: calculating the computing power coefficient of each terminal: ci = pi / Σpi, Σpi is the sum of the computing power of all terminals, and calculating the data set coefficient of each terminal: di = ni / Σni, Σni is the sum of the total number of data sets of all terminals.

[0043] The weight coefficient is the combination of the computing power coefficient and the data set coefficient: wi = α*ci + (1-α)*di, where α is a parameter for adjusting the weight ratio of computing power and data set, and its value range is [0,1].

[0044] 206.Blockchain network broadcasts update gradients.

[0045] 207. After any terminal obtains the updated gradient, it updates the local target model according to the updated gradient.

[0046] When this embodiment performs data processing, the terminal performs federated learning on the target model based on local data to obtain gradient data, thereby avoiding the risk of data leakage in transmitting the original data and improving the security of collaboration among multiple terminals. In addition, the use of a decentralized blockchain network to process data and the use of smart contracts to review chain applications further improves the security of data processing.

[0047] In another embodiment, when data processing is performed, the terminals participating in the data processing may be rewarded to encourage more terminals to participate in the data processing. It should be noted that the reward may correspond to the authority, and the terminal may use the reward to open different authorities. Figure 3 As shown, the data processing includes steps 301 to 310, wherein steps 301 to 307 are Figure 2 Steps 201 to 207 in the illustrated embodiment are similar, and reference may be made to the previous description.

[0048] 301. The terminal side device performs federated learning training on the target model based on local data to obtain gradient data.

[0049] Among them, the target model can be obtained by the terminal side device from the blockchain.

[0050] 302. The terminal sends a chain application to the blockchain network.

[0051] 303. Blockchain network obtains on-chain application.

[0052] In actual applications, the blockchain network can obtain on-chain applications issued by at least two terminals. Any on-chain application includes: the gradient data obtained by the terminal sending the on-chain application through federated learning training of the target model based on local data.

[0053] 304. The blockchain network verifies the application for chain connection.

[0054] In some possible implementations, verifying the on-chain application includes: determining whether the on-chain application is an on-chain application of an attacking nature; when it is determined that the on-chain application is not an on-chain application of an attacking nature, the on-chain application passes the verification.

[0055] In some possible implementations, the on-chain application includes timestamp information, and the timestamp information is used to identify the time consumed by the terminal for federated learning training; the on-chain application is verified, including: determining whether the timestamp information included in the on-chain application is true, and determining whether the on-chain application is an attack-type on-chain application based on whether the timestamp information is true.

[0056] 305. The blockchain network performs gradient fusion on the gradient data in the verified on-chain application to obtain the updated gradient of the target model.

[0057] In some possible implementations, the step of determining a target blockchain node is also included, and gradient fusion is performed on the gradient data in the verified on-chain application, including: the target blockchain node performs gradient fusion on the gradient data in the verified on-chain application.

[0058] In some possible embodiments, gradient aggregation can be used to perform weighted aggregation on the gradient data in the verified on-chain application according to a preset algorithm to obtain an updated gradient of the target model.

[0059] For example, in one embodiment, if the update gradient is g, the preset algorithm includes:

[0060] g=w1g1+w2g2+...+wn*gn

[0061] Among them, w1, w2, ..., wn are the weights of each terminal, and g1, g2, ..., gn are the gradient data uploaded by each terminal.

[0062] The wi calculation method includes: calculating the computing power coefficient of each terminal: ci = pi / Σpi, Σpi is the sum of the computing power of all terminals, and calculating the data set coefficient of each terminal: di = ni / Σni, Σni is the sum of the total number of data sets of all terminals.

[0063] The weight coefficient is the combination of the computing power coefficient and the data set coefficient: wi = α*ci + (1-α)*di, where α is a parameter for adjusting the weight ratio of computing power and data set, and its value range is [0,1].

[0064] 306. Blockchain network broadcasts update gradients.

[0065] 307. After any terminal obtains the updated gradient, it updates the local target model according to the updated gradient.

[0066] 308. The target blockchain node determines reward information for each of the at least two terminals based on the smart contract.

[0067] The target blockchain node can be randomly determined among the blockchain nodes that meet the computing power conditions, and the selected blockchain node determines the reward information for each terminal based on the reward mechanism in the smart contract.

[0068] In some possible implementations, the smart contract may include the following functions: collecting the gradient data uploaded by all terminals in this round, and designing a reward mechanism. The reward mechanism may include: detecting malicious nodes on the collected gradient data. After detecting attacks or abnormal data, filtering out unqualified gradient data, and generating updated gradients for this round through the weighted aggregation algorithm FedAvg. At the same time, based on the contribution size and reputation value of the terminal, the reward calculation module is called to automatically calculate the reward information.

[0069] The reward mechanism is conducive to attracting more terminals to participate in training and perform computing tasks honestly. The reward mechanism provides a fair incentive method. In some possible implementations, the reward mechanism can be implemented using the following four models: attack detection model, reputation model, contribution model and reward model. The attack detection model can be used to detect false / malicious data uploaded by malicious terminals, measure the utility of the terminal based on contribution and reputation, and comprehensively determine the reward information for rewarding (or punishing) the terminal.

[0070] Below, specific implementation examples of the attack detection model, reputation model, contribution model and reward model are described.

[0071] Among them, the attack detection model can be designed with the following steps to implement attack detection:

[0072] (1) Collect the gradient data {g1,g2,...,gn} uploaded by all terminals in each round.

[0073] (2) Calculate the mean μ = Σgi / n and mean square error of all gradient data

[0074] (3) For each terminal i, calculate the distance dist(gi,μ) between its local gradient gi and the mean μ.

[0075] (4) Set a coefficient β and then use β*δ 2 To represent the dynamic threshold of τ, the value range of β is usually between [2,3]. When β takes a smaller value, the detection is more strict and sensitive. If dist(gi,μ)>τ, the abnormal gradient data of node i in this round is recorded.

[0076] (5) The detected abnormal gradient data are excluded from the parameter aggregation process and are not included in the model update.

[0077] (6) The reputation value of the client that uploaded the abnormal data is adjusted through the reputation model.

[0078] For example, suppose there are 5 clients in this round, and the uploaded gradient data are represented by vectors as follows:

[0079] g1=[1.2,3.5,2.6]

[0080] g2=[1.1,4.2,2.3]

[0081] g3=[1.5,3.8,2.1]

[0082] g4=[2.2,8.7,5.6]

[0083] g5=[1.4,3.6,2.4]

[0084] Then the following data is calculated:

[0085] Mean vector μ = [1.48, 4.76, 3.0]

[0086] Mean square error δ^2 = [0.2169, 6.8721, 1.62]

[0087] Assuming that α=2 is set, the dynamic threshold τ of this round is calculated as:

[0088] τ=α*δ^2=[0.4338,13.7442,3.24]

[0089] Compare the distance between each terminal gradient vector and the mean vector:

[0090] dist(g1,μ)=[0.28,1.26,0.4]

[0091] dist(g2,μ)=[0.38,0.56,0.7]

[0092] dist(g3,μ)=[0.02,0.96,0.9]

[0093] dist(g4,μ)=[0.72,3.94,2.6]

[0094] dist(g5,μ)=[0.06,1.16,0.6]

[0095] According to the calculation results, g4 has the largest distance from the mean and is greater than the threshold τ. Therefore, g4 is detected as an abnormal attack gradient and is eliminated in this round.

[0096] The reputation model can be implemented by designing the following steps:

[0097] (1) Define a reputation value for each terminal, which represents a subjective measure of its trustworthiness. It can be expressed as a triple (b, d, u), where the parameters represent the trustworthiness, untrustworthiness, and uncertainty of the terminal, respectively.

[0098] (2) Initially, the reputation value of each newly added terminal registered through the blockchain service can be set to (0.5, 0.5, 1), that is, the degree of untrustworthiness and trustworthiness is the same, the uncertainty is 1, and the triple (b, d, u) takes the value distribution [0, 1].

[0099] (3) After each round of iteration, the selected target blockchain node adjusts its reputation value based on the performance of the terminal.

[0100] For example, the following steps may be included:

[0101] (3-1) The calculation rules of the terminal trustworthiness b include: when the terminal uploads correct and valid parameters,

[0102] b=b+random(0,0.01)

[0103] When an attack gradient is detected, it is adjusted with an error rate r:

[0104] b=b×(1-r)

[0105] r is the ratio of the attack parameters in this round to all parameters.

[0106] The calculation rules of the terminal untrustworthiness level d include: when the client uploads correct and valid parameters,

[0107] d = d - random (0, 0.01)

[0108] When an attack gradient is detected, it is adjusted with an error rate r:

[0109] d=d+r

[0110] r is the ratio of the attack parameters in this round to all parameters.

[0111] The calculation rules of the terminal uncertainty u include: when the client uploads correct and valid parameters, u decays according to the λ coefficient:

[0112] u=u*λ

[0113] The value of λ is (0<λ<1). The larger the value, the slower the attenuation. The coefficient can be configured more flexibly according to the frequency of terminal participation (for example, a small coefficient corresponds to a high frequency and a large coefficient corresponds to a low frequency, so as to realize dynamic adjustment of terminals with different frequencies).

[0114] When an attack gradient is detected, u is reset to its initial value of 1, indicating that the uncertainty has risen again.

[0115] (4) Calculate the vector modulus of the triple (b, d, u) and normalize it to the interval [0, 1].

[0116] Calculate the vector modulus: v = √(b^2+d^2+u^2)

[0117] Normalization process, get the reputation value: R = (v-min) / (max-min)

[0118] Among them, max and min are the maximum and minimum values ​​of the vector modulus.

[0119] (5) Calculate the difference between the certainty and uncertainty of the triple (b, d, u) diff = bd. When diff < 0, R = -R, and the final reward will be the deduction reward.

[0120] (6) Considering time decay, the earlier the round, the smaller the impact on the credibility value.

[0121] Time decay calculation: Ri = α*Ri-1+(1-α)*R0

[0122] The value of α is (0<α<1). The larger the value, the slower the attenuation. The coefficient can be configured more flexibly according to the frequency of client participation (for example, a high frequency corresponds to a small coefficient, a low frequency corresponds to a large coefficient, and dynamic adjustment of clients with different frequencies can be achieved).

[0123] By introducing the α decay coefficient, the reputation value decays back to the initial level over time, where R0 is the initial value.

[0124] For example, if there are 5 terminals in this round, the vectors corresponding to the uploaded gradient data include:

[0125] g1=[1.2,3.5,2.6]

[0126] g2=[1.1,4.2,2.3]

[0127] g3=[1.5,3.8,2.1]

[0128] g4=[2.2,8.7,5.6]

[0129] g5=[1.4,3.6,2.4]

[0130] In the attack detection, g4 is judged to be a malicious attack gradient, and the error rate r = 1 / 5 = 0.2.

[0131] Then the reputation value of each terminal is adjusted to:

[0132] g1:

[0133] b=b+0.005 (correct gradient, b micro-increment random number is 0.005)

[0134] d = d-0.003 (correct gradient, d is slightly reduced to 0.003)

[0135] u=u*0.95(attenuation coefficient λ=0.95)

[0136] The result of the triple (b, d, u) is:

[0137] g1:(0.505,0.495,0.95)

[0138] g2:(0.51,0.49,0.93)

[0139] g3:(0.52,0.48,0.91)

[0140] g4:(0.4,0.6,1)

[0141] g5:(0.507,0.493,0.96)

[0142] The reputation value R is:

[0143] R1=0.852

[0144] R2=0.848

[0145] R3=0.844

[0146] R4=-0.818

[0147] R5=0.855

[0148] Because terminal 4 is a malicious attack gradient, R4 is a negative value, and the final reward information will deduct the corresponding reward value.

[0149] The contribution model is implemented through the following steps:

[0150] The blockchain node aggregates the local gradients uploaded by all terminals through the gradient aggregation algorithm to obtain the global gradient g of this round.

[0151] Gradient aggregation algorithm: g = w1g1 + w2g2 + ... + wn*gn,

[0152] w1,w2,...,wn are the weights of each terminal, and g1,g2,...,gn are the gradient data uploaded by each terminal.

[0153] The calculation method of wi is as follows:

[0154] Calculate the computing power coefficient of each terminal: ci = pi / Σpi,

[0155] Σpi is the sum of all terminal computing power,

[0156] Calculate the data set coefficient for each terminal: di = ni / Σni,

[0157] Σni is the sum of the total number of terminal data sets,

[0158] The weight coefficient is the combination of the computing power coefficient and the data set coefficient: wi = α*ci + (1-α)*di,

[0159] Among them, α is a parameter that adjusts the ratio of computing power and data set weight, and its value range is [0,1].

[0160] For each terminal i, calculate the contribution index of its local gradient gi.

[0161] Calculate the cosine similarity between gi and the global gradient g: cos_sim(gi,g),

[0162] The larger the cosine similarity value is, the more consistent the directions of the two vectors are, and the better the gradient contribution of terminal i is.

[0163] Normalized processing, the contribution index is obtained:

[0164] Contribution(i)=cos_sim(gi,g) / (max(cos_sim)-min(cos_sim))

[0165] Among them, max(cos_sim) and min(cos_sim) are the maximum and minimum cosine similarities among all nodes.

[0166] A minimum contribution threshold τ1 is set, and terminal i can get the reward only when Contribution(i)≥τ1.

[0167] The value range of τ1 is between 0 and 1. τ1 can be configured according to the actual situation. If the quality of terminal gradient data is uniform, τ1 can be appropriately increased so that higher quality clients can receive due rewards.

[0168] An example is given below: The gradient vectors uploaded by the five terminals are:

[0169] g1=[1.2,3.5,2.6]

[0170] g2=[1.1,4.2,2.3]

[0171] g3=[1.5,3.8,2.1]

[0172] g4=[2.2,8.7,5.6]

[0173] g5=[1.4,3.6,2.4]

[0174] According to the computing power and data set size, the weight is calculated as:

[0175] w1=0.2, w2=0.15, w3=0.25, w4=0.3, w5=0.1.

[0176] Gradient aggregation obtains the global gradient:

[0177] g=w1g1+w2g2+w3g3+w4g4+w5g5=[1.54,4.76,3.22]

[0178] Calculate cosine similarity:

[0179] cos_sim1 = 0.976

[0180] cos_sim2=0.945

[0181] cos_sim3=0.924

[0182] cos_sim4=0.913

[0183] cos_sim5=0.967

[0184] After normalization, we get the contribution value Contribution(i):

[0185] Contribution(1)1=0.866

[0186] Contribution(2)=0.789

[0187] Contribution(3)=0.821

[0188] Contribution(4)=0.833

[0189] Contribution(5)=0.853

[0190] Assuming that the minimum contribution threshold τ1 is 0.8, the contribution of client 2 is lower than τ1 and no reward is received.

[0191] The reward model can be implemented through the following steps:

[0192] (1) Count the number of calculations Ci for each terminal i.

[0193] (2) The terminal’s reward formula is calculated as:

[0194] Reward(i)=Weight_reward(i)*Reputation(i)*Contribution(i)

[0195] in:

[0196] Weight_reward is the calculation scale, and the design formula is: Weight_reward(i)=Ci / ΣCi, Ci represents the number of calculations of terminal i, and ΣCi represents the sum of the number of calculations of all terminals.

[0197] Reputation(i) is the reputation value of node i,

[0198] Based on the reputation model formula: Reputation(i)=α*Reputation(i-1)+(1-α)*Reputation(0).

[0199] Contribution(i) is the contribution index of terminal i to the model, based on the contribution model formula: Contribution(i) = cos_sim(gi,g) / (max(cos_sim)-min(cos_sim)).

[0200] (3) The penalty can be reflected according to the value of Reputation(i). When Reputation(i)<0, the reward will be deducted.

[0201] (4) The smart contract records the calculated Reward(i) in the ledger and automatically transfers the digital tokens to the client user as the reward expenditure for each client.

[0202] An example is as follows: The gradient data includes:

[0203] g1=[1.2,3.5,2.6]

[0204] g2=[1.1,4.2,2.3]

[0205] g3=[1.5,3.8,2.1]

[0206] g4=[2.2,8.7,5.6]

[0207] g5=[1.4,3.6,2.4]

[0208] Reputation data includes:

[0209] R1=0.852

[0210] R2=0.848

[0211] R3=0.844

[0212] R4=-0.818

[0213] R5=0.855

[0214] Contribution data includes:

[0215] Contribution1 = 0.866

[0216] Contribution2 = 0.789

[0217] Contribution3 = 0.821

[0218] Contribution4 = 0.833

[0219] Contribution5 = 0.853

[0220] According to the gradient data, the calculation times of the five terminals is 1 (the gradients are all 1*3 matrices, 1 represents the number of training times), so the count Ci is equal to 1, and Weight_reward(i) is equal to 0.2.

[0221] The reward calculation result is:

[0222] Reward1=1*0.2*0.852*0.866=0.1489

[0223] Reward2=1*0.2*0.848*0.789=0.127

[0224] Reward3=1*0.2*0.844*0.821=0.1407

[0225] Reward4=1*0.2*(-0.818)*0.833=-0.1396(tokens need to be deducted)

[0226] Reward5=1*0.2*0.855*0.853=0.1451

[0227] 309. Broadcast the reward information.

[0228] 310. The terminal obtains reward information.

[0229] This embodiment is conducive to attracting more terminals to participate in training and perform computing tasks honestly by setting up a reward mechanism.

[0230] An embodiment of the present application also provides a blockchain network, which includes at least two blockchain nodes, and the blockchain network executes the following data processing method: obtaining chain applications issued by at least two terminals, and any chain application includes: the terminal sending the chain application performs federated learning training on the target model based on local data to obtain gradient data; verifying the chain application to exclude chain applications with attacking nature in the chain application; performing gradient fusion on the gradient data in the chain application that passes the verification to obtain an updated gradient of the target model; broadcasting the updated gradient, and the updated gradient is used to update the local target model after being obtained by any terminal.

[0231] In some possible implementations, the blockchain network uses gradient aggregation to perform weighted aggregation on the gradient data in the verified on-chain applications according to a preset algorithm.

[0232] In some possible implementations, the blockchain network verifies the on-chain application, including: determining whether the on-chain application is an on-chain application of an attacking nature; when it is determined that the on-chain application is not an on-chain application of an attacking nature, the on-chain application passes the verification.

[0233] In some possible implementations, the on-chain application includes timestamp information, and the timestamp information is used to identify the time consumed by the terminal for the federated learning training.

[0234] The blockchain network verifies the on-chain application, including: determining whether the timestamp information included in the on-chain application is authentic, and determining whether the on-chain application is an attack-type on-chain application based on whether the timestamp information is authentic.

[0235] In some possible implementations, the blockchain network is also used to determine a target blockchain node; the blockchain network performs gradient fusion on the gradient data in the verified on-chain application, including: the target blockchain node performs gradient fusion on the gradient data in the verified on-chain application.

[0236] In some possible implementations, the blockchain network is also used to determine, by the target blockchain node based on the smart contract, reward information for rewarding each of the at least two terminals; and broadcast the reward information.

[0237] The embodiment of the present application also provides a terminal, the terminal includes: a processor and a memory; the memory is coupled to the processor, the memory is used to store computer program code, the computer program code includes computer instructions, the processor calls the computer instructions to enable the terminal to execute Figure 2 or Figure 3 The data processing method executed by the terminal on the terminal side of the middle terminal. Please refer to the description in the previous method embodiment for details, which will not be repeated here.

[0238] An embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.

[0239] An embodiment of the present application provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments can be implemented.

[0240] The present application implements all or part of the processes in the above-mentioned embodiment method, which can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a computer-readable storage medium. When the computer program is executed by the processor, the steps of each of the above-mentioned method embodiments can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in source code form, object code form, executable file or some intermediate form. The computer-readable medium may at least include: any entity or device that can carry the computer program code to the camera / terminal, a recording medium, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electric carrier signal, a telecommunication signal, and a software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk or an optical disk. In some jurisdictions, according to legislation and patent practice, computer-readable media cannot be electric carrier signals and telecommunication signals.

[0241] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described or recorded in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.

[0242] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0243] In the embodiments provided in the present application, it should be understood that the disclosed methods and terminals can be implemented in other ways. For example, the device / network equipment embodiments described above are merely schematic. For example, the division of the modules or units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some interfaces, indirect coupling or communication connection of devices or units, which can be electrical, mechanical or other forms.

[0244] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0245] It should be understood that when used in the present specification and the appended claims, the term "comprising" indicates the presence of described features, wholes, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or combinations thereof.

[0246] It should also be understood that the term “and / or” used in the specification and appended claims refers to any and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0247] References to "one embodiment" or "some embodiments" etc. described in the specification of this application mean that one or more embodiments of the present application include specific features, structures or characteristics described in conjunction with the embodiment. Therefore, the statements "in one embodiment", "in some embodiments", "in some other embodiments", "in some other embodiments", etc. that appear in different places in this specification do not necessarily refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in other ways. The terms "including", "comprising", "having" and their variations all mean "including but not limited to", unless otherwise specifically emphasized in other ways.

[0248] The embodiments described above are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, a person skilled in the art should understand that the technical solutions described in the aforementioned embodiments may still be modified, or some of the technical features may be replaced by equivalents. Such modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.

Claims

1. A data processing method, characterized in that: Applied to a blockchain network including a plurality of blockchain nodes, the method comprises: Obtaining on-chain applications sent by at least two terminals, wherein any of the on-chain applications includes: gradient data obtained by the terminal sending the on-chain application performing federated learning training on a target model based on local data; Use the trusted timestamp technology in the Intel SGX trusted execution environment to create a secure encryption zone, and run the corresponding code in the secure encryption zone to generate timestamp information; wherein the timestamp information is used to identify the time consumed by the terminal for federated learning training; Determine whether the on-chain application is an on-chain application of an attacking nature based on whether the timestamp information is true, thereby excluding on-chain applications of an attacking nature from the on-chain applications; Determine the target blockchain node; According to a preset weighted aggregation algorithm, the target blockchain node performs weighted aggregation on the gradient data in the verified on-chain application to obtain an updated gradient of the target model; Broadcasting the update gradient, wherein the update gradient is acquired by any of the terminals and used to update the local target model; The target blockchain node determines reward information for each of the at least two terminals based on a reward mechanism in the smart contract, and broadcasts the reward information; the reward mechanism is implemented by an attack detection model, a reputation model, a contribution model, and a reward model; The implementation steps of the attack detection model include: Collect the gradient data {g1,g2,...,gn} uploaded by all terminals in each round; Calculate the mean μ = Σgi / n and mean square error of all gradient data For each terminal i, calculate the distance dist(gi,μ) between its local gradient gi and the mean μ; Set a coefficient β, using β*δ 2 To represent the dynamic threshold of τ, where the value range of β is between [2,3]. When β takes a smaller value, the detection is more strict and sensitive. If dist(gi,μ)>τ, the abnormal gradient data of node i in this round is recorded. For the detected abnormal gradient data, it is excluded from the parameter aggregation process and not included in the model update; The reputation value of the client that uploaded the abnormal data is adjusted through the reputation model; The implementation steps of the reputation model include: Define a reputation value for each terminal, which represents a subjective measure of its trustworthiness. Specifically, it is represented by a triple (b, d, u), where b represents the trustworthiness of the terminal, d represents the degree of untrustworthiness, and u represents uncertainty. Initially, the reputation value of each newly added terminal is set to (0.5, 0.5, 1), that is, the untrustworthy and trustworthy levels are the same, the uncertainty is 1, and the triple (b, d, u) values ​​are distributed in [0, 1]; After each round of iteration, adjusting the reputation value according to the performance of the terminal through the target blockchain node; The implementation steps of the contribution model include: The gradient data uploaded by all terminals are aggregated through the weighted aggregation algorithm to obtain the updated gradient g of this round, where g = w1g1+w2g2+...+wn*gn, w1,w2,...,wn are the weights of each terminal, g1,g2,...,gn are the gradient data uploaded by each terminal; Weight coefficient wi = α*ci + (1-α) * di, where ci = pi / Σpi, di = ni / Σni, ci represents the computing power coefficient of the terminal, Σpi is the sum of the computing power of all terminals, di represents the data set coefficient of the terminal, Σni is the sum of the total number of data sets of all terminals, and α represents the parameter for adjusting the weight ratio of computing power and data set, with a value range of [0,1]; For each terminal i, calculate the contribution index of its local gradient gi; Calculate the cosine similarity between gi and the updated gradient g: cos_sim(gi,g). The larger the cosine similarity value, the more consistent the directions of the two vectors are, and the better the gradient contribution of terminal i is. Through normalization processing, the contribution index Contribution(i)=cos_sim(gi,g) / (max(cos_sim)-min(cos_sim)) is obtained, where max(cos_sim) represents the maximum cosine similarity and min(cos_sim) represents the minimum cosine similarity; Set the minimum contribution threshold τ1, which ranges from 0 to 1. When Contribution(i)≥τ1, terminal i can get a reward. If the quality of the terminal's gradient data is uniform, τ1 can be appropriately increased, so that the client can get the due reward. The implementation steps of the reward model include: Count the number of calculations Ci of each terminal i; The reward formula for the terminal is: Reward(i) = Weight_reward(i)*Reputation(i)*Contribution(i); where Weight_reward represents the scale of calculation, Weight_reward(i) = Ci / ΣCi, Ci represents the number of calculations of terminal i, ΣCi represents the sum of the number of calculations of all terminals, Reputation(i) represents the reputation value of terminal i, Reputation(i) = α*Reputation(i-1)+(1-α)*Reputation(0), Contribution(i) represents the contribution index of terminal i to the model, Contribution(i) = cos_sim(gi,g) / (max(cos_sim)-min(cos_sim)); When Reputation(i)<0, deduct the reward; The calculated Reward(i) is recorded in the ledger, and the digital tokens are automatically transferred to the client user as the reward expenditure for each client.

2. The method according to claim 1, characterized in that The verifying the on-chain application includes: Determine whether the on-chain application is an on-chain application of an attacking nature. When it is determined that the on-chain application is not an on-chain application of an attacking nature, the on-chain application passes the verification.

3. A data processing method, characterized in that: Terminals used to communicate with blockchain networks; The terminal obtains the update gradient broadcast in the data processing method according to any one of claims 1 to 2; Update the local target model according to the update gradient; Obtaining reward information broadcast by the blockchain network; The reward information is determined by the blockchain network based on a reward mechanism in a smart contract, and the reward mechanism is implemented through an attack detection model, a reputation model, a contribution model, and a reward model; The implementation steps of the attack detection model include: Collect the gradient data {g1,g2,...,gn} uploaded by all terminals in each round; Calculate the mean μ = Σgi / n and mean square error of all gradient data For each terminal i, calculate the distance dist(gi,μ) between its local gradient gi and the mean μ; Set a coefficient β, using β*δ 2 To represent the dynamic threshold of τ, where the value range of β is between [2,3]. When β takes a smaller value, the detection is more strict and sensitive. If dist(gi,μ)>τ, the abnormal gradient data of node i in this round is recorded. For the detected abnormal gradient data, it is excluded from the parameter aggregation process and not included in the model update; The reputation value of the client that uploaded the abnormal data is adjusted through the reputation model; The implementation steps of the reputation model include: Define a reputation value for each terminal, which represents a subjective measure of its trustworthiness. Specifically, it is represented by a triple (b, d, u), where b represents the trustworthiness of the terminal, d represents the degree of untrustworthiness, and u represents uncertainty. Initially, the reputation value of each newly added terminal is set to (0.5, 0.5, 1), that is, the untrustworthy and trustworthy levels are the same, the uncertainty is 1, and the triple (b, d, u) values ​​are distributed in [0, 1]; After each round of iteration, adjusting the reputation value according to the performance of the terminal through the target blockchain node; The implementation steps of the contribution model include: The gradient data uploaded by all terminals are aggregated through the weighted aggregation algorithm to obtain the updated gradient g of this round, where g = w1g1+w2g2+...+wn*gn, w1,w2,...,wn are the weights of each terminal, g1,g2,...,gn are the gradient data uploaded by each terminal; Weight coefficient wi = α*ci + (1-α) * di, where ci = pi / Σpi, di = ni / Σni, ci represents the computing power coefficient of the terminal, Σpi is the sum of the computing power of all terminals, di represents the data set coefficient of the terminal, Σni is the sum of the total number of data sets of all terminals, and α represents the parameter for adjusting the weight ratio of computing power and data set, with a value range of [0,1]; For each terminal i, calculate the contribution index of its local gradient gi; Calculate the cosine similarity between gi and the updated gradient g: cos_sim(gi,g). The larger the cosine similarity value, the more consistent the directions of the two vectors are, and the better the gradient contribution of terminal i is. Through normalization processing, the contribution index Contribution(i)=cos_sim(gi,g) / (max(cos_sim)-min(cos_sim)) is obtained, where max(cos_sim) represents the maximum cosine similarity and min(cos_sim) represents the minimum cosine similarity; Set the minimum contribution threshold τ1, which ranges from 0 to 1. When Contribution(i)≥τ1, terminal i can get a reward. If the quality of the terminal's gradient data is uniform, τ1 can be appropriately increased, so that the client can get the due reward. The implementation steps of the reward model include: Count the number of calculations Ci of each terminal i; The reward formula for the terminal is: Reward(i) = Weight_reward(i)*Reputation(i)*Contribution(i); where Weight_reward represents the scale of calculation, Weight_reward(i) = Ci / ΣCi, Ci represents the number of calculations of terminal i, ΣCi represents the sum of the number of calculations of all terminals, Reputation(i) represents the reputation value of terminal i, Reputation(i) = α*Reputation(i-1)+(1-α)*Reputation(0), Contribution(i) represents the contribution index of terminal i to the model, Contribution(i) = cos_sim(gi,g) / (max(cos_sim)-min(cos_sim)); When Reputation(i)<0, deduct the reward; The calculated Reward(i) is recorded in the ledger, and the digital tokens are automatically transferred to the client user as the reward expenditure for each client.

4. A blockchain network, characterized in that: The blockchain network includes at least two blockchain nodes, and the blockchain network executes the data processing method according to any one of claims 1 to 2.

5. A terminal, characterized in that: The terminal comprises: Processor and memory; The memory is coupled to the processor, and the memory is used to store computer program codes, wherein the computer program codes include computer instructions, and the processor calls the computer instructions to enable the terminal to execute the data processing method according to claim 3.

Citation Information

Patent Citations

  • High-quality federal learning system and learning method based on block chain and reputation mechanism

    CN114154649A

  • Federal learning model training method and device and automobile

    CN116484969A