A federated learning computing method based on a trusted execution environment and related devices
Patent Information
- Application Number
- CN202311727012.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-14
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2043-12-14
AI Technical Summary
[0003]同时,由于联邦学习服务器架设在一个独立于各方的第三方设备(比如公有云)上,参与运算的各方可能并不信任这个第三方,有可能各方提供宝贵的私有数据训练而成的模型被第三方窃取
[0044]从以上技术方案可以看出,本申请实施例具有以下优点:通过本申请实施例公开的一种基于可信执行环境的联邦学习计算方法,通过在可信执行环境中将联邦学习模型划分,保证了联邦学习模型可以在不同设备上进行训练,使得各联邦学习训练参与方不仅可以将他们的模型部署到本地计算设备上,而且可以安全地部署到公有云的服务器中。同时,通过高效的可信执行环境,提高了联邦学习模型效率。再有,通过模型划分,使得即使IoT这种内存和计算能力受限的设备也可以参与大模型的联邦学习。
Smart Images

Figure CN117688576B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular to a federated learning computing method and related equipment based on a trusted execution environment. Background Technology
[0002] Federated learning is a deep learning algorithm that can train a shared model using private datasets from multiple parties while ensuring the data security and privacy of each party. In federated learning, generally, each party's private data does not leave its own infrastructure to ensure data security and reduce network transmission, especially when the data provider is a bandwidth-constrained Internet of Things (IoT) device.
[0003] Meanwhile, because the federated learning server is hosted on a third-party device (such as a public cloud) independent of all parties involved, the participating parties may not trust this third party. There is a possibility that the model trained using valuable private data provided by each party could be stolen by the third party. Specifically, since interaction parameters pose a risk of data leakage, existing federated learning solutions often require the integration of other privacy protection technologies to achieve a secure federated model training process. Therefore, how to preserve the final public model and global parameters for their own inference services, and how to ensure the data security of all data providers in federated learning during the inference process, are pressing technical challenges that need to be addressed. Summary of the Invention
[0004] This application provides a federated learning computation based on a trusted execution environment, which is used to protect the data privacy and security of federated learning training participants and the security of the trained model in a trusted execution environment.
[0005] The first aspect of this application provides a federated learning computation method based on a trusted execution environment, applied to a computer device. The computer device is communicatively connected to a federated learning server. A target federated learning model runs on the computer device and the federated learning server. A trusted execution environment is deployed on the federated learning server and the computer device. The method includes:
[0006] The bottom-level local model in the target federated learning model is determined, and the bottom-level local model is set as the first-level federated learning model. The upper-level global model is divided into two sub-models using the first irreversible operation layer of the target federated learning upper-level global model as the dividing point. The first sub-model of the target federated learning upper-level global model is set as the second-level federated learning model, and the second sub-model of the target federated learning upper-level global model is set as the third-level federated learning model. The first irreversible operation layer is the irreversible operation layer with the first ranking in the target federated learning model.
[0007] The first-level federated learning model is deployed in the first-level trusted execution environment of the computer device, the second-level federated learning model is deployed within the second-level trusted execution environment of the federated learning server, and the third-level federated learning model is deployed outside the second-level trusted execution environment of the federated learning server.
[0008] Obtain the target identification code when multiple federated learning training participants train the federated learning model in the first-level trusted execution environment, so as to determine the target training data corresponding to different federated learning training participants based on the target identification code;
[0009] The target training data is input into the first-level federated learning model to obtain initial output data; the initial output data is transmitted to the second-level federated learning model to obtain intermediate output data; the intermediate output data is transmitted to the third-level federated learning model to obtain model parameter data corresponding to the third-level federated learning model.
[0010] Based on the model parameter data and the prediction result data corresponding to the target training data, the first model parameter of the first-level federated learning model, the second model parameter of the second-level federated learning model, and the third model parameter of the third-level federated learning model are adjusted respectively to obtain the trained first-level federated learning model, the second-level federated learning model, and the third-level federated learning model; wherein, the trained first-level federated learning model, the second-level federated learning model, and the third-level federated learning model are used to form the trained federated learning model.
[0011] Optionally, obtaining the target identification code when multiple federated learning training participants train the federated learning model in the first-level trusted execution environment, and determining the target training data corresponding to different federated learning training participants based on the target identification code, includes:
[0012] Within a first-level trusted execution environment, the training dataset of the federated learning training participants is obtained through a first secure communication channel; wherein, the training dataset includes training data with different identification codes, and there is an association between the training dataset of any first-level trusted execution environment and any federated learning training participant;
[0013] The training dataset placed in the first-level trusted execution environment is subjected to intersection operation through the first secure communication channel that connects the first-level trusted execution environments pairwise, so as to obtain the same identification code of each federated learning training participant, and the same identification code is set as the target identification code;
[0014] The training data corresponding to the target identification code in the training dataset of any of the federated learning training participants is determined as the initial training data;
[0015] The initial training data provided by all federated learning training participants is input into the first-level federated learning model corresponding to each of the federated learning training participants to obtain the target training data after training is completed.
[0016] Optionally, before obtaining the training dataset of the federated learning training participants through the first secure communication channel within the first-level trusted execution environment, the method further includes:
[0017] Establish a first public communication channel between any of the federated learning training participants and the first-level trusted execution environment; wherein, the first public communication channel is used for verification between the federated learning training participants and the first-level trusted execution environment;
[0018] When the first-level trusted execution environment meets the first preset verification conditions, the first secure communication channel of the federated learning training participants is established.
[0019] Optionally, before obtaining the target identification code of multiple federated learning training participants during federated learning model training in the first-level trusted execution environment, and determining the target training data corresponding to different federated learning training participants based on the target identification code, the method further includes:
[0020] Establish a second public communication channel between any two federated learning training participants on the first-level trusted execution environment of the computer device; wherein, the second public communication channel is used by the federated learning training participants to transmit verification request information and verification result information;
[0021] When the verification request information and the verification result information meet the second preset verification conditions, a second secure communication channel is established between any two federated learning training participants; wherein, the second secure communication channel is used to transmit the target identification code.
[0022] Optionally, after establishing a second public communication channel between any two federated learning training participants on the first-level trusted execution environment of the computer device, the method further includes:
[0023] Trigger an information location command to verify the information location function of the first-level federated learning model according to the information location command;
[0024] If the information location function meets the preset functional requirements, the first-level federated learning model is determined to have passed the verification.
[0025] Optionally, before obtaining the target identification code of multiple federated learning training participants during federated learning model training in the first-level trusted execution environment, and determining the target training data corresponding to different federated learning training participants based on the target identification code, the method further includes:
[0026] A third public communication channel is established between the computer device and the federated learning server; wherein, the third public communication channel is used by the computer device to verify the third-level trusted execution environment of the federated learning server;
[0027] When the second-level trusted execution environment of the federated learning server meets the third preset verification condition, a third secure communication channel is established between the computer device and the federated learning server; wherein, the third secure communication channel is used to transmit the initial output data and the model parameter data.
[0028] Optionally, before obtaining the target identification code of multiple federated learning training participants during federated learning model training in the first-level trusted execution environment, and determining the target training data corresponding to different federated learning training participants based on the target identification code, the method further includes:
[0029] Verify whether the second-level federated learning model has an irreversible operation layer, and whether the irreversible operation layer runs in the second-level federated learning model;
[0030] After adjusting the first model parameters of the first-level federated learning model, the second model parameters of the second-level federated learning model, and the third model parameters of the third-level federated learning model according to the model parameter data and the prediction result data corresponding to the target training data, to obtain the trained first-level federated learning model, second-level federated learning model, and third-level federated learning model, the method further includes:
[0031] When the second-level federated learning model has the irreversible operation layer and the second-level federated learning model runs the irreversible operation layer, the second model parameters and the third model parameters are sent to any federated learning training participant, and the first model parameters corresponding to any federated learning training participant are determined.
[0032] A second aspect of this application provides a federated learning computing system based on a trusted execution environment, applied to a computer device. The computer device is communicatively connected to a federated learning server. A target federated learning model runs on the computer device and the federated learning server. The federated learning server and the computer device are deployed with a trusted execution environment. The system includes:
[0033] A segmentation unit is used to determine the bottom-level local model in the target federated learning model, set the bottom-level local model as the first-level federated learning model, and segment the upper-level global model into two sub-models using the first irreversible operation layer of the target federated learning upper-level global model as the segmentation point. The first sub-model of the target federated learning upper-level global model is set as the second-level federated learning model, and the second sub-model of the target federated learning upper-level global model is set as the third-level federated learning model. The first irreversible operation layer is the irreversible operation layer with the first ranking in the target federated learning model.
[0034] The deployment unit is used to deploy the first-level federated learning model in the first-level trusted execution environment of the computer device, deploy the second-level federated learning model within the second-level trusted execution environment of the federated learning server, and deploy the third-level federated learning model outside the second-level trusted execution environment of the federated learning server.
[0035] The acquisition unit is used to acquire the target identification code of multiple federated learning training participants when they train the federated learning model in the first-level trusted execution environment, so as to determine the target training data corresponding to different federated learning training participants based on the target identification code.
[0036] The input unit is used to input the target training data into the first-level federated learning model to obtain initial output data; transmit the initial output data to the second-level federated learning model to obtain intermediate output data; and transmit the intermediate output data to the third-level federated learning model to obtain model parameter data corresponding to the third-level federated learning model.
[0037] The adjustment unit is used to adjust the first model parameters of the first-level federated learning model, the second model parameters of the second-level federated learning model, and the third model parameters of the third-level federated learning model according to the model parameter data and the prediction result data corresponding to the target training data, so as to obtain the trained first-level federated learning model, the second-level federated learning model, and the third-level federated learning model; wherein the trained first-level federated learning model, the second-level federated learning model, and the third-level federated learning model are used to form the trained federated learning model.
[0038] The second aspect of this application provides a method for performing the federated learning computation method described in the first aspect.
[0039] A third aspect of this application provides a federated learning computing apparatus based on a trusted execution environment, comprising:
[0040] Central processing unit, memory, input / output interfaces, wired or wireless network interfaces, and power supply;
[0041] The memory is either a short-term storage memory or a persistent storage memory;
[0042] The central processing unit is configured to communicate with the memory and execute instructions in the memory to perform the federated learning computation method described in the first aspect.
[0043] A fourth aspect of this application provides a computer-readable storage medium, characterized in that the computer-readable storage medium includes instructions that, when executed on a computer, cause the computer to perform the federated learning computation method described in the first aspect.
[0044] As can be seen from the above technical solutions, the embodiments of this application have the following advantages: The federated learning computation method based on a trusted execution environment disclosed in this application ensures that the federated learning model can be trained on different devices by partitioning the federated learning model within the trusted execution environment. This allows each federated learning training participant to deploy their model not only on local computing devices but also securely on public cloud servers. Simultaneously, the efficient trusted execution environment improves the efficiency of the federated learning model. Furthermore, model partitioning enables even IoT devices with limited memory and computing power to participate in the federated learning of large models. Attached Figure Description
[0045] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments recorded in this application. For those skilled in the art, other drawings can be obtained based on these drawings.
[0046] Figure 1 This is a schematic diagram of the system architecture of an existing federated learning computation method.
[0047] Figure 2 This is a schematic diagram of the architecture of a federated learning computing system based on a trusted execution environment disclosed in an embodiment of this application;
[0048] Figure 3 This is a schematic diagram illustrating the verification and channel establishment process of a local trusted execution environment as disclosed in an embodiment of this application;
[0049] Figure 4 This is a schematic diagram of a mutual verification process for a local trusted execution environment disclosed in an embodiment of this application;
[0050] Figure 5 This is a schematic diagram of a process for generating local training data disclosed in an embodiment of this application;
[0051] Figure 6 This is a flowchart illustrating a federated learning computation method based on a trusted execution environment disclosed in an embodiment of this application;
[0052] Figure 7 This is a flowchart illustrating another federated learning computation method based on a trusted execution environment disclosed in an embodiment of this application;
[0053] Figure 8 This is a flowchart illustrating another federated learning computation method based on a trusted execution environment disclosed in an embodiment of this application;
[0054] Figure 9 This is a schematic diagram of the structure of a federated learning computing system based on a trusted execution environment disclosed in an embodiment of this application;
[0055] Figure 10 This is a schematic diagram of the structure of a federated learning computing device based on a trusted execution environment disclosed in an embodiment of this application. Detailed Implementation
[0056] It should be noted that the terms "first," "second," "third," "fourth," etc. (if present) in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in a sequence other than that illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0057] It should also be noted that the descriptions involving "first," "second," etc., in this application are for descriptive purposes only and should not be construed as indicating or implying their relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include at least one of that feature. Furthermore, the technical solutions of the various embodiments can be combined with each other, but this must be based on the ability of those skilled in the art to implement them. When the combination of technical solutions is contradictory or impossible to implement, it should be considered that such a combination of technical solutions does not exist and is not within the scope of protection claimed in this application.
[0058] Please see Figure 1 , Figure 1 This is a schematic diagram of the system architecture of an existing federated learning computation method. Specifically, Figure 1The example shown is a federated learning system involving a community hospital, a research institution, and a specialized hospital. Each party has its own private dataset and a local private model that is identical to the global model on the federated learning global server. Figure 1 In this process, each party participating in the computation performs one round of training using its local private dataset and private model. After training, the parameters of the private model are uploaded to the global model located on the federated learning global server, such as... Figure 1 As shown in Figures 1, 1', and 1″. Furthermore, the global model in the federated learning global server aggregates the parameters of the three private models uploaded by the three parties according to a predefined weighted average algorithm, such as... Figure 1 As shown in Figure 2. Secondly, the federated learning global server sends the aggregated and averaged parameters to each participating third party, such as... Figure 1 As shown in Figure 3, the three parties involved in the computation update their local models using the aggregated and averaged parameters received from the global federated learning server. The three parties then use the updated model and their local private datasets for the next round of training. In step 1 of federated learning, the data formats in the private datasets can be categorized into horizontal and vertical federated learning. The specific dataset formats for horizontal or vertical federated learning will not be described in detail here.
[0059] For example: Figure 1 The datasets from community hospitals and specialized hospitals consist of patient medical records. Because both hospitals use the same medical record books, each record has the same format, including patient name, gender, age, diagnosis, and treatment plan. Since the format of each record is identical horizontally, only the data on each side contains different cases (different patients), merging the two private datasets can be done simply by overlaying the records vertically. This federated learning scheme is called horizontal federated learning. Figure 1 Each record in the research institution and each record in the two hospitals have a different format. For example, the research institution and a hospital may contain the same information, such as patient name, gender, and age, but they also contain different information, such as the hospital record containing the diagnosis and treatment plan, while the research institution's record may contain genetic information and virus culture results. Furthermore, both institutions may contain information about a specific patient. For these two institutions, if they need to merge their private datasets, they need to find the specific patient that exists in both institutions, and horizontally combine the information shared by both institutions, such as patient name, gender, and age, with the institution-specific information, such as diagnosis, treatment plan, genetic information, and virus culture results, into a single record. This federated learning scheme is called horizontal federated learning. Figure 1Since the federated learning scheme is horizontal for the two hospitals but vertical for any one hospital and research institution, it is a hybrid of horizontal and vertical federated learning schemes for these three institutions, and is called hybrid federated learning.
[0060] Therefore, to find whether a specific record exists in each party's dataset while ensuring that each party's dataset is invisible to other parties, a special case of secure multi-party computation (MPC), the private sets intersection (PSI) algorithm, is needed. Assuming that each record in each party is represented by the same key value (Key ID), the goal of PSI is to use MPC to find the set of IDs of records existing in all participating parties' datasets while ensuring that each party's dataset is invisible to other parties. Thus, as described above, after finding a specific ID that exists in all datasets, it will be discovered that the record format corresponding to that ID may not be the same in each party's dataset. Figure 1 In contrast, hospital records might contain IDs, names, genders, ages, diagnoses, and treatment plans, while research institution records might contain IDs, names, genders, ages, genetic information, and virus culture results. Due to these different formats, a single deep learning model's input layer cannot be used to accommodate both. Therefore, vertical federated learning requires different processing for different inputs: a bottom-model, unique to each party, handles each party's specific input format, while a common model performs the same computations after the input heterogeneity is resolved. Figure 1 In this model, each party's local model has one more underlying model than the global model on the federated service's global server. During parameter aggregation, the local and global models only need to process the parameters in the global model. Furthermore, because the federated learning server is hosted on a third-party device (such as a public cloud) independent of the participating parties, the parties may not trust this third party. There is a possibility that the intellectual property rights of the models trained using valuable private data provided by each party could be stolen by this third party.
[0061] Therefore, current federated learning schemes are implemented as described above. These implementations have the following problems: 1. Most of these implementations are based on MPC and homomorphic encryption. Furthermore, some schemes also use TEE-based approaches to simulate MPC implementations, placing the entire model into the TEE for training. 2. All participating parties must train their own private models locally. 3. TEE-based approaches simulate MPC implementations by placing the entire model into the TEE for training.
[0062] Therefore, to solve the above problems, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of this application without creative effort are within the scope of protection of this application. Please refer to... Figure 6 , Figure 6 This is a flowchart illustrating a federated learning computation method based on a trusted execution environment (TEE) disclosed in an embodiment of this application. It includes steps 601-605. It should be noted in advance that the technical solution of this application is mainly applied to computer equipment, wherein the computer equipment is communicatively connected to a federated learning server, and the relevant federated learning model runs on both the computer equipment and the federated learning server. TEEs are deployed in both the federated learning server and the computer equipment. For ease of understanding and description, this will not be elaborated further hereafter.
[0063] 601. Determine the bottom-level local model in the target federated learning model, set the bottom-level local model as the first-level federated learning model, and divide the upper-level global model into two sub-models using the first irreversible operation layer of the target federated learning upper-level global model as the dividing point. Set the first sub-model of the target federated learning upper-level global model as the second-level federated learning model, and set the second sub-model of the target federated learning upper-level global model as the third-level federated learning model.
[0064] Specifically, first, the bottom-level local models in the target federated learning model are determined. These bottom-level local models are then set as the first-level federated learning model. Next, the irreversible operation layers of the target federated learning model are determined. Then, using the first irreversible operation layer of the target federated learning's upper-level global model as the dividing point, the upper-level global model is divided into two sub-models. The first sub-model of the upper-level global model is set as the second-level federated learning model, and the second sub-model is set as the third-level federated learning model. It is easy to understand that the first irreversible operation layer is the first irreversible operation layer in the target federated learning model. It should be noted that this embodiment does not restrict the order of the first irreversible operation layer in the target federated learning model. For example, the first irreversible operation layer can be the fifth irreversible operation layer or the first irreversible operation layer in the order of the first irreversible operation layer; specific details are not elaborated here. Then, the second-level federated learning model includes the irreversible operation layers or reversible operation layers preceding the first irreversible operation layer. In the third-level federated learning model, there are either irreversible or reversible operation layers after the first irreversible operation layer; the specifics are not limited here.
[0065] In one specific embodiment, it can also be achieved through a two-level TEE and an irreversible mathematical partitioning of the model. Details will not be elaborated here.
[0066] 602. Deploy the first-level federated learning model within the first-level trusted execution environment of the computer device, deploy the second-level federated learning model within the second-level trusted execution environment of the federated learning server, and deploy the third-level federated learning model outside the second-level trusted execution environment of the federated learning server.
[0067] Based on the description in step 601, the first-level federated learning model is deployed in the first-level trusted execution environment of the computer device, the second-level federated learning model is deployed within the second-level trusted execution environment of the federated learning server, and the third-level federated learning model is deployed outside the second-level trusted execution environment of the federated learning server.
[0068] In one specific embodiment, specifically: 1. Two-level TEE deployment: a) The first-level TEE is deployed on the private computing devices of the participating parties; b) The second-level TEE is deployed on a third-party federated learning server. 2. The model is segmented into three parts according to the principle of mathematical irreversibility: a) The first part is within the first-level TEE; b) The second part is within the second-level TEE; c) The third part completes the computation of the remaining part of the model outside the federated server TEE. The first-level TEE takes the private datasets of each party as input and completes the PSI operation of MPC. The result of the PSI operation (vertical type) or the local private dataset is used as the input for the first part of the model segmentation, and the result of the first part is used as the output. The second-level TEE takes the output of the first-level TEE as input, completes the computation of the second part of the model segmentation, and the result of the first part is used as the output. The federated learning server uses local computing resources (CPU or GPU) to complete the computation of the remaining third part of the model.
[0069] Furthermore, see below. Figure 2 , Figure 2 This is a schematic diagram of the architecture of a federated learning computing system based on a trusted execution environment, as disclosed in an embodiment of this application. Specifically,
[0070] 1. A Level 1 Trusted Execution Environment (TEE) on the local computing environment (computer device). Each party participating in federated computing creates such a TEE on its local computing environment. This TEE contains: (a) a PSI operation to find a set of identical key value IDs used to find the same key value IDs from each party's dataset; Figure 2The common IDs are ID1, ID2, and ID3. The name PSI is retained, but since PSI calculations are performed within the local TEE, its algorithm can directly use general mathematical intersection operations instead of the MPC PSI implementation, thus achieving higher efficiency. Because each party's PSI needs to compare its own IDs with all other parties' IDs, all PSI modules within the TEE environment should have network communication capabilities with other PSI modules. (b) After the PSI completes the search for common IDs, each party needs to find the detailed data records corresponding to these common IDs in its local dataset. Figure 2 In the process, PSI found three common ID values (ID1, ID2, and ID3) in the three-party dataset. Each party found three records corresponding to these three IDs in its local records, such as... Figure 4 As shown, the data format and value of the specific records found by each party may be different. (c) Take the record corresponding to the common ID in each party's local record as input and perform the calculation of the underlying model in this example.
[0071] 2. A second-level Trusted Execution Environment (TEE) on the federated learning server environment. This TEE is globally unique. It contains one or more layers of the global model header. The specific division within the global model should adhere to the principle of irreversible data computation. This TEE takes the outputs of all participants in the federated learning process as input, executes the computation of one or more layers of the model header, and outputs the result of the last layer.
[0072] 3. External Execution Environment on the Federated Learning Server Environment: This environment computes all layers of the global model except for the header layer or more contained in the Level 2 Trusted Execution Environment (TEE). Typically, to improve performance, this external execution environment can be a CPU or any accelerated computing device such as a graphics processing unit (GPU), a field-programmable gate array (FPGA), or an application-specific integrated circuit (ASIC).
[0073] To protect the local data of each party, if the underlying model of a party within the Level 1 Trusted Execution Environment (TEE) does not contain irreversible operations, thus allowing the input of that party to be derived from the output of the Level 1 TEE, the global model can be divided into three parts according to the principle of mathematical irreversibility. The first part, combined with the underlying model of each party, is placed in the Level 1 TEE; the second part is placed in the Level 2 TEE; and the third part is executed in the external environment. In summary, the Level 1 federated learning model can be understood as a sub-model of the target federated learning model, while the Level 2 and Level 3 federated learning models can be understood as two partitions or divisions of the target federated learning model.
[0074] It is not difficult to understand that, by Figure 2 As we can see, Norm, Multi-HeadAttention, and MLP in the second-level trusted execution environment are all irreversible operations and can all serve as dividing lines. Similarly, this dividing line can also be at any layer within any subsequent dividing line. The specific division depends on the user's need for a balance between security and performance. In short, the more computations placed in the trusted execution environment, the more secure it is. Conversely, the more computations placed outside the feasible execution environment, the better the performance.
[0075] Since the calculation result of the first MLP layer in the communication data between the two parts is O = σ(M×X+B), this operation is an irreversible layer when M is irreversible.
[0076] Therefore, based on the above Figure 2 As described above, the technical solution of this application mainly provides an efficient multi-level TEE implementation scheme for large-scale model federated computing based on trusted execution environment and irreversible operation on an untrusted server. Therefore, the participants in this scheme are divided into three roles:
[0077] 1. Untrusted server platform provider: This platform provider is typically a public cloud provider or a private cloud belonging to a participant in a federated computing model training process. It provides the hardware (computing resources, network resources, and storage resources) and software (operating system, software execution environment such as Python, model training framework such as TensorFlow, PyTorch, or a third-party training framework) required for training large models. This model training framework must provide the ability to split the entire model and deploy it independently; alternatively, the provider of the patented solution described below can develop the model independently using the development interface provided by the model training framework. The splitting and independent deployment of the model is not within the technical scope described in this patent.
[0078] 2. Solution Provider: The solution provider provides all the common implementations in the solution, allowing other participants to focus only on their specific business without needing to concern themselves with the implementations of these common computations. These common implementations include: (a) In the first-level TEE: i. the implementation of PSI computation, as well as mutual verification and communication; ii. locating the corresponding record in the local training data based on the PSI computation result ID; iii. inputting the found record into the local model provided by the computation participant. (b) Providing the implementation of verification for each level of TEE. (c) Providing data communication and exchange between each level of TEE and between the TEE and external systems. (d) Dividing the model provided by the computation participant according to the principle of mathematical irreversibility and deploying the division to the corresponding TEE computation environments at each level.
[0079] 3. Federated Computing Model Participants (Federated Learning Training Participants): Due to the existence of untrusted server platform providers and solution providers, federated computing model participants can focus solely on the data and how to define the model itself, without needing to consider the details of the federated computing implementation. Specifically, this includes: (a) how to define their own training dataset format (ID and training data records) according to the patent solution provider's PSI computing implementation; and (b) how to define the underlying model suitable for the local data format. Due to different applications, the definition of the local underlying model will vary greatly, and how to define the local underlying model and input the outputs of the underlying models of each federated computing model participant into the public model will also change with the specific application.
[0080] For ease of understanding and description, this will not be elaborated upon further.
[0081] 603. Obtain the target identification code when multiple federated learning training participants train the federated learning model in the first-level trusted execution environment, so as to determine the target training data corresponding to different federated learning training participants based on the target identification code.
[0082] As shown in step 602, to facilitate the training of the federated learning model in this embodiment and to obtain the training results corresponding to the data of the federated learning training participants, the federated learning training participants can provide the corresponding target training data to the computer device through a secure communication channel. It is easy to understand that the target training data is used to train the first-level federated learning model in the first-level trusted execution environment deployed on the computer device. The target training data includes training data with the same target identification code from different federated learning training participants.
[0083] In one specific embodiment, after all federated learning training participants and their respective Level 1 or Level 2 TEE environments have passed security verification, a secure communication channel between the federated learning training participants and the computer equipment can be established. It is easy to understand that, in this embodiment, this secure communication channel can also be understood as a communication channel through which federated learning training participants transmit training data to the target federated learning model. Specific limitations on the secure communication channel are not specified here, and will not be elaborated further.
[0084] 604. Input the target training data into the first-level federated learning model to obtain the initial output data; transfer the initial output data to the second-level federated learning model to obtain the intermediate output data; transfer the intermediate output data to the third-level federated learning model to obtain the model parameter data corresponding to the third-level federated learning model.
[0085] After dividing the second-level and third-level federated learning models, the target federated learning model can be trained. Specifically, the target training data provided by the federated learning training participants is first obtained, and then the target training data is input into the first-level federated learning model to obtain the initial output data; the initial output data is then transferred to the second-level federated learning model to obtain the intermediate output data; and the intermediate output data is then transferred to the third-level federated learning model to obtain the model parameter data corresponding to the third-level federated learning model.
[0086] In one specific embodiment, after the target training data is input into the underlying local model in the first-level trusted execution environment, the underlying local model trains on the target training data to obtain initial output data. Then, the computation layer in the second-level trusted execution environment performs calculations on the initial output data to obtain intermediate output data. The target training data can be medical data or public security data containing corresponding IDs, as described above; the specific content of the target training data is not limited here. After obtaining the intermediate output data, it is transmitted to the computation layer outside the second-level trusted execution environment to obtain model parameter data. This is, as is easily understood, the computation layer on the GPU. Furthermore, in this embodiment, the model parameter data can be understood as the result data after calculation of the target training data in the federated computing global server; details are not elaborated here.
[0087] 605. Based on the model parameter data and the prediction results corresponding to the target training data, adjust the first model parameters of the first-level federated learning model, the second model parameters of the second-level federated learning model, and the third model parameters of the third-level federated learning model respectively to obtain the trained first-level federated learning model, second-level federated learning model, and third-level federated learning model.
[0088] After obtaining the model parameter data, the first model parameters of the first-level federated learning model, the second model parameters of the second-level federated learning model, and the third model parameters of the third-level federated learning model are adjusted according to the model parameter data and the prediction results corresponding to the target training data. This results in the trained first-level, second-level, and third-level federated learning models, thus obtaining the trained federated learning model. It should be noted that the adjustment order should be understood as adjusting the third model parameters, then the second model parameters, and finally the first model parameters in sequence. It is easy to understand that the training results of the target training data can be predicted in advance to obtain the prediction results. For example, when using medical data or public security data corresponding to an ID as the target training data, the prediction results could be medical diagnosis results or related contact results corresponding to a specific person. No specific restrictions are placed on the specific prediction results here. The trained first-level, second-level, and third-level federated learning models can be used to form the trained federated learning model.
[0089] In one specific embodiment, the model parameters of the second-level federated learning model and the third-level federated learning model are first adjusted using model parameter data and prediction result data. Then, the adjusted second-level federated learning model and the third-level federated learning model are obtained. The result data corresponding to the second-level federated learning model, calculated by backpropagation gradient, is then input into the first-level federated learning model to adjust the model parameters of the first-level federated learning model. This process continues until the prediction result data matches or converges with the model parameter data in subsequent training, at which point the training of the federated learning model can be considered complete.
[0090] In another specific embodiment, multiple sets of training data can be input into the second-level federated learning model and the third-level federated learning model until all training data has been trained, at which point the federated learning model is considered to have completed training.
[0091] This embodiment discloses a federated learning computation method based on a trusted execution environment (TEA). By partitioning the federated learning model within the TEA, it ensures that the model can be trained on different devices. This allows each participant in the federated learning training to deploy their model not only to local computing devices but also securely to public cloud servers. Simultaneously, the efficient TEA improves the efficiency of the federated learning model. Furthermore, model partitioning enables even memory- and computing-limited devices like IoT devices to participate in the federated learning of large models.
[0092] For the convenience of understanding the above Figure 6 For a detailed description of the federated learning computation method described in [the document], please refer to [the document / reference]. Figure 7 , Figure 7 This is a flowchart illustrating another federated learning computation method based on a trusted execution environment disclosed in an embodiment of this application. It includes steps 701-710. It should be noted that... Figure 7 The described technical solution requires a detailed description of the verification method for the federated learning model deployed in a trusted execution environment.
[0093] 701. Determine the bottom-level local model in the target federated learning model, set the bottom-level local model as the first-level federated learning model, and divide the upper-level global model into two sub-models using the first irreversible operation layer of the target federated learning upper-level global model as the dividing point. Set the first sub-model of the target federated learning upper-level global model as the second-level federated learning model, and set the second sub-model of the target federated learning upper-level global model as the third-level federated learning model.
[0094] 702. Deploy the first-level federated learning model within the first-level trusted execution environment of the computer device, deploy the second-level federated learning model within the second-level trusted execution environment of the federated learning server, and deploy the third-level federated learning model outside the second-level trusted execution environment of the federated learning server.
[0095] In this embodiment, steps 701-702 are the same as those described above. Figure 6 Steps 601-602 are similar and will not be elaborated here.
[0096] 703. Establish a first public communication channel between any federated learning training participant and the first-level trusted execution environment, so that when the first-level trusted execution environment meets the first preset verification conditions, a first secure communication channel is established between the federated learning training participants.
[0097] Before federated learning participants provide local training data to all local Level 1 trusted execution environments, the local Level 1 trusted execution environments also need to be verified. Specifically, a first common communication channel is established between any federated learning training participant and the Level 1 trusted execution environment. When the Level 1 trusted execution environment meets a first preset verification condition, a first secure communication channel is established between the federated learning training participants and the Level 1 trusted execution environment. This first common communication channel is used for verification between the federated learning training participants and the Level 1 trusted execution environment.
[0098] In one specific embodiment, to increase system flexibility, considering that some federated learning training participants may lack the capability to build their own local underlying local model training capabilities, it is also necessary to deploy the Level 1 Trusted Execution Environment (TEE) to a third party, such as a public cloud. Therefore, by establishing a public communication channel between any federated learning training participant and the Level 1 TEE, the underlying local model on the Level 1 TEE can be verified. When the underlying local model meets the relevant design requirements, such as whether it can complete data structure adjustments and data combinations, no specific design requirements are limited here. It is easy to understand that the design requirements described above are the corresponding first preset verification conditions. Thus, when the underlying local model meets the relevant design requirements, a first secure communication channel can be established.
[0099] 704. Establish a second public communication channel between any two federated learning training participants on the first-level trusted execution environment, so that when the verification request information and verification result information meet the second preset verification conditions, a second secure communication channel is established between any two federated learning training participants.
[0100] It should be noted in advance that in this embodiment, please refer to... Figure 3 , Figure 3 This is a schematic diagram illustrating the verification and channel establishment process of a local trusted execution environment (TEE) disclosed in an embodiment of this application. The local first-level TEE on the computer device includes a PSI mutual verification and communication module, a PSI data query and training set generation module, a second-level TEE verification and communication module, and a local underlying model. Specifically, to verify the local first-level TEE, each of the aforementioned modules and models needs to be verified. Specifically, a second public communication channel is first established between any two federated learning training participants on the trusted execution environment of the computer device. Then, when the verification request information and verification result information meet the second preset verification conditions, the second public communication channel is deleted, and a communication channel key is set to establish a first secure communication channel between any two federated learning training participants based on the communication channel key. It is easy to understand that the second public communication channel is used by the federated learning training participants to transmit verification request information and verification result information.
[0101] In one specific embodiment, please refer to Figure 4 , Figure 4 This is a schematic diagram illustrating the mutual verification process of a local trusted execution environment disclosed in an embodiment of this application.
[0102] Depend on Figure 4As can be seen, the Level 1 TEE environment verification for different federated learning training participants is mainly completed through mutual PSI verification and communication modules between the two parties. Before verification is completed, both parties use a common channel to transmit verification requests and results, i.e., the verification request information and verification result information described above. For example, in this embodiment, parties A, B, and C first perform mutual PSI verification through a second common communication channel. After the verification is complete, the second common communication channel is dismantled, and communication channel keys are set between each pair, thereby establishing a secure encrypted channel based on the communication channel keys, i.e., the first secure communication channel described above. Specifically, the two parties establish a secure encrypted channel and exchange their key value ID fields. This will be described in detail later.
[0103] Furthermore, the main purpose of this verification is to confirm that the PSI data query and training set generation module within the other party's local trusted execution environment truly reads genuine records from the local training dataset according to the key value ID field and submits them to the other party's local model for training, preventing any other party from providing a fake training dataset. It should also be noted that before the first-level TEE environment mutual verification is completed, the network communication between our PSI mutual verification and communication module and the other party's PSI mutual verification and communication module uses a public channel, which is only used for verifying the other party's first-level TEE environment. After our party completes the first-level TEE environment verification for a specific party, the public channel between our party's PSI mutual verification and communication module and the other party's PSI mutual verification and communication module is dismantled, and a secure communication channel (TSL channel) is established. The channel password is automatically maintained by the TEE environment hardware. After completing the first-level TEE environment verification for a specific party, our party's PSI mutual verification and communication module only sends the key value ID field content from the records externally, without including any content from any records.
[0104] 705. Trigger the information location command to verify the information location function of the first-level federated learning model according to the information location command, and determine that the first-level federated learning model has passed the verification when the information location function meets the preset functional requirements.
[0105] Based on the content described in step 704 above, in order to verify the first-level federated learning model, an information location command can be triggered, thereby verifying the information location function of the first-level federated learning model according to the information location command, and when the information location function meets the preset functional requirements, it is determined that the first-level federated learning model has passed the verification.
[0106] In one specific embodiment, to verify whether the first-level federated learning model meets the design requirements, it is necessary to verify the underlying model. Specifically, a specific information location instruction is triggered to receive training data from the PSI data query and training set generation module, thereby verifying the relevant location function. If the location function is verified successfully, the first-level federated learning model is determined to have passed verification.
[0107] Furthermore, during the verification process of the PSI data query and training set generation module, the PSI data query and training set generation module is executed only after step 703 is completed. Specifically, this module only receives the key value ID field content from its own PSI mutual verification and communication module, and automatically extracts records that match the key value ID field content from its own local data based on the key value ID field content, and provides them to the local underlying model.
[0108] 706. Establish a third public communication channel between the computer equipment and the federated learning server, so that when the trusted execution environment of the federated learning server meets the third preset verification conditions, a third secure communication channel is established between the computer equipment and the federated learning server.
[0109] After completing the above verifications, it is necessary to verify the interaction between the federated learning training participants and the second-level federated learning model on the federated learning server. Specifically, a third common communication channel is first established between the computer device and the federated learning server. Then, when the trusted execution environment of the federated learning server meets the third preset verification conditions, a third secure communication channel is established between the computer device and the federated learning server. It should be noted that the third common communication channel is used by the computer device to verify the trusted execution environment of the federated learning server, while the third secure communication channel is used to transmit target training data and model parameter data.
[0110] In one specific embodiment, step 706 primarily involves verifying the local Level 2 TEE and related communication modules. Specifically, firstly, a public channel (i.e., the third public communication channel described above) is established between the Level 2 TEE verification and communication module and the federated learning server. This channel is used only for verifying the Level 2 TEE environment on the federated learning server. Then, after verifying the Level 2 TEE environment on the federated learning server, the public channel transmission between the module and the federated learning server is discontinued, and a secure communication channel (TSL channel) is established, i.e., the third secure communication channel described above. The channel password for this communication channel, i.e., the second communication channel key described above, is automatically maintained by the hardware of both TEE environments.
[0111] Furthermore, after verifying the second-level TEE environment on the federated learning server, this module only receives results sent from the local underlying model and transmits them to the second-level TEE environment via a relevant encrypted channel. Simultaneously, it can also receive backpropagation gradients sent from the second-level TEE environment via an encrypted channel and send them to the local underlying model. For ease of understanding, this will be described in detail later. It is not difficult to understand that, in one feasible technical solution, the third preset verification condition can be understood as verifying whether the federated learning server is properly deployed with a trusted execution environment, or whether the corresponding federated learning model is properly configured, etc.
[0112] 707. Verify whether the second-level federated learning model has an irreversible operation layer, and whether the irreversible operation layer runs on the second-level federated learning model. When the second-level federated learning model has an irreversible operation layer and runs on the second-level federated learning model, send the second model parameters and the third model parameters to any federated learning training participant, and determine the first model parameters corresponding to any federated learning training participant.
[0113] After the above verification is completed, it is necessary to verify whether the second-level federated learning model has an irreversible operation layer, and whether the irreversible operation layer is running on the second-level federated learning model. When the second-level federated learning model has an irreversible operation layer and the second-level federated learning model is running an irreversible operation layer, the first model parameters, the second model parameters, and the third model parameters are sent to any federated learning training participant through a secure communication channel.
[0114] In one specific embodiment, step 707 can only be performed after the verification in steps 703-706 above is completed. Specifically, it verifies the federated learning training participants' understanding of the secondary TEE environment on the federated learning server. Further, this verification can be completed through the secondary TEE verification and communication module within the local primary TEE execution environment. The verification content specifically includes: verifying that the mathematical irreversible operations performed on the sub-models within the secondary TEE environment on the federated learning server are indeed correct; and verifying that the secondary TEE environment on the federated learning server only sends the model parameters within the environment to each federated learning training participant, and not to any other third party (including writing to the local file system).
[0115] In another specific embodiment, the verification can also be performed concurrently with step 703 to improve efficiency; no specific restrictions are imposed here.
[0116] 708. Obtain the target identification code when multiple federated learning training participants train the federated learning model in the first-level trusted execution environment, so as to determine the target training data corresponding to different federated learning training participants based on the target identification code.
[0117] 709. Input the target training data into the first-level federated learning model to obtain the initial output data; transfer the initial output data to the second-level federated learning model to obtain the intermediate output data; transfer the intermediate output data to the third-level federated learning model to obtain the model parameter data corresponding to the third-level federated learning model.
[0118] 710. Based on the model parameter data and the prediction results corresponding to the target training data, adjust the first model parameters of the first-level federated learning model, the second model parameters of the second-level federated learning model, and the third model parameters of the third-level federated learning model respectively to obtain the trained first-level federated learning model, second-level federated learning model, and third-level federated learning model.
[0119] In this embodiment, steps 708-710 are the same as those described above. Figure 6 Steps 603-605 are similar and will not be described in detail here. However, it should be noted that in this embodiment, [the process involves...]. Figure 7 As can be seen from the above description of the steps, in this embodiment, during a training process, the target training data is only the training data corresponding to one specific target identification code.
[0120] In one specific embodiment, after the underlying model in the first-level federated learning model completes its forward computation, the result is sent to the sub-model within the second-level federated learning server via the verification and communication module of the second-level TEE in the local first-level TEE. After completing its forward computation, the second-level federated learning model within this second-level TEE sends the computation result to the third-level federated learning model outside the second-level TEE, completing the forward computation of the entire global model. The gradient transfer process for backward computation is the reverse of the forward computation data flow described above, and will not be elaborated further.
[0121] Furthermore, when model training is complete or when training results need to be cached, the model parameters within the secondary TEE are sent to each federated learning training participant, who is responsible for storing them instead of saving them locally. Model parameters outside the secondary TEE can be stored or cached on the local file system of the federated learning server, as described in step 706.
[0122] This embodiment discloses a federated learning computation method based on a Trusted Execution Environment (TEE). By performing model partitioning within the TEE, it ensures that large models can be trained on different devices. This allows each federated learning training participant to deploy their model not only on local private computing devices but also securely on the public cloud. Furthermore, model partitioning enables even memory- and computing-limited devices like IoT devices to participate in federated learning of large models. Each federated learning training participant only needs to run a very small local underlying model; the cumbersome calculations and extensive computations are completed on the federated learning server with ample memory and computing resources. This contrasts with traditional federated learning, where model computation is performed on local devices with limited memory and computing power, and the federated learning server only handles parameter reception, aggregation, and synchronization. Secondly, it improves the efficiency of large models in federated learning. Specifically, it achieves secure multi-party computation through an efficient TEE instead of inefficient methods such as homomorphic encryption. The TEE only runs one or two very small parts of the model, unlike traditional federated learning which performs extremely inefficient MPC computations or homomorphic encryption on all layers. Finally, by protecting the model's header parameters, we can prevent third parties from stealing the intellectual property rights of the trained model.
[0123] Furthermore, for the convenience of understanding the above... Figure 6 or Figure 7 For a detailed description of how to adjust the model parameters, please refer to [link / reference]. Figure 8 , Figure 8 This is a flowchart illustrating another federated learning computation method based on a trusted execution environment disclosed in an embodiment of this application. It includes steps 801-807.
[0124] 801. Within the first-level trusted execution environment, the training dataset of the federated learning training participants is obtained through the first secure communication channel. The training dataset placed in the first-level trusted execution environment is then subjected to intersection operation through the first secure communication channel that connects the first-level trusted execution environments pairwise to obtain the same identification code for each federated learning training participant. The same identification code is then set as the target identification code.
[0125] It is not difficult to understand that, Figure 8 Specifically, this refers to a detailed step corresponding to step 603 or step 708. Specifically, the training datasets of all federated learning training participants can be obtained through the first secure communication channel. The training datasets placed in the trusted execution environment are then subjected to intersection operations, and the same identification code from different federated learning training participants is set as the target identification code. The training dataset includes training data with different identification codes, and there is a correlation between the training dataset of any first-level trusted execution environment and the training dataset of any federated learning training participant. It is easy to understand that the identification code is the key value ID described above.
[0126] In one specific embodiment, see [reference] Figure 4 Based on steps 703 to 704 for Figure 4 The description, in Figure 7 Once the communication channel verification is complete, PSI operations can be used to find the datasets of each federated learning training participant from the secure communication channel, thereby identifying the set of participants with the same key value ID. Based on Figure 4 As can be seen, different key values are represented by three ID values: ID1, ID2, and ID3. In this embodiment, the PSI name is retained. Furthermore, since the PSI calculation is performed within the TEE environment of the local computer device, a general mathematical intersection operation can be directly used without employing the MPC PSI implementation, thus improving efficiency. Because each party's PSI needs to compare its own IDs with all other parties' IDs, all PSI modules within the TEE environment should have network communication capabilities with other PSI modules. After the PSI completes the search for common IDs, each federated learning training participant needs to find the detailed data records corresponding to these common IDs in their local dataset. Therefore, the IDs of the data to be acquired can be set as the target identifier.
[0127] 802. Determine the training data corresponding to the target identification code in the training dataset of any federated learning training participant as the initial training data.
[0128] Therefore, based on the target identification code found in step 801, the training data corresponding to the target identification code in the training dataset of any federated learning training participant needs to be determined as the initial training data.
[0129] In one specific embodiment, at Figure 4 In the process, PSI found three common ID values (ID1, ID2, and ID3) in the three-party dataset. Each federated learning training participant found three records corresponding to these three IDs in their local records. Furthermore, as... Figure 4 As shown, the data format and values of the specific records found by each federated learning training participant may be different. Therefore, the training data corresponding to the target identification code can be set as the initial training data.
[0130] For example, in the dataset of each federated learning training participant, the data corresponding to ID1 (with the relevant data format and value) will be set as the initial training data.
[0131] Furthermore, in one specific embodiment, please refer to Figure 5 , Figure 5 This is a schematic diagram illustrating a process for generating local training data as disclosed in an embodiment of this application. Specifically, after completing the above... Figure 7Various verifications in the process.
[0132] Furthermore, based on the initial training data found in step 802, the data structure of the first training data of the first federated learning training participant is adjusted, and the data structure of the second training data of the second federated learning training participant is adjusted to obtain intermediate training data with the same data structure. Then, the intermediate training data corresponding to the first or second federated learning training participant are combined to obtain the target training data. Specifically, the initial training data of all federated learning training participants is input into the first-level federated learning model to obtain the target training data after training.
[0133] In one specific embodiment, the record corresponding to the common ID in the local records of each federated learning training participant is used as input to perform calculations on the underlying model of this example. Specifically, for example, the first federated learning training participant is a community hospital and a specialist hospital, since their data corresponding to ID1 consists of the medical records of patients. The format of the data of the first federated learning training participant includes patient name, gender, age, diagnosis, and treatment plan. The second federated learning training participant is a research institution, whose data corresponding to ID1 may have some similarities to the data of the first federated learning training participant, such as patient name, gender, and age, but also contains different information. For example, hospital records may also include diagnosis and treatment plan, while research institutions may include genetic information and virus culture results. Therefore, it is necessary to adjust the data structure of the data corresponding to ID1 in either the first or second federated learning training participant to obtain training data with the same data structure. This training data is then placed in the underlying model for combination and arrangement to obtain the target training data. In other words, it can be understood that three rows of data from the first federated learning training participant and two rows of data from the second federated learning training participant are needed. The corresponding three rows of data and two rows of data are combined to obtain the final five rows of data, which is the target training data.
[0134] 803. Input the target training data corresponding to the target identification code into the second-level federated learning model to obtain intermediate output data, and then transfer the intermediate output data to the third-level federated learning model to obtain the training result data corresponding to the third-level federated learning model.
[0135] In this embodiment, step 803 is the same as described above. Figure 6Step 604 is similar and will not be elaborated here. However, it should be noted that after obtaining the target training data corresponding to the target identification code, the target training data can be input into the second-level federated learning model through a secure communication channel to obtain the intermediate output data of the second-level federated learning model. Then, the intermediate output data is transmitted to the third-level federated learning model to obtain the model parameter data corresponding to the third-level federated learning model.
[0136] 804. Determine the ranking order of all irreversible operation layers in the third-level federated learning model, and input the training result data and prediction result data into all irreversible operation layers of the third-level federated learning model according to the reverse order of the ranking order, obtain the first loss function value corresponding to the third irreversible operation layer, and adjust the second model parameters according to the first loss function value.
[0137] When the model parameter data output by the third-level federated learning model is obtained, the ranking order of all irreversible operation layers in the third-level federated learning model can be determined simultaneously. Then, according to the order opposite to the ranking order, the model parameter data and prediction result data are input to all irreversible operation layers of the third-level federated learning model to obtain the first loss function value corresponding to the third irreversible operation layer, and the second model parameters are adjusted according to the first loss function value.
[0138] In one specific embodiment, when the second model parameters of the second-level federated learning model are adjusted, after the intermediate output data is transmitted to the third-level federated learning model deployed in an untrusted execution environment, it is necessary to determine the ranking order of all irreversible operation layers in the third-level federated learning model. Then, according to the reverse order of the ranking order, the model parameter data and prediction result data are input to all irreversible operation layers of the third-level federated learning model, thereby obtaining the first loss function value corresponding to the irreversible operation layer. It is easy to understand that this first loss function value is the loss function value of the irreversible operation layer in the third-level federated learning model whose ranking order is the first layer. It is also easy to understand that the prediction result data described in this embodiment can be found in [reference needed]. Figure 6 The details of step 605 are not elaborated here.
[0139] In one specific embodiment, the loss function value of the third-level federated learning model can be determined based on model parameter data and prediction result data. Then, the backward gradient descent algorithm is performed on all irreversible layers of the third-level federated learning model to obtain the first loss function value. After obtaining the first loss function value, the second model parameters can be adjusted to obtain the trained second-level federated learning model.
[0140] In one specific embodiment, after adjusting the second model parameters using the first loss function value, training data provided by the federated learning training participants can be received. If the model parameter data generated by the training data is the same as the prediction result data, or if the intermediate output data generated based on the initial training data converges, then the training of the second-level federated learning model can be determined to be complete.
[0141] Based on the above embodiments, in another specific embodiment, after the various computational layers in the trusted execution environment have completed the parameter update, they read in the next training data, and so on, to complete the training of the entire model.
[0142] 805. According to the reverse order of ranking, the training result data and prediction result data are sequentially transmitted to all irreversible operation layers of the third-level federated learning model to obtain the second loss function value corresponding to each irreversible operation layer, so as to adjust the third model parameters of the irreversible operation layer corresponding to each second loss function value.
[0143] When adjusting the third model parameters of the third-level federated learning model, the model parameter data and prediction result data are sequentially transmitted to all irreversible operation layers of the third-level federated learning model in reverse order of ranking, obtaining the second loss function value corresponding to each irreversible operation layer. It is easy to understand that, in this embodiment, each irreversible operation layer in the third-level federated learning model can be understood as an operation layer composed of model parameters. Therefore, by transmitting the model parameter data and prediction result data sequentially from the top layer to the first irreversible operation layer in the third-level federated learning model in reverse order of ranking, the second loss function value of each irreversible operation layer can be determined.
[0144] In one specific embodiment, the loss function value of the third-level federated learning model can be determined based on model parameter data and prediction result data. Then, the backward gradient descent algorithm is executed on all irreversible operation layers in the third-level federated learning model based on this loss function value. The loss function value is first input to the last irreversible operation layer in the third-level federated learning model to determine the actual result value and prediction result value of the last irreversible operation layer, thereby determining the loss function value of that irreversible operation layer. This process is repeated sequentially from the last layer to the first layer in the third-level federated learning model to determine the second loss function value of an irreversible operation layer.
[0145] Based on the above steps, whenever the second loss function value is determined, the third model parameters of the irreversible operation layer corresponding to the second loss function value can be adjusted accordingly, thereby obtaining the trained third-level federated learning model.
[0146] In one specific embodiment, based on the second loss function value of each irreversible operational layer, the third model parameters of that irreversible operational layer are adjusted, so that the operation results of that irreversible operational layer gradually converge to or approach the prediction results data of each layer. When the above conditions are met, the training of the third-level federated learning model is determined to be complete.
[0147] 806. According to the reverse order of ranking, the training result data and prediction result data are transmitted sequentially to all irreversible operation layers of the third-level federated learning model to obtain the second loss function value corresponding to each irreversible operation layer, so as to adjust the first model parameters of the irreversible operation layer corresponding to each second loss function value.
[0148] Based on the above steps, the model parameter data can be input back into the third-level federated learning model in reverse order of ranking. The data output from the third-level federated learning model is then input into the second-level federated learning model to obtain the target result data output by the second-level federated learning model. Next, the target result data and related prediction result data are transmitted to all irreversible operation layers of the first-level federated learning model to obtain the third loss function value corresponding to the irreversible operation layer. Based on the third loss function value, the first model parameters of the irreversible operation layer corresponding to the third loss function value are adjusted.
[0149] In one specific embodiment, after the second-level federated learning model transmits the target result data to the first-level federated learning model of the first-level TEE through a secure communication channel, all irreversible operation layers in the first-level federated learning model perform backward gradient calculation on the target result data. The calculated result data is then compared with the relevant prediction result data to obtain the third loss function value corresponding to all irreversible operation layers in the first-level federated learning model. Thus, the first model parameters of the first-level federated learning model can be adjusted according to the third loss function value.
[0150] In one specific embodiment, the first model parameters of the irreversible operation layer of the first-level federated learning model are adjusted according to the third loss function value, so that the operation results of the irreversible operation layer gradually converge to or approach the prediction results data of each layer. When the above conditions are met, it is determined that the training of the first-level federated learning model is complete.
[0151] 807. Send the second model parameters and the third model parameters to any federated learning training participant, and determine the first model parameters corresponding to any federated learning training participant.
[0152] Specifically, in this embodiment, step 807 is the same as described above. Figure 7Similar to step 710, specifically, when the federated learning model completes training or when training results need to be cached, the second-level federated learning model within the second-level TEE sends its second-level model parameters to all federated learning training participants (a one-to-one correspondence is required). Each participant is responsible for saving these parameters instead of storing them locally. Model parameters outside the second-level TEE (e.g., the third-level federated learning model on the GPU) can be saved or cached on the local file system of the federated learning server. It is easy to understand that this embodiment does not restrict the specific storage method of model parameters, and this will not be elaborated further later.
[0153] based on Figure 6 and Figure 7 The described technical solution, in the federated learning computation method based on a trusted execution environment disclosed in this embodiment, can be further extended to federated learning of any model, and correspondingly, it can also be extended to inference applications related to federated learning, without specific limitations here. Furthermore, by modifying the model parameters of the federated learning model in real time and then returning the modified model parameters to each federated learning training participant, the solution is secure even if each participant deploys their local model on a public cloud rather than on a local private computing device, thus improving the feasibility of the solution.
[0154] Furthermore, in combination with the above Figures 6 to 8The technical solution addresses the protection of private training data for each federated learning participant as follows: Private training data between the federated learning participant and its local Level 1 TEE is transmitted via an encrypted channel, ensuring secure transmission. All components within the local Level 1 TEE of each federated learning participant have undergone functional verification by the participant. These modules, except for exchanging key value IDs with the outside world, do not expose any other private data fields outside the local Level 1 TEE. Therefore, the private training data of each federated learning participant is secure within the local Level 1 TEE. Data transmission between the local Level 1 TEE of the federated learning participant and the Level 2 TEE of the federated learning server is also via an encrypted channel, ensuring the security of the underlying model's results. Furthermore, since the operations of the underlying model are irreversible, it is impossible to deduce the data in the private dataset from the results of the underlying model. If the underlying model cannot guarantee irreversible final results (e.g., in horizontal federated computation, where the underlying model merely copies the original input), the global model can be partitioned at a point of irreversible data operation. The first partition can then be placed within the local Level 1 TEE and merged with the local underlying model, thus ensuring the irreversibility of operations within the local Level 1 TEE. Regarding the protection of intellectual property rights for the final trained model parameters, since the model operations in the second-level TEE of the federated learning server are irreversible, the parameters of the model cannot be derived from the results of the second-level TEE. These parameters are only sent to each federated learning training participant via an encrypted channel for safekeeping; the federated learning server does not have a local backup of this data. Therefore, even if the third party providing the federated learning server stores the parameters of the sub-models running outside the second-level TEE environment, the third party cannot recover the parameters of the head model by fine-tuning the training to obtain the parameters of the last one or two layers of the tail model (fine-tuning can only keep the head model parameters unchanged to obtain the parameters of the last one or two layers of the tail model). Therefore, to recover the parameters of all layers of the model, the third party would have to retrain the entire model using the private data of each federated learning training participant. From the above analysis, it is clear that it is impossible for a third party to obtain the private training data of each federated learning training participant free of charge through security vulnerabilities.
[0155] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0156] Please see Figure 9 , Figure 9 This is a schematic diagram of the structure of a federated learning computing system based on a trusted execution environment disclosed in an embodiment of this application.
[0157] The segmentation unit 901 is used to determine the bottom local model in the target federated learning model, set the bottom local model as the first-level federated learning model, and divide the target federated learning model into a second-level federated learning model and a third-level federated learning model with the first irreversible operation layer of the target federated learning model as the segmentation point; wherein, the first irreversible operation layer is the irreversible operation layer in the target federated learning model that ranks first.
[0158] Deployment unit 902 is used to determine the bottom-level local model in the target federated learning model, set the bottom-level local model as the first-level federated learning model, and divide the upper-level global model into two sub-models using the first irreversible operation layer of the target federated learning upper-level global model as the dividing point. The first sub-model of the target federated learning upper-level global model is set as the second-level federated learning model, and the second sub-model of the target federated learning upper-level global model is set as the third-level federated learning model. The first irreversible operation layer is the irreversible operation layer that ranks first in the target federated learning model.
[0159] The acquisition unit 903 is used to acquire the target identification code when multiple federated learning training participants train the federated learning model in the first-level trusted execution environment, so as to determine the target training data corresponding to different federated learning training participants based on the target identification code.
[0160] The input unit 904 is used to input the target training data into the first-level federated learning model to obtain the initial output data; to transmit the initial output data to the second-level federated learning model to obtain the intermediate output data; and to transmit the intermediate output data to the third-level federated learning model to obtain the model parameter data corresponding to the third-level federated learning model.
[0161] The adjustment unit 905 is used to adjust the first model parameters of the first-level federated learning model, the second model parameters of the second-level federated learning model, and the third model parameters of the third-level federated learning model according to the model parameter data and the prediction result data corresponding to the target training data, so as to obtain the trained first-level federated learning model, the second-level federated learning model, and the third-level federated learning model; wherein, the trained first-level federated learning model, the second-level federated learning model, and the third-level federated learning model are used to form the trained federated learning model.
[0162] For example, the system further includes: a setting unit 906 and a determining unit 907;
[0163] The acquisition unit 903 is specifically used to acquire the training dataset of the federated learning training participants through the first secure communication channel within the first-level trusted execution environment; wherein, the training dataset includes training data with different identification codes, and there is a correlation between the training dataset of any first-level trusted execution environment and the training dataset of any federated learning training participant;
[0164] Setting unit 906 is used to perform intersection operation on the training dataset placed in the first-level trusted execution environment through the first secure communication channel that connects the pairs of first-level trusted execution environments, to obtain the same identification code of each federated learning training participant, and set the same identification code as the target identification code.
[0165] The determining unit 907 is used to determine the training data corresponding to the target identification code in the training dataset of any federated learning training participant as the initial training data;
[0166] Input unit 904 is specifically used to input the initial training data provided by all federated learning training participants into the first-level federated learning model corresponding to each federated learning training participant, so as to obtain the target training data after training is completed.
[0167] For example, the system further includes: a setup unit 908;
[0168] Establishment unit 905 is specifically used to establish a first public communication channel between any federated learning training participant and the first-level trusted execution environment; wherein, the first public communication channel is used for verification between the federated learning training participant and the first-level trusted execution environment;
[0169] The establishment unit 905 is also used to establish a first secure communication channel for the federated learning training participants when the first-level trusted execution environment meets the first preset verification conditions.
[0170] For example, the system also includes:
[0171] Establishment unit 908 is also used to establish a second common communication channel between any two federated learning training participants on the first-level trusted execution environment of the computer device; wherein, the second common communication channel is used by the federated learning training participants to transmit verification request information and verification result information;
[0172] The establishment unit 908 is also used to establish a second secure communication channel between any two federated learning training participants when the verification request information and verification result information meet the second preset verification conditions; wherein, the second secure communication channel is used to transmit the target identification code.
[0173] For example, the system further includes: a verification unit 909;
[0174] Verification unit 909 is used to trigger information location instructions to verify the information location function of the first-level federated learning model according to the information location instructions;
[0175] The determination unit 907 is also used to determine that the first-level federated learning model has passed verification when the information positioning function meets the preset functional requirements.
[0176] For example, the system also includes:
[0177] Establishment unit 908 is also used to establish a third common communication channel between the computer device and the federated learning server; wherein, the third common communication channel is used by the computer device to verify the third-level trusted execution environment of the federated learning server;
[0178] The establishment unit 908 is also used to establish a third secure communication channel between the computer device and the federated learning server when the second-level trusted execution environment of the federated learning server meets the third preset verification conditions; wherein, the third secure communication channel is used to transmit initial output data and model parameter data.
[0179] Exemplarily, the system further includes: a sending unit 910;
[0180] The verification unit 909 is also used to verify whether the second-level federated learning model has an irreversible operation layer and whether the irreversible operation layer runs in the second-level federated learning model.
[0181] The sending unit 910 is used to send the second model parameters and the third model parameters to any federated learning training participant when the second-level federated learning model has an irreversible operation layer and the second-level federated learning model is running an irreversible operation layer, and to determine the first model parameters corresponding to any federated learning training participant.
[0182] Please refer to the following: Figure 10 The schematic diagram of a federated learning computing device based on a trusted execution environment disclosed in this application includes:
[0183] Central processing unit 1001, memory 1005, input / output interface 1004, wired or wireless network interface 1003, and power supply 1002;
[0184] Memory 1005 is either a short-term storage memory or a persistent storage memory;
[0185] The central processing unit 1001 is configured to communicate with the memory 1005 and execute instructions stored in the memory 1005 to perform the aforementioned operations. Figures 6 to 8 Federated learning computation method in any of the embodiments shown.
[0186] This application also provides a chip system, characterized in that the chip system includes at least one processor and a communication interface, the communication interface and the at least one processor are interconnected via a circuit, and the at least one processor is used to run computer programs or instructions to perform the aforementioned... Figures 6 to 8 Federated learning computation method in any of the embodiments shown.
[0187] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0188] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between apparatuses or units through some interfaces, and may be electrical, mechanical, or other forms.
[0189] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0190] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0191] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
Claims
1. A federated learning computation method based on a trusted execution environment, characterized in that, The method, applied to a computer device communicatively connected to a federated learning server, wherein a target federated learning model runs on the computer device and the federated learning server, and the federated learning server and the computer device are deployed with a trusted execution environment, includes: The bottom-level local model in the target federated learning model is determined, and the bottom-level local model is set as the first-level federated learning model. The upper-level global model of the target federated learning model is divided into two sub-models using the first irreversible operation layer as the dividing point. The first sub-model of the upper-level global model of the target federated learning model is set as the second-level federated learning model, and the second sub-model of the upper-level global model of the target federated learning model is set as the third-level federated learning model. The first irreversible operation layer is the irreversible operation layer with the first ranking in the target federated learning model. The first-level federated learning model is deployed in the first-level trusted execution environment of the computer device, the second-level federated learning model is deployed within the second-level trusted execution environment of the federated learning server, and the third-level federated learning model is deployed outside the second-level trusted execution environment of the federated learning server. Obtain the target identification code when multiple federated learning training participants train the federated learning model in the first-level trusted execution environment, so as to determine the target training data corresponding to different federated learning training participants based on the target identification code; wherein, the training dataset of the multiple federated learning training participants includes training data with different identification codes, and the target identification code is the same identification code of the multiple federated learning training participants. The target training data is input into the first-level federated learning model to obtain initial output data; the initial output data is transmitted to the second-level federated learning model to obtain intermediate output data; the intermediate output data is transmitted to the third-level federated learning model to obtain model parameter data corresponding to the third-level federated learning model. Based on the model parameter data and the prediction result data corresponding to the target training data, the first model parameters of the first-level federated learning model, the second model parameters of the second-level federated learning model, and the third model parameters of the third-level federated learning model are adjusted respectively, so that the first-level federated learning model is trained on the computer equipment of the federated learning training participants, and the second-level federated learning model and the third-level federated learning model are obtained on the federated learning server; wherein, the trained first-level federated learning model, the second-level federated learning model, and the third-level federated learning model are used to form the trained federated learning model.
2. The federated learning computation method according to claim 1, characterized in that, The step of obtaining the target identification code when multiple federated learning training participants train the federated learning model in the first-level trusted execution environment, and determining the target training data corresponding to different federated learning training participants based on the target identification code, includes: Within a first-level trusted execution environment, the training dataset of the federated learning training participants is obtained through a first secure communication channel; wherein, any first-level trusted execution environment is associated with the training dataset of any federated learning training participant; The training dataset placed in the first-level trusted execution environment is subjected to intersection operation through the first secure communication channel that connects the first-level trusted execution environments pairwise, so as to obtain the same identification code of each federated learning training participant, and the same identification code is set as the target identification code; The training data corresponding to the target identification code in the training dataset of any of the federated learning training participants is determined as the initial training data; The initial training data provided by all federated learning training participants is input into the first-level federated learning model corresponding to each of the federated learning training participants to obtain the target training data after training is completed.
3. The federated learning computation method according to claim 2, characterized in that, Before obtaining the training dataset of the federated learning training participants through the first secure communication channel within the first-level trusted execution environment, the method further includes: Establish a first public communication channel between any of the federated learning training participants and the first-level trusted execution environment; wherein, the first public communication channel is used for verification between the federated learning training participants and the first-level trusted execution environment; When the first-level trusted execution environment meets the first preset verification conditions, the first secure communication channel of the federated learning training participants is established.
4. The federated learning computation method according to claim 1, characterized in that, Before obtaining the target identification codes of multiple federated learning training participants during federated learning model training in the first-level trusted execution environment, and before determining the target training data corresponding to different federated learning training participants based on the target identification codes, the method further includes: Establish a second public communication channel between any two federated learning training participants on the first-level trusted execution environment of the computer device; wherein, the second public communication channel is used by the federated learning training participants to transmit verification request information and verification result information; When the verification request information and the verification result information meet the second preset verification conditions, a second secure communication channel is established between any two federated learning training participants; wherein, the second secure communication channel is used to transmit the target identification code.
5. The federated learning computation method according to claim 4, characterized in that, After establishing a second public communication channel between any two federated learning training participants on the first-level trusted execution environment of the computer device, the method further includes: Trigger an information location command to verify the information location function of the first-level federated learning model according to the information location command; If the information location function meets the preset functional requirements, the first-level federated learning model is determined to have passed the verification.
6. The federated learning computation method according to claim 1, characterized in that, Before obtaining the target identification codes of multiple federated learning training participants during federated learning model training in the first-level trusted execution environment, and before determining the target training data corresponding to different federated learning training participants based on the target identification codes, the method further includes: A third public communication channel is established between the computer device and the federated learning server; wherein the third public communication channel is used by the computer device to verify the second-level trusted execution environment of the federated learning server; When the second-level trusted execution environment of the federated learning server meets the third preset verification condition, a third secure communication channel is established between the computer device and the federated learning server; wherein, the third secure communication channel is used to transmit the initial output data and the model parameter data.
7. The federated learning computation method according to claim 1, characterized in that, Before obtaining the target identification code when multiple federated learning training participants train the federated learning model in the first-level trusted execution environment, and determining the target training data corresponding to different federated learning training participants based on the target identification code, the method further includes: verifying whether the second-level federated learning model has an irreversible operation layer, and whether the irreversible operation layer runs in the second-level federated learning model. After adjusting the first model parameters of the first-level federated learning model, the second model parameters of the second-level federated learning model, and the third model parameters of the third-level federated learning model according to the model parameter data and the prediction result data corresponding to the target training data, to obtain the trained first-level federated learning model, second-level federated learning model, and third-level federated learning model, the method further includes: when the second-level federated learning model has the irreversible operation layer and the second-level federated learning model runs the irreversible operation layer, sending the second model parameters and the third model parameters obtained by the federated learning server to the computer device of any federated learning training participant, and determining the first model parameters corresponding to any federated learning training participant.
8. A federated learning computing system based on a trusted execution environment, characterized in that, An application is made in a computer device, which is communicatively connected to a federated learning server. A target federated learning model runs on the computer device and the federated learning server. The federated learning server and the computer device are deployed with a trusted execution environment. The system includes: A segmentation unit is used to determine the bottom-level local model in the target federated learning model, set the bottom-level local model as the first-level federated learning model, and segment the upper-level global model into two sub-models using the first irreversible operation layer of the upper-level global model of the target federated learning model as the segmentation point. The first sub-model of the upper-level global model of the target federated learning model is set as the second-level federated learning model, and the second sub-model of the upper-level global model of the target federated learning model is set as the third-level federated learning model. The first irreversible operation layer is the irreversible operation layer in the target federated learning model that has the first position in its ranking. The deployment unit is used to deploy the first-level federated learning model in the first-level trusted execution environment of the computer device, deploy the second-level federated learning model within the second-level trusted execution environment of the federated learning server, and deploy the third-level federated learning model outside the second-level trusted execution environment of the federated learning server. The acquisition unit is used to acquire the target identification code of multiple federated learning training participants when training the federated learning model in the first-level trusted execution environment, so as to determine the target training data corresponding to different federated learning training participants based on the target identification code; wherein, the training dataset of the multiple federated learning training participants includes training data with different identification codes, and the target identification code is the same identification code of the multiple federated learning training participants. The input unit is used to input the target training data into the first-level federated learning model to obtain initial output data; transmit the initial output data to the second-level federated learning model to obtain intermediate output data; and transmit the intermediate output data to the third-level federated learning model to obtain model parameter data corresponding to the third-level federated learning model. An adjustment unit is configured to adjust the first model parameters of the first-level federated learning model, the second model parameters of the second-level federated learning model, and the third model parameters of the third-level federated learning model, respectively, based on the model parameter data and the prediction result data corresponding to the target training data, so as to obtain the trained first-level federated learning model on the computer device of the federated learning training participant, and obtain the second-level federated learning model and the third-level federated learning model on the federated learning server; wherein the trained first-level federated learning model, the second-level federated learning model, and the third-level federated learning model are used to form the trained federated learning model.
9. A federated learning computing device based on a trusted execution environment, characterized in that, The device includes: Central processing unit, memory, input / output interfaces, wired or wireless network interfaces, and power supply; The memory is either a short-term storage memory or a persistent storage memory; The central processing unit is configured to communicate with the memory and execute instructions in the memory to perform the federated learning computation method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes instructions that, when executed on a computer, cause the computer to perform the federated learning computation method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Federated learning method based on trusted execution environment
CN111241580A
Federal learning content pushing method and device based on multi-party multi-model privacy intersection
CN115907043A