A personalized federated learning method and system based on shuffle differential privacy protection
By adopting a personalized federated learning method based on shuffled differential privacy protection in federated learning, the problems of poor availability and low computing efficiency of personalized federated learning solutions in the prior art are solved, and strong privacy protection and training efficiency of client local data are achieved to adapt to the privacy preferences of different clients.
Patent Information
- Application Number
- CN202410187832.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-02-19
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-02-19
AI Technical Summary
In the prior art, the personalized federated learning schemes with local differential privacy have poor availability, low security multi-party computing and computational efficiency, and the federated learning schemes with shuffled differential privacy cannot meet the different privacy preferences of different clients.
A personalized federated learning method based on shuffling differential privacy protection is adopted. A random generator locally on the client determines the privacy budget based on user privacy preferences and privacy hierarchy classification strategy, adds noise to the local model gradient, generates perturbation gradients, and disrupts the gradient sequence and privacy protection hierarchy sequence through shuffling servers, and transmits it to the analyzer for global model updates.
While achieving strong privacy protection for client local data in federated learning, it improves training efficiency, adapts to the privacy preferences of different clients, and improves privacy protection performance in high-dimensional scenarios.
Smart Images

Figure CN117932683B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data privacy protection, and in particular to a personalized federated learning method and system based on shuffled differential privacy protection. Background Art
[0002] Federated Learning allows participants to collaborate on training global models by simply passing model parameters without leaving the data locally, thus breaking down data silos. It can be divided into the following two types according to the different data distributions of the participants: horizontal federated learning and vertical federated learning, corresponding to situations where label space overlaps and sample space overlaps, respectively. Among them, horizontal federated learning is suitable for situations where the data features of the participants overlap a lot, but the sample IDs overlap less, such as the electricity consumption data features of power companies in different regions overlap a lot, but the samples overlap less.
[0003] Figure 1 The schematic diagram of the horizontal federated learning process is shown, including: the client downloads the latest model from the central server, the client uses local data to train the model, the client sends the model update parameters to the server and the server aggregates them, the server aggregates and updates, sends the updated global model to the client, the client updates the local model, and iterates the training until convergence. In this process, different clients collaborate on training without leaving the local data to obtain a usable global model, breaking the "data island" while ensuring the data security of the client. Although the data does not leave the local data during the federated learning training process, it introduces a large number of parameter exchange processes (gradient upload and model download). Existing research has shown that malicious training parties can reconstruct complete training data through the plaintext of the gradient, so more means are urgently needed to protect the data privacy of the training party (ie, the client).
[0004] In the prior art, it is proposed to combine local differential privacy technology to add noise to local training data to obtain the perturbed gradient. However, it is difficult to infer the original training data from the perturbed gradient, but adding less noise cannot defend against reconstruction attacks, and adding more noise will seriously restrict the model performance. Therefore, the availability of personalized federated learning solutions based on local differential privacy is relatively poor. It is also proposed to use secure multi-party computing in federated learning to achieve secure aggregation of gradients on the server. At this time, it is difficult for the attacker to obtain gradient information from each client. This technical solution can achieve anonymous communication in the parameter sending and uploading stages, but secure multi-party computing relies on a large amount of ciphertext calculations and security proofs, which seriously restricts computing efficiency. In the prior art, it is also proposed that a federated learning solution based on shuffled differential privacy can simultaneously meet the strong privacy protection requirements of local and central servers, but it only supports scenarios with consistent local privacy requirements and cannot meet the different privacy preferences of different clients. Summary of the invention
[0005] The present invention aims to solve the technical problems in the prior art, such as the poor availability of personalized federated learning solutions with local differential privacy, the low computational efficiency of secure multi-party computing, the inability to improve training efficiency while providing strong privacy protection for local data of federated learning clients, and the inability of existing federated learning solutions with shuffled differential privacy to meet the different privacy preferences of different clients. A personalized federated learning method and system based on shuffled differential privacy protection is provided.
[0006] In order to achieve the above-mentioned object of the present invention, according to the first aspect of the present invention, the present invention provides a personalized federated learning method based on shuffled differential privacy protection, the analyzer publishes a privacy level classification strategy and an initial global model, and repeatedly performs the following steps until the global iteration stop condition is reached: the client updates the local model through the global model of the current global iteration round, locally trains the local model using local data, and uploads the local model gradient after local training to the local random generator; the local random generator of the client determines the user privacy budget according to the preset user privacy preference and privacy level classification strategy, and adds noise to the local model gradient based on the user privacy budget; the random generator generates a perturbation gradient based on the local model gradient after adding noise, and uploads the perturbation gradient, privacy protection level and gradient dimension index to the shuffle server, where b is a positive integer; the shuffle server respectively forms a perturbation gradient sequence and a privacy protection level sequence with the received perturbation gradient and privacy protection level, scrambles the perturbation gradient sequence and the privacy protection level sequence respectively, and uploads the scrambled perturbation gradient sequence and the privacy protection level sequence to the analyzer; the analyzer obtains and publishes the global model of the next global iteration round based on the scrambled perturbation gradient sequence and the privacy protection level sequence.
[0007] In order to achieve the above-mentioned purpose of the present invention, according to the second aspect of the present invention, the present invention provides a training system for the personalized federated learning method based on shuffled differential privacy protection described in the first aspect of the present invention, including n clients, a local random generator for each client, a shuffle server and an analyzer, the client is connected to the clavicle random generator, the random generator is connected to the shuffle server, the shuffle server is connected to the analyzer, and the n clients are also connected to the analyzer respectively, where n is a positive integer.
[0008] The present invention determines the user privacy budget according to the preset user privacy preference and privacy level classification strategy based on the local random generator of the user client, and adds different noises in the local model gradient according to the user privacy budget to perturb the local model gradient, which can better adapt to the scenario where the user's local privacy requirements are inconsistent, so that the client can adjust the privacy budget according to its own data sensitivity, realizes local differential privacy protection, and ensures that the attacker cannot reconstruct the training data from the perturbed gradient. In particular, the random generator replaces the non-largest b dimensions with preset values in generating the perturbed gradient, so that the attacker cannot obtain which specific dimensions are the required largest b dimensions, which can further improve the privacy protection performance in high temperature scenarios; the present invention also combines differential privacy and a trusted third-party shuffling server to protect the security of gradient parameters. The shuffling server disrupts the gradient sequence so that it is difficult for the attacker to match the local model with the client one by one. Based on the localized differential privacy and downsampling amplification theory, the localized differential privacy processed by the shuffling server can provide a greater degree of differential privacy protection for the analyzer, and the central server in the analyzer can add less noise protection, personalized local model training, accelerate the model convergence speed, and improve training efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0009] Figure 1 It is a flow chart of horizontal federated learning training in the prior art;
[0010] Figure 2 It is a flowchart of a personalized federated learning method based on shuffled differential privacy protection in a preferred embodiment of the present invention;
[0011] Figure 3 is a framework diagram of a training system in a preferred embodiment of the present invention;
[0012] Figure 4 It is a schematic diagram of a shuffling process in a preferred embodiment of the present invention. DETAILED DESCRIPTION
[0013] Embodiments of the present invention are described in detail below, examples of which are shown in the accompanying drawings, wherein the same or similar reference numerals throughout represent the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and cannot be understood as limiting the present invention.
[0014] In the description of the present invention, it is necessary to understand that the terms "longitudinal", "lateral", "up", "down", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inside", "outside", etc., indicating the orientation or position relationship, are based on the orientation or position relationship shown in the accompanying drawings, and are only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore cannot be understood as a limitation on the present invention.
[0015] In the description of the present invention, unless otherwise specified and limited, it should be noted that the terms "installed", "connected" and "connected" should be understood in a broad sense. For example, it can be a mechanical connection or an electrical connection, or it can be the internal connection between two components. It can be a direct connection or an indirect connection through an intermediate medium. For ordinary technicians in this field, the specific meanings of the above terms can be understood according to the specific circumstances.
[0016] The present invention discloses a personalized federated learning method based on shuffle differential privacy protection, which is executed by a training system, and the training system includes n clients, n random generators, a third-party trusted shuffle server, and an analyzer. The n clients correspond to the n random generators one by one, and each client has a local random generator. The client specifically refers to the user's electronic device, and the electronic device is preferably but not limited to a personal computer, a server or an intelligent terminal. The analyzer includes a central server. The hardware connection block diagram of the training system can be referred to Figure 3 As shown, the corresponding clients and random generators are connected and communicated with each other, the n random generators are connected and communicated with the shuffling servers respectively, the shuffling servers are also connected and communicated with the central server of the analyzer, and the n clients are also connected and communicated with the analyzer respectively, where n is a positive integer.
[0017] In a preferred embodiment, the method flow diagram is as follows Figure 2 As shown, including:
[0018] Step S1: The analyzer publishes a privacy level classification strategy and an initial global model.
[0019] The analyzer broadcasts the privacy level classification strategy and the initial global model to all clients in the training system. There are n clients in the training system. The i-th client holds the dataset x i , i∈[1,n], random generator M that satisfies local differential privacy i And the privacy preference level R set by the user according to his or her own privacy protection strength i The privacy level classification strategy is represented by ε(ε A , ε B , ε C ), where εA , ε B , ε C denote the privacy budgets of privacy levels A, B, and C respectively, and ε A <ε B <ε C ω t represents the global model released by the analyzer at the tth global iteration, and ω0 can be used to represent the initial global model generated by the analyzer.
[0020] After executing step S1, the following steps S2 to S5 are repeatedly executed until the global iteration stopping condition is reached, and the global iteration stopping condition is that the global iteration round t reaches the preset maximum global iteration number T.
[0021] In step S2, the client updates the local model through the global model of the current global iteration round, performs local training on the local model using local data, and uploads the local model gradient after local training to the local random generator.
[0022] In a preferred embodiment, in the step of updating the local model by the global model of the current global iteration round, the i-th client executes:
[0023] Step S21, obtain the local model gradient obtained after the local training of the i-th client in the previous global iteration round is completed t represents the current global iteration round, i∈[1,n], and R represents the maximum local training round of the i-th client in the previous global iteration round t-1;
[0024] Step S22, obtain the initial local model of the local training in the current global iteration round of the i-th client according to the following formula: ω t represents the global model gradient of the current global iteration round, and ρ represents the second hyperparameter.
[0025] The traditional federated average algorithm has a slow convergence speed and low model accuracy when facing non-independent and identically distributed data. However, the above-mentioned local model updating scheme, namely the local model initialization algorithm, allows the use of personalized loose initialization states at the beginning of each local training phase. t To the latest local model The local state (initial local model) is initialized by moving in the opposite direction of . This initialization algorithm helps to correct local divergence and improve the level of local consistency, better deal with the client drift problem caused by non-independent and identically distributed data, speed up training convergence, shorten training time, and improve training efficiency.
[0026] In a preferred embodiment, in order to further accelerate the convergence speed of the model and improve the training efficiency, a local personalized model training process is introduced in the local training, and the local model is fine-tuned. Therefore, the step of locally training the local model using local data includes:
[0027] Step S23, the i-th client divides the batch data D i , the batch size is |D|, using batch data D i Perform multiple rounds of local training on the local model until the local training round reaches the preset maximum local training round R. At the rth local training round, r∈[1, R], the personalized model of the rth local training round of the i-th client is obtained according to the following local optimization objective formula:
[0028]
[0029] Among them, r represents the local training number index, θ i represents the personalized model parameters of the i-th client, represents the gradient of the local model obtained by the rth local training round of the ith client in the tth global iteration, represents the loss function of the i-th client, λ represents the regularization parameter that controls the gradient strength of the personalized model, and d represents the number of dimensions of the local model gradient; Equivalent to local data D i Train the local personalized model and use the gradient descent method to obtain the personalized model A high-precision approximation of process.
[0030] Step S24: according to the obtained personalized model Update local model Among them, η is the learning rate.
[0031] Step S25: when the maximum number of local training rounds R is reached, upload the local model gradient of the Rth local training round of the i-th client.
[0032] In the above local training scheme, personalized federated learning can be formulated as a two-level optimization problem: The model gradient reference point ω is determined by aggregating the data of n clients in the external layer; in the internal layer, θ is optimized for the data distribution of client i. i , and let θ i Keep a bounded distance from ω. i (θ i ) represents the loss of the personalized model on the i-th client, F i(ω) represents the expected loss of the data distribution of the i-th client, based on which the client can update the local model in different directions without deviating from the reference point ω. In addition, when client i trains the local personalized model, the gradient descent method is used to obtain the personalized model A high-precision approximation of Training personalized models locally allows clients to update local models in different directions, effectively alleviating the impact of data heterogeneity on model generalization performance, and fine-tuning local models based on local data to accelerate model convergence.
[0033] In step S3, the local random generator of the client determines the user privacy budget according to the preset user privacy preference and privacy level classification strategy, and adds noise to the local model gradient based on the user privacy budget; the random generator generates a perturbation gradient based on the local model gradient after adding noise, and uploads the perturbation gradient, privacy protection level and gradient dimension index to the shuffling server.
[0034] In a preferred embodiment, the client local random generator determines the user privacy budget step according to the preset user privacy preference and privacy level classification strategy, including:
[0035] Step S31: Let the privacy level classification strategy be denoted as ε(ε A , ε B , ε C ), where ε A , ε B , ε C denote the privacy budgets of privacy levels A, B, and C respectively, and ε A <ε B <ε C ;
[0036] Step S32: Let the user privacy preference of the i-th client be represented by R i ;
[0037] Step S33, obtaining the privacy calculation and privacy protection level, including:
[0038] When R i <ε A When the privacy protection level of the i-th client is The privacy budget of the i-th client is ε i =R i ε A ;
[0039] When R i >ε C When the privacy protection level of the i-th client is The privacy budget of the i-th client is ε i =Ri ε C ;
[0040] Otherwise, the privacy protection level of the i-th client is The privacy budget of the i-th client is ε i =R i ε B .
[0041] The above privacy computing acquisition scheme can be determined according to the user's privacy preference, so that the client can adjust the privacy budget according to its own data sensitivity.
[0042] In a preferred implementation, in step S3, the client adds noise to the local model gradient based on the user privacy budget, specifically including:
[0043] The local random generator M corresponding to the i-th client i Calculate the standard deviation σ of the Gaussian distribution i , add Gauss noise to the local model gradient It meets the requirements of ε-localized differential privacy protection: That is, the random algorithm π satisfies the requirement of outputting the same result y for any two records v and v′.
[0044] In a preferred embodiment, in step S3, the random generator generates a perturbation gradient based on the local model gradient after adding noise, including: retaining the largest b dimensions in the local model gradient after adding noise, b is a positive integer, and replacing the dimension values that do not belong to the largest b dimensions in the local model gradient after adding noise with preset values, and using the newly generated gradient as the perturbation gradient. The preset value is preferably but not limited to 0. The above scheme can further improve the privacy protection performance in high-dimensional scenarios.
[0045] In specific applications, let the local model gradient of the i-th client after adding noise be Apply a sparsification algorithm based on post-processing (in order to ensure the privacy of the selected dimensions, the method of perturbation before selection is adopted) to select the perturbed gradient The largest b-dimensional index set I is obtained, and the remaining dimensions are perturbed with 0 and then sent: b : Where k is the dimension index and d is Then, for The k-th dimension value of the local model gradient after adding noise to the i-th client Fill with 0.
[0046] Step S4: The shuffling server constructs a perturbation gradient sequence with the received perturbation gradient and privacy protection level. And privacy protection level sequence The perturbation gradient sequence and the privacy protection level sequence are shuffled respectively, and the shuffled perturbation gradient sequence and the shuffled privacy protection level sequence are uploaded to the analyzer respectively.
[0047] In a preferred embodiment, in order to further improve privacy protection and prevent the attacker from restoring client data, in step S4, the process of the shuffling server disrupting the perturbation gradient sequence is:
[0048] The perturbed gradient sequence includes the perturbed gradients uploaded by the local random generators of n clients. The dimension values corresponding to each gradient dimension index in the perturbed gradient sequence are arranged into dimension values, and the dimension values corresponding to all gradient dimension indexes are arranged to obtain the perturbed gradient sequence after perturbation. Specifically, for each dimension k∈[j] of the gradient, d is the perturbed gradient of the i-th client. The number of dimensions, generating the dimension value arrangement π k , arranging π based on the dimension value k Shuffle the gradient sequence:
[0049] In step S4, the process of the shuffling server disrupting the privacy protection level sequence is as follows: based on [n] (representing an integer set consisting of 1 to n integers), a permutation π is generated, and based on the perturbation π, the privacy parameter sequence is perturbed:
[0050] Figure 4 A schematic diagram of a shuffling process corresponding to step S4 in an application scenario is disclosed, including:
[0051] Step 501: For each dimension k∈[d] of the gradient, generate a permutation π k , based on the permutation π k Shuffle the gradient sequence:
[0052] Step 502: Generate a permutation π based on [n], and perturb the privacy parameter sequence based on the permutation π:
[0053] Step 503: The shuffle server sends the shuffled gradient sequence and privacy parameter sequence to the analyzer.
[0054] In step S5, the analyzer obtains and publishes the global model of the next global iteration round based on the disrupted perturbation gradient sequence and the privacy protection level sequence.
[0055] In a preferred embodiment, step S5 comprises:
[0056] Step S51, sampling the perturbation gradients of S clients from the disrupted perturbation gradient sequence, the sampling size is unified as S in the global iterative training, and the collected client subset is represented as S t , aggregate the perturbation gradients of S clients according to the preset aggregation formula to obtain the global model aggregation gradient, where S is a positive integer.
[0057] The default aggregation formula is to aggregate according to each dimension k∈[d]: k∈[d], Represents the k-th dimension value of the perturbed gradient of the shuffled local model of the i-th client in the client subset.
[0058] Step S52: Aggregate the privacy protection level sequence to obtain the aggregated privacy protection level. Since the noise added by different clients is not uniform, in order to quantify the differential privacy protection level of the training process, the analyzer needs to aggregate the privacy parameter sequence, and aggregate the privacy protection level sequence according to the following formula to obtain the aggregated privacy protection level: in, represents the privacy protection level of the i-th client, i∈[1,n], and n represents the number of clients.
[0059] Step S53 generates the next round of global model, including: if the aggregate privacy protection level is less than or equal to the global differential privacy budget threshold ε max , ε<ε max , then the next round of global model is obtained according to the following global update formula:
[0060] If the aggregate privacy protection level is greater than the global differential privacy budget threshold, the global model gradient is updated according to the global update formula, and noise that meets the global differential privacy budget threshold is added to the updated global model to obtain the next round of global model ω t+1 :
[0061]
[0062] Among them, t represents the current global iteration round, ω t represents the global model gradient released by the analyzer at the current global iteration round, ω t+1 represents the global model gradient of the next global iteration round; β represents the first hyperparameter, which is a hyperparameter for controlling the update of the global model and can effectively improve the convergence speed of the model; represents the global model aggregate gradient, N(,) represents Gaussian distribution noise, N represents the number of clients (i.e., users) participating in this global iterative training, N≤n, c represents the first constant, δ represents the relaxation term, and the value of δ can be 10 -5 , C represents the gradient clipping threshold, C is a hyperparameter, εmax represents the global differential privacy budget threshold, and ε represents the aggregate privacy protection level.
[0063] The present invention also discloses a training system based on the personalized federated learning method based on shuffle differential privacy protection, such as Figure 3 As shown, it includes n clients, a local random generator for each client, a shuffling server and an analyzer, the client is connected to the clavicle random generator, the random generator is connected to the shuffling server, the shuffling server is connected to the analyzer, and the n clients are also connected to the analyzer respectively, and n is a positive integer.
[0064] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "examples", "specific examples", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present invention. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner.
[0065] Although the embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the claims and their equivalents.
Claims
1. A personalized federated learning method based on shuffle differential privacy protection, characterized in that: The analyzer publishes the privacy level classification strategy and the initial global model, and repeats the following steps until the global iteration stop condition is reached: The client updates the local model through the global model of the current global iteration round, uses local data to perform local training on the local model, and uploads the local model gradient after local training to the local random generator; wherein, in the step of updating the local model through the global model of the current global iteration round, the i-th client executes: Get the local model gradient obtained after the local training of the i-th client in the previous global iteration round is completed t represents the current global iteration round, i∈[0,n], and R represents the maximum local training round of the i-th client in the previous global iteration round t-1; The initial local model trained locally in the current global iteration round t of the i-th client is obtained according to the following formula: ω t represents the global model gradient of the current global iteration round t, and ρ represents the second hyperparameter; The local random generator of the client determines the user privacy budget according to the preset user privacy preference and privacy level classification strategy, and adds noise to the local model gradient based on the user privacy budget; the random generator generates a perturbation gradient based on the local model gradient after adding noise, and uploads the perturbation gradient, privacy protection level and gradient dimension index to the shuffling server; The shuffling server constructs the received perturbation gradient and privacy protection level into a perturbation gradient sequence and a privacy protection level sequence, shuffles the perturbation gradient sequence and the privacy protection level sequence, and uploads the shuffled perturbation gradient sequence and the privacy protection level sequence to the analyzer; The analyzer obtains and publishes the global model for the next global iteration round based on the shuffled perturbation gradient sequence and privacy protection level sequence.
2. The personalized federated learning method based on shuffled differential privacy protection as claimed in claim 1, characterized in that: The client local random generator determines the user privacy budget according to the preset user privacy preference and privacy level classification strategy, including: Let the privacy level classification strategy be denoted as ε(ε A , ε B , ε C ), where ε A , ε B , ε C denote the privacy budgets of privacy levels A, B, and C respectively, and ε A <ε B <ε C ; Let the user privacy preference of the i-th client be represented by R i ; When R i <ε A When the privacy protection level of the i-th client is The privacy budget of the i-th client is ε i =R i ε A ; When R i >ε C When the privacy protection level of the i-th client is The privacy budget of the i-th client is ε i =R i ε C ; Otherwise, the privacy protection level of the i-th client is The privacy budget of the i-th client is ε i =R i ε B ; Where i∈[1,n], n represents the number of clients.
3. The personalized federated learning method based on shuffled differential privacy protection according to claim 1 or 2, characterized in that: The random generator generates a perturbation gradient based on the local model gradient after adding noise, including: The largest b dimensions of the local model gradient after adding noise are retained, and the dimension values that do not belong to the largest b dimensions in the local model gradient after adding noise are replaced with preset values, and the newly generated gradient is used as the perturbation gradient, and b is a positive integer.
4. The personalized federated learning method based on shuffled differential privacy protection as claimed in claim 3, characterized in that: The process of the shuffle server disrupting the perturbation gradient sequence is: The perturbation gradient sequence includes perturbation gradients uploaded by random generators local to n clients. The dimension values corresponding to each gradient dimension index in the perturbation gradient sequence in the n perturbation gradients are arranged into dimension values, and the dimension value arrangements corresponding to all gradient dimension indexes are disrupted to obtain a disrupted perturbation gradient sequence.
5. The personalized federated learning method based on shuffled differential privacy protection as described in claim 1, 2 or 4, characterized in that: The analyzer obtains the next round of global model based on the disrupted perturbation gradient sequence and the privacy protection level sequence, including: Sample the perturbation gradients of S clients from the disrupted perturbation gradient sequence, aggregate the perturbation gradients of S clients according to the preset aggregation formula, and obtain the global model aggregate gradient, where S is a positive integer; The privacy protection level sequence is aggregated to obtain the aggregated privacy protection level. If the aggregated privacy protection level is less than or equal to the global differential privacy budget threshold, the next round of global model is obtained according to the global update formula. If the aggregated privacy protection level is greater than the global differential privacy budget threshold, the global model gradient is updated according to the global update formula, and noise that meets the global differential privacy budget threshold requirements is added to the updated global model to obtain the next round of global model.
6. The personalized federated learning method based on shuffled differential privacy protection as claimed in claim 5, characterized in that: Aggregate the privacy protection level sequence according to the following formula to obtain the aggregated privacy protection level: in, represents the privacy protection level of the i-th client, i∈[1,n], and n represents the number of clients.
7. The personalized federated learning method based on shuffled differential privacy protection as claimed in claim 5, characterized in that: If the aggregate privacy protection level is less than or equal to the global differential privacy budget threshold, then If the aggregate privacy protection level is greater than the global differential privacy budget threshold, then: Among them, t represents the current global iteration round, ω t represents the global model gradient of the current global iteration round t, ω t+1 represents the global model gradient of the next global iteration round, β represents the first hyperparameter, represents the global model aggregate gradient, N(,) represents Gaussian distribution noise, N represents the number of clients participating in this global iterative training, c represents the first constant, δ represents the relaxation term, C represents the gradient clipping threshold, and ε max represents the global differential privacy budget threshold, and ε represents the aggregate privacy protection level.
8. The personalized federated learning method based on shuffled differential privacy protection as claimed in claim 1, characterized in that: The locally training the local model using the local data includes: The i-th client divides the batch data D i , using batch data D i Perform multiple rounds of local training on the local model until the preset maximum local training round R is reached. At the rth local training round, r∈[1, R], the personalized model of the rth local training round of the i-th client is obtained according to the following local optimization objective formula Among them, r represents the local training number index, θ i represents the personalized model parameters of the i-th client, represents the gradient of the local model obtained by the rth local training round of the ith client in the tth global iteration, represents the loss function of the i-th client, λ represents the regularization parameter that controls the gradient strength of the personalized model, and d represents the number of dimensions of the local model gradient; According to the obtained personalized model Update local model Where η is the learning rate; When the maximum number of local training rounds R is reached, upload the local model gradients of the Rth local training round of the i-th client 9. A training system based on the personalized federated learning method based on shuffled differential privacy protection according to any one of claims 1 to 8, characterized in that: It includes n clients, a local random generator for each client, a shuffling server and an analyzer, wherein the client is connected to the clavicle random generator, the random generator is connected to the shuffling server, the shuffling server is connected to the analyzer, and the n clients are also connected to the analyzer respectively, where n is a positive integer.
Citation Information
Patent Citations
Personalized federal learning and recognition method and system based on differential privacy
CN115952533A