An Adversarial Federated Learning Method Based on Cluster Head Selection and Knowledge Distillation in Vehicular Networks

By adopting an adversarial federated learning method based on cluster head selection and knowledge distillation in the Internet of Vehicles, the problems of increased communication overhead and gradient reverse attack in federated learning are solved, and efficient and secure model aggregation is achieved.

CN118230270BActive Publication Date: 2025-05-27HENAN UNIV OF SCI & TECH
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410263673.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-07
Publication Date
2025-05-27
Estimated Expiration
2044-03-07

AI Technical Summary

Technical Problem

Federated learning faces the challenges of increased communication overhead and gradient reverse attacks in the Internet of Vehicles, and existing methods have failed to effectively combine vehicle cluster characteristics and gradient security.

Method used

Adversarial federated learning method based on cluster head selection and knowledge distillation is adopted, cluster head vehicles are selected as teacher models, and other member vehicles are used as student models, and generators and discriminators are set up in the model to form an adversarial network to prevent gradient reverse attacks and improve aggregation efficiency.

Benefits of technology

It effectively avoids redundant duplicate judgments, saves computing resources, and makes it difficult for attackers to obtain complete gradient information, improving the security and aggregation efficiency of the learning process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118230270B_ABST
    Figure CN118230270B_ABST
Patent Text Reader

Abstract

The present invention discloses an adversarial federated learning method based on cluster head selection and knowledge distillation in a vehicle networking. First, cluster head vehicles are selected from vehicle clusters, and then an adversarial federated learning model is deployed. The image classification model to be learned is used as the student model. A generator and a teacher model are deployed on the cluster head vehicles, and a discriminator and the student model are deployed on the member vehicles. Then, adversarial federated learning is carried out. During the learning process, the generator generates adversarial samples and uses them as the input images for the teacher model and the student model. When calculating the loss function, the prediction probabilities of the teacher model and the student model for the labels of the adversarial samples are considered. After the adversarial federated learning is completed, the parameters of the student model are aggregated to update the parameters of the image classification model. The present invention can improve the aggregation efficiency of federated learning while defending against gradient reversal attacks and improve the classification accuracy of the aggregated model.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of vehicle networking. More specifically, it relates to an adversarial federated learning method based on cluster head selection and knowledge distillation in vehicle networking. Background Art

[0002] As a distributed learning method, federated learning has gradually become a key technology in the field of vehicle networking applications. Federated learning allows vehicles to achieve real-time data transmission and rapid intelligent decision-making while maintaining data privacy, and improves the performance of the overall vehicle networking system through the knowledge of local models such as vehicles and roadside units. This distributed learning model does not require sharing of original data, and realizes the execution of latency-sensitive and computationally intensive tasks by sharing model parameters, ensuring the security of data sharing in vehicle networking. There are some challenges and problems in the actual deployment of federated learning in vehicle networking: (1) Federated learning frequently exchanges model parameters among different vehicles and traffic participants, and some redundant parameters increase the communication overhead in the process of aggregating the model. (2) Federated learning only shares model parameters when processing data locally, but still faces gradient reverse attacks on the model. Attackers obtain the gradient and reverse reconstruct the model to obtain the original data.

[0003] To meet the security and efficiency requirements of federated learning training and intelligent decision-making in vehicle networking. Existing methods mostly adopt methods such as gradient compression to reduce redundant gradients, gradient pruning, and fixed compression ratio thresholds, ignoring the impact of the time-varying nature and other attributes of vehicles in federated learning on distributed learning. Therefore, there is an urgent need for a class of methods that can combine the characteristics of vehicle cluster formation and gradient security protection to solve the above problems. Summary of the Invention

[0004] The purpose of the present invention is to overcome the deficiencies of the prior art and provide an adversarial federated learning method based on cluster head selection and knowledge distillation in vehicle networking. The cluster head vehicle in the vehicle cluster is selected to deploy the teacher model, and other member vehicles in the vehicle cluster are used to deploy the student model. A generator and a discriminator are set up to form an adversarial network, so as to improve the aggregation efficiency of federated learning while defending against gradient reverse attacks and balancing the available computing power resources within the vehicle cluster.

[0005] To achieve the above object of the invention, the adversarial federated learning method based on cluster head selection and knowledge distillation in vehicle networking of the present invention includes the following steps:

[0006] S1: The adversarial federated learning server uses self-organizing networking in the vehicle ad hoc network to construct vehicle clusters, and then selects cluster head vehicles in each vehicle cluster;

[0007] S2: Set a teacher model and a generator G according to the image classification model for adversarial federated learning, and deploy the generator G and the teacher model on the cluster head vehicle; the generator G is used to generate adversarial samples based on the real samples local to the cluster head vehicle, and the adversarial samples are used as knowledge distillation data;

[0008] Then deploy the image classification model as a student model on other member vehicles within the vehicle cluster, and configure a discriminator D for each student model to discriminate and distinguish between adversarial samples and real samples;

[0009] S3: Perform adversarial federated learning using the following method:

[0010] S3.1: Let the iteration number g = 1;

[0011] S3.2: The cluster head vehicle collects M t real samples (x i , y i ), where x i represents the input image of the i-th real sample, and y i represents the label y i of the input image x i , y i = 1, 2, …, K, where K represents the number of classes, and i = 1, 2, …, M t ; then pass each input image x i through the generator G to generate the input image of the adversarial sample and set the label of the input image ; then send the adversarial sample to the adversarial federated learning server and other member vehicles in the vehicle cluster;

[0012] S3.3: The cluster head vehicle inputs the real samples and the adversarial samples into the teacher model to obtain the probability q i,k that each real sample belongs to the k-th class, and the probability that each adversarial sample belongs to the k-th class, where k = 1, 2, …, K; then use the following formula to calculate the cross-entropy loss L t of the real samples in the teacher model:

[0013]

[0014] where k = 1, 2, …, K;

[0015] The cluster head vehicle sends the cross-entropy loss L t of the teacher model and the probability corresponding to each adversarial sample to the adversarial federated learning server;

[0016] S3.4: Each member vehicle in the vehicle cluster separately collects real samples (x n,m , y n,m ), where x n,m represents the input image of the m-th real sample collected by the n-th member vehicle, and y n,m represents the label of the input image x n,m . Here, m = 1, 2, …, M s,n , and M s,n represents the number of real samples of the input student model collected by the n-th member vehicle in the vehicle cluster, where n = 1, 2, …, N - 1;

[0017] The member vehicle inputs the locally collected real samples and adversarial samples into its student model, and obtains the probability p n,m,k that each real sample belongs to the k-th class and the probability that each adversarial sample belongs to the k-th class Each member vehicle in the vehicle cluster calculates the cross-entropy loss L s,n of the real samples in the student model using the following formula:

[0018]

[0019] where y n,m represents the label of the m-th real sample collected by the n-th member vehicle;

[0020] The member vehicle inputs the locally collected real samples and adversarial samples into the discriminator D, obtains the discrimination result of whether it is a real sample, and then calculates the generation loss and the discrimination loss

[0021] The member vehicle where each student model is located sends its cross-entropy loss L s,n , generation loss , discrimination loss and the probability that each adversarial sample corresponds to the k-th class to the adversarial federated learning server;

[0022] S3.5: Calculate the cross-entropy loss function L A of the predictions of the student model and the teacher model for the adversarial samples:

[0023]

[0024] Calculate the KL divergence loss L KL of the predictions of the student model and the teacher model for the adversarial samples:

[0025]

[0026] where Denote the KL divergence between the prediction results of the student model and the teacher model on the nth member vehicle, and its calculation formula is:

[0027]

[0028] The loss function LOSS of the teacher model is calculated using the following formula t :

[0029]

[0030] where λ is the hyperparameter coefficient;

[0031] The generation loss LOSS of the generator G is calculated using the following formula G :

[0032]

[0033] The shared loss function LOSS of the student model is calculated using the following formula s :

[0034]

[0035] The shared discrimination loss LOSS of the discriminator is calculated using the following formula D :

[0036]

[0037] S3.6: The adversarial federated learning server calculates the gradient Δ t according to the loss function LOSS of the teacher model t , calculates the gradient Δ G according to the generation loss LOSS of the generator G G , calculates the shared gradient Δ s of the student model according to the shared loss function LOSS of the student model s , calculates the shared gradient Δ D of the discriminator D according to the shared discrimination loss LOSS of the discriminator D ; The adversarial federated learning server sends the gradient Δ t and the gradient Δ G to the cluster head vehicle, and the teacher model on the cluster head vehicle updates the parameters according to the gradient Δ t , and the generator G updates the parameters according to the gradient Δ G ; The adversarial federated learning server sends the shared gradient Δ s and the shared gradient Δ D to each member vehicle in the vehicle cluster, and the student model on the member vehicle updates the parameters according to the shared gradient Δ s , and the discriminator D updates the parameters according to the shared gradient ΔD Update parameter;

[0038] S3.7: Determine whether the number of iterations g < G, where G represents the preset maximum number of iterations. If so, go to step S3.8; otherwise, the adversarial federated learning ends.

[0039] S3.8: Let g = g + 1, and return to step S3.2.

[0040] S4: Each member vehicle sends the parameters of its local student model to the adversarial federated learning server. The adversarial federated learning server aggregates the parameters of N - 1 student models and updates the parameters of the image classification model with the finally obtained parameters.

[0041] In the method for adversarial federated learning based on cluster head selection and knowledge distillation in the vehicle networking of the present invention, first, a cluster head vehicle is selected from the vehicle clusters, and then an adversarial federated learning model is deployed. The image classification model to be learned is used as the student model. A generator and a teacher model are deployed on the cluster head vehicle, and a discriminator and a student model are deployed on the member vehicles. Then, adversarial federated learning is carried out. During the learning process, the generator generates adversarial samples and uses them as the input of the teacher model and the student model. When calculating the loss function, the prediction probabilities of the teacher model and the student model for the adversarial samples are considered. After the adversarial federated learning is completed, the parameters of the student models are aggregated, and the aggregated parameters are used as the parameters of the image classification model.

[0042] The present invention has the following beneficial effects:

[0043] (1) In the process of clustering and networking in the vehicle ad - hoc network of the present invention, a cluster head vehicle is selected from the vehicle clusters, a teacher model is deployed on the cluster head vehicle, and student models are deployed on other member vehicles within the cluster. The method of knowledge distillation is used to complete model compression, and the large model (teacher model) is used to supervise the small model (student model), improving the transmission rate during the federated learning aggregation process.

[0044] (2) In the present invention, a generator is deployed for the teacher model, and a discriminator is deployed for the student model to calculate the generated adversarial samples. The discriminant results are shared among the student models, effectively avoiding redundant repeated discrimination, saving computing power resources. The attacker can only obtain partial gradient information, avoiding model reconstruction, and efficiently resisting gradient inversion attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0045] Figure 1 is the flowchart of the specific implementation of the method for adversarial federated learning based on cluster head selection and knowledge distillation in the vehicle networking of the present invention;

[0046] Figure 2 is the flowchart of the cluster head vehicle selection of the present invention;

[0047] Figure 3It is the flow chart of the adversarial federated learning in the present invention;

[0048] Figure 4 It is the schematic diagram of the scenario of two vehicle clusters in this embodiment;

[0049] Figure 5 It is the visualization evaluation comparison chart of the model reconstruction of the present invention and the comparative method in this embodiment;

[0050] Figure 6 It is the curve graph of the state change of the local aggregation loss function of each group of vehicle clusters in the present invention and the comparative method in this embodiment;

[0051] Figure 7 It is the experimental graph of the comparison and evaluation of the confusion matrix on the FMNIST and CIFAR10 data sets in this embodiment. Detailed implementation manners

[0052] The following describes the specific implementation manners of the present invention in conjunction with the accompanying drawings, so that those skilled in the art can better understand the present invention. It should be particularly noted that in the following description, when the detailed descriptions of known functions and designs may dilute the main content of the present invention, these descriptions will be omitted here.

[0053] To better illustrate the technical solution of the present invention, the technical principle of the present invention will be briefly described first.

[0054] Federated learning supports cross-client collaborative modeling of vehicles in the vehicle network. However, the dynamic heterogeneous self-organizing network leads to frequent parameter exchanges between vehicles, increasing the computing cost and affecting the model aggregation efficiency in limited bandwidth resources. At the same time, gradient reverse attacks are difficult to defend in conventional federated learning. In the present invention, the method of federated knowledge distillation is adopted, where a complex teacher model transfers knowledge to a simplified student model to guide the training of the student model. The cluster head selection and knowledge distillation of the entire adversarial federated learning are divided into three stages: self-organizing vehicle clusters select cluster heads based on the three-dimensional attributes of vehicles; the student model (cluster members) deploy discriminators and share the training results within the cluster; the teacher model (cluster heads) deploy generators, and the student model generates soft targets to support the complex teacher model to generate more realistic data samples.

[0055] According to the above requirements and application steps, the present invention proposes an adversarial federated learning method based on cluster head selection and knowledge distillation in the vehicle network. Figure 1 It is the flow chart of the specific implementation manner of the adversarial federated learning method based on cluster head selection and knowledge distillation in the vehicle network of the present invention. As Figure 1 shown, the specific steps of the adversarial federated learning method based on cluster head selection and knowledge distillation in the vehicle network of the present invention include:

[0056] S101: Selection of vehicle cluster heads:

[0057] Against the federated learning server, autonomous clustering networking is adopted in the vehicular ad hoc network to construct vehicle clusters, and then cluster head vehicles are selected in each vehicle cluster. In each vehicle cluster, the cluster head vehicle serves as the teacher model in the federated adversarial distillation architecture, and other in-cluster member vehicles serve as student models. In the present invention, the cluster head vehicle is responsible for managing other member vehicles in the vehicle cluster, so the selection of the vehicle cluster head is crucial. To improve the management efficiency of the cluster head vehicle, in this embodiment, the cluster head vehicle is selected based on three attributes: the average speed of the vehicle cluster, the core position of the cluster head, and the communication performance. Figure 2 This is the flowchart of the selection of the cluster head vehicle in this embodiment. As Figure 2 shown, the specific steps of the selection of the cluster head vehicle in this embodiment include:

[0058] S201: Calculate the speed function:

[0059] Denote the vehicle cluster as U, which contains N vehicles. Denote the j-th vehicle as V j , j = 1, 2,..., N. Denote the vehicle cluster after vehicle V j drives away as U j = U / {V j}}, and use the following formula to calculate the speed function of vehicle V j :

[0060]

[0061] Among them, ν j′ represents the speed value of vehicle V j in vehicle cluster U j′ , is the average speed of all vehicles in vehicle cluster U j .

[0062] S202: Calculate the core position function:

[0063] In the present invention, the vehicle position coordinates (a j , b j ) are used as one of the criteria for cluster head selection. The communication distance between the central position in the vehicle cluster and other vehicles is relatively the shortest. Therefore, use the following formula to calculate the core position function LF j of vehicle V j :

[0064]

[0065] Among them, (a j′ , b j′ ) represents the position coordinates of vehicle V j in vehicle cluster U j′ , (a j , b j ) represents vehicle Vj The position coordinates, |||| indicates obtaining the norm.

[0066] S203: Calculate the communication performance function:

[0067] In the present invention, a communication performance function is also defined to quantitatively evaluate the influence of cluster head node selection on communication performance. The following formula is used to calculate the communication performance function URF of vehicle V j j :

[0068]

[0069] Wherein, represents the average value of the end-to-end delay, indicating the average time difference for information to be transmitted from a vehicle node V within the cluster to other vehicle nodes in vehicle cluster U. T j represents the average time difference for information to be transmitted from vehicle V j to other vehicle nodes in vehicle cluster U. T jj′ represents the time for information to be transmitted from vehicle V j to vehicle V j′ . UTR j′ is the transmission rate of vehicle V in vehicle cluster U j , that is, the maximum data transmission capacity per second of vehicle V j′ . MTR j′ is the minimum data transmission rate for data transmission of a preset vehicle node through a cluster head node. Generally, in order to ensure the successful transmission of data, the maximum value of UTR j is not greater than the minimum value of MTR j . j

[0070] S204: Calculate the comprehensive benchmark function:

[0071] The following formula is used to calculate the comprehensive benchmark function UAF of each vehicle V j j :

[0072] UAF j = w 1 VF j + w 2 LF j + w 3 URF j

[0073] Wherein, w 1 , w 2 , w 3 represent preset weights, and satisfy w 1 + w 2 + w 3 = 1, w 1 >> w 2 , w​​​3 。

[0074] S205: Determine the cluster head vehicle:

[0075] According to the calculation formula of the comprehensive benchmark function, the smaller the value of the comprehensive benchmark function, the smaller the impact on the stability of in-cluster information exchange. Therefore, the vehicle with the smallest comprehensive benchmark function is selected from the vehicle cluster U as the cluster head vehicle.

[0076] S102: Deploy the adversarial federated learning model:

[0077] To implement adversarial federated learning, the adversarial federated learning server needs to deploy relevant models in the vehicle cluster, that is, set up a teacher model and a student model. At the same time, the present invention also sets up a generator and a discriminator for implementing adversarial federated learning. The deployment method of the adversarial federated learning model in the present invention is as follows:

[0078] Set up a teacher model and a generator G according to the image classification model for which adversarial federated learning is to be performed, and deploy the generator G and the teacher model on the cluster head vehicle. The generator G is used to generate adversarial samples based on the real samples local to the cluster head vehicle, and the adversarial samples are used as knowledge distillation data.

[0079] Then deploy the image classification model as the student model on other member vehicles in the vehicle cluster, and configure a discriminator D for each student model to discriminate and distinguish between adversarial samples and real samples.

[0080] S103: Adversarial federated learning:

[0081] In federated learning, the student model is required to simulate the behavior of the teacher model as accurately as possible, that is, generate results as similar as possible to the prediction results of the teacher model. A part of the training data of the teacher model comes from local real samples, and a part comes from the adversarial samples generated by the generator and is transmitted to each student model for training. Since the computing resources held by the vehicle members in the vehicle cluster are limited, in the present invention, both the cluster head vehicle and the member vehicles upload the training results, and the adversarial federated learning server calculates the loss function, reducing redundancy and repeated calculations, realizing shared distillation, and reducing the computing cost of the model. In addition, in the present invention, the cluster head vehicle sends the adversarial samples generated by the generator to each student model, so that the output of the student model in federated distillation approximates the output of the teacher model as much as possible, minimizing the cross-entropy error between the teacher model and the student model, thereby resisting gradient reverse attacks. Figure 3 is the flowchart of the adversarial federated learning in the present invention. As Figure 3 shown, the specific steps of the adversarial federated learning in the present invention include:

[0082] S301: Let the iteration number g = 1.

[0083] S302: Generate adversarial samples:

[0084] The cluster head vehicle collects M t real samples (x i , y i ), where x i represents the input image of the i-th real sample, and y i represents the label y i of the input image x i , and y i = 1, 2, …, K, where K represents the number of classes, and i = 1, 2, …, M t . Then, each input image x i generates the input image of the adversarial sample through the generator G and sets the label of the input image . Then, the adversarial samples are sent to the adversarial federated learning server and other member vehicles in the vehicle cluster.

[0085] S303: Teacher model training:

[0086] The cluster head vehicle inputs the real samples and adversarial samples into the teacher model to obtain the probability q i,k that each real sample belongs to the k-th class, and the probability that each adversarial sample belongs to the k-th class. Then, the cross-entropy loss L t of the real samples in the teacher model is calculated using the following formula:

[0087]

[0088] where k = 1, 2, …, K.

[0089] The cluster head vehicle sends the cross-entropy loss L t of the teacher model and the probability corresponding to each adversarial sample to the adversarial federated learning server.

[0090] S304: Student model training:

[0091] Each member vehicle in the vehicle cluster separately collects real samples (x n,m , y n,m ), where x n,m represents the input image of the m-th real sample collected by the n-th member vehicle, and y n,m represents the label of the input image x n,m , m = 1, 2, …, M s,n , and M s,n represents the number of real samples input into the student model collected by the n-th member vehicle in the vehicle cluster, and n = 1, 2, …, N - 1.

[0092] The member vehicle inputs the real samples and adversarial samples collected locally into its student model, and obtains the probability p that each real sample belongs to the k-th category. n,m,k and the probability that each adversarial sample belongs to the k-th category Each member vehicle in the vehicle cluster calculates the cross-entropy loss L of the real samples in the student model using the following formula s,n :

[0093]

[0094] where y n,m represents the label of the m-th real sample collected by the n-th vehicle.

[0095] The member vehicle inputs the real samples and adversarial samples collected locally into the discriminator D, obtains the discrimination result of whether it is a real sample, and then calculates the generation loss and the discrimination loss The calculation formula of the generation loss is expressed as:

[0096]

[0097] The discrimination loss The calculation formula is expressed as:

[0098]

[0099] where P(x n,m ) represents the distribution of the real samples collected by the n-th member vehicle, represents the distribution of the adversarial samples, and D() represents the discrimination result.

[0100] Each member vehicle where the student model is located sends its cross-entropy loss L s,n , generation loss discrimination loss and the probability corresponding to each adversarial sample to the adversarial federated learning server.

[0101] S305: Calculate the shared loss function:

[0102] The adversarial federated learning server calculates the shared loss function according to the data uploaded by the teacher model and the student model. The specific method is:

[0103] Calculate the cross-entropy loss function L of the predictions of the student model and the teacher model for the adversarial samples A :

[0104]

[0105] Calculate the KL divergence loss L of the student model and the teacher model for the prediction of adversarial samples KL :

[0106]

[0107] Among them, represents the KL divergence of the prediction results of the student model and the teacher model for adversarial samples on the nth member vehicle, and its calculation formula is:

[0108]

[0109] Use the following formula to calculate the loss function LOSS of the teacher model t :

[0110]

[0111] Among them, λ is the hyperparameter coefficient.

[0112] Use the following formula to calculate the generation loss LOSS of the generator G G :

[0113]

[0114] Use the following formula to calculate the shared loss function LOSS of the student model s :

[0115]

[0116] Use the following formula to calculate the shared discriminant loss LOSS of the discriminator D :

[0117]

[0118] S306: Update the model parameters:

[0119] The adversarial federated learning server calculates the gradient Δ t according to the loss function LOSS of the teacher model t , calculates the gradient Δ G according to the generation loss LOSS of the generator G G , calculates the shared gradient Δ s of the student model according to the shared loss function LOSS of the student model s , calculates the shared gradient Δ D of the discriminator D according to the shared discriminant loss LOSS of the discriminator D . The adversarial federated learning server sends the gradient Δ t and the gradient Δ G to the cluster head vehicle, and the teacher model on the cluster head vehicle is based on the gradient Δt Update the parameters, and the generator G updates according to the gradient Δ G Update the parameters; the adversarial federated learning server shares the gradient Δ s and the shared gradient Δ D Send to each member vehicle in the vehicle cluster. The student model on the member vehicle updates the parameters according to the shared gradient Δ s Update the parameters, and the discriminator D updates the parameters according to the shared gradient Δ D Update the parameters.

[0120] S307: Determine whether the number of iterations g < G, where G represents the preset maximum number of iterations. If so, go to step S308; otherwise, the adversarial federated learning ends.

[0121] S308: Let g = g + 1, and return to step S302.

[0122] S104: Aggregation of student model parameters:

[0123] Each member vehicle sends the parameters of its student model to the adversarial federated learning server. The adversarial federated learning server aggregates the parameters of N - 1 student models and updates the parameters of the image classification model with the finally obtained parameters.

[0124] Through the above - mentioned adversarial federated learning method process based on cluster - head selection and knowledge distillation, the cluster - head vehicle, as the teacher model, generates adversarial samples to approximate the output of the student model. Students share the training model parameters, avoiding repeated discrimination and reducing the computational overhead of the aggregation model. At the same time, the attacker cannot obtain the complete gradient information and it is difficult to reconstruct the model and the original samples, increasing the security of the learning process.

[0125] Embodiment

[0126] To better illustrate the technical solution of the present invention, specific examples are used to simulate and verify the present invention. In this embodiment, complex application scenarios are created according to application requirements to verify the effectiveness of the method. In this embodiment, two complex maps are generated, and 30 and 50 vehicle clients are respectively configured. The average speed of the vehicles within the cluster is 60 km / h and 120 km / h, and the communication transmission rate of the vehicle cluster is set to 10 Mbit / s - 60 Mbit / s. Figure 4 is a schematic diagram of two vehicle - cluster scenarios in this embodiment. As Figure 4 shown, the vehicle numbers in the two scenarios are respectively recorded as A1 - A30 and A1 - A50, which include malicious participants. The cluster - head vehicle is represented by a red mark, and the blue mark is the cluster - head member vehicle. It can be seen that in Figure 4 (a) The cluster - head vehicle in the shown scenario is A13, with a communication rate of 36 Mbit / s, a speed of 61 km / h, and position information: x(201.89, 88.35), Figure 4In the scenario shown in (b), the cluster head vehicle is A46, with a communication rate of 46 Mbit / s, a speed of 102 km / h, and location information: x(465.02, 438.04)). Then, an adversarial federated learning model is deployed in the vehicle cluster.

[0127] To simulate data heterogeneity in the application scenario, in this embodiment, two settings of independent and identically distributed and non-independent and identically distributed are established, different datasets (FMNIST and CIFAR10) are evaluated, and heterogeneity is simulated by assigning different data volume labels to different datasets. The FMNIST dataset focuses on complex object recognition tasks and contains 10 categories of daily items. The CIFAR10 dataset contains 60,000 RGB images, and the validation samples in the dataset are selected as vehicle-related images (cars, trucks, and other vehicles). To verify the effectiveness and robustness of the defense against gradient reversal attacks, in this embodiment, the test is repeated by changing the labels in each dataset, and gradient reversal reconstruction simulation is performed in the above two datasets and the vehicle cluster.

[0128] To compare the technical effects of the present invention, in this embodiment, the FedAvg and FedDD algorithms are used as baseline methods. Figure 5 It is a visualization evaluation comparison chart of the model reconstruction of the present invention and the comparative method in this embodiment. Figure 5 The results in the first row show the original target image (randomly selected target images of the same category), the second to third rows are the visualization images of the reconstructed FedAvg and FedDD algorithms for comparative evaluation, and the fourth row is the method proposed by the present invention. As Figure 5 shown, in the first group of experimental groups, it is observed that the images reconstructed using the conventional FedAvg method contain some features and textures similar to the original images; in the second group of experiments, the selected data samples are RGB images, and it is observed that the technology proposed by the present invention can better defend against attackers from reconstructing the original images. Especially when the background color is similar to the object color, it is more difficult for the reconstructed images to retain the information of the original data samples.

[0129] To verify the performance of the method of the present invention under different cluster head attribute constraints, a neural network is deployed on the vehicle client to complete the classification task of the method. The 6-layer convolutional neural network deployed on the local client contains 3 convolutional layers, 1 max pooling layer, and 2 fully connected layers. Logit is the unnormalized probability and is used as the input of softmax in knowledge distillation. In the federated learning training, each vehicle client in the vehicle cluster trains the local model for 500 local iterations.

[0130] Figure 6 It is a curve graph showing the state change of the local aggregation loss function of each vehicle cluster in the present invention and the comparative method in this embodiment. Figure 6 (a) and Figure 6(b) is the loss function curves of two groups of vehicle clusters and data samples in the inventive method. Figure 6 (c) and Figure 6 (d) are the loss function curves of FedAvg and FedDD. Figure 6 It is described that Student Loss Real is the loss value of the discriminator's student model for real data, which measures the classification difference degree of the student model on real data samples, and Student Loss Fake is the loss value of the student model on fake data, which measures the difference degree between the prediction of the student model and the fake label. The observation results show that in the first group of experiments, within the range where the model is trained to epochs = 40, the discriminative loss value of the generated samples is reduced to 0.2. In the multi-dimensional RGB image data samples of the second group of experiments, the discriminative performance of the student model remains relatively stable, and the loss value is within the range of 0.1, showing a certain degree of robustness. Compared with the other two methods, the curves of SLR and SLF of the present invention gradually decline. The gradual increase of GAN loss is because the competition between the generator and the discriminator becomes more intense, and the discriminator is more sensitive to the features of the samples generated by the generator. The discriminator as the student model can support the adversarial samples generated by the teacher model to be closer to real samples, thus ensuring the security of the data.

[0131] Next, evaluate the performance of the teacher model of the present invention in the machine learning classification task, and repeat the test in two groups of experimental data respectively. Figure 7 It is the experimental graph of the comparative evaluation of the confusion matrix on the FMNIST and CIFAR10 data sets in this embodiment. Figure 7 (a) In the FMNIST data set, the performance of the local aggregation model within the vehicle cluster is improved relative to Figure 7 (c) the model classification accuracy of the same data samples. For example, for the category of the label "shirt", the misclassification index is reduced from 97 to 2. In CIFAR10, in the RGB image task of the present invention, the proposed adversarial federated learning method based on cluster head selection and knowledge distillation in the vehicle network is reasonably allocated in limited computing resources. While the performance classification of the student model is guaranteed, the local aggregation model of the teacher model has superiority in the evaluation. For example, in the label "dog", the number of misclassifications is greatly reduced.

[0132] In summary, the present invention effectively avoids attackers from obtaining the gradient to reverse engineer the model, and the teacher model shows superior performance in terms of effectiveness and generalization ability.

[0133] Although the above-described illustrative embodiments of the present invention have been described to facilitate understanding of the present invention by those skilled in the art, it should be clear that the present invention is not limited to the scope of the specific embodiments. For those of ordinary skill in the art, as long as various changes are within the spirit and scope of the present invention defined and determined by the appended claims, these changes are obvious, and all inventions made using the concept of the present invention are within the scope of protection.

Claims

1. An adversarial federated learning method based on cluster head selection and knowledge distillation in Internet of Vehicles, characterized in that: The following steps are involved: S1: The adversarial federated learning server uses autonomous clustering networking in the vehicle self-organizing network to build vehicle clusters, and then selects the cluster head vehicle in each vehicle cluster; S2: Set a teacher model and generator G according to the image classification model to be used for adversarial federated learning, and deploy the generator G and the teacher model on the cluster head vehicle; the generator G is used to generate adversarial samples based on the real samples of the cluster head vehicle, and the adversarial samples are used as knowledge distillation data; The image classification model is then deployed as a student model on other member vehicles in the vehicle cluster. At the same time, a discriminator D is configured for each student model to discriminate and distinguish adversarial samples from real samples. S3: Use the following method to conduct adversarial federated learning: S3.1: Let the number of iterations g = 1; S3.2: Cluster head vehicle collection M t True samples (x i ,y i ), x i represents the input image of the i-th real sample, y i Represents the input image x i Label y i ,y i =1,2,…,K, K represents the number of categories, i=1,2,…,M t ; Then for each input image x i Generate adversarial sample input images through generator G And set the input image Tags Then the adversarial sample Sent to the adversarial federated learning server and other member vehicles in the vehicle cluster; S3.3: The cluster head vehicle inputs the real samples and adversarial samples into the teacher model and obtains the probability q that each real sample belongs to the kth category i,k , and the probability that each adversarial example belongs to the kth category k=1,2,…,K; then use the following formula to calculate the cross entropy loss L of the real sample in the teacher model t : Where k = 1, 2, ..., K; The cluster head vehicle converts the cross entropy loss L of the teacher model t And the probability corresponding to each adversarial sample Send to the adversarial federated learning server; S3.4: Each member vehicle in the vehicle cluster collects real samples (x n,m ,y n,m ), x n,m represents the input image of the mth real sample collected by the nth member vehicle, y n,m Represents the input image x n,m Labels, m = 1, 2, ..., M s,n , M s,n represents the number of real samples collected by the nth member vehicle in the vehicle cluster and input into the student model, n = 1, 2, ..., N-1, N represents the number of vehicles in the vehicle cluster; The member vehicles input the real samples and adversarial samples collected locally into their student models and obtain the probability p that each real sample belongs to the kth category. n,m,k And the probability that each adversarial example belongs to the kth category Each member vehicle in the vehicle cluster uses the following formula to calculate the real sample cross entropy loss L in the student model: s,n : Among them, y n,m represents the label of the mth real sample collected by the nth member vehicle; The member vehicles input the real samples and adversarial samples collected locally into the discriminator D to obtain the discriminant result of whether it is a real sample, and then calculate the generation loss and the discriminative loss Each member vehicle of the student model has its cross entropy loss L s,n , Generate loss Discriminative loss The probability of each adversarial sample corresponding to the kth category Send to the adversarial federated learning server; S3.5: Calculate the cross entropy loss function L of the student model and the teacher model for adversarial sample prediction A : Calculate the KL divergence loss L between the student model and the teacher model for the adversarial sample prediction KL : in, It represents the KL divergence of the prediction results of the student model and the teacher model for the adversarial sample on the nth member vehicle. The calculation formula is: The loss function LOSS of the teacher model is calculated using the following formula: t : Among them, λ is the hyperparameter coefficient; The generation loss LOSS of the generator G is calculated using the following formula: G : The shared loss function LOSS of the student model is calculated using the following formula: s : The shared discriminant loss LOSS of the discriminator is calculated using the following formula: D : S3.6: Adversarial federated learning server based on the loss function LOSS of the teacher model t Calculate the gradient Δ t , according to the generation loss LOSS of the generator G G Calculate the gradient Δ G , according to the shared loss function LOSS of the student model s Calculate the shared gradient Δ of the student model s , according to the shared discriminant loss LOSS of the discriminator D Calculate the shared gradient Δ of the discriminator D D ; The adversarial federated learning server will be gradient Δ t and the gradient Δ G Sent to the cluster head vehicle, the teacher model on the cluster head vehicle is based on the gradient Δ t Update the parameters, the generator G according to the gradient Δ G Update parameters; adversarial federated learning servers will share gradients Δ s and the shared gradient Δ D Sent to each member vehicle in the vehicle cluster, the student model on the member vehicle is based on the shared gradient Δ s Update the parameters, the discriminator D according to the shared gradient Δ D Update parameters; S3.7: Determine whether the number of iterations g < G, where G represents the preset maximum number of iterations. If so, proceed to step S3.8, otherwise, adversarial federated learning ends; S3.8: Set g=g+1, and return to step S3.2; S4: Each member vehicle sends the parameters of its student model to the adversarial federated learning server. The adversarial federated learning server aggregates the parameters of N-1 student models and uses the final parameters to update the parameters of the image classification model.

2. The adversarial federated learning method according to claim 1, characterized in that: The method for selecting the cluster head vehicle in step S1 is: S1.1: Let the vehicle cluster be U, which contains N vehicles, and let the jth vehicle be V j , j = 1, 2, ..., N, record vehicle V j The vehicle cluster after leaving is U j =U / {V j }, the vehicle V is calculated using the following formula j The speed function is: Among them, ν j′ Represents the vehicle cluster U j Vehicle V j′ The speed value, is the vehicle cluster U j The average speed of all vehicles in S1.2: Calculate the vehicle V using the following formula j The core position function LF j : Among them, (a j′ ,b j′ ) represents the vehicle cluster U j Vehicle V j′ The position coordinates of j ,b j ) indicates vehicle V j The position coordinates of , |||| means to find the norm; S1.3: Calculate the vehicle V using the following formula j Communication performance function URF j : in, represents the average end-to-end delay, indicating that information is transmitted from a vehicle node V in the cluster j Teleport to vehicle cluster U j The average time difference of other vehicle nodes in the jj′ Indicates information from vehicle V j Transmitted to vehicle V j′ Time; UTR j′ is the vehicle cluster U j Vehicle V j′ The transmission rate of the vehicle V j′ Maximum data transmission rate per second; MTR j It is the preset minimum data transmission rate of vehicle nodes through cluster head nodes; S1.4: Calculate each vehicle's V using the following formula j A comprehensive benchmark function UAF j : UAF j =w1VF j +w2LF j +w3URF j Wherein, w1, w2, w3 represent preset weights and satisfy w1+w2+w3=1, w1>>w2, w3; S1.5: Select the vehicle with the smallest comprehensive benchmark function from vehicle cluster U as the cluster head vehicle.

Citation Information

Patent Citations

  • Point cloud scene segmentation method based on knowledge distillation and semantic fusion

    CN111462137A

  • Internet of vehicles intrusion detection model training method based on federated learning, intrusion detection method and equipment

    CN116055335A