Persistent Verification Method for the Right to Be Forgotten of the Federal Federated Learning Client
By injecting permanent private imprints into federated restore learning and leveraging backdoor attack verification methods, the problem of inaccurate client data verification is solved, the accuracy and security of verification is improved, and the model performance is maintained.
Patent Information
- Application Number
- CN202411289520.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-14
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2044-09-14
AI Technical Summary
The existing federated restore learning methods are difficult to provide exiting clients with means to independently verify whether their data has been effectively removed, and the backdoor attack-based approach has the problem of trigger catastrophic forgetting under the federated learning framework, resulting in inaccurate verification.
Ensure that the imprint remains valid in the model by injecting permanent private imprints into the client's data and scaling adjustments during the central server aggregation phase. Using the backdoor attack method, by observing the model's response to data with private imprints, verifying whether the data has been successfully forgotten.
Improve the accuracy and security of data verification of forgotten client, ensure that the execution of data deletion requests can be effectively verified, avoid potential privacy leakage problems, and ensure the persistence of the imprint while maintaining the accuracy of the main task of the model.
Smart Images

Figure CN119106448B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to federated learning technology, and particularly to a method for continuously verifying the right to be forgotten of a federated reduction learning client. Background Art
[0002] Federated learning is a distributed machine learning method aimed at protecting data privacy, which allows multiple participants to jointly train a model without sharing the original data. Although federated learning can theoretically reduce the risk of data leakage, with the increasing demand for data privacy, how to effectively delete specific data from the trained global model has become a new challenge. Federated reduction learning emerges as the times require, aiming to provide privacy protection for data subjects and ensure that their data can be completely removed from the model when a deletion request is made. To meet the compliance requirements of the "right to be forgotten", the goal of federated reduction learning is to ensure that the impact of the data of a specified client on the model is completely eliminated while maintaining the model performance. This can be achieved by completely re-initializing the model and re-training it with the data of the remaining clients, or by adjusting the model parameters and decision boundaries to minimize the residual impact of the deleted data on the model.
[0003] Existing federated reduction learning methods mainly focus on evaluating from the perspective of the global model, while ignoring the needs of clients that have exited the federated learning process. These methods usually quantify the forgetting effect by calculating the "Rate of Unlearning" (ROU), but they cannot provide a means for exited clients to independently verify whether their data has been effectively removed. Moreover, among the existing reduction learning evaluation metrics, one possible evaluation method is to implement it through a Membership Inference Attack (MIA). MIA is mainly used to determine whether a certain data sample exists in the training dataset of the model, and usually uses metrics such as accuracy, recall, and precision to quantify the forgetting degree of the model. However, in the federated learning framework, due to the possible similar data distributions among different clients, it is difficult for MIA to accurately identify which specific client the forgotten data comes from. In addition, MIA may also lead to the privacy leakage of the training data.
[0004] To solve these problems, another method is to utilize a Backdoor Attack. Different from MIA, the backdoor attack implants specific "triggers" in part of the training data, so that the model can exhibit specific and controllable behaviors when encountering these triggers. In federated reduction learning, the backdoor attack generates unique triggers for the client that makes a forgetting request, trains them together with the training data, and then aggregates the client parameters and submits them to the central server. By observing the reaction of the model to the triggers before and after forgetting learning, that is, the accuracy on the backdoor task, the "forgetting" degree of the data is evaluated.
[0005] However, under the federated learning framework, verifying the forgetting effect of federated reduction learning based on backdoor attack methods faces many challenges. Each aggregation and update of federated learning will cause changes in the parameters of the global model, which may trigger the catastrophic forgetting problem of the trigger, resulting in inaccurate data forgetting verification metrics. Summary of the Invention
[0006] Object of the Invention: The object of the present invention is to solve the deficiencies existing in the prior art and provide a method for continuously verifying the right to be forgotten of a federated reduction learning client.
[0007] Technical Solution: The method for continuously verifying the right to be forgotten of the federated reduction learning client of the present invention involves two types of entities: a central server and several clients, and includes the following steps:
[0008] Step 1, injecting a permanent imprint;
[0009] For the data to be sent from the client participating in the reduction learning to the central server, first generate different local imprints by combining the global imprint of the data using an extended local imprint combination method, then combine and extend the different local imprints using a local trigger generation strategy, and then inject the combined and extended permanent private imprint into the data. In the aggregation stage of the central server, scale and adjust the client updates containing the private imprint;
[0010] Step 2, training federated reduction learning for each forgetting client;
[0011] The central server selects a set C = {C1, C2,..., Ci,..., Cn} of N clients to participate in the federated learning training. Each client stores a different local dataset D = {D1, D2,..., Di,..., Dn}, i ∈ {1, 2,..., n}. In each round of federated learning training, a certain proportion of misclassified samples are added for training, and the samples contain the private imprint obtained in Step 1, and then the imprint is injected into the local model;
[0012] Here, the client that submits a data deletion request is called a forgetting client. Assume that the forgetting client Cn initiates a deletion request. For federated reduction learning, delete the influence of all updates of the client Cn in the global model G t and then eliminate the influence of the local data Dn of the client Cn on the final global model, and output a final model F u , as if the client Cn has never participated in the federated learning training process;
[0013] Step 3, verifying the forgetting client;
[0014] By determining whether the data with a private imprint can be activated, it helps the forgetting client verify whether the detection center server complies with the data deletion request, such as Figure 1 As shown, after the imprinted client trains the model, there are imprinted features in the model. Therefore, we can use it to detect whether the requests of the forgetting client are followed.
[0015] The present invention effectively verifies the execution of the forgetting client's deletion request. Before the client sends data to the central server, a private imprint is injected into the data of each forgetting client, and the source label of these data is changed to the target label. To enhance the persistence of the private imprint, a set of extended local imprint combinations is constructed to ensure that the global model can learn a more complete backdoor pattern, so that even after multiple rounds of model iteration updates, a high attack success rate can be maintained. On the basis of optimizing the private imprint, a scaling strategy is also introduced in the central server aggregation stage to appropriately scale and adjust the client updates containing the private imprint, improving the stability and persistence of the private imprint and making it remain effective in the model for a longer time.
[0016] Further, the specific process of injecting the permanent imprint in step 1 is as follows:
[0017] Step 1.1: Generate the imprint;
[0018] Divide the global imprint into multiple local imprints, and use a combination method to permute and combine all local imprints to generate different local imprints, and distribute them to each forgetting client for training according to the distributed attack setting;
[0019] Step 1.2: Local trigger generation strategy, that is, generate diverse imprint combinations by combining different triggers;
[0020] For a total of M forgetting clients, the total number of corresponding local triggers LT, it is necessary to infer m kinds of imprint combinations, and obtain a better trigger partition through an optimized combination algorithm: while ensuring the effectiveness of the private imprint, minimize the trigger partition granularity m and the combination size k, and solve:
[0021]
[0022] In the above formula, M represents the number of clients to be forgotten, m represents the granularity of the global trigger partition, that is, divided into m basic units, and k represents the combination size of the local trigger, that is, select k from m units for combination;
[0023] First, solve the minimum value of m, so that any selection from m parts can generate a sufficient number of unique combinations to be assigned to all M forgetting clients;
[0024] Then calculate the combination method of the triggers: Divide the global triggers into m different units, and generate local triggers with different combinations of different units. The expression is as follows:
[0025]
[0026] Step 1.3: Inject the imprint;
[0027] During the t-th round of communication, the central server sends the current shared model G t to N selected participating parties. The selected participating party i will perform local training using the optimization algorithm locally to obtain a new local model Then the local participating parties will update the model;
[0028] After the central server receives the model update, it uses its own learning rate to average all the updates to generate a new global model G t+1 , as shown in the following formula:
[0029]
[0030] The injected private imprint uses the coefficient η to amplify the weights of the backdoor model to ensure the effectiveness of the private imprint when triggered. The global model at this time is expressed as:
[0031]
[0032] Furthermore, to ensure the security of users' personal data during the federated learning training process, the present invention allows deleting the data contributions of specific clients from the global model during federated learning, giving clients the right to be forgotten. The goal is to, while forgetting the influence of certain clients' data on the global model as much as possible, still maintain the overall performance of the model to ensure that even if some clients' data is deleted, the global model can still maintain high performance, thereby effectively protecting users' data privacy; The updated model expression in step 2 is as follows:
[0033]
[0034] where p represents the number of remaining clients (excluding the forgotten clients), t represents the current t-th round of communication, represents the local model of client i during the t-th round of communication.
[0035] Furthermore, when verifying the forgotten clients in step 3, the definition of the forgetting degree of the forgotten clients is as follows:
[0036] Express the forgetting rate after the i-th round of forgetting as:
[0037]
[0038] Among them, assume that A0 is the backdoor success rate measured under the best state performance of the model when the imprint is just injected, and A fu represents the success rate of the backdoor attack on the model after forgetting ends; it is quantified by measuring the performance difference of the model on the backdoor task (i.e., the sensitivity triggered by the imprint) before and after forgetting. When the model is no longer sensitive to the imprint, it means that the success rate on the backdoor task will decrease. The present invention does not require all clients to participate in the verification, only the forgetting clients, and their backdoor success rates are as follows:
[0039]
[0040] Among them, represents the test set of the forgetting client i, which contains the private imprint embedded by the client i. x represents a sample in the test set, yj represents its true label, and yt represents the target label. Let represent the global model obtained after the r-th round of federated reduction learning, and θ r represents the parameters of the model in the r-th round, represents the size (total number of samples) of the test set of the forgetting client i, φ represents the number of samples of the condition, and II(·) represents the indicator function, which takes the value of 1 when the condition is true and 0 otherwise.
[0041] Beneficial effects: By embedding persistent imprints, the present invention can effectively evaluate the forgetting effect of the forgotten data in the federated learning process. Compared with traditional methods, the method of the present invention has significant advantages in multiple aspects:
[0042] (1) Improve verification accuracy: The present invention embeds the EnduraMark imprint in the data of the forgetting client and tracks the performance of the global model in multiple training rounds to ensure that it can accurately verify whether the data is successfully forgotten. Experimental results show that even after multiple model iteration updates, the triggering effect of the imprint still remains good, thus improving the reliability of the verification.
[0043] (2) Protect client privacy: Different from traditional membership inference attack methods, the present invention uses backdoor attacks to evaluate the forgetting effect, avoiding potential privacy leakage problems. The behavior triggered by the imprint is specific and controllable, further enhancing the security of the forgetting effect verification.
[0044] (3) Protect the effectiveness of client verification: The present invention introduces an improved scaling strategy and imprint enhancement data augmentation method, enhancing the persistence of the private imprint in the federated learning model and reducing the impact of model benign updates on imprint dilution, so that the client still has high effectiveness in long-term model training.
[0045] (4) Little impact on the main task of the model: While maintaining the accuracy of the model's main task, the method of the present invention can effectively embed and maintain private imprints. Experiments show that the accuracy of the model using EnduraMark of the present invention on the main task is almost the same as that of the model without using imprints, indicating that the solution of the present invention will not significantly reduce the model performance while verifying the forgetting effect. Description of the Drawings
[0046] Figure 1 Schematic structural diagram of the system of the present invention;
[0047] Figure 2 Schematic diagram of injecting imprints in the embodiment;
[0048] Figure 3 Experimental comparison chart of the attack success rate in the MNIST dataset in the embodiment;
[0049] Figure 4 Experimental comparison chart of the attack success rate in the Fashion-MNIST dataset in the embodiment;
[0050] Figure 5 Experimental comparison chart of the attack success rate in the CIFAR-10 dataset in the embodiment;
[0051] Figure 6 Experimental comparison chart of the accuracy in the MNIST dataset in the embodiment;
[0052] Figure 7 Experimental comparison chart of the accuracy in Fashion-MNIST in the embodiment;
[0053] Figure 8 Experimental comparison chart of the accuracy in the CIFAR-10 dataset in the embodiment. Detailed Embodiment
[0054] The technical solution of the present invention will be described in detail below, but the protection scope of the present invention is not limited to the described embodiments.
[0055] To reduce the negative impact of the trigger on the model while maintaining the accuracy of the main task of the global model, the present invention proposes a method for continuously verifying the right to be forgotten of a client in federated reduction learning. The entire technical solution faces two key challenges. First, due to the online learning characteristics of federated learning, model training is a dynamic and continuous process; once the trigger stops being injected, subsequent normal updates may quickly dilute the backdoor effect in the global model, resulting in a decrease in the effectiveness of the backdoor attack as the number of iterations increases; therefore, designing a method that can improve the persistence of the trigger, as a verification metric for federated reduction learning, has become a challenge. Second, since the client holding the trigger participates in the aggregation of the global model through distributed training, the presence of the trigger may cause the model to exhibit incorrect behavior on the main task.
[0056] As Figure 1 shown, to solve the above problems, the method for continuously verifying the right to be forgotten of a client in federated reduction learning of the present invention involves two types of entities: a central server and several clients, and includes the following steps:
[0057] Step 1, inject a permanent mark;
[0058] For the data to be sent from the client participating in reduction learning to the central server, first generate different local marks using the extended local mark combination method for the global mark of the data, then use the local trigger generation strategy to combine and expand the different local marks, and then inject the combined and expanded permanent private mark into the data. In the central server aggregation stage, scale and adjust the client updates containing the private mark.
[0059] Step 2, train federated reduction learning for each forgetting client;
[0060] The central server selects a set C = {C1, C2,..., Ci,..., Cn} of N clients to participate in federated learning training. Each client stores a different local dataset D = {D1, D2,..., Di,..., Dn}, i ∈ {1, 2,..., n}. In each round of federated learning training, a certain proportion of misclassified samples are added for training, and the samples contain the private mark obtained in Step 1, and then the mark is injected into the local model.
[0061] Here, the client that submits a data deletion request is called a forgetting client. Assume that the forgetting client Cn initiates a deletion request. For federated reduction learning, delete the influence of all updates of the global model G t that belong to the client Cn, and then eliminate the influence of the local data Dn of the client Cn on the final global model, and output a final model F u ;
[0062] Step 3, verify the forgetting client;
[0063] By determining whether the data with the private mark can be activated, it helps the forgetting client verify whether the detection center server complies with the data deletion request.
[0064] The specific process of injecting the permanent mark in step 1 of this embodiment is as follows:
[0065] Step 1.1: Generate marks;
[0066] Divide the global mark into multiple local marks, and use the combination method to permute and combine all local marks to generate different local marks, and distribute them to each forgetting client for training according to the distributed attack setting;
[0067] Step 1.2: Local trigger generation strategy, that is, generate diverse mark combinations by combining different triggers;
[0068] For a total of M forgetting clients, the total number of corresponding local triggers LT, it is necessary to infer m mark combinations, and obtain a better trigger partition through an optimized combination algorithm: while ensuring the effectiveness of the private mark, minimize the trigger partition granularity m and the combination size k, and solve:
[0069]
[0070] In the above formula, M represents the number of clients to be forgotten, m represents the granularity of the global trigger partition, that is, divided into m basic units, and k represents the combination size of the local trigger, that is, select k from m units for combination;
[0071] First, solve the minimum value of m so that any selection from m parts can generate a sufficient number of unique combinations to be assigned to all M forgetting clients;
[0072] Then calculate the combination method of the trigger: divide the global trigger into m different units, and generate local triggers by different combinations of different units, and its expression is as follows:
[0073]
[0074] For example, assume represents the global trigger, which is used to control the style of the global trigger represents the local trigger of the forgetting client C(i). For image data, it can be decomposed into the trigger size TS, the trigger location TL, and the trigger gap TG and other factors.
[0075] For ease of description, it is assumed here that three clients submit forgetting requests. By means of transformation and combination, three unique trigger mode combinations are generated from the global trigger and embedded into the datasets of the corresponding clients.
[0076] The purpose of the experiment is to assign a predetermined target label, denoted as Yt, to the data containing the backdoor trigger, while the clean data retains its original label, denoted as Yj. The main purpose of the present invention is to train a model to, without affecting its ability to accurately identify and classify unmodified data, especially respond to the imprint generation method (EnduraMark), induce the model to control the response, and facilitate the study of the model's ability to selectively forget the data associated with the embedded trigger under the constraint of maintaining the overall performance;
[0077] Step 1.3, Inject the imprint;
[0078] At the t-th round of communication, the central server sends the current shared model G t to N selected participating parties. The selected participating party i will perform local training using an optimization algorithm locally to obtain a new local model Then the local participating party will update the model;
[0079] After receiving the model update, the central server uses its own learning rate to average all the updates to generate a new global model G t+1 , as shown in the following formula:
[0080]
[0081] The injected private imprint uses the coefficient η to amplify the weights of the backdoor model to ensure the effectiveness of the private imprint when triggered. The global model at this time is expressed as:
[0082]
[0083] The updated model expression in step 2 of this embodiment is as follows:
[0084]
[0085] where p represents the number of remaining clients (excluding the forgetting clients), t represents the current t-th round of communication, represents the local model of client i at the t-th round of communication.
[0086] When verifying the forgetting clients in step 3 of this embodiment, the definition of the forgetting degree of the forgetting clients is as follows:
[0087] The forgetting rate after the i-th round of forgetting is expressed as:
[0088]
[0089] Among them, assume that A0 is the backdoor success rate measured under the best state performance of the model when the imprint is just injected, and A fu represents the success rate of the backdoor attack on the model after forgetting ends; the backdoor success rate is defined as follows:
[0090]
[0091] represents the test set of forgetting client i, which contains the private imprint embedded by client i, x represents a sample in the test set, and y j represents its true label, and y t represents the target label. Let represents the global model obtained after the r-th round of federated forgetting learning, and θ r represents the parameters of the model in the r-th round. Among them, represents the size (total number of samples) of the test set of forgetting client i, φ represents the number of samples of the condition, and II(·) represents the indicator function, which takes the value of 1 when the condition is true and 0 otherwise.
[0092] Example 1
[0093] To maintain fairness, in this example, the technical solution of the present invention and the traditional backdoor attack method both complete backdoor injection in the same round, and use a consistent global trigger for evaluation, and start the attack after the forgetting learning in the same round is completed. This example focuses on the persistence of the backdoor attack. The backdoor success rate is calculated for 0 - 100 rounds after the imprint is injected, and the persistence of the attack can be illustrated according to the curve trend of the attack success rate.
[0094] To prove the existence of the problem of imprint timeliness during the model training process, this example conducts experiments on the MNIST, Fashion - MNIST, and CIFAR - 10 datasets. Among them, the client with pre - forgotten data has 50% clean samples and 50% imprinted samples to study the impact of the model's benign update.
[0095] Figures 3 to 5Shows the experimental results of this embodiment. At the 50th round, the timeliness of the two methods remains the same. After increasing the number of training rounds after 50 rounds of imprint training, although the benign updates will dilute the attack success rate, the attenuation speed trend of the Enduramark of the present invention is slower than that of the traditional backdoor (BadNet) method. After 100 rounds of training, the results of the Enduramark of the present invention on MNIST, Fashion-MNIST and CIFAR-10 are 86.27%, 89.27%, and 52.79% respectively, while the attack success rates of the traditional BadNet method are 68.77%, 78.15%, and 16.85% respectively. In comparison, the triggering effect of the Enduramark method still performs excellently.
[0096] Example 2
[0097] This embodiment conducts experiments on the accuracy of the technical solution. By calculating the accuracy on the main task before and after federated forgetting learning respectively and calculating the impact of the EnduraMark of the present invention on the model based on their difference. The reason for this setting is that the forgetting algorithm may also lead to the accuracy of the model on the main task. The accuracy is used to measure the prediction ability of the classifier generated by training in the test set, that is, how many samples are correctly predicted by the classifier. Then the accuracy difference is expressed as:
[0098] Accd = Acc - Acc unlearning
[0099] For normal federated training and federated training with imprints added by a single user until global convergence, compare the change in the accuracy difference during the training process, as Figure 6 shown. The accuracy of the two training methods increases rapidly in the initial few rounds. Especially after the first 10 rounds, the accuracy growth starts to level off and finally stabilizes. Throughout the training cycle, the accuracy of the model using the imprint technique is very close to that of the conventional training model, which indicates that the imprint generation method EnduraMark of the present invention performs well in maintaining the model performance and has little impact on the model accuracy.
[0100] Example 3
[0101] For the verification of federated forgetting learning, in this embodiment, an imprint is injected into the data of the forgetting clients so as to subsequently verify whether the central server complies with the data deletion request. Specifically, an enduramark is injected into the user's private data, and then the source label of the data is changed to the target label. In each round, 10 clients are selected to submit local update aggregations. The target label is set to "3" for the MNIST dataset, "Sandal" for the FashionMNIST dataset, and "Bird" for the CIFAR-10 dataset. Excluding the key factor analysis, the trigger factor for MNIST is set to The trigger factor for CIFAR-10 is set to {6, 3, 0}, and the global learning rate lr for all datasets is set to 0.005.
[0102] In this embodiment, the success rate of the imprint trigger is tested in two stages before and after forgetting, and then the accurate forgetting rate is calculated through formula (10); the federated forgetting learning forgetting rates are measured on PGA, FedEraser, and FedAccum respectively, and the results are as Figure 7 , Figure 8 and Table 1 show.
[0103] Table 1
[0104]
[0105] In summary, by embedding persistent markers, the present invention enables the clients that withdraw from the FL cooperation to continuously verify the execution effect of FU for a long time. The verification method of the present invention uses the backdoor enhancement technology, combines the original global trigger (global marker) to generate multiple local markers, and injects them into the dataset for backdoor training, thereby enhancing the model's response to these specific markers.
Claims
1. A method for continuous verification of the right to be forgotten of a federated restoration learning client, characterized in that: Involving two types of entities: a central server and several clients, the following steps are included: Step 1: Inject permanent marks; For the data to be sent to the central server by the client participating in the restoration learning, the global imprint of the data is first generated into different local imprints using the extended local imprint combination method, and then the different local imprints are combined and extended using the local trigger generation strategy, and then the combined and extended permanent private imprint is injected into the data. In the central server aggregation stage, the client updates containing private imprints are scaled and adjusted; The specific method of injecting the imprint is: In the tth round of communication, the central server sends the current shared model G t Sent to N selected participants, the selected participant i will use the optimization algorithm to perform local training locally to obtain a new local model The local parties will then update the model; After receiving the model update, the central server uses its own learning rate to average all updates to generate a new global model G t+1 , as shown below: The injected private imprint uses the coefficient η to amplify the weight of the backdoor model to ensure the effectiveness of the private imprint when it is triggered. The global model at this time is expressed as: It refers to the total number of local triggers in round t+1; m represents the granularity of global trigger partition; Step 2: Train federated restoration learning on each forgotten client; The central server selects N client sets C = {C1, C2, ..., Ci..., Cn} to participate in the federated learning training. Each client saves a different local data set D = {D1, D2, ..., Dv..., Dq}, v∈{1, 2, ..., q}. In each round of federated learning training, a certain proportion of misclassified samples are added for training. The samples contain the private imprint obtained in step 1, and then the imprint is injected into the local model. Here, the client that makes a data deletion request is called a forgotten client. Assume that the forgotten client Cn initiates a deletion request. For federated restoration learning, the global model G is deleted. t The influence of all updates of client Cn in the model is eliminated, thereby eliminating the influence of client Cn’s local data Dq on the final global model and outputting a final model F u ; Step 3: Verify the forgotten client; By determining whether data with private imprints can be activated, it helps the forgetting client verify whether the detection center server complies with the data deletion request.
2. The method for continuous verification of the right to be forgotten of the federated restoration learning client according to claim 1 is characterized in that: The specific process of injecting the permanent mark in step 1 is: Step 1.1, generate imprint; Divide the global imprint into multiple local imprints, and use the combination method to permute and combine all local imprints to generate different local imprints, and distribute them to each forget client for training according to the distributed attack setting; Step 1.2: local trigger generation strategy, i.e. generating diversified imprint combinations by combining different triggers; For a total of M forgotten clients, the total number of local triggers corresponding to them is LT. It is necessary to infer m combinations of imprints and obtain better partitioning of triggers by optimizing the combination algorithm: while ensuring the validity of private imprints, minimize the trigger partition granularity m and the combination size k. Solve: In the above formula, M represents the number of clients that need to be forgotten, m represents the granularity of the global trigger partition, that is, it is divided into m basic units, and k represents the combination size of the local trigger, that is, k units are selected from m units for combination; First, find the minimum value of m such that any selection from the m parts can generate enough unique combinations to distribute to all M forgotten clients; Then calculate the combination of triggers: divide the global trigger into m different units, and generate local triggers with different units in different combinations. The expression is as follows: Step 1.3, inject the imprint.
3. The method for continuous verification of the right to be forgotten of the federated restoration learning client according to claim 1 is characterized in that: The updated model expression in step 2 is as follows: Where p represents the number of remaining clients, t represents the current tth round of communication, Represents the local model of client i in the tth round of communication.
4. The method for continuous verification of the right to be forgotten of a federated restoration learning client according to claim 1 is characterized in that: When verifying the forgotten client in step 3, the definition of the forgotten degree of the forgotten client is as follows: The forgetting rate after the i-th round of forgetting is expressed as: Assume that A0 is the backdoor success rate measured under the best performance of the model when the imprint is just injected, and A fu It indicates the success rate of backdoor attack on the model after forgetting ends; the backdoor success rate is defined as follows: represents the test set of forgotten client i, which contains the private imprint embedded by client i, and x represents a sample y in the test set. j represents its true label, y t represents the target label, let M θr represents the global model obtained after the rth round of federated reduction learning, θ r represents the parameters of the model in the rth round, where represents the size of the test set of the forgotten client i, φ represents the number of samples of the condition, and II(·) represents the indicator function, which takes the value of 1 when the condition is true and 0 otherwise.
Citation Information
Patent Citations
Platform for forgetting and verifying data in federal learning
CN113887743A
Federal forgetting learning method based on historical update correction
CN118036708A