A federated learning method, apparatus, medium, and product
Patent Information
- Application Number
- CN202411135328.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-19
- Publication Date
- 2026-09-25
- Estimated Expiration
- 2044-08-19
AI Technical Summary
然而,当前联邦学习领域依然面临诸多挑战,例如传统集中式服务器下的单点故障问题,分布式客户端的数据伪造和激励不足问题等,这些挑战使得探索更安全、更透明的联邦学习技术成为当前该领域研究的重点
[0029]本发明提出并实现了一种创新的区块链联邦学习知识产权保护框架(BFLIPR),旨在解决去中心化场景下联邦学习中的数据安全和模型确权问题。BFLIPR框架创新性地将区块链技术、数字水印技术与联邦学习技术相结合,通过集成区块链不可篡改特性、数字水印的隐蔽性和联邦学习的分布式特性,提供了一种有效的知识产权保护机制,显著增强了数据安全性和知识产权保护能力。
Smart Images

Figure CN119204254B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of artificial intelligence, and in particular to a federated learning method, apparatus, medium, and product. Background Technology
[0002] In the era of large-scale models, federated learning, with its distributed machine learning paradigm, has become a highly anticipated cutting-edge technology. This technology trains models on multiple local data sources, eliminating the need to centralize the original datasets. After each training round, distributed clients upload the gradient parameters of their local models to a central server for aggregation. Federated learning technology enables multi-party data utilization while protecting privacy and reducing data transmission, providing an effective solution to the data silo problem. However, the field of federated learning still faces many challenges, such as the single point of failure problem inherent in traditional centralized servers, and data forgery and insufficient incentives for distributed clients. These challenges make exploring more secure and transparent federated learning technologies a key focus of current research in this field. Summary of the Invention
[0003] The purpose of this invention is to provide a federated learning method, apparatus, medium, and product that realizes source authentication of input data for federated learning model training and ownership protection of output models. At the same time, under the tamper-proof characteristics of the blockchain network, it realizes traceability of model operation records and watermark embedding for verification, which greatly enhances the robustness of the traditional federated learning framework and expands the application fields of the federated learning framework.
[0004] To achieve the above objectives, the present invention provides the following solution:
[0005] A federated learning method, the method comprising:
[0006] The parameters of the initial local business model and the private watermark parameters of multiple federated learning clients are obtained through multiple first nodes of the blockchain; where each first node corresponds to one federated learning client.
[0007] The private watermark parameters of each federated learning client are matrixed by a predefined smart contract to obtain a watermark matrix containing multiple private watermark vectors.
[0008] The private watermark vector of the watermark matrix is embedded into the parameters of the initial local business model of the corresponding federated learning client, and the federated averaging algorithm is applied to aggregate them to obtain the parameters of the initial global business model. The parameters of the initial global business model are then stored in the preset second node of the blockchain.
[0009] The consensus mechanism of the blockchain is used to verify the private watermark vector of the parameters of the initial global business model, and the verification result is obtained; the verification result includes correct and incorrect.
[0010] When the verification result is incorrect, each federated learning client uses its local dataset to train the initial local business model, obtains the updated parameters of the initial local business model, and returns to the step "obtain the parameters of the initial local business model and the private watermark parameters of each federated learning client through multiple first nodes of the blockchain" to continue execution.
[0011] When the verification result is correct, the initial global business model is used to determine whether it has converged.
[0012] When the initial global business model fails to converge, the parameters of the initial global business model are returned to each federated learning client as the parameters of the initial local business model of each federated learning client. Each federated learning client uses its local dataset to train the initial local business model, obtains the updated parameters of the initial local business model, and returns to the step "obtain the parameters of the initial local business model and the private watermark parameters of each federated learning client through multiple first nodes of the blockchain" to continue execution.
[0013] When the initial global business model converges, a global business model is obtained; the global business model is the initial global business model.
[0014] Optionally, the consensus mechanism is a practical Byzantine fault-tolerant consensus algorithm.
[0015] Optionally, a feature-based watermarking method or a backdoor-based watermarking method can be applied to embed the private watermark vector of the watermark matrix into the parameters of the initial local business model of the corresponding federated learning client.
[0016] Optionally, the feature watermarking method embeds the private watermark vector of the watermark matrix into the parameters of the initial local business model of the corresponding federated learning client through a loss function.
[0017] Optionally, when the feature watermarking method is applied to embed the private watermark vector of the watermark matrix into the parameters of the initial local business model of the corresponding federated learning client, the consensus mechanism of the blockchain is applied to verify the private watermark vector of the parameters of the initial global business model, specifically including:
[0018] Extract watermark information from the parameters of the initial global business model;
[0019] Calculate the similarity between the extracted watermark information and the private watermark parameters;
[0020] The verification result is correct when the similarity is greater than the first preset threshold; otherwise, the verification result is incorrect.
[0021] Optionally, when a backdoor-based watermarking method is applied to embed the private watermark vector of the watermark matrix into the parameters of the initial local business model of each of the federated learning clients, the consensus mechanism of the blockchain is applied to verify the private watermark vector of the parameters of the initial global business model, specifically including:
[0022] The system calls the trigger parameters stored on the blockchain, applies a predefined set of trigger samples, and calculates the accuracy of the initial global business model. The trigger parameters are stored on the blockchain when the private watermark vector of the watermark matrix is embedded into the initial local business model of each federated learning client using a backdoor-based watermarking method.
[0023] The verification result is correct when the accuracy is greater than the second preset threshold; otherwise, the verification result is incorrect.
[0024] Optionally, the method used by each federated learning client to train the initial local business model using a local dataset is stochastic gradient descent.
[0025] A computer apparatus includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the processor executing the computer program to implement the federated learning method described in any of the preceding claims.
[0026] A computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the federated learning method described in any of the preceding claims.
[0027] A computer program product includes a computer program that, when executed by a processor, implements the federated learning method described in any of the preceding claims.
[0028] According to specific embodiments provided by the present invention, the present invention discloses the following technical effects:
[0029] This invention proposes and implements an innovative blockchain federated learning intellectual property protection framework (BFLIPR), aiming to solve the problems of data security and model ownership verification in decentralized federated learning scenarios. The BFLIPR framework innovatively combines blockchain technology, digital watermarking technology, and federated learning technology. By integrating the immutability of blockchain, the anonymity of digital watermarking, and the distributed nature of federated learning, it provides an effective intellectual property protection mechanism, significantly enhancing data security and intellectual property protection capabilities. Attached Figure Description
[0030] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0031] Figure 1 A schematic diagram of a federated learning framework based on a blockchain network;
[0032] Figure 2 This is a schematic diagram of the BFLIPR framework system architecture;
[0033] Figure 3 This is a schematic diagram illustrating the generation and embedding process of the BFLIPR framework.
[0034] Figure 4 This is a schematic diagram of the digital watermark verification process within the BFLIPR framework.
[0035] Figure 5 This is a schematic diagram of the federated learning method provided in Embodiment 1 of the present invention;
[0036] Figure 6 This is a flowchart illustrating the PBFT workflow.
[0037] Figure 7 This is a diagram of the internal structure of a computer device. Detailed Implementation
[0038] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0039] The purpose of this invention is to provide a federated learning method, apparatus, medium, and product, which aims to achieve source authentication of input data for federated learning model training and ownership protection of output models. At the same time, under the immutable characteristics of the blockchain network, it enables traceable records of model operations and watermark embedding for verification, thereby enhancing the robustness of traditional federated learning frameworks and expanding the application areas of federated learning frameworks.
[0040] To make the above-mentioned objects, features and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0041] Example 1
[0042] like Figure 5 As shown, the federated learning method in this embodiment includes:
[0043] Step S1: Obtain the parameters of the initial local business model and the private watermark parameters of multiple federated learning clients through multiple first nodes of the blockchain; wherein, each first node corresponds to a federated learning client.
[0044] Step S2: The private watermark parameters of each federated learning client are matrixed using a predefined smart contract to obtain a watermark matrix containing multiple private watermark vectors.
[0045] Step S3: Embed the private watermark vector of the watermark matrix into the parameters of the initial local business model of the corresponding federated learning client, and apply the federated averaging algorithm to aggregate them to obtain the parameters of the initial global business model. Store the parameters of the initial global business model in the preset second node of the blockchain.
[0046] Specifically, the private watermark vector of the watermark matrix is embedded into the parameters of the initial local business model of the corresponding federated learning client by applying a feature watermarking method or a backdoor-based watermarking method.
[0047] Furthermore, the feature watermarking method embeds the private watermark vector of the watermark matrix into the parameters of the initial local business model of the corresponding federated learning client through a loss function.
[0048] Step S4: Apply the consensus mechanism of the blockchain to verify the private watermark vector of the parameters of the initial global business model, and obtain the verification result; the verification result includes correct and incorrect. The consensus mechanism is a practical Byzantine fault-tolerant consensus algorithm.
[0049] Specifically, when the feature watermarking method is applied to embed the private watermark vector of the watermark matrix into the parameters of the initial local business model of the corresponding federated learning client, the consensus mechanism of the blockchain is used to verify the private watermark vector of the parameters of the initial global business model, specifically including:
[0050] Step S411: Extract watermark information from the parameters of the initial global business model.
[0051] Step S412: Calculate the similarity between the extracted watermark information and the private watermark parameters.
[0052] Step S413: When the similarity is greater than the first preset threshold, the verification result is correct; otherwise, the verification result is incorrect.
[0053] When a backdoor-based watermarking method is applied to embed the private watermark vector of the watermark matrix into the parameters of the initial local business model of each of the federated learning clients, the consensus mechanism of the blockchain is used to verify the private watermark vector of the parameters of the initial global business model, specifically including:
[0054] Step S421: Call the trigger parameters stored on the blockchain, apply the predefined trigger sample set, and calculate the accuracy of the initial global business model; the trigger parameters are the parameters stored on the blockchain when the private watermark vector of the watermark matrix is embedded into the initial local business model of each federated learning client using the backdoor-based watermarking method.
[0055] Step S422: When the accuracy is greater than the second preset threshold, the verification result is correct; otherwise, the verification result is incorrect.
[0056] Step S5: When the verification result is incorrect, each federated learning client uses the local dataset to train the initial local business model, obtains the updated parameters of the initial local business model, and returns to step S1 to continue execution.
[0057] Step S6: When the verification result is correct, determine whether the initial global business model has converged based on the parameters of the initial global business model.
[0058] Step S7: When the initial global business model does not converge, the parameters of the initial global business model are returned to each federated learning client as the parameters of the initial local business model of each federated learning client. Each federated learning client uses the local dataset to train the initial local business model, obtains the updated parameters of the initial local business model, and returns to step S1 to continue execution.
[0059] Specifically, the method used by each federated learning client to train the initial local business model using a local dataset is stochastic gradient descent.
[0060] Step S8: When the initial global business model converges, a global business model is obtained; the global business model is the initial global business model.
[0061] As a specific implementation method, 1) The federated learning client uploads the trained local model information and private digital watermark parameters to the blockchain network. 2) Upon uploading to the blockchain network, the data is first verified on the blockchain via a smart contract. The smart contract allocates nodes according to pre-written steps to process the private watermark parameters (the digital watermark parameters are matrixed) to form a watermark matrix. 3) The consensus mechanism records and globally broadcasts the processed watermark matrix to all nodes for confirmation. Only if more than 2 / 3 of the nodes agree can the process proceed. 4) Finally, the confirmed watermark matrix is aggregated with the local model at the model level to form the global model for this training round. The blockchain network sends the global model to the client, which receives it and begins a new round of training. 5) Steps 1) to 4) are repeated until global convergence.
[0062] In practical applications, this invention, aiming to explore more secure and transparent federated learning technologies, considers trusted federated learning, which integrates the decentralized and immutable characteristics of blockchain technology, as one of the most promising research directions. Blockchain technology, with its core features of decentralization, immutability, and transparency, was initially designed for cryptocurrency systems but is now widely used in various fields. Blockchain ensures data immutability by linking transaction data together in timestamp order in blocks, each block containing the hash value of the previous block. Simultaneously, blockchain stores data on multiple nodes in the network, each node having the right to verify and record transactions, improving the system's resistance to attacks and fault tolerance. Figure 1 As shown, combining blockchain technology with federated learning technology has broad research value in addressing issues such as participant behavior tracing, single-point risks in federated learning systems, and positive incentives for participants. However, the federated learning framework integrating blockchain technology has shortcomings. While it has made significant progress in improving system security and data privacy protection, it still faces significant challenges in establishing model ownership, particularly in preventing illegal copying, misuse, and theft of models. Currently, some research uses digital watermarking technology as a supplementary means of model ownership verification and has conducted research based on this. As an information embedding method, digital watermarking technology achieves information authentication and tracking by embedding invisible identifiers in data. Furthermore, in multi-user scenarios, digital watermarking can also be used to verify data sources, ensure content authenticity, and track unauthorized copying or modification, thereby protecting data ownership. In current research on digital watermarking to ensure model ownership verification, this technology can significantly reduce the security risks of model theft and misuse, playing a crucial role in information security and intellectual property protection. Therefore, innovating and integrating mature digital watermarking technology into the centralized federated learning field can solve the model ownership problem for federated learning clients and prevent the risk of model misuse and theft.
[0063] In traditional federated learning (FL), sensitive user data is trained locally, while collaborative model updates occur on a centralized server. This increases the risk of system robustness and data leakage. As federated learning continues to evolve, optimizations based on traditional frameworks may not adequately address issues such as data fragmentation, privacy breaches, and model authentication. Therefore, integrating blockchain technology with federated learning aims to leverage blockchain's decentralized, immutable, and smart contract characteristics to provide a new paradigm for federated learning frameworks. This paradigm can better address issues such as data privacy breaches, collaborative model training, and data traceability.
[0064] These studies have leveraged blockchain technology to improve various aspects of federated learning. They have achieved some success not only in decentralized data management, enabling transparent and verifiable collaborative training of models, but also enhanced model credibility through smart contracts and data traceability mechanisms. However, a major limitation of these works is the lack of an effective solution for protecting the trained models.
[0065] Federated learning has certain shortcomings in the areas of model protection and ownership confirmation, especially in ensuring the privacy of the training data source and the output model. Given the difficulty of guaranteeing model security with existing methods, exploring effective authentication and ownership confirmation mechanisms for federated learning models is currently a research focus. Digital watermarking technology has a solid research foundation in centralized machine learning scenarios and provides an effective solution for ensuring the credibility and integrity of machine learning models. Therefore, applying digital watermarking technology to the distributed scenario of federated learning, providing a possibility to ensure model traceability, verify legitimate ownership, and prevent unauthorized copying, is a valuable exploration. Digital watermarking technology can be embedded in model parameters to form a unique identifier, thereby maintaining the uniqueness and traceability of the model during its propagation and use. The embedded nature of digital watermarking technology provides a means of preventing model tampering, and the legality of the model can be verified through watermark extraction. However, these works are currently only in the exploratory stage, and the robustness of aggregated watermarks and the conflict between multiple watermarks in distributed scenarios remain key limitations in this research field.
[0066] Currently, research on using blockchain, federated learning, and digital watermarking technologies to protect model ownership in distributed scenarios remains severely insufficient. This is because: 1) Traditional machine learning's single-watermark embedding technology needs innovation to support multi-participant, multi-watermark embedding in federated learning and blockchain, resolving multi-watermark conflicts caused by multiple participants. 2) While federated learning combined with digital watermarking technology, there is a lack of storage protection for watermarks in distributed scenarios.
[0067] To address the aforementioned problems, this invention proposes and constructs a decentralized blockchain federated learning framework based on a blockchain network, integrating digital watermarking and federated learning technologies through a personalized consensus mechanism. This framework achieves verifiable model ownership, traceable transaction behavior, and fair participation by multiple parties. The main contributions of this invention are:
[0068] 1) A distributed digital watermarking technology integrating blockchain consensus mechanism and smart contract digital watermarking technology was proposed; 2) By integrating the public and immutable characteristics of blockchain, the privacy protection advantages of federated learning and the copyright protection mechanism of digital watermarking, a fusion federated learning model framework for rights confirmation, copyright verification and efficient management was constructed.
[0069] Specifically, this invention innovatively integrates blockchain and smart contract technologies into the Federated Learning Model Intellectual Property Rights (FedIPR) framework, proposing the Blockchain Federated Learning Model Intellectual Property (BFLIPR) framework, which better conforms to current privacy and information security standards. The BFLIPR framework provides a more secure and reliable decentralized distributed scenario for digital watermarking applications in federated learning environments. In other words, this invention designs a distributed digital watermarking technology that integrates blockchain consensus mechanisms and smart contracts, constructing a decentralized and verifiable federated learning framework centered on blockchain networks and federated learning technology. This framework achieves source authentication of input data for federated learning model training and ownership protection of the output model. Furthermore, leveraging the immutability of the blockchain network, it enables traceable recording of model operations and verifiable watermark embedding, greatly enhancing the robustness and applicability of traditional federated learning frameworks.
[0070] The BFLIPR framework provided by this invention consists of three key interconnected aspects: system architecture and design, digital watermark generation and embedding process, and blockchain-based digital watermark verification mechanism. The complete workflow of the BFLIPR framework is described below.
[0071] 1) First, the system architecture and design section introduces the basic architecture, operating mechanism, and components of the entire framework, including the blockchain network, federated learning client, and digital watermarking components. The blockchain network section covers nodes, the watermark consensus mechanism, and pre-defined smart contracts responsible for managing the verification, storage, and synchronization of on-chain data, as well as the processing and broadcasting of data uploaded to the chain. The federated learning client uses private data for model training and integrates the digital watermarking component, generating unique digital watermark information and synchronously uploading it to the chain during model updates and uploads. The watermark consensus mechanism utilizes the PBFT consensus mechanism for global broadcasting and 2 / 3 node agreement, while smart contracts handle data classification, interface, and storage. 2) The digital watermark generation and embedding process based on the BFLIPR architecture, building upon 1), details the process of using smart contracts for model training of digital watermarks within the framework using two watermark types, including private watermark privacy storage, matrix processing, and global aggregation. 3) The blockchain-based digital watermark verification mechanism demonstrates how to reliably verify watermarks using on-chain storage and immutability, including using the formulas and calculation methods from the watermark generation stage to back-calculate the original private watermark parameters, and using blockchain storage to ensure the accuracy of subsequent watermark information.
[0072] Furthermore, this paper introduces BFLIPR from three aspects: system architecture and design, blockchain-based digital watermark generation and embedding, and blockchain-based reliable digital watermark verification mechanism.
[0073] 1. BFLIPR System Architecture and Design.
[0074] like Figure 2 As shown, the BFLIPR system framework requires each client to simultaneously transmit the participant's private watermark parameters (B) via a smart contract when submitting model update parameters. i ;θ i ;T i Information such as (B) and model gradient parameters is uploaded to the blockchain, among which, (B) i ;θ i These are the target watermark and the watermark extraction parameters, respectively. i This is the watermark trigger set for backdoor watermarks. Participants' private watermark parameters are uniformly matrixed by a smart contract and stored on the blockchain. The processed global watermark matrix E is then broadcast through a consensus mechanism. t Among them, the private watermark parameter (B) i ;θ i ;T i It remains available but not visible to other participants.
[0075] Based on FedIPR, the BFLIPR framework also utilizes smart contracts to achieve integration and optimization between various components of the system framework, and implements a pluggable modular design for the framework. This invention will introduce the blockchain-enhanced federated learning and innovative digital watermarking module and the smart contract-driven blockchain network module respectively.
[0076] (1) Blockchain-enhanced federated learning and innovative digital watermarking module.
[0077] Building upon the original FedIPR framework's approach of combining a black-box model with a white-box model for model embedding and verification, BFLIPR leverages a smart contract-based nested verification algorithm to interface with the black-box model, resulting in a lightweight optimization of the original framework. The white-box model is offered as an optional component of the system framework, innovatively achieving the design objectives of the original white-box model on the blockchain and reducing the complexity of the merged framework. Regarding watermark types, BFLIPR continues to use the two watermarking methods proposed by the FedIPR framework:
[0078] 1) Feature watermarking: This type of watermark is designed to be directly embedded into the parameters of a federated learning model, and by changing the model's weights, it can contain specific, hard-to-detect patterns. Specifically, for a given set of model parameters W, feature watermarking can be achieved by adding an optimization term L. watermark (W) to the original loss function L original This is implemented in (W). The optimization term aims to adjust the model parameters to include specific watermark information without significantly affecting the performance of the original task. Ultimately, the total loss function L... total The mathematical expression for (W) is:
[0079] L total (W)=L original (W)+λL watermark (W) (1)
[0080] Here, λ is an adjustment term used to balance watermark embedding and model performance.
[0081] 2) Backdoor-based Watermarks: The core idea of this type of watermark is to create a specific set of input-output pairs (i.e., a set of triggers). When the model encounters a specific input pattern (trigger), it produces a predefined output, thus proving ownership of the model. The mathematical form of this watermark is: given a set of trigger samples... When the model encounters (x) i When ), the output should be (y). i ).
[0082] (2) Blockchain network module driven by smart contracts.
[0083] In the blockchain network module, BFLIPR innovatively integrates this module with other modules through smart contracts and consensus mechanisms. This allows all participants to maintain a continuously growing list of records (blocks) in a decentralized network to record all important transactions and data changes during model training, playing a crucial role in the overall system framework. Simultaneously, the system's modular composition greatly generalizes the selectivity and flexibility of various components within the blockchain network, including customized consensus mechanisms, blockchain network types, smart contract verification algorithms, and more. To effectively ensure data consistency and system robustness, this invention selects the Practical Byzantine Fault Tolerance (PBFT) consensus mechanism as the experimental consensus algorithm. Through its meticulously designed role allocation and operational procedures, it provides BFLIPR with an efficient and reliable consensus solution. The following is an introduction to the PBFT consensus mechanism and its role in the framework.
[0084] 1) The PBFT system primarily comprises two roles: Leader and Followers. The Leader is responsible for initiating new requests or proposals, while the Followers are responsible for validating and voting on these proposals. For example... Figure 6 As shown, the PBFT workflow can be divided into:
[0085] Pre-prepare phase: The master node receives requests from clients, assigns a unique sequence number to each, and then broadcasts this request and sequence number as a message to all slave nodes. This message is digitally signed using the master node's private key, ensuring its non-repudiation and verification of origin. This message can be represented as M. pre =sign(H(request, sequence number), SKleader), where H is a hash function used to generate a unique representation of the request and sequence number, and SK... leader This is the master node's private key. In the BFLIPR framework, the watermark matrix E is sent along with the verification message. k .
[0086] Preparation phase: The slave node receives and uses the master node's public key (PK). leader Verify the digital signature of the prepared message sent by the master node to ensure it is correct. The verification function is V(M). pre PK leaderThe verification process ensures the authenticity of the message and the correctness of the sequence number, preventing replay attacks and message tampering. Upon successful verification, the slave node broadcasts a ready message, indicating that it is ready to process the request.
[0087] Commit Phase: After a slave node receives a sufficient number of prepare messages (usually exceeding the total number of network nodes), Broadcasting a commit message. This step signifies the node's final approval of the request. The key to the commit phase is ensuring that a majority of nodes in the network agree on the current request state, thus achieving consensus. After receiving commit messages from a majority of other nodes, the node executes the request and returns the result to the client. Broadcasting a commit message can be represented as:
[0088] Commit=true if|{valid prepare messages}|>2f (2)
[0089] Where f is the maximum possible number of malicious nodes in the network.
[0090] These phases constitute the core of the PBFT consensus mechanism, ensuring that the BFLIPR framework can still achieve consensus even in scenarios where there may be participating nodes with malicious behavior.
[0091] In summary, the BFLIPR framework significantly enhances the security and effectiveness of federated learning models by integrating blockchain technology and smart contracts. This framework not only innovatively extends FedIPR but also further improves the system's robustness and data consistency by introducing the PBFT consensus mechanism. This design provides a novel research approach for intellectual property protection and privacy security in federated learning models.
[0092] 2. Blockchain-based digital watermark generation and embedding.
[0093] The BFLIPR framework has made technological innovations in the generation and embedding of digital watermarks. For example... Figure 3 As shown, the BFLIPR framework combines the security of blockchain with the flexibility of smart contracts, not only optimizing the implementation method of watermarking but also ensuring its effectiveness and anonymity in federated learning environments. By deeply integrating the mathematical model of the original framework with blockchain technology, BFLIPR proposes a robust and secure watermarking solution, effectively strengthening the intellectual property protection and data security of federated learning models. The following is a detailed introduction to two types of digital watermark generation and embedding:
[0094] (1) Integration and optimization of global feature watermarking encoding and training process.
[0095] Generation Phase: The global feature watermark for each round is generated by all client feature watermarks B. k It is generated through complex encoding techniques, the encoding process of which includes converting the watermark into a series of binary strings. And so on. These strings are designed to be directly mapped to model parameters, making them difficult for third parties to detect. Before encoding is complete, the smart contract encrypts these client watermark parameters and stores them on the blockchain using the PBFT consensus mechanism to ensure information consistency and security. After encoding is complete, the PBFT consensus mechanism sends the global feature watermark and model parameters together to all clients as preparation information, completing a global broadcast and storing this important transaction on the chain. The encoding method is as follows: Each client possesses a feature-based private watermark B known only to itself. k The definition of a watermark is determined by business requirements. In experiments, a watermark is usually defined as the client's ID. For example, the watermark information for client number 2 is defined as 2, which, when converted to binary, is B2 = 010.
[0096] Embedding stage: Feature watermarking is achieved through a customized loss function L watermark (W) is integrated into model training to optimize model parameters to include watermark information. This loss function is expressed as:
[0097]
[0098] Where, f(B) k,i W i The watermark parameter B is used to measure the training time in the i-th round. k,i With model parameters W i The difference between them is N, where N is the number of training rounds required to complete the training.
[0099] The parameter update process employs more targeted optimization algorithms, such as stochastic gradient descent with momentum. Here, W new These are the updated model parameters, where η is the learning rate. This is the gradient of the total loss function. The goal is to embed watermark information while preserving the original task performance and minimizing the impact on model performance.
[0100] (2) Backdoor watermark generation and activation strategy of the model.
[0101] Generation stage: Backdoor-based watermarking The trigger set is generated through adversarial learning techniques, where each trigger ((x) i ,y i Designed for specific layers of the model to maximize activation of specific neural network paths. Optimization formulas are used during the generation process:
[0102]
[0103] Where N represents the model's prediction function, and δ is the result of minimizing the loss function L(y). i ,N(x i The perturbation is determined by the constraint |δ|≤∈, which ensures that the magnitude of the perturbation will not exceed the predetermined threshold∈.
[0104] Meanwhile, all trigger samples and their parameters are encrypted via smart contracts after generation and stored on the blockchain. The PBFT consensus mechanism ensures the accuracy and security of this information. During this process, the trigger parameters are not globally broadcast, which provides tamper-proof and persistent protection for subsequent watermark information verification.
[0105] Embedding Phase: The model's training strategy employs projective gradient descent to ensure effective trigger embedding without impacting the model's core performance. This involves adjusting the learning rate and using optimization algorithms, such as stochastic gradient descent with momentum, to ensure the watermark is activated and retained in specific layers. The aim of this process is to enhance the model's sensitivity to these specific samples and reduce interference with overall model performance. During this phase, the smart contract automatically manages the embedding process of the trigger set, including trigger sample selection, adjustment of embedding time and frequency, and broadcasting of watermark information. This automation reduces the need for human intervention and improves the efficiency and reliability of the entire embedding process.
[0106] In summary, the BFLIPR framework, by integrating blockchain and smart contract technologies, is more intelligent, standardized, and secure, providing a safe and effective intellectual property protection solution for federated learning models. The application of these technologies not only enhances the concealment and robustness of watermarks but also improves the overall system's ability to protect intellectual property. The next section will delve into the digital watermark verification process within the BFLIPR framework.
[0107] 3. A reliable digital watermark verification mechanism based on blockchain.
[0108] Within the BFLIPR framework, the digital watermarking verification process is deeply integrated with blockchain technology to enhance security, transparency, and consistency. This process covers advanced verification mechanisms, including signature-based watermarking and backdoor-based watermarking.
[0109] (1) Decoding and verification of feature watermarks.
[0110] Verification of feature watermarks relies on algorithms used in FedIPR. For example... Figure 4 The diagram illustrates the complete digital watermark verification process. First, the verifier needs to extract watermark information from the model parameters using the same algorithm as when embedding the watermark. To ensure the accuracy of the extracted information. Extracted watermark information. Compared with the original watermark information B stored on the blockchain k The similarity between them is calculated by comparing them using equation (5):
[0111]
[0112] During the model design phase, the verification mechanism proposed in equation (5) was integrated and deployed in the smart contract. Therefore, the actual execution of the verification process is automated by the smart contract, effectively ensuring the accuracy and consistency of the verification.
[0113] (2) Smart contract-driven automated backdoor watermark verification.
[0114] Backdoor-based watermark verification covers the use of predefined trigger sample sets. Test the model. Trigger sample set. During the verification process, the smart contract calls trigger parameters stored on the blockchain to ensure the consistency and security of the test:
[0115]
[0116] in, The average calculation of the trigger sample set is used to normalize the total number of correct predictions, I[N(x)]. i )=y i ] is an indicator function for validating input data.
[0117] Similarly, this process is pre-deployed in smart contracts. The automation function of smart contracts ensures the efficiency and reliability of the verification process, while reducing the need for human intervention and eliminating the probability of verification errors.
[0118] This invention delves into the generation and embedding process of digital watermarks within the BFLIPR framework, as well as the verification mechanism for digital watermarks. It details the specific implementation of watermarking technology and how to ensure the effectiveness and reliability of federated learning models while protecting their intellectual property and privacy.
[0119] In summary, the BFLIPR framework, integrated with blockchain technology, not only ensures the secure storage and management of verification data but also provides transparent and tamper-proof verification records. Smart contracts automatically execute verification steps, reducing the possibility of human intervention and ensuring the accuracy and integrity of the data, while the PBFT consensus mechanism further ensures consistent acceptance of the verification results by all clients.
[0120] Example 2
[0121] A computer device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, the processor executing the computer program to implement the federated learning method in Embodiment 1.
[0122] Example 3
[0123] A computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements the federated learning method of Embodiment 1.
[0124] Example 4
[0125] A computer program product includes a computer program that, when executed by a processor, implements the federated learning method of Embodiment 1.
[0126] Example 5
[0127] A computer device, which may be a database, may have an internal structure diagram as shown below. Figure 7 As shown, the computer device includes a processor, memory, input / output (I / O) interfaces, and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computational and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs stored in the non-volatile storage media. The database stores pending transactions. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communicating with external terminals via a network connection. When the computer program is executed by the processor, it implements the federated learning method in Embodiment 1.
[0128] It should be noted that the object information (including but not limited to object device information, object personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this invention are all information and data authorized by the object or fully authorized by all parties, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.
[0129] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided by this invention can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided by this invention may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided by this invention may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0130] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0131] This document uses specific examples to illustrate the principles and implementation methods of the present invention. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of the present invention. Furthermore, those skilled in the art will recognize that, based on the ideas of the present invention, there will be changes in the specific implementation methods and application scope. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. A federated learning method, characterized in that, The method includes: The parameters of the initial local business model and the private watermark parameters of multiple federated learning clients are obtained through multiple first nodes of the blockchain; where each first node corresponds to one federated learning client. The private watermark parameters of each federated learning client are matrixed by a predefined smart contract to obtain a watermark matrix containing multiple private watermark vectors. The private watermark vector of the watermark matrix is embedded into the parameters of the initial local business model of the corresponding federated learning client by applying a feature watermarking method or a backdoor-based watermarking method, and then aggregated by a federated averaging algorithm to obtain the parameters of the initial global business model. The parameters of the initial global business model are then stored in the preset second node of the blockchain. The consensus mechanism of the blockchain is used to verify the private watermark vector of the parameters of the initial global business model, and the verification result is obtained; the verification result includes correct and incorrect. When the verification result is incorrect, each federated learning client uses its local dataset to train the initial local business model, obtains the updated parameters of the initial local business model, and returns to the step "obtain the parameters of the initial local business model and the private watermark parameters of each federated learning client through multiple first nodes of the blockchain" to continue execution. When the verification result is correct, the initial global business model is used to determine whether it has converged. When the initial global business model does not converge, the parameters of the initial global business model are returned to each federated learning client as the parameters of the initial local business model of each federated learning client. Each federated learning client uses its local dataset to train the initial local business model, obtains the updated parameters of the initial local business model, and returns to the step "obtain the parameters of the initial local business model and the private watermark parameters of each federated learning client through multiple first nodes of the blockchain" to continue execution. When the initial global business model converges, a global business model is obtained; the global business model is the initial global business model. When the feature watermarking method is applied to embed the private watermark vector of the watermark matrix into the parameters of the initial local business model of the corresponding federated learning client, the consensus mechanism of the blockchain is used to verify the private watermark vector of the parameters of the initial global business model, specifically including: Extract watermark information from the parameters of the initial global business model; Calculate the similarity between the extracted watermark information and the private watermark parameters; The verification result is correct when the similarity is greater than the first preset threshold; otherwise, the verification result is incorrect. When a backdoor-based watermarking method is applied to embed the private watermark vector of the watermark matrix into the parameters of the initial local business model of each of the federated learning clients, the consensus mechanism of the blockchain is used to verify the private watermark vector of the parameters of the initial global business model, specifically including: The system calls the trigger parameters stored on the blockchain, applies a predefined set of trigger samples, and calculates the accuracy of the initial global business model. The trigger parameters are stored on the blockchain when the private watermark vector of the watermark matrix is embedded into the initial local business model of each federated learning client using a backdoor-based watermarking method. The verification result is correct when the accuracy is greater than the second preset threshold; otherwise, the verification result is incorrect.
2. The federated learning method according to claim 1, characterized in that, The consensus mechanism is a practical Byzantine fault-tolerant consensus algorithm.
3. The federated learning method according to claim 1, characterized in that, The feature watermarking method embeds the private watermark vector of the watermark matrix into the parameters of the initial local business model of the corresponding federated learning client through a loss function.
4. The federated learning method according to claim 1, characterized in that, The method used by each federated learning client to train the initial local business model using a local dataset is stochastic gradient descent.
5. A computer device, comprising: The memory and processor contain a computer program stored in the memory and executable on the processor, characterized in that the processor executes the computer program to implement the federated learning method according to any one of claims 1-4.
6. A computer-readable storage medium having a computer program stored thereon, characterized in that, When executed by a processor, the computer program implements the federated learning method described in any one of claims 1-4.
7. A computer program product, comprising a computer program, characterized in that, When executed by a processor, the computer program implements the federated learning method described in any one of claims 1-4.