Privacy Protection Method and Device Against Internal Dishonest Participants
By using commitment functions and smart contracts in the federated learning framework of blockchain, identifying and punishing dishonest participants, the framework's lack of resilience to internal dishonest participants is solved, achieving higher privacy security and protection of global model parameters.
Patent Information
- Application Number
- CN202411486644.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-23
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2044-10-23
AI Technical Summary
The existing federated learning framework based on blockchain has weak resistance and defense capabilities to internal dishonest participants, which poses privacy and security risks, which may lead to overall privacy leakage.
Through the predetermined commitment function, the local model parameters to be uploaded are calculated to obtain the promise function value, and a smart contract based on the promise function is written in the blockchain. In the event of dishonest participant denial, identify dishonest participants as contract open commitments and perform data privacy enhancements on global model parameters.
The federated learning framework based on blockchain has improved its resistance and defense capabilities for internal dishonest participants, guarantees privacy and security, prevents invalid local model parameters from cheating global model parameters, and accurately locates dishonest participants when global model parameters are leaked.
Smart Images

Figure CN119397591B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of blockchain technology, and in particular, to a privacy protection method and device for resisting internal dishonest participants. Background Art
[0002] In a Blockchain-based Federated Learning (BFL) framework, the blockchain is used instead of a central server. Participants submit parameters such as the local model gradients of a single local training to miners. The miners perform gradient verification, aggregation according to a consensus mechanism or a smart contract, generate the global model of a single training and write its parameters into a block, and then use the block to store and broadcast the global model parameters. Participants can download the global model parameters of this time and perform the next round of local model training.
[0003] The existing BFL framework has weak resistance and defense capabilities against internal dishonest participants. Internal dishonest participants may obtain the global model parameters aggregated by the overall system training by providing invalid local model parameters, or obtain the training data, identity information, or local model information of other participants through interaction and eavesdropping within the BFL system, and even collude with external adversaries to actively disclose the obtained global model or local model information, forming a great privacy security risk and possibly causing overall privacy leakage. Summary of the Invention
[0004] The present invention provides a privacy protection method and device for resisting internal dishonest participants, so as to improve the resistance and defense capabilities of the blockchain-based federated learning framework against internal dishonest participants, thereby ensuring privacy security.
[0005] The present invention provides a privacy protection method for resisting internal dishonest participants, including the following steps:
[0006] Obtain the local model parameters to be uploaded by participants in a Blockchain-based Federated Learning (BFL) framework;
[0007] Based on a pre-determined commitment function, perform commitment calculation on the local model parameters to obtain a commitment function value;
[0008] Send the local model parameters and their corresponding commitment function values to the miner with the bookkeeping right, so that the miner with the bookkeeping right writes the local model parameters and their corresponding commitment function values into the block in the BFL framework and synthesizes the global model;
[0009] Perform data privacy enhancement on the global model parameters in the global model based on each participant respectively, and write the globally model parameters after data privacy enhancement into the block in the BFL framework.
[0010] According to a privacy protection method for resisting internal dishonest participants provided by the present invention, after determining that the block miner with the bookkeeping right writes the local model parameters and their corresponding commitment function values into the block in the BFL framework and synthesizes the global model, it further includes:
[0011] Receiving abnormal local model parameters, where the abnormal local model parameters are local model parameters for which the participant has objections to the verification process or local model parameters that the participant denies uploading, and the verification process is the verification before the block miner with the bookkeeping right writes the local model parameters and their corresponding commitment function values into the block in the BFL framework;
[0012] Based on the commitment function, parsing the abnormal local model parameters for public verification.
[0013] According to a privacy protection method for resisting internal dishonest participants provided by the present invention, the
[0014] Respectively perform data privacy enhancement on the global model parameters in the global model based on each participant, including:
[0015] Respectively add different parameter noises to the global model parameters in the global model based on each participant, and perform a data blinding operation on the global model parameters with added parameter noises based on the public keys of each participant to generate blinded global model parameters;
[0016] Sign the blinded global model parameters based on the private keys of each participant.
[0017] According to a privacy protection method for resisting internal dishonest participants provided by the present invention, the
[0018] Performing a data blinding operation on the global model parameters with added parameter noises includes:
[0019] Performing a data blinding operation on the global model parameters with added parameter noises based on a blinding factor.
[0020] According to a privacy protection method for resisting internal dishonest participants provided by the present invention, it further includes:
[0021] In the case of a leakage of global model parameters in the BFL framework, obtaining the leaked global model parameters;
[0022] Based on the blinding factor and the public keys of the participants, parsing the leaked global model parameters to determine the target participant corresponding to the leaked global model parameters.
[0023] According to a privacy protection method for resisting internal dishonest participants provided by the present invention, after determining the target participant corresponding to the leaked global model parameters, the method further includes:
[0024] Deduct the token deposits of a preset number of the target participants, and after determining that the token deposits of the target participants have been deducted, delete the target participants from the BFL framework. The token deposits are the deposits that the target participants need to pay before joining the BFL framework.
[0025] The present invention also provides a privacy protection device for resisting internal dishonest participants, including the following modules:
[0026] A parameter acquisition module, configured to acquire the local model parameters to be uploaded by participants in a blockchain-based federated learning BFL framework;
[0027] A commitment calculation module, configured to perform commitment calculation on the local model parameters based on a pre-determined commitment function to obtain a commitment function value;
[0028] An aggregation module, configured to send the local model parameters and their corresponding commitment function values to the bookkeeping right miner, so that the bookkeeping right miner writes the local model parameters and their corresponding commitment function values into the block in the BFL framework and synthesizes a global model;
[0029] A privacy enhancement module, configured to perform data privacy enhancement on the global model parameters in the global model based on each participant respectively, and write the globally model parameters after data privacy enhancement into the block in the BFL framework.
[0030] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the privacy protection method for resisting internal dishonest participants as described in any one of the above.
[0031] The present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the privacy protection method for resisting internal dishonest participants as described in any one of the above.
[0032] The present invention also provides a computer program product, including a computer program. When the computer program is executed by a processor, it implements the privacy protection method for resisting internal dishonest participants as described in any one of the above.
[0033] The privacy protection method and device for resisting internal dishonest participants provided by the present invention perform commitment calculation on the local model parameters to be uploaded through a pre-determined commitment function, and obtain a commitment function value for defending against the situation where internal dishonest participants maliciously deceive global model parameters using invalid local model parameters. An intelligent contract based on the commitment function is written in the blockchain. When a dishonest participant reneges, the commitment is opened according to the contract to identify the dishonest participant, which improves the resistance and defense capabilities of the blockchain-based federated learning framework against internal dishonest participants and ensures privacy security. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0035] Figure 1 It is a schematic flowchart of the privacy protection method for resisting internal dishonest participants provided by the present invention.
[0036] Figure 2 It is a schematic diagram of the privacy protection architecture provided by the present invention.
[0037] Figure 3 It is a schematic structural diagram of the privacy protection device for resisting internal dishonest participants provided by the present invention.
[0038] Figure 4 It is a schematic structural diagram of the electronic device provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0039] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention in conjunction with the drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments in the present invention belong to the scope of protection of the present invention.
[0040] Federated learning can break data silos and complete machine learning training in compliance without data leaving the local area, so it has received extensive attention and has been gradually applied to various industries. However, the centralized attribute of federated learning poses great privacy and security risks. The decentralized feature of blockchain provides an opportunity for the development of federated learning. In recent years, the Blockchain-based Federated Learning (BFL) framework has been proposed. Using blockchain to replace the central server, participants submit parameters such as the local model gradients of a local training to miners. Miners perform gradient verification, aggregation according to the consensus mechanism or smart contract, generate the global model of a training and write its parameters into the block. Subsequently, the block is used to store and broadcast the global model parameters, and participants can download the global model parameters of this time and conduct the next round of local model training.
[0041] The BFL framework in related methods has weak resistance and defense capabilities against internal dishonest participants: Internal dishonest participants may deceive the global model parameters aggregated by the overall system training by providing invalid local model parameters, or obtain the training data, identity information, or local model information of other participants through internal interaction and eavesdropping in the BFL system. They may even collude with external adversaries to actively disclose the obtained global model or local model information, forming a great privacy and security risk and potentially causing overall privacy leakage. Therefore, it is necessary to screen out the dishonest participants in the system and remove them from the system.
[0042] In the research on blockchain-based federated learning in related methods, there are mainly four types of privacy protection schemes, but they all have problems: 1) Some schemes use differential privacy technology to add noise to local gradients to ensure privacy, which is likely to cause bias in the joint model and cannot screen out dishonest participants; 2) Some schemes use homomorphic encryption or secret sharing to achieve external privacy, and cannot avoid the situation where internal dishonest participants collude to leak privacy; 3) Some schemes use channel isolation technology to ensure the privacy of information transmission, which is only applicable to consortium blockchain systems that support this technology and does not have universality; 4) Some schemes use the method of regularly electing a committee or leader for model aggregation, which provides an opportunity for dishonest participants to obtain all data and increases the risk of privacy leakage due to single-point failure.
[0043] Aiming at the defects of related methods, the present invention provides a privacy protection method for resisting internal dishonest participants. Figure 1 It is a schematic flowchart of the privacy protection method for resisting internal dishonest participants provided by the present invention. As Figure 1 shown, the method includes the following:
[0044] Step 110, obtaining the local model parameters to be uploaded by participants in the Blockchain-based Federated Learning (BFL) framework.
[0045] Step 120: Based on a pre-determined commitment function, perform a commitment calculation on the local model parameters to obtain a commitment function value;
[0046] Step 130: Send the local model parameters and their corresponding commitment function values to the miner with the bookkeeping right, so that the miner with the bookkeeping right writes the local model parameters and their corresponding commitment function values into the block in the BFL framework and synthesizes a global model;
[0047] Step 140: Respectively enhance the data privacy of the global model parameters in the global model based on each participant, and write the globally model parameters with enhanced data privacy into the block in the BFL framework.
[0048] The execution subject of the privacy protection method for resisting internal dishonest participants provided by the present invention may be an electronic device, a component in the electronic device, an integrated circuit, or a chip. The electronic device may be a mobile electronic device or a non-mobile electronic device. Exemplarily, the mobile electronic device may be a mobile phone, a tablet computer, a laptop computer, a handheld computer, an ultra-mobile personal computer (UMPC), a netbook, or a personal digital assistant (PDA), etc., and the non-mobile electronic device may be a server, a Network Attached Storage (NAS), or a personal computer (PC), etc. The present invention does not make specific limitations.
[0049] Next, taking a computer executing the privacy protection method for resisting internal dishonest participants provided by the present invention as an example, the technical solution of the present invention will be described in detail.
[0050] In step 110, obtain the local model parameters to be uploaded by the participants in the blockchain-based federated learning BFL framework.
[0051] In federated learning, each participant (such as different data holders or computing nodes) first performs model training locally. In this process, the participant trains the model using its own dataset and calculates the local model parameters. These local model parameters reflect the optimization direction and degree of the model on the participant's local dataset.
[0052] Obtain the local model parameters to be uploaded by the participants. The local model parameters may be the calculated local gradient parameters.
[0053] In step 120, based on a pre-determined commitment function, perform a commitment calculation on the local model parameters to obtain a commitment function value.
[0054] To ensure the authenticity and integrity of local model parameters while protecting their privacy, the BFL framework introduces a commitment function. The commitment function is a cryptographic tool that allows participants to "commit" or "encapsulate" data in a certain form without exposing the actual data. Specifically, participants perform a commitment calculation on the local model parameters to obtain a commitment function value. This commitment function value will be used in subsequent processes to verify the authenticity and integrity of the local model parameters.
[0055] The focus of the commitment function is to defend against the situation where dishonest internal participants maliciously deceive the global model parameters using invalid local model parameters. A smart contract based on the commitment function is written in the blockchain. In the event of a dishonest participant's denial, the commitment will be opened according to the contract, and the dishonest participant will be announced and punished.
[0056] In step 130, the local model parameters and their corresponding commitment function values are sent to the miner with the bookkeeping right, so that the miner with the bookkeeping right verifies the local model parameters and their corresponding commitment function values and writes them into the block in the BFL framework, and synthesizes the global model.
[0057] In the BFL framework, miners with the bookkeeping right play an important role. They are responsible for verifying and writing the local model parameters of participants and their corresponding commitment function values into the block. To achieve this process, the local model parameters and the commitment function values are sent to the miners with the bookkeeping right together. After receiving this information, the miners with the bookkeeping right will perform verification and recording work. The verification process includes checking whether the commitment function value matches the local model parameters to ensure the authenticity and integrity of the data. Once the verification passes, the miners with the bookkeeping right will write this information into the block and broadcast it to other nodes in the network.
[0058] In the BFL framework, the synthesis of the global model is achieved by aggregating the local model parameters of all participants. Specifically, after writing the local model parameters into the block, the miners with the bookkeeping right use these parameters to update the global model. This process usually involves weighted averaging or other forms of aggregation operations on the local model parameters. Through this process, the BFL framework can use distributed data and resources to jointly train a global model, thereby improving the generalization ability and performance of the model.
[0059] In step 140, data privacy enhancement is performed on the global model parameters in the global model based on each participant respectively, and the globally model parameters after data privacy enhancement are written into the block in the BFL framework.
[0060] In the BFL framework, data privacy protection is of utmost importance. To enhance the data privacy of global model parameters, the BFL framework can adopt various technical means for privacy enhancement. These technical means include, but are not limited to, differential privacy, homomorphic encryption, and the privacy protection mechanism of federated learning itself, etc. Through the application of these technical means, the BFL framework can achieve the training and update of the global model while protecting the data privacy of participants.
[0061] Specifically, before writing the globally model parameters enhanced with data privacy into the block, the BFL framework will perform necessary processing and transformation on these parameters. These processing and transformation aim to ensure the security and privacy of the global model parameters during transmission and storage.
[0062] Optionally, for local model parameters, a reusable commitment function can be constructed for commitment calculation. A reusable commitment function can be constructed based on Pedersen commitment as follows:
[0063] Suppose and are two safe prime numbers, let be the modulus of an RSA scheme. is 's unique cyclic subgroup, where the order is , in the group the discrete logarithm problem is difficult: g and h are two elements in the group, and is computationally difficult.
[0064] Suppose is a universal hash function: .
[0065] Key generation algorithm :
[0066] Each participant generates a public-private key pair of the commitment function: Let and be two safe prime numbers and satisfy , then . Among them, is the security parameter.
[0067] Commitment generation algorithm :
[0068] Each participant generates a commitment to the local model parameters of this round according to the system requirements:
[0069] ;
[0070] i is the identity identifier, and the participant sends the local model parameters of this round and the corresponding commitment function to the system.
[0071] Commitment verification algorithm :
[0072] The miner with the right to record transactions (for example, in a blockchain system adopting the PoS consensus mechanism, the miner with the highest stake has the right to record transactions) has the ability to verify commitments.
[0073] The miner with the right to record transactions verifies the commitment function of each participant:
[0074] ;
[0075] ;
[0076] Verify s = t whether it holds.
[0077] If the commitment verification passes, the commitment value is written into the block storage, and subsequent global model aggregation and other operations are performed. If the commitment verification fails, it means that the participant has dishonest behavior. To prevent information leakage or data from being maliciously defrauded, the system will disclose the identity i and data of this participant. Anyone can use the public key to verify the commitment, making it unable to deny its dishonest identity.
[0078] Among them, the hash function H is used to resist forgery attacks with multiplicative coefficients. pk will not disclose sk any information of, so that it can be ensured that the commitment verification cannot be forged and is therefore reusable.
[0079] This commitment function satisfies data hiding: the commitment is indistinguishable from any random element value in the group. It satisfies data binding: for an adversary in polynomial time, since it is difficult to calculate the value of the discrete logarithm , it is difficult to find a pair of values that satisfy . Even for an all-powerful adversary who can calculate the value of , then we can get . Since is a collision-resistant hash function, it is difficult to find another identity that calculates the same hash value, so it is impossible to forge identities and commitments.
[0080] The focus of this commitment function is to defend against the situation where dishonest internal participants maliciously deceive the global model parameters using invalid local model parameters. An intelligent contract based on the commitment function is written in the blockchain. When there is a situation where a dishonest participant uses invalid data and refuses to admit it, the commitment is opened according to the contract to expose and punish the dishonest participant.
[0081] It can be understood that based on the constructed commitment function, it is possible to resist dishonest participants in the BFL system, that is, dishonest internal participants cannot deceive the global model parameters of the system by providing invalid local model parameters, and cannot actively disclose local model information. Once there is an act of deceiving data or actively leaking secrets, the system can accurately locate and screen out the dishonest participant and remove it from the system to ensure the privacy and security of the BFL system.
[0082] Optionally, a reusable commitment function can be used to ensure the security of the local model parameters generated by each participant, differential privacy and blind signature can be used to ensure the security of the globally aggregated model parameters, and the blockchain token reward and punishment mechanism can be combined to reward honest participants and punish and remove dishonest participants. The overall architecture of the solution is as Figure 2 shown in the privacy protection architecture diagram provided by the present invention.
[0083] The specific steps of the solution include: 1) Construct a reusable commitment function. Before uploading the local gradient parameters, the participant performs commitment calculation and then sends the local gradient parameters together with the corresponding commitment function values to the miner; 2) The miner with the bookkeeping right verifies the local gradient parameters and the commitment function values, and discards the mismatched data; evaluates the validity and contribution degree of the local gradient parameters according to the contract regulations, and discards the invalid data; 3) The miner aggregates the correct and valid local gradients, writes the commitment function values corresponding to the local model parameters of this round into the block storage; 4) When a participant has an objection to the verification or refuses to admit the uploaded local gradient parameters, the commitment function can be opened for public verification. 5) After the miner with the bookkeeping right synthesizes the global model, different parameter noises are added to the global model parameters respectively according to the contract requirements, and the data blinding operation is performed using the public keys of the participants to generate different global model parameters consistent with the number of participants, and then the blinded global model parameters are sent to the participants corresponding to the public keys; 6) The participant signs the blinded information, and cannot interpret the blinded data nor forge the signature. Each blinded and signed global model parameter is different but within the allowable privacy error range; 7) The miner with the bookkeeping right writes the blinded and signed global model parameters into the block, and sends the corresponding unblinded global model parameters to the participants for the next round of training; 8) If the global model information is leaked, the system uses the blinding factor to unblind and disclose the signature, compares it with the leaked information, and publicly verifies the identity of the dishonest participant.
[0084] The privacy protection method for resisting internal dishonest participants provided by the present invention performs commitment calculation on the local model parameters to be uploaded through a pre-determined commitment function, and obtains a commitment function value for defending against the situation where internal dishonest participants maliciously defraud global model parameters using invalid local model parameters. An intelligent contract based on the commitment function is written in the blockchain. When a dishonest participant reneges, the commitment is opened according to the contract to identify the dishonest participant, improving the resistance and defense capabilities of the blockchain-based federated learning framework against internal dishonest participants and ensuring privacy security.
[0085] In one embodiment, after determining that the bookkeeping right miner writes the local model parameters and their corresponding commitment function values into the block in the BFL framework and synthesizes the global model, it further includes: receiving abnormal local model parameters, where the abnormal local model parameters are local model parameters for which a participant has an objection to the verification process or local model parameters that the participant reneges on uploading, and the verification process is the verification before the bookkeeping right miner writes the local model parameters and their corresponding commitment function values into the block in the BFL framework; based on the commitment function, parsing the abnormal local model parameters for public verification.
[0086] When a participant has an objection to the verification or reneges on uploading the local gradient parameters, the commitment function value can be opened for public verification.
[0087] It can be understood that the commitment function is mainly used to defend against the situation where internal dishonest participants maliciously defraud global model parameters using invalid local model parameters. An intelligent contract based on the commitment function is written in the blockchain. When a dishonest participant reneges, the commitment is opened according to the contract to announce and punish the dishonest participant.
[0088] The commitment function is pre-determined. After determining the abnormal local model parameters, the abnormal local model parameters can be parsed based on the commitment function used for commitment calculation to implement the public verification process for parsing the abnormal local model parameters.
[0089] In one embodiment, data privacy enhancement is respectively performed on the global model parameters in the global model based on each participant, including: adding different parameter noises to the global model parameters in the global model based on each participant, and performing a data blinding operation on the global model parameters with added parameter noises based on the public keys of each participant to generate blinded global model parameters; signing the blinded global model parameters based on the private keys of each participant.
[0090] The performing a data blinding operation on the global model parameters with added parameter noises includes: performing a data blinding operation on the global model parameters with added parameter noises based on a blinding factor.
[0091] Optionally, for the global model parameters, a blind signature and differential privacy scheme are constructed to implement the data privacy enhancement process.
[0092] The following is the construction of the scheme using the RSA blind signature algorithm and the centralized differential privacy technology:
[0093] Assume that the blockchain adopts the PoS consensus mechanism. Then, the miner with the highest stake has the right to keep accounts and execute the privacy protection smart contract. According to the contract regulations, after the local gradient aggregation of this round is completed, Laplace noise is first added to the global model parameters, then the blinding operation is performed, and finally it is sent to each participant for blind signature calculation.
[0094] Let and be two secure prime numbers, and let be the modulus of an RSA scheme.
[0095] Noise addition algorithm :
[0096] For each participant , add noise M with different parameters but with the privacy budget all within the threshold range to the global model parameters , generating the unique global parameter for each participant :
[0097] ;
[0098] where is the learning rate, is the gradient function, is the dynamic noise adjustment coefficient, is the sensitivity of the function.
[0099] Key generation algorithm :
[0100] Each participant generates a public-private key pair for signature: Let and be two secure prime numbers and satisfy , then .
[0101] The public-private key pair for signature can be used throughout the training process without the need for frequent replacement.
[0102] Data blinding algorithm :
[0103] Select a blinding factor , and use the participant The public key , generate the blinded data to be signed:
[0104] ;
[0105] And send to the participant .
[0106] Signature algorithm :
[0107] After the participant receives , use the personal private key to sign it:
[0108] ;
[0109] And send to the miner with the right to record accounts.
[0110] Since the message has been blinded, the participant does not know the specific content of the message when signing.
[0111] Signature de - blinding algorithm :
[0112] The miner with the right to record accounts calculates the original correct signature according to the de - blinding factor of the participant :
[0113] ;
[0114] Signature verification algorithm :
[0115] When the global model parameters in this training are leaked, the system makes the signature of the leaker and the public key public according to the smart contract, and anyone can conduct public verification:
[0116] ;
[0117] Note: Due to the addition of noise with different parameters, the global model parameters obtained by each participant are slightly different, so it is convenient to determine the source of the leaked message.
[0118] This solution is mainly used to defend against the situation where internal dishonest participants disclose global model parameters. An intelligent contract based on the blind signature mechanism is written in the blockchain. When the global model is leaked, the signature of the leaked data is published according to the contract, and the dishonest participants are publicly verified, punished and removed to ensure the privacy and security of the system. This solution is applicable to the situation of a small number of participants. An increase in the number of participants will lead to a decrease in computing efficiency and a linear increase in storage costs.
[0119] In one embodiment, it further includes: in the case of global model parameter leakage in the BFL framework, obtaining the leaked global model parameters, and based on the blinding factor and the public key of the participant, parsing the leaked global model parameters to determine the target participant corresponding to the leaked global model parameters.
[0120] It can be understood that since each global model parameter has a signature executed by the corresponding participant using the public key. Therefore, after parsing the obtained leaked global model parameters, the identity information of the specific participant can be located based on the signature information.
[0121] After locating the identity information of the participant corresponding to the leaked global model parameters, relevant punishment measures can be executed to restrain the data fraud or malicious leakage behavior of dishonest participants to ensure privacy and security.
[0122] In one embodiment, after determining the target participant corresponding to the leaked global model parameters, it further includes: deducting a preset amount of the token deposit of the target participant, and after determining that the token deposit deduction of the target participant is completed, deleting the target participant from the BFL framework, where the token deposit is the deposit that the target participant needs to pay before joining the BFL framework.
[0123] Adopting a token reward and punishment mechanism, participants need to pay a certain amount of token deposit before participating in federated learning. If there are situations of commitment mismatch and invalid data, or after determining dishonest participants by public signature, a certain amount of tokens will be deducted as punishment. When the participant's deposit is zero, they will be removed from the system. At the same time, honest participants will receive token rewards according to their contribution to the global model.
[0124] Next, the privacy protection device for resisting internal dishonest participants provided by the present invention will be described. The privacy protection device for resisting internal dishonest participants described below can be mutually corresponding and referred to the privacy protection method for resisting internal dishonest participants described above.
[0125] As Figure 3 shown, the device includes:
[0126] A parameter acquisition module 310, configured to acquire local model parameters to be uploaded by participants in a blockchain-based federated learning BFL framework;
[0127] A commitment calculation module 320, configured to perform commitment calculation on the local model parameters based on a predetermined commitment function to obtain a commitment function value;
[0128] Aggregation module 330, used to send the local model parameters and their corresponding commitment function values to the accounting right miner, so that the accounting right miner writes the local model parameters and their corresponding commitment function values into the block in the BFL framework and synthesizes the global model;
[0129] The privacy enhancement module 340 is used to perform data privacy enhancement on the global model parameters in the global model based on each participant, and write the global model parameters after data privacy enhancement into the blocks in the BFL framework.
[0130] The privacy protection device for resisting internal dishonest participants provided by the present invention performs commitment calculation on the uploaded local model parameters through a predetermined commitment function, and obtains a commitment function value for resisting the situation where internal dishonest participants use invalid local model parameters to maliciously defraud global model parameters. It realizes writing a smart contract based on the commitment function in the blockchain. When a dishonest participant denies, the dishonest participant is determined by opening the commitment according to the contract, which improves the resistance and defense capabilities of the blockchain-based federated learning framework against internal dishonest participants and ensures privacy security.
[0131] In one embodiment, the aggregation module 330 is specifically configured to:
[0132] After determining that the accounting right miner writes the local model parameters and their corresponding commitment function values into the block in the BFL framework and synthesizes the global model, it also includes:
[0133] Receive abnormal local model parameters, where the abnormal local model parameters are local model parameters that the participants disagree with during the verification process or deny uploading. The verification process is the verification before the accounting right miner writes the local model parameters and their corresponding commitment function values into the block in the BFL framework;
[0134] Based on the commitment function, the abnormal local model parameters are parsed for public verification.
[0135] In one embodiment, the privacy enhancement module 340 is specifically used to:
[0136] The data privacy is enhanced for the global model parameters in the global model based on each participant, respectively, including:
[0137] Add different parameter noises to the global model parameters in the global model based on each participant respectively, and perform a data blinding operation on the global model parameters with added parameter noises based on the public keys of each participant to generate blinded global model parameters;
[0138] Sign the blinded global model parameters based on the private keys of each participant.
[0139] In one embodiment, the privacy enhancement module 340 is further specifically configured to:
[0140] The data blinding operation performed on the global model parameters with added parameter noises includes:
[0141] Perform a data blinding operation on the global model parameters with added parameter noises based on a blinding factor.
[0142] In one embodiment, the privacy enhancement module 340 is further specifically configured to:
[0143] In the case of leakage of global model parameters in the BFL framework, obtain the leaked global model parameters;
[0144] Parse the leaked global model parameters based on the blinding factor and the public key of the participant to determine the target participant corresponding to the leaked global model parameters.
[0145] In one embodiment, the privacy enhancement module 340 is further specifically configured to:
[0146] After determining the target participant corresponding to the leaked global model parameters, it further includes:
[0147] Deduct the token deposits of a preset number of the target participants, and after determining that the token deposits of the target participants have been deducted, delete the target participants from the BFL framework, where the token deposits are the deposits that the target participants need to pay before joining the BFL framework.
[0148] Figure 4 Illustrate a schematic physical structure diagram of an electronic device, as Figure 4 shown, the electronic device may include: a processor 410, a communication interface 420, a memory 430, and a communication bus 440. Among them, the processor 410, the communication interface 420, and the memory 430 complete communication with each other through the communication bus 440. The processor 410 may call logical instructions in the memory 430 to execute a privacy protection method against internal dishonest participants, and the method includes: obtaining local model parameters to be uploaded by participants in a blockchain-based federated learning BFL framework;
[0149] Based on a pre-determined commitment function, perform commitment calculation on the local model parameters to obtain a commitment function value;
[0150] Send the local model parameters and their corresponding commitment function values to the miner with the bookkeeping right, so that the miner with the bookkeeping right writes the local model parameters and their corresponding commitment function values into the block in the BFL framework and synthesizes a global model;
[0151] Respectively enhance data privacy for the global model parameters in the global model based on each participant, and write the globally model parameters with enhanced data privacy into the block in the BFL framework.
[0152] In addition, when the logical instructions in the above-mentioned memory 430 can be implemented in the form of software functional units and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0153] On the other hand, the present invention also provides a computer program product. The computer program product includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the privacy protection method for resisting internal dishonest participants provided by the above-mentioned various methods. The method includes: obtaining the local model parameters to be uploaded by participants in the federated learning BFL framework based on the blockchain;
[0154] Based on a pre-determined commitment function, perform commitment calculation on the local model parameters to obtain a commitment function value;
[0155] Send the local model parameters and their corresponding commitment function values to the miner with the bookkeeping right, so that the miner with the bookkeeping right writes the local model parameters and their corresponding commitment function values into the block in the BFL framework and synthesizes a global model;
[0156] Based on each participant, enhance the data privacy of the global model parameters in the global model, and write the globally model parameters with enhanced data privacy into the block in the BFL framework.
[0157] In another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements a privacy protection method for resisting internal dishonest participants provided by the above methods. The method includes: obtaining local model parameters to be uploaded by participants in a blockchain-based federated learning BFL framework;
[0158] Based on a pre-determined commitment function, perform commitment calculation on the local model parameters to obtain a commitment function value;
[0159] Send the local model parameters and their corresponding commitment function values to the bookkeeping right miner, so that the bookkeeping right miner writes the local model parameters and their corresponding commitment function values into the block in the BFL framework and synthesizes a global model;
[0160] Based on each participant, enhance the data privacy of the global model parameters in the global model, and write the globally model parameters with enhanced data privacy into the block in the BFL framework.
[0161] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative labor.
[0162] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course also by hardware. Based on this understanding, the above technical solutions, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., including several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.
[0163] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A privacy protection method against internal dishonest participants, characterized in that: The method comprises: Obtain the local model parameters to be uploaded by participants in the blockchain-based federated learning BFL framework; Based on a predetermined commitment function, performing commitment calculation on the local model parameters to obtain a commitment function value; Send the local model parameters and their corresponding commitment function values to the bookkeeping rights miner, so that the bookkeeping rights miner verifies the local model parameters and their corresponding commitment function values and writes them into the block in the BFL framework, and synthesizes the global model; Performing data privacy enhancement on global model parameters in the global model based on each participant, and writing the global model parameters after data privacy enhancement into the blocks in the BFL framework; The data privacy enhancement of the global model parameters in the global model based on each participant respectively includes: Adding different parameter noises to the global model parameters in the global model based on each participant respectively, and performing a data blinding operation on the global model parameters with added parameter noise based on the public key of each participant to generate blinded global model parameters; Based on the private key of each participant, the blinded global model parameters are signed; The determination formula of the commitment function is: ; The bookkeeping miners verify the commitment function of each participant. s=t whether it is established; in, ; ; in, is a local model parameter The commitment function, i is the participant's identifier, Is the participant's identifier i The hash value of g and h are two elements in the unique cyclic subgroup, is the modulus of the RSA scheme, and are two safe prime numbers, is the order of the unique cyclic subgroup, and is the public-private key pair used by each participant to generate the commitment function, and are two safe prime numbers that satisfy , ; If the commitment verification passes, the commitment value will be written to the block storage and the subsequent global model aggregation operation will be performed. If the commitment verification fails, it means that the participant has acted dishonestly and the identity of the participant will be made public. i and local model parameters , anyone can use the public key to verify the commitment, making it impossible to deny the dishonest identity.
2. The privacy protection method against internal dishonest participants according to claim 1, characterized in that: The performing of a data blinding operation on the global model parameters to which parameter noise is added comprises: Based on the blinding factor, data blinding is performed on the global model parameters with added parameter noise.
3. The privacy protection method against internal dishonest participants according to claim 2, characterized in that: Also includes: In the case where there is a global model parameter leakage in the BFL framework, obtaining the leaked global model parameter; Based on the blinding factor and the public key of the participant, the leaked global model parameter is parsed to determine the target participant corresponding to the leaked global model parameter.
4. The privacy protection method against internal dishonest participants according to claim 3, characterized in that: After determining the target participant corresponding to the leaked global model parameter, the method further includes: Deduct a preset amount of the target participant's token deposit, and after determining that the deduction of the target participant's token deposit is completed, delete the target participant from the BFL framework, wherein the token deposit is the deposit that the target participant needs to pay before joining the BFL framework.
5. A privacy protection device for resisting internal dishonest participants, characterized in that: include: The parameter acquisition module is used to obtain the local model parameters to be uploaded by participants in the blockchain-based federated learning BFL framework; A commitment calculation module, used to perform commitment calculation on the local model parameters based on a predetermined commitment function to obtain a commitment function value; An aggregation module is used to send the local model parameters and their corresponding commitment function values to the bookkeeping rights miners, so that the bookkeeping rights miners verify the local model parameters and their corresponding commitment function values and write them into the blocks in the BFL framework, and synthesize the global model; A privacy enhancement module, used for performing data privacy enhancement on global model parameters in the global model based on each participant, and writing the global model parameters after data privacy enhancement into the blocks in the BFL framework; The data privacy enhancement of the global model parameters in the global model based on each participant respectively includes: Adding different parameter noises to the global model parameters in the global model based on each participant respectively, and performing a data blinding operation on the global model parameters with added parameter noise based on the public key of each participant to generate blinded global model parameters; Based on the private key of each participant, the blinded global model parameters are signed; The determination formula of the commitment function is: ; The bookkeeping miners verify the commitment function of each participant. s=t whether it is established; in, ; ; in, is a local model parameter The commitment function, i is the participant's identifier, Is the participant's identifier i The hash value of g and h are two elements in the unique cyclic subgroup, is the modulus of the RSA scheme, and are two safe prime numbers, is the order of the unique cyclic subgroup, and is the public-private key pair used by each participant to generate the commitment function, and are two safe prime numbers that satisfy , ; If the commitment verification passes, the commitment value will be written to the block storage and the subsequent global model aggregation operation will be performed. If the commitment verification fails, it means that the participant has acted dishonestly and the identity of the participant will be made public. i and local model parameters , anyone can use the public key to verify the commitment, making it impossible to deny the dishonest identity.
6. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the privacy protection method for resisting internal dishonest participants as described in any one of claims 1 to 4 is implemented.
7. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the privacy protection method for resisting internal dishonest participants as described in any one of claims 1 to 4 is implemented.
8. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the privacy protection method for resisting internal dishonest participants as described in any one of claims 1 to 4 is implemented.
Citation Information
Patent Citations
Federated learning method for model aggregation under multiple keys and related equipment
CN112183767A
Intelligent Internet of Things privacy protection federal learning method based on block chain
CN118400089A