一种具有隐私保护的联邦学习方法

By using public-key encryption and private-key decryption techniques in federated learning, combined with a pseudo-random number generator and Mahalanobis distance verification, malicious nodes are eliminated, thus solving the problems of Byzantine attacks and privacy leaks, and achieving security and privacy protection for model training.

CN119398134BActive Publication Date: 2026-07-17JIAMUSI UNIVERSITY

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
JIAMUSI UNIVERSITY
Filing Date
2024-10-12
Publication Date
2026-07-17

AI Technical Summary

Technical Problem

In federated learning, Byzantine attacks affect model training and pose a risk of client privacy breaches, which are difficult to effectively address with existing technologies.

Method used

The gradient parameters are encrypted and transmitted using public-key encryption and private-key decryption techniques. The correctness and integrity of the gradient parameters are verified by a pseudo-random number generator and Mahalanobis distance, potential malicious nodes are eliminated, and the global model parameters are updated using the stochastic gradient descent algorithm.

Benefits of technology

This improves the accuracy of Byzantine node identification, avoids model training failures and privacy leaks, and ensures the security and privacy protection of model training.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119398134B_ABST
    Figure CN119398134B_ABST
Patent Text Reader

Abstract

一种具有隐私保护的联邦学习方法,它属于联邦学习技术领域。本发明解决了现有的联邦学习方法中,拜占庭攻击对模型训练存在影响以及客户端存在隐私泄露风险的问题。本发明将梯度参数经过伪随机数生成器,再基于生成的随机数对参与方提交梯度参数的正确性和完整性进行验证,以避免传递参数的过程中出现错误,通过对比来排查参与方是否重复提交梯度参数。服务器基于马氏距离来判断通过验证的梯度参数的相似性,以排除恶意梯度参数。再对剩余的梯度参数进行聚合,最后使用随机梯度下降算法计算得出更新的全局模型参数。本发明方法可以避免拜占庭攻击对模型训练产生影响,解决了参与方存在隐私泄露风险的问题。本发明方法可以应用于联邦学习领域。
Need to check novelty before this filing date? Find Prior Art