Multi-party authorization system for federated learning
By adjusting the model aggregation module, verification module, and control module, vulnerabilities in the federated learning protocol are resolved, the security and stability of the multi-party authorization system are improved, and unauthorized use and dissemination are prevented.
Patent Information
- Application Number
- CN202411332357.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-24
- Publication Date
- 2025-12-19
- Estimated Expiration
- 2044-09-24
AI Technical Summary
Existing federated learning protocols contain vulnerabilities that attackers can exploit to compromise data privacy, cause errors in data transmission, and lead to the loss of authorization credentials. This results in the system failing to recognize the credentials, thus reducing the security of the multi-party authorization system.
By employing a model aggregation module, a verification module, and a control module, the operational security of the multi-party authorization system is optimized by adjusting the transmission rate of authorization credentials, the memory usage of the secret share generator, and the training cycle of the federated model, thereby ensuring the accuracy and integrity of authorization credentials.
It improves the operational security of the multi-party authorization system, reduces the probability of data transmission errors caused by network fluctuations and component incompatibility, enhances the system's reliability and robustness, and prevents unauthorized use and dissemination.
Smart Images

Figure CN119402201B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of data sharing, and particularly relates to a multi-party authorization system for federated learning. BACKGROUND
[0002] The concept of federated learning is initially proposed to build a machine learning model based on data sets distributed among multiple users without sharing data with each other. The main idea is to aggregate local models learned on multiple devices without sending private data to semi-honest third-party servers or other devices; considering the privacy of secret data distributed among multiple institutions, Yang Qiang et al. extend the application of federated learning to a wide range of use cases and divide the scenarios into three categories: horizontal federated learning, vertical federated learning and federated transfer learning. Yang Qiang et al. further propose the concept of trusted federated learning to emphasize the importance of model intellectual property rights when building a secure federated learning system.
[0003] Under the background of privacy problems plaguing major platforms, federated learning has become a hot research direction. In the process of distributed learning, each role participating in learning does not exchange the data it possesses, but only exchanges model parameters or intermediate results to complete the overall model training, thereby meeting the requirements of data security, data non-exit domain and privacy protection under the premise of financial supervision, and completing a series of business model creation and optimization through sample or feature expansion.
[0004] After years of development, there are many kinds of federated learning. According to the network topology, there are centralized federated learning and decentralized federated learning, and according to the data partition, there are horizontal federated learning, vertical federated learning and federated transfer learning; the successful application of deep neural network (DNN) in computer vision, natural language processing and data mining tasks is at the cost of an expensive training process, which requires a lot of effort and cost in professional knowledge, special hardware and design and training of DNN models; on the other hand, a large amount of training data is needed to improve the performance of the model, and the amount of training data often increases monotonously with the increase of the amount of training data. Therefore, it is urgently needed to protect valuable training data and trained DNN models from being illegally copied, redistributed or misused; so far, both white-box watermarking and black-box watermarking methods have been widely used in the verification of DNN model ownership. In the white-box watermarking aspect, a specified binary string is added as a watermark code to the model, and the verifier verifies the copyright by extracting the corresponding binary string. However, most deep learning models deployed on cloud servers, including pirated models, are in a black-box scenario. A black-box watermarking method uses backdoor as a watermark key image. A specific backdoor image will trigger the backdoor and verify the copyright ownership.
[0005] CN117763616A discloses a federal learning sharing process multi-subject contribution evaluation method and system, the method comprises: a data sharing contribution evaluation model based on a blockchain, combined with smart contract calculation, to obtain a contribution evaluation result; the interaction process of the data sharing contribution evaluation model based on the blockchain comprises: each entity first registers using organization authentication authorization to ensure the identity and trustworthiness of the user; the entity includes a participant, a coordinator and a blockchain; the participant transmits the contribution evaluation statistics to the contribution evaluation smart contract, the contribution evaluation smart contract receives and analyzes the input data, and processes it according to the preset contribution evaluation rules and algorithms to obtain the contribution evaluation result, and stores the contribution evaluation result; wherein, the evaluation statistics data mainly includes four dimensions of basic information, data value, local model evaluation and model contribution weight. As can be seen, the federal learning sharing process multi-subject contribution evaluation method and system has the problem that the existing federal learning protocol has been proven to have vulnerabilities, attackers can exploit these vulnerabilities to compromise data privacy, resulting in errors in the data transmission process, causing data loss of the authorization credentials, and further causing the system to fail to identify the credentials, thereby causing the running safety of the multi-party authorization system to decline. SUMMARY
[0006] To this end, the present application provides a multi-party authorization system for federal learning to overcome the problem in the prior art that the existing federal learning protocol has been proven to have vulnerabilities, attackers can exploit these vulnerabilities to compromise data privacy, resulting in errors in the data transmission process, causing data loss of the authorization credentials, and further causing the system to fail to identify the credentials, thereby causing the running safety of the multi-party authorization system to decline.
[0007] To achieve the above object, the application provides a multi-party authorization system for federated learning, comprising: a model aggregation module configured to process local models of participants to output a federated model, comprising a model training unit configured to train local models of a plurality of participants to output a plurality of to-be-aggregated models, and a model aggregation unit connected to the model training unit and configured to perform an aggregation operation on the corresponding plurality of to-be-aggregated models to output a federated model; a verification module connected to the model aggregation module and configured to verify a use authority of a user according to an authorization credential of the participant, comprising a secret share generator configured to generate a corresponding secret share according to a backdoor information code of the participant, an authorization credential distributor connected to the secret share generator and configured to distribute the secret share to the participant, and a credential restorer configured to verify the use authority of the user; and a control module connected to the model aggregation module and the verification module respectively, configured to adjust a transmission rate of the authorization credential or determine a running memory proportion of the secret share generator according to an average generation number of the secret share when determining that a running safety of the multi-party authorization system does not meet a requirement according to a proportion of a byte amount of the authorization credential of the user, and initially adjust a training period of the federated model according to a byte difference amount before and after decoding the authorization credential, and secondarily adjust the training period of the federated model according to an average training time length of the federated model for the same data amount after the federated model runs a single cycle at the initially adjusted training period.
[0008] Further, the model aggregation module further comprises a trusted server configured to adjust a federated model process.
[0009] Further, the verification module further comprises a backdoor information encoder configured to generate the backdoor information code.
[0010] Further, the process of verifying the use authority of the user is that the user provides the secret share to the trusted server, the trusted server first decrypts the secret share, then performs secret sharing recovery on the secret share to obtain the backdoor information code, the backdoor information code is input into a credential decoder, the credential decoder generates a group of backdoor instances for verification according to the input backdoor information code and returns, the trusted server inputs the backdoor instances into the model and returns a confidence degree, and the use authority of the user is judged according to the confidence degree.
[0011] Further, the control module is connected to the authorization verification unit and configured to calculate a proportion of a byte amount of the authorization credential of the user when being verified according to the byte amount of the authorization credential of the user when being verified and an original byte amount of the authorization credential of the user, and determine that the running safety of the multi-party authorization system does not meet the requirement when the proportion of the byte amount of the authorization credential of the user when being verified meets a first proportion condition or a second proportion condition.
[0012] The control module is connected with the secret share generator, and is configured to preliminarily determine that multi-party authorization stability does not meet the requirement when the proportion of the byte amount of the authorization credential of the user during the verification only meets the first proportion condition, and secondarily determine whether the multi-party authorization stability meets the requirement according to the average generation quantity of the secret shares;
[0013] The control module is connected with the credential transmission unit, and is configured to reduce the transmission rate of the authorization credential when the proportion of the byte amount of the authorization credential of the user during the verification only meets the second proportion condition;
[0014] The first proportion condition is that the proportion of the byte amount of the authorization credential of the user during the verification is greater than a preset first proportion and less than or equal to a preset second proportion, and the second proportion condition is that the proportion of the byte amount of the authorization credential of the user during the verification is greater than the preset second proportion.
[0015] Further, the calculation formula of the proportion of the byte amount of the authorization credential of the user during the verification is:
[0016]
[0017] The S is the proportion of the byte amount of the authorization credential of the user during the verification, T1 is the byte amount of the authorization credential of the user during the verification, and T2 is the original byte amount of the authorization credential of the user.
[0018] Further, the transmission rate of the authorization credential after the reduction is determined by the difference between the proportion of the byte amount of the authorization credential of the user during the verification and the preset second proportion.
[0019] Further, the control module is connected with the secret share generator, and is configured to secondarily determine that the multi-party authorization stability does not meet the requirement when the average generation quantity of the secret shares meets the first quantity condition or the second quantity condition, and preliminarily determine that the effectiveness of the authorization verification does not meet the requirement when the average generation quantity of the secret shares only meets the second quantity condition, and secondarily determine whether the effectiveness of the authorization verification meets the requirement according to the byte difference amount before and after the decoding of the authorization credential;
[0020] The control module is connected with the secret share generator, and is configured to increase the running memory proportion of the secret share generator when the average generation quantity of the secret shares only meets the first quantity condition.
[0021] The running memory proportion of the secret share generator after the increase is determined by the difference between the average generation quantity of the secret shares and the preset first quantity.
[0022] The first quantity condition is that the average number of secret shares generated is greater than a preset first quantity and less than or equal to a preset second quantity; and the first quantity condition is that the average number of secret shares generated is greater than the preset second quantity.
[0023] Further, the control module is connected with the secret share generator and the model training unit respectively, to determine that the validity of the authorization verification does not meet the requirement when the byte difference amount before and after decoding the authorization credential is greater than a preset difference amount, and to increase the training period of the federated model;
[0024] The training period of the federated model after the increase is determined by the difference between the byte difference amount before and after decoding the authorization credential and the preset difference amount.
[0025] Further, the control module is connected with the secret share generator and the model training unit respectively, to determine that the processing efficiency of the federated model does not meet the requirement when the average training duration of the federated model for the same data amount is greater than a preset training duration, and to decrease the training period of the federated model after the increase.
[0026] The training period of the federated model after the decrease is determined by the difference between the average training duration of the federated model for the same data amount and the preset training duration.
[0027] Compared with the prior art, the system has the beneficial effects that: the system sets a model aggregation module, a verification module and a control module, adjusts the transmission rate of the authorization credential according to the byte amount proportion of the authorization credential of the user during verification, reduces the probability of data transmission errors caused by network fluctuations, adjusts the running memory proportion of the secret share generator according to the average number of secret shares generated, improves the resource utilization rate of the generator, reduces the influence caused by incompatibility, adjusts the training period of the federated model according to the byte difference amount before and after the authorization credential decoding, reduces the influence caused by different character encodings of the credential data, adjusts the training period of the federated model according to the average training time of the federated model for the same data amount, reduces the influence caused by different character encodings of the credential data, and improves the processing efficiency of the federated model.
[0028] Further, in the system, the authorization of the model is no longer owned by a single central server, but is realized through multi-party authorization. No one can decide the use rights of the model alone, ensuring the fairness and reliability of the authorization. Only after collecting a sufficient number of authorization credentials can the user use the model, thereby avoiding unauthorized use. Through the implementation of the multi-party authorization mechanism, access to the model becomes more difficult and limited. Users need to spend time and effort to collect authorization credentials, improving the scarcity and value of the model. At the same time, the multi-party authorization mechanism can also dynamically adjust the number of authorizations and the acquisition threshold according to the demand, further improving the value of the model. Through the multi-party authorization mechanism, the system effectively prevents unauthorized illegal use and dissemination. Only those users with legal authorization can use the model, which can prevent piracy, infringement and unauthorized use.
[0029] Further, unlike traditional centralized authorization systems, the present system adopts a distributed authorization credential generation and management mechanism involving multiple participants. This distributed approach not only protects authorization information but also reduces the risk of single-point failure, improving system scalability and robustness. In the system, authorization credential generation and management are distributed among multiple participants, so even if a node is attacked or fails, other nodes can continue to operate, maintaining system availability and stability. Authorization credentials and data in the system are distributed across multiple nodes, and attackers need to attack multiple nodes simultaneously to obtain complete information, increasing the difficulty of attacks.
[0030] Further, the system of the present application adjusts the transmission rate of the authorization credential by setting the preset first proportion and the preset second proportion. Due to network fluctuations at the user end, errors occur in the data transmission process, resulting in data loss of the authorization credential, which in turn leads to unsuccessful identification of the credential by the system, resulting in authorization failure. By reducing the transmission rate of the authorization credential, the probability of data transmission errors caused by network fluctuations is reduced, further improving the operational safety of the multi-party authorization system.
[0031] Further, the system of the present application adjusts the running memory proportion of the secret share generator by setting the preset first number and the preset second number. Since the secret share generator may rely on other components or services, when the components are updated, incompatible changes may be introduced, causing the secret share generator to be incompatible with the components, which in turn causes the generator to fail to generate the correct number of shares. By increasing the running memory proportion of the secret share generator, the resource utilization of the generator is improved, reducing the impact of incompatibility problems, further improving the operational safety of the multi-party authorization system.
[0032] Further, the system of the present application adjusts the training period of the federated model by setting the preset difference amount. Since the character encoding of the credential data may be different, the credential decoder fails to correctly process, resulting in parsing errors, improper handling of the boundary conditions of the credential data, and problems with the credential decoder, leading to unsuccessful verification. By increasing the training period of the federated model, the model is further optimized for credential data, reducing the impact of different character encodings of the credential data causing verification failure, further improving the operational safety of the multi-party authorization system.
[0033] Further, the system disclosed in the application adjusts the training period of the federal model by setting a preset training duration, because an excessively long training period will lead to a prolonged training duration, resulting in a longer waiting time for the user to transmit the local model to the central server, thereby prolonging the overall training duration, the processing efficiency of the federal model is improved by reducing the training period of the federal model, and the operation safety of the multi-party authorization system is further improved. BRIEF DESCRIPTION OF DRAWINGS
[0034] Figure 1 The overall structure block diagram of the multi-party authorization system for federated learning of the embodiment of the application is shown in the figure.
[0035] Figure 2 The specific flowchart of the federal model training and aggregation process of the multi-party authorization system for federated learning of the embodiment of the application is shown in the figure.
[0036] Figure 3 The specific flowchart of the process of processing the local model of the user to output the federal model of the multi-party authorization system for federated learning of the embodiment of the application is shown in the figure.
[0037] Figure 4 The logic flowchart of the multi-party authorization system for federated learning of the embodiment of the application is shown in the figure. DETAILED DESCRIPTION
[0038] In order to make the objects and advantages of the application clearer, the application will be further described below with reference to the embodiments. It should be understood that the specific embodiments described herein are only used to explain the application and do not limit the application.
[0039] The preferred embodiments of the application will be described below with reference to the accompanying drawings. Those skilled in the art should understand that these embodiments are only used to explain the technical principles of the application and do not limit the protection scope of the application.
[0040] In addition, it should be further pointed out that in the description of the application, unless otherwise explicitly specified and limited, the terms "mounting", "connecting", "connecting" should be understood broadly, for example, it can be fixedly connected, or it can be detachably connected, or integrally connected; it can be mechanically connected, or it can be electrically connected; it can be directly connected, or it can be indirectly connected through an intermediate medium, or it can be the communication inside two elements. Those skilled in the art can understand the specific meaning of the above terms in the application according to the specific circumstances.
[0041] Please refer to Figure 1 , Figure 2 , Figure 3 and Figure 4As shown, they are the overall structure block diagram of the multi-party authorization system for federated learning of the embodiment of the application, the specific flowchart of the federated model training aggregation process, the specific flowchart of the process of processing the local model of the user to output the federated model, and the logical flowchart. The multi-party authorization system for federated learning of the application comprises:
[0042] The model aggregation module is used to process the local model of the participant to output the federated model, comprising a model training unit used to train the local model of the plurality of participants to output the to-be-aggregated model and a model aggregation unit connected with the model training unit and used to perform the aggregation operation on the corresponding number of to-be-aggregated models to output the federated model;
[0043] The verification module connected with the model aggregation module is used to verify the use authority of the user according to the authorization credential of the participant, comprising a secret share generator used to generate the corresponding secret share according to the backdoor information code of the participant, an authorization credential distributor connected with the secret share generator and used to distribute the secret share to the participant, and a credential restorer used to verify the use authority of the user;
[0044] The control module connected with the model aggregation module and the verification module respectively is used to adjust the transmission rate of the authorization credential or determine the running memory proportion of the secret share generator according to the average generation number of the secret share when the running safety of the multi-party authorization system does not meet the requirements according to the proportion of the byte amount of the authorization credential of the user, and initially adjust the training period of the federated model according to the byte difference amount before and after the decoding of the authorization credential, and secondarily adjust the training period of the federated model according to the average training time of the federated model for the same data amount after the federated model runs a single cycle with the training period after the initial adjustment.
[0045] Specifically, the role of aggregation is to combine the updated local models of a plurality of users to generate a federated model.
[0046] Specifically, the meaning of the byte difference amount before and after the decoding of the authorization credential is the difference between the data byte amount of the authorization credential data and the data byte amount after the decoding of the authorization credential data by the credential decoder.
[0047] Specifically, the process of processing the local model of the user to output the federated model is: first uploaded to the trusted server by the local model of the participant, the trusted server feeds back the federated model available to each node through the model training unit and the model aggregation unit, and then the trusted server generates backdoor information. In the model training unit, the generated backdoor information is converted into a backdoor information code by the backdoor information encoder of the trusted server. Then a part of the training information is selected from each node, the backdoor information code is embedded therein, a backdoor instance is generated, and the backdoor instance is used as a backdoor dataset, and the generation of the backdoor dataset is also included in the model training unit. After constructing the backdoor dataset, the trusted server also needs to construct an authorization authentication unit, and the trusted server generates a certain number of secret shares according to the Shamir secret sharing scheme based on the backdoor information code. After the above process is completed, the trusted server encrypts the certain number of secret shares obtained, and packs the backdoor dataset for distribution to each node. Next, each node trains a model with a backdoor through the backdoor dataset, and uploads it to the trusted server. The trusted server calls the model training unit and the model aggregation unit again, aggregates the backdoor model and distributes it to each node, so that each node obtains a federated model with a backdoor and an encrypted secret share.
[0048] Specifically, if the model is trained using the backdoor dataset, the structure of the model will be fine-tuned by the backdoor dataset, and then become a model with a backdoor.
[0049] Specifically, the determination process of the secret share generator is: each participant negotiates to determine the minimum number of participants that can represent the "overall" authorization, that is, the threshold. Then, based on the Shamir algorithm, N secret shares are generated based on the threshold n, the backdoor information code c and the number N of federated participants.
[0050] Specifically, the operation process of the authorization credential distributor is: after the secret share and the backdoor dataset are generated, the authorization credential distributor first homomorphically encrypts the key, and then distributes the backdoor dataset and the secret share to each federated node.
[0051] Specifically, the operation process of the credential restorer is: the user provides the share to the trusted server, and the server first decrypts the share, and then restores the share by secret sharing to obtain the backdoor information code. The backdoor information code is input to the credential decoder. The credential decoder generates a group of backdoor instances for verification according to the input backdoor information code and returns. The server inputs the instance to the model to return the confidence, and judges the user's authority according to the confidence.
[0052] Specifically, the steps of federated model training and aggregation include:
[0053] Step S1, global model parameter initialization;
[0054] Step S2, the trusted server transmits the global model parameters to all participants, and selects several participants according to a fixed proportion for training;
[0055] Step S3, the selected participants initialize the local model using the global model parameters, perform multiple rounds of gradient descent, and update the parameters multiple times;
[0056] Step S4, the selected participants transmit the local model parameters to the trusted server;
[0057] Step S5, the trusted server aggregates the local model parameters into global model parameters through weighted average aggregation.
[0058] Specifically, in the system described in the present application, the authorization of the model is no longer owned by a single central server, but is realized through multi-party authorization. No one can decide the use rights of the model alone, ensuring the fairness and reliability of the authorization. Only after collecting enough authorization credentials, the user can use the model, thereby avoiding unauthorized use. Through the implementation of the multi-party authorization mechanism, it makes the access to the model more difficult and limited. Users need to spend time and effort to collect authorization credentials, which improves the scarcity and value of the model. At the same time, the multi-party authorization mechanism can also dynamically adjust the number of authorizations and the threshold for obtaining, further improving the value of the model. Through the multi-party authorization mechanism, the present system effectively prevents unauthorized illegal use and dissemination. Only those users with legal authorization can use the model, which can prevent piracy, infringement and unauthorized use.
[0059] Specifically, unlike traditional centralized authorization systems, the present system adopts a distributed authorization credential generation and management mechanism with multiple participants. This distributed approach not only protects authorization information, but also reduces the risk of single point failure, while improving the scalability and robustness of the system. In the system, the generation and management of authorization credentials are distributed among multiple participants, so even if a node is attacked or fails, other nodes can still continue to run, maintaining the availability and stability of the system. The authorization credentials and data in the system are dispersed among multiple nodes, and attackers need to attack multiple nodes simultaneously to obtain complete information, increasing the difficulty of attacks.
[0060] In the implementation, the system disclosed by the application adjusts the transmission rate of the authorization credential according to the byte amount proportion of the authorization credential of the user during verification, reduces the probability of data transmission errors caused by network fluctuations, adjusts the running memory proportion of the secret share generator according to the average number of secret shares generated, improves the resource utilization of the generator, reduces the influence of incompatibility, adjusts the training period of the federated model according to the byte difference of the authorization credential before and after decoding, optimizes the model for credential data, reduces the influence of different character encodings of credential data, adjusts the training period of the federated model according to the average training time of the federated model for the same data amount, reduces the training period, improves the processing efficiency of the federated model, and improves the operation security of the multi-party authorization system.
[0061] Specifically, the model aggregation module further includes a trusted server for adjusting the federated model process.
[0062] Specifically, the verification module further includes a backdoor information encoder for generating the backdoor information code.
[0063] Specifically, the process of verifying the use permission of the user is that the user provides a secret share to the trusted server. The trusted server first decrypts the secret share, then recovers the secret share by secret sharing to obtain a backdoor information code. The backdoor information code is input to the credential decoder, which generates a set of backdoor instances for verification according to the input backdoor information code and returns. The trusted server inputs the backdoor instance into the model and returns the confidence. The use permission of the user is judged according to the confidence.
[0064] Specifically, the control module is connected with the authorization verification unit, to calculate a byte proportion of the authorization credential of the user in the verification according to a byte amount of the authorization credential of the user in the verification and an original byte amount of the authorization credential of the user, and determine that the operation safety of the multi-party authorization system does not meet the requirement when the byte proportion of the authorization credential of the user in the verification meets a first proportion condition or a second proportion condition.
[0065] The control module is connected with the secret share generator, to preliminarily determine that the multi-party authorization stability does not meet the requirement when the byte proportion of the authorization credential of the user in the verification only meets the first proportion condition, and secondarily determine whether the multi-party authorization stability meets the requirement according to an average generation number of the secret shares.
[0066] The control module is connected with the credential transmission unit, to reduce a transmission rate of the authorization credential when the byte proportion of the authorization credential of the user in the verification only meets the second proportion condition.
[0067] The first proportion condition is that the byte proportion of the authorization credential of the user in the verification is greater than a preset first proportion and less than or equal to a preset second proportion, and the second proportion condition is that the byte proportion of the authorization credential of the user in the verification is greater than the preset second proportion.
[0068] Optionally, a preferred embodiment of the preset first proportion Q1 is Q1 = 0.7, and a preferred embodiment of the preset second proportion Q2 is Q2 = 0.75.
[0069] Specifically, the byte proportion of the authorization credential of the user in the verification is denoted as Q, a difference between the byte proportion of the authorization credential of the user in the verification and the preset second proportion is denoted as AQ, and AQ = Q-Q2 is set.
[0070] In implementation, the system determines the operation safety of the multi-party authorization system by setting the preset first proportion and the preset second proportion, reduces the influence of the decline of the operation stability of the federated model caused by the inaccurate determination of the operation safety of the multi-party authorization system, and further improves the operation safety of the multi-party authorization system.
[0071] Specifically, the process of the user in the verification can be that the user wants to use a service provided by a model based on federated training. Since the model is public to each federated node, assuming that the number of nodes is N, the user needs to send a use request to no less than n (threshold) nodes. After receiving the request of the user, the nodes provide the encrypted secret share to the user.
[0072] The user calls a credential recovery interface of the trusted server, inputs no less than n secret shares to the trusted server, and calls a verification module by the trusted server for processing. The module outputs a confidence degree for judging whether the user has the right to use.
[0073] Specifically, the trusted server judges the right of the node as follows: if the model presents backdoor behavior with high confidence, it means that the user has the right to use the model; if the user only gets the right shares that do not meet the threshold number (i.e., only gets partial authorization) or directly forges the right shares, the model presents the backdoor behavior with low confidence, and the user cannot pass the verification.
[0074] Specifically, the calculation formula of the byte amount proportion of the authorized credential of the user during verification is:
[0075]
[0076] Wherein, S is the byte amount proportion of the authorized credential of the user during verification, T1 is the byte amount of the authorized credential of the user during verification, and T2 is the original byte amount of the authorized credential of the user.
[0077] Specifically, the transmission rate of the reduced authorized credential is determined by the difference between the byte amount proportion of the authorized credential of the user during verification and the preset second proportion.
[0078] Specifically, the specific process of determining the transmission rate of the authorized credential by the difference between the byte amount proportion of the authorized credential of the user during verification and the preset second proportion is:
[0079] If ΔQ≤ΔQ0, the control module adjusts the transmission rate of the authorized credential to the first transmission rate using the preset second transmission rate adjustment coefficient;
[0080] If ΔQ>ΔQ0, the control module adjusts the transmission rate of the authorized credential to the second transmission rate using the preset first transmission rate adjustment coefficient.
[0081] Wherein, the preset first transmission rate adjustment coefficient is smaller than the preset second transmission rate adjustment coefficient.
[0082] Optionally, the preferred embodiment of the preset proportion difference ΔQ0 is ΔQ0=0.1.
[0083] Specifically, the preset first transmission rate adjustment coefficient is denoted as α1, and α1=0.8 is set. The preset second transmission rate adjustment coefficient is denoted as α2, and α2=0.9 is set. The transmission rate of the authorized credential is denoted as V, wherein 0<α1<α2<1. The adjusted transmission rate of the authorized credential is denoted as V', and V'=V×(1+αi) / 2 is set, wherein αi is the preset ith transmission rate adjustment coefficient, and i=1, 2 is set.
[0084] In the implementation, the system adjusts the transmission rate of the authorization credential by setting the preset first proportion and the preset second proportion. Due to network fluctuation of the user end, errors occur in the data transmission process, data loss of the authorization credential occurs, and the system fails to successfully identify the credential, thereby causing authorization failure. By reducing the transmission rate of the authorization credential, the probability of data transmission errors caused by network fluctuation is reduced, and the operation safety of the multi-party authorization system is further improved.
[0085] Specifically, the control module is connected with the secret share generator, and is configured to twice determine that the multi-party authorization stability does not meet the requirement when the average generation quantity of the secret shares meets the first quantity condition or the second quantity condition, and preliminarily determine that the validity of the authorization verification does not meet the requirement when the average generation quantity of the secret shares only meets the second quantity condition, and twice determine whether the validity of the authorization verification meets the requirement according to the byte difference quantity before and after decoding of the authorization credential.
[0086] The control module is connected with the secret share generator, and is configured to increase the running memory proportion of the secret share generator when the average generation quantity of the secret shares only meets the first quantity condition.
[0087] The first quantity condition is that the average generation quantity of the secret shares is greater than a preset first quantity and less than or equal to a preset second quantity, and the second quantity condition is that the average generation quantity of the secret shares is greater than the preset second quantity.
[0088] Optionally, a preferred embodiment of the preset first quantity P1 is P1=10, and a preferred embodiment of the preset second quantity P2 is P2=12.
[0089] Specifically, the average generation quantity of the secret shares is denoted as P, the difference between the average generation quantity of the secret shares and the preset first quantity is denoted as ΔP, and ΔP=P-P1 is set.
[0090] Specifically, the calculation formula of the average generation quantity of the secret shares is:
[0091]
[0092] wherein P is the average generation quantity of the secret shares, Xa is the number of the secret shares generated in the a th generation cycle, n is the number of the generation cycles, and n is a natural number greater than or equal to 1. a wherein P is the average generation quantity of the secret shares, Xa is the number of the secret shares generated in the a th generation cycle, n is the number of the generation cycles, and n is a natural number greater than or equal to 1.
[0093] In the implementation, the system determines the multi-party authorization stability twice by setting the preset first quantity and the preset second quantity, reduces the influence of the decline of the operation safety of the multi-party authorization system caused by the inaccurate second determination of the multi-party authorization stability, and further improves the operation safety of the multi-party authorization system.
[0094] Specifically, the increased running memory proportion of the secret share generator is determined by the difference between the average generation quantity of the secret share and the preset first quantity.
[0095] Specifically, the specific process of determining the running memory proportion of the secret share generator by the difference between the average generation quantity of the secret share and the preset first quantity is as follows:
[0096] If ΔP≤ΔP0, the control module adjusts the running memory proportion of the secret share generator to the first proportion by using the preset first proportion adjustment coefficient.
[0097] If ΔP>ΔP0, the control module adjusts the running memory proportion of the secret share generator to the second proportion by using the preset second proportion adjustment coefficient.
[0098] The preset first proportion adjustment coefficient is smaller than the preset second proportion adjustment coefficient.
[0099] Optionally, the preferred embodiment of the preset quantity difference ΔP0 is ΔP0=3.
[0100] Specifically, the preset first proportion adjustment coefficient is denoted as β1, β1 is set to 1.2, the preset second proportion adjustment coefficient is denoted as β2, β2 is set to 1.4, the running memory proportion of the secret share generator is denoted as H, 1<β1<β2, the adjusted running memory proportion of the secret share generator is denoted as H', H' is set to H×(1+2βj) / 3, βj is the preset jth proportion adjustment coefficient, and j is set to 1 and 2.
[0101] In the implementation, the system adjusts the running memory proportion of the secret share generator by setting the preset first quantity and the preset second quantity. Since the secret share generator may depend on other components or services, when the components are updated, incompatible changes may be introduced, which causes the secret share generator to be incompatible with the components, and further causes the generator to fail to generate the correct quantity of shares. By increasing the running memory proportion of the secret share generator, the resource utilization of the generator is improved, the influence of the problems caused by the incompatibility is reduced, and the operation safety of the multi-party authorization system is further improved.
[0102] Specifically, the control module is connected with the secret share generator and the model training unit respectively, to determine that the validity of the authorization verification does not meet the requirement when the byte difference amount before and after the decoding of the authorization credential is greater than the preset difference amount, and to increase the training period of the federated model.
[0103] Optionally, a preferred embodiment of the preset difference amount Y0 is Y0=200 Byte.
[0104] Specifically, the byte difference amount before and after the decoding of the authorization credential is denoted as Y, the difference between the byte difference amount before and after the decoding of the authorization credential and the preset difference amount is denoted as △Y, and it is set that △Y=Y0-Y.
[0105] Specifically, the calculation formula of the byte difference amount before and after the decoding of the authorization credential is:
[0106] Y=|E1-E2|
[0107] Y is the byte difference amount before and after the decoding of the authorization credential, E1 is the byte amount before the decoding of the authorization credential data, and E2 is the byte difference amount after the decoding of the authorization credential data.
[0108] In implementation, the system of the present application determines the validity of the authorization verification again by setting the preset difference amount, reduces the influence of the decline of the operation safety of the multi-party authorization system due to the inaccurate second determination of the validity of the authorization verification, and further improves the operation safety of the multi-party authorization system.
[0109] Specifically, the training period of the federated model after the increase is determined by the difference between the byte difference amount before and after the decoding of the authorization credential and the preset difference amount.
[0110] Specifically, the specific process of determining the training period of the federated model by the difference between the byte difference amount before and after the decoding of the authorization credential and the preset difference amount is as follows:
[0111] If △Y≤△Y0, the control module adjusts the training period of the federated model to a first period using a preset first period adjustment coefficient.
[0112] If △Y>△Y0, the control module adjusts the training period of the federated model to a second period using a preset second period adjustment coefficient.
[0113] The preset first period adjustment coefficient is less than the preset second period adjustment coefficient.
[0114] Optionally, a preferred embodiment of the preset difference amount difference △Y0 is △Y0=50 Byte.
[0115] Specifically, the preset first period adjustment coefficient is denoted as γ1, γ1 is set as 1.1, the preset second period adjustment coefficient is denoted as γ2, γ2 is set as 1.3, the training period of the federated model is denoted as L, wherein 1 < γ1 < γ2, the training period of the adjusted federated model is denoted as L', L' is set as L x (1 + 3γm) / 4, wherein γm is the preset m period adjustment coefficient, and m is set as 1 or 2.
[0116] In implementation, the system disclosed in the application adjusts the training period of the federated model by setting the preset difference amount. Since the character encoding of the credential data may be different, the credential decoder fails to correctly process, resulting in analysis errors, improper handling of boundary conditions of the credential data, and further problems of the credential decoder, thereby causing unsuccessful verification. By increasing the training period of the federated model, the model is further optimized for the credential data, the influence of verification failure caused by different character encoding of the credential data is reduced, and the running safety of the multi-party authorization system is further improved.
[0117] Specifically, the control module is connected with the secret share generator and the model training unit respectively, so as to determine that the processing efficiency of the federated model does not meet the requirements when the average training time length of the federated model for the same data amount is greater than the preset training time length, and to reduce the training period of the increased federated model.
[0118] Optionally, the preferred embodiment of the preset training time length R0 is R0 = 3s.
[0119] Specifically, the average training time length of the federated model for the same data amount is denoted as R, and the difference between the average training time length of the federated model for the same data amount and the preset training time length is denoted as ΔR, and ΔR is set as R-R0.
[0120] Specifically, the calculation formula of the average training time length of the federated model for the same data amount is:
[0121]
[0122] Wherein, R is the average training time length of the federated model for the same data amount, B f is the training time length of the federated model for the same data amount in the fth running period, c is the number of running periods, and c is a natural number greater than or equal to 1.
[0123] In implementation, the system disclosed in the application determines the processing efficiency of the federated model by setting the preset training time length, reduces the influence of the decline of the running safety of the multi-party authorization system caused by inaccurate determination of the processing efficiency of the federated model, and further improves the running safety of the multi-party authorization system.
[0124] Specifically, the reduced training period of the federal model is determined by the difference between the average training time of the federal model for the same amount of data and the preset training time.
[0125] Specifically, the specific process of determining the training period of the federal model by the difference between the average training time of the federal model for the same amount of data and the preset training time is as follows:
[0126] If ΔR≤ΔR0, the control module uses a preset fourth period secondary adjustment coefficient to secondarily adjust the training period of the federal model to a third period;
[0127] If ΔR>ΔR0, the control module uses a preset third period secondary adjustment coefficient to secondarily adjust the training period of the federal model to a fourth period;
[0128] Wherein, the third period secondary adjustment coefficient is smaller than the fourth period secondary adjustment coefficient.
[0129] Optionally, the preferred embodiment of the preset training time difference ΔR0 is ΔR0=1s.
[0130] Specifically, the preset third period secondary adjustment coefficient is denoted as γ3, and γ3=0.7 is set. The preset fourth period secondary adjustment coefficient is denoted as γ4, and γ4=0.8 is set. Wherein, 0<β3<β4<1, the adjusted training period of the federal model is denoted as L'', and L''=L'×(1+3γw) / 4 is set, wherein γw is a preset w period secondary adjustment coefficient, and w=3,4 is set.
[0131] In implementation, the system of the present application secondarily adjusts the training period of the federal model by setting a preset training time. Since an excessively long training period will lead to an extended training time, the user needs to wait for a longer time to transmit the local model to the central server, thereby leading to an extended overall training time. By reducing the training period of the federal model, the processing efficiency of the federal model is improved, and the operation safety of the multi-party authorization system is further improved.
[0132] Embodiment 1
[0133] In this embodiment 1, a multi-party authorization system for federal learning is used to provide services for multiple federal nodes. The control module adjusts the transmission rate of the authorization credential according to the difference between the byte amount proportion of the user's authorization credential during verification and the preset second proportion. Wherein, the preset first transmission rate adjustment coefficient is denoted as α1, the preset second transmission rate adjustment coefficient is denoted as α2, and the transmission rate of the authorization credential is denoted as V, wherein 0<α1<α2<1, α1=0.8 is set, α2=0.9 is set, ΔQ0=0.1, V=20Mbps, Q=0.9, Q2=0.75, and ΔQ=Q-Q2.
[0134] The embodiment 1 obtains AQ=0.15, the control module determines AQ> AQ0and adjusts the transmission rate of the authorization credential to a second transmission rate using a preset first transmission rate adjustment coefficient, and calculates V'=20 Mbps x (1+0.8) / 2=18 Mbps.
[0135] So far, the technical solutions of the present application have been described in combination with the preferred embodiments shown in the drawings, but those skilled in the art can easily understand that the protection scope of the present application is obviously not limited to these specific embodiments. Those skilled in the art can make equivalent changes or replacements to the related technical features without deviating from the principles of the present application, and the technical solutions after these changes or replacements will all fall within the protection scope of the present application.
Claims
1. A multi-party authorization system for federated learning, characterized in that, The method comprises the following steps: a model aggregation module is used to process local models of participants to output a federated model, comprising a model training unit used to train local models of a plurality of participants to output models to be aggregated, and a model aggregation unit connected to the model training unit and used to perform an aggregation operation on a corresponding number of models to be aggregated to output a federated model; a verification module connected to the model aggregation module is used to verify the use authority of a user according to the authorized credentials of the participants, comprising a secret share generator used to generate a corresponding secret share according to the backdoor information code of the participants, an authorized credential distributor connected to the secret share generator and used to distribute the secret share to the participants, and a credential restorer used to verify the use authority of the user; a control module connected to the model aggregation module and the verification module is used to adjust the transmission rate of the authorized credentials when it is determined that the running safety of the multi-party authorization system does not meet the requirements according to the proportion of the byte amount of the authorized credentials of the user, or to determine the running memory proportion of the secret share generator according to the average number of generated secret shares, and to initially adjust the training period of the federated model according to the byte difference amount before and after the decoding of the authorized credentials, and to secondarily adjust the training period of the federated model according to the average training time of the federated model for the same data amount after the federated model runs for a single period with the initially adjusted training period.
2. The federated learning oriented multi-party authorization system according to claim 1, wherein, The model aggregation module further comprises a trusted server used to adjust the federated model process.
3. The federated learning oriented multi-party authorization system according to claim 1, wherein, The verification module further comprises a backdoor information encoder used to generate the backdoor information code.
4. The federated learning oriented multi-party authorization system according to claim 1, wherein, The process of verifying the use authority of the user is that the user provides a secret share to the trusted server, the trusted server first decrypts the secret share, then restores the secret share by secret sharing to obtain a backdoor information code, the backdoor information code is input into a credential decoder, the credential decoder generates a set of backdoor instances for verification according to the input backdoor information code and returns, the trusted server inputs the backdoor instances into the model and returns the confidence, and the use authority of the user is judged according to the confidence.
5. The federated learning oriented multi-party authorization system according to claim 1, wherein, The control module connected to the verification module is used to calculate the proportion of the byte amount of the authorized credentials of the user when verifying according to the byte amount of the authorized credentials of the user when verifying and the original byte amount of the authorized credentials of the user, and to determine that the running safety of the multi-party authorization system does not meet the requirements when the proportion of the byte amount of the authorized credentials of the user when verifying meets the first proportion condition or the second proportion condition; The control module connected to the secret share generator is used to preliminarily determine that the multi-party authorization stability does not meet the requirements when the proportion of the byte amount of the authorized credentials of the user when verifying only meets the first proportion condition, and to secondarily determine whether the multi-party authorization stability meets the requirements according to the average number of generated secret shares; The control module connected to the verification module is used to reduce the transmission rate of the authorized credentials when the proportion of the byte amount of the authorized credentials of the user when verifying only meets the second proportion condition. The first proportion condition is that the byte proportion of the authorization credential of the user during verification is greater than a preset first proportion and less than or equal to a preset second proportion; and the second proportion condition is that the byte proportion of the authorization credential of the user during verification is greater than the preset second proportion.
6. The federated learning oriented multi-party authorization system according to claim 5, wherein, The calculation formula of the byte amount proportion of the authorized credential of the user during the verification is: Wherein, S is the byte amount proportion of the authorized credential of the user during the verification, T1 is the byte amount of the authorized credential of the user during the verification, and T2 is the original byte amount of the authorized credential of the user.
7. The federated learning oriented multi-party authorization system according to claim 6, wherein, The transmission rate of the reduced authorization credential is determined by the difference between the byte proportion of the authorization credential of the user during verification and the preset second proportion.
8. The federated learning oriented multi-party authorization system according to claim 7, wherein, The control module is connected with the secret share generator, and is configured to determine that multi-party authorization stability does not meet the requirement when the average number of generated secret shares meets the first number condition or the second number condition, and preliminarily determine that the validity of authorization verification does not meet the requirement when the average number of generated secret shares only meets the second number condition, and secondarily determine whether the validity of authorization verification meets the requirement according to the byte difference between before and after decoding the authorization credential. The control module is connected with the secret share generator, and is configured to increase the running memory proportion of the secret share generator when the average number of generated secret shares only meets the first number condition. The increased running memory proportion of the secret share generator is determined by the difference between the average number of generated secret shares and the preset first number. The first number condition is that the average number of generated secret shares is greater than a preset first number and less than or equal to a preset second number; and the second number condition is that the average number of generated secret shares is greater than the preset second number.
9. The federated learning oriented multi-party authorization system according to claim 8, wherein, The control module is connected with the secret share generator and the model training unit, and is configured to secondarily determine that the validity of authorization verification does not meet the requirement when the byte difference between before and after decoding the authorization credential is greater than a preset difference, and increase the training period of the federated model. The increased training period of the federated model is determined by the difference between the byte difference between before and after decoding the authorization credential and the preset difference.
10. The federated learning oriented multi-party authorization system according to claim 9, wherein, The control module is connected with the secret share generator and the model training unit, and is configured to determine that the processing efficiency of the federated model does not meet the requirement when the average training time of the federated model for the same data amount is greater than a preset training time, and reduce the increased training period of the federated model. The reduced training period of the federated model is determined by the difference between the average training time of the federated model for the same data amount and the preset training time.
Citation Information
Patent Citations
Federal learning sharing process multi-subject contribution evaluation method and system
CN117763616A
Key management system and method for federated learning security audit, and storage medium
CN113364589A
Authorization control method and system, intelligent terminal and computer readable storage medium
CN114143100A