Poisoning Defense Method, Device, Equipment, Medium and Product for Federated Learning
By combining model update data and client behavior data for multimodal anomaly detection and trust score adjustment, injecting adaptive noise and weighted aggregation, the security problem of federated learning system under poisoning attacks is solved, and higher defense adaptability and robustness are achieved.
Patent Information
- Application Number
- CN202411650719.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-19
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2044-11-19
AI Technical Summary
The decentralized nature of federated learning makes it vulnerable to poisoning attacks. Malicious clients destroy the performance of the global model by uploading fake model updates, and even cause the model to make wrong decisions, threatening the security of the global model.
By combining the model update data uploaded by the client and the client behavior data, multimodal features are generated, abnormal detection is performed, trust scores are adjusted, and adaptive noise is injected into clients with low trust scores. Finally, weighted aggregation is performed based on trust scores to generate a global model.
It effectively improves the ability of federated learning systems to deal with complex poisoning attacks, and can accurately detect malicious clients in more complex and sparse data scenarios, improves the adaptability and robustness of defense, and improves the security of the global model.
Smart Images

Figure CN119520096B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to the field of network security technology. More specifically, embodiments of the present invention relate to a poisoning defense method, apparatus, device, medium and product for federated learning. Background Art
[0002] This section aims to provide background or context for the embodiments of the present invention described in the claims. The description herein is not admitted to be prior art merely by including it in this section.
[0003] With the rapid development of information technology and the improvement of data privacy protection awareness, Federated Learning (FL), as a distributed machine learning framework, has received extensive attention and applications because it can achieve multi-party collaborative training without sharing raw data.
[0004] However, the decentralized nature of federated learning makes it vulnerable to malicious attacks, especially poisoning attacks. In such attacks, malicious clients try to undermine the performance of the global model by uploading forged model updates, and even cause the model to make wrong decisions, thus threatening the security of the global model. Summary of the Invention
[0005] In this context, embodiments of the present invention are expected to provide a poisoning defense method, apparatus, device, medium and product for federated learning.
[0006] In the first aspect of the embodiments of the present invention, a poisoning defense method for federated learning is provided. The method includes:
[0007] Combining the model update data and client behavior data uploaded by each client to obtain multi-modal features corresponding to each client respectively;
[0008] Performing anomaly detection on the multi-modal features of each client to obtain an anomaly detection result;
[0009] Adjusting the trust score of each client based on the anomaly detection result to obtain an adjusted trust score;
[0010] Injecting adaptive noise into a target client whose adjusted trust score is lower than a preset score to obtain a malicious client, where the adaptive noise is generated based on the anomaly detection result;
[0011] Performing weighted aggregation on each client based on the adjusted trust score to obtain a global model, where the malicious client is included in each client.
[0012] In an embodiment of the present embodiment, the model update data is the updated data after the client's training, and the client behavior data at least includes the upload frequency and data sparsity information.
[0013] In an embodiment of the present embodiment, the composition formula of the multimodal feature is:
[0014] v i (t) = [g i (t), b i (t)]
[0015] where v i (t) represents the multimodal feature, g i (t) represents the model update data of client i at time t, and b i (t) represents the client behavior data of client i at time t.
[0016] In an embodiment of the present embodiment, the calculation formula of the adjusted trust score is:
[0017] T i (t + 1) = T i (t) × (1 - λ × α i (t))
[0018] where T i (t + 1) represents the adjusted trust score of client i, T i (t) represents the trust score of client i before adjustment, λ represents the adjustment coefficient, and α i (t) represents the degree of abnormality of client i at time t.
[0019] In an embodiment of the present embodiment, the formula for injecting adaptive noise into the target client is:
[0020] g noisy (t) = g test (t) + ∈(t) × n(t);
[0021] where g test (t) represents the malicious client, g test (t) represents the target client, ∈(t) represents the noise intensity coefficient of the adaptive noise, and n(t) represents the adaptive noise at time t.
[0022] In an embodiment of the present embodiment, aggregating each client with weights based on the adjusted trust score to obtain a global model includes:
[0023] Determining the weights of each client based on the adjusted trust score;
[0024] Perform weighted aggregation on each client based on the weights to obtain a global model.
[0025] In the second aspect of the embodiments of the present invention, a poisoning defense device for federated learning is provided. The device includes:
[0026] A combination unit for combining the model update data and client behavior data uploaded by each client to obtain multimodal features corresponding to each client respectively;
[0027] A detection unit for performing anomaly detection on the multimodal features of each client to obtain an anomaly detection result;
[0028] An adjustment unit for adjusting the trust score of each client based on the anomaly detection result to obtain an adjusted trust score;
[0029] An injection unit for injecting adaptive noise into a target client whose adjusted trust score is lower than a preset score to obtain a malicious client; wherein the adaptive noise is generated based on the anomaly detection result;
[0030] An aggregation unit for performing weighted aggregation on each client based on the adjusted trust score to obtain a global model; wherein the malicious client is included in each client.
[0031] In the third aspect of the embodiments of the present invention, a computing device is provided. The computing device includes: at least one processor, a memory, and an input / output unit; wherein the memory is used to store a computer program, and the processor is used to call the computer program stored in the memory to execute the method described in any one of the first aspect.
[0032] In the fourth aspect of the embodiments of the present invention, a computer-readable storage medium is provided, which includes instructions that, when running on a computer, cause the computer to execute the method described in any one of the first aspect.
[0033] In the fifth aspect of the embodiments of the present invention, a computer program product is provided, including a computer program that, when executed by a processor, implements the method described in any one of the first aspect.
[0034] A poisoning defense method, device, equipment, medium and product for federated learning according to an embodiment of the present invention combines the model update data and client behavior data uploaded by each client to obtain multimodal features corresponding to each client; performs anomaly detection on the multimodal features of each client to obtain an anomaly detection result; adjusts the trust score of each client based on the anomaly detection result to obtain an adjusted trust score; injects adaptive noise into a target client whose adjusted trust score is lower than a preset score to obtain a malicious client; performs weighted aggregation on each client based on the adjusted trust score to obtain a global model. Through multi-level defense mechanisms such as multimodal anomaly detection, adaptive trust management, and noise injection, the present invention effectively improves the ability of the federated learning system to cope with complex poisoning attacks. Compared with traditional single-dimensional anomaly detection methods, the present invention can accurately detect malicious clients in more complex and data-sparse scenarios, and flexibly adjust the trust score and noise intensity, thereby improving the adaptability and robustness of the defense, and further enhancing the security of the global model. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] By reading the following detailed description with reference to the accompanying drawings, the above and other objects, features and advantages of the exemplary embodiments of the present invention will become readily understood. In the drawings, several embodiments of the present invention are shown by way of example and not limitation, wherein:
[0036] Figure 1 It is a schematic flow chart of a poisoning defense method for federated learning provided by an embodiment of the present invention;
[0037] Figure 2 It is a schematic structural diagram of a poisoning defense device for federated learning provided by an embodiment of the present invention;
[0038] Figure 3 It schematically shows a structural diagram of a medium according to an embodiment of the present invention;
[0039] Figure 4 It schematically shows a structural diagram of a computing device according to an embodiment of the present invention;
[0040] Figure 5 It schematically shows a comparison diagram of the defense effects of the poisoning defense method for federated learning according to an embodiment of the present invention and the FLDetector method on ER@5 on the ML-100k dataset;
[0041] Figure 6 It schematically shows a comparison diagram of the defense effects of the poisoning defense method for federated learning according to an embodiment of the present invention and the FLDetector method on ER@5 on the ML-1M dataset.
[0042] In the accompanying drawings, the same or corresponding reference numerals denote the same or corresponding parts. Detailed implementation manners
[0043] The principles and spirit of the present invention will be described below with reference to several exemplary implementation manners. It should be understood that these implementation manners are provided only to enable those skilled in the art to better understand and then implement the present invention, and do not limit the scope of the present invention in any way. On the contrary, these implementation manners are provided to make the present disclosure more thorough and complete, and to be able to fully convey the scope of the present disclosure to those skilled in the art.
[0044] Those skilled in the art know that the implementation manners of the present invention can be implemented as a system, device, equipment, method, or computer program product. Therefore, the present disclosure can be specifically implemented in the following forms, namely: completely hardware, completely software (including firmware, resident software, microcode, etc.), or a combination of hardware and software.
[0045] According to an implementation manner of the present invention, a poisoning defense method, device, equipment, medium, and product for federated learning are provided.
[0046] It should be noted that any number of elements in the accompanying drawings are for illustration rather than limitation, and any naming is only for distinction and does not have any limiting meaning.
[0047] The principles and spirit of the present invention will be elaborated below with reference to several representative implementation manners of the present invention.
[0048] Exemplary method
[0049] Below with reference to Figure 1 , Figure 1 is a schematic flowchart of a poisoning defense method for federated learning provided in an embodiment of the present invention. It should be noted that the implementation manners of the present invention can be applied to any applicable scenario.
[0050] Figure 1 The process of a poisoning defense method for federated learning provided in an embodiment of the present invention shown in the figure includes:
[0051] Step S101, combining the model update data uploaded by each client and the client behavior data to obtain multi-modal features corresponding to each client respectively.
[0052] In the embodiments of the present invention, after the model is trained locally on the client side, the client will upload the model update data to the central server and upload the client behavior data at the same time. These uploaded client behavior data, combined with the model update data, are used to detect whether there are abnormal behaviors of the client subsequently. The model update data is the updated data after the client training, and the client behavior data at least includes the upload frequency and data sparsity information. The client behavior data is used to represent the behavior characteristics of the client user.
[0053] In addition, the model update data can be model gradient information, such as mean, variance, etc. The client behavior data can also include frequency, stability, etc. The model update data and the client behavior data will be used as the input basic data for subsequent anomaly detection to more comprehensively identify potential malicious behaviors.
[0054] In the embodiments of the present invention, the composition formula of the multimodal feature is:
[0055] v i (t) = [g i (t), b i (t)];
[0056] Among them, v i (t) represents the multimodal feature, g i (t) represents the model update data of client i at time t, such as model update parameters such as gradients, and b i (t) represents the client behavior data of client i at time t (such as behavior characteristics, including data upload frequency or data sparsity).
[0057] Step S102, perform anomaly detection on the multimodal features of each client to obtain the anomaly detection result.
[0058] In the embodiments of the present invention, anomaly detection methods such as the Isolation Forest algorithm and the Local Outlier Factor (LOF) algorithm can be used to analyze the multimodal features to identify potential malicious client behaviors. After constructing the comprehensive feature vector, a comprehensive anomaly degree calculation formula based on anomaly detection is designed to combine the global and local anomaly detection results. The anomaly degree formula is:
[0059] α i (t) = ω1·f global (v i (t)) + ω2·f local (v i (t))
[0060] Among them: α i (t) is the anomaly degree of client i at time t, fglobal (v i (t)) represents the scoring result based on global anomaly detection (such as Isolation Forest), which identifies the degree of deviation of the client in the global data distribution. f local (v i (t)) represents the scoring result based on local anomaly detection (such as LOF), which is used to detect abnormal situations of the client in the neighborhood. ω1 and ω2 are weight parameters that can be adjusted according to the client's historical behavior to adapt to the dynamic attack environment.
[0061] In this design, an adaptive adjustment mechanism is particularly introduced to dynamically adjust the values of ω1 and ω2. According to the behavioral characteristics of the client, the system can adjust the weights in real time to give priority to detecting global or local anomalies. For example, when the client's upload frequency increases abnormally or the model update changes violently, the weight of ω1 can be increased so that the global anomaly degree has a higher impact; while when the data sparsity is relatively high, more emphasis is placed on local anomaly detection.
[0062] At the same time, in order to ensure the comparability of the anomaly degrees of different clients, we perform normalization processing on the anomaly degrees. The calculation formula is as follows:
[0063]
[0064] where min(α) and max(α) represent the minimum and maximum values of the anomaly degrees of all clients respectively. The normalized anomaly degrees are used for trust score adjustment and subsequent noise injection to ensure the consistency and fairness of the scores.
[0065] This anomaly degree calculation design effectively improves the recognition rate of malicious clients in a complex federated learning environment and provides strong support for the defense system.
[0066] Step S103, adjust the trust scores of each client based on the anomaly detection results to obtain the adjusted trust scores.
[0067] In the embodiment of the present invention, if the anomaly detection result indicates that the client has an anomaly, then this client will be given a lower trust score, that is, it is confirmed that this client is a malicious client, thereby weakening its influence on the global model. Correspondingly, the system will increase the trust score of the normal client whose anomaly detection result indicates that the client has no anomaly to increase the weight ratio during the global model update, ensuring that the influence of malicious clients is minimized during the global model update.
[0068] In the embodiment of the present invention, the calculation formula for the adjusted trust score is:
[0069] T i (t + 1) = T i (t) × (1 - λ × αi (t));
[0070] Among them, T i (t + 1) represents the adjusted trust score of client i, and T i (t) represents the trust score of client i before adjustment. λ represents the adjustment coefficient, which controls the degree of change of the trust score, and α i (t) represents the degree of abnormality of client i at time t, which is usually determined based on the anomaly detection result.
[0071] Step S104: Inject adaptive noise into the target client whose adjusted trust score is lower than the preset score to obtain a malicious client.
[0072] In the embodiment of the present invention, the adaptive noise is generated based on the anomaly detection result.
[0073] In the embodiment of the present invention, to further weaken the damage of malicious clients to the global model, the system will introduce adaptive noise according to the detected situation of malicious clients. During the model aggregation process, for the detected abnormal behavior, the system will dynamically inject disruptive adaptive noise, and the noise intensity will be dynamically adjusted according to the trust score and the anomaly detection result. This measure can effectively disrupt the impact of malicious updates and protect the security and stability of the global model.
[0074] In the embodiment of the present invention, the formula for injecting adaptive noise into the target client is:
[0075] g noisy (t) = g test (t) + ∈(t) × n(t)
[0076] Among them, g test (t) represents the malicious client (i.e., the model update with noise), and g test (t) represents the target client (i.e., the model update without noise). ∈(t) represents the noise intensity coefficient of the adaptive noise, and n(t) represents the adaptive noise at time t.
[0077] Step S105: Perform weighted aggregation on each client based on the adjusted trust score to obtain a global model.
[0078] The implementation process of weighted aggregation: In each round of federated learning training, according to the updated trust score, the system dynamically calculates the weights of each client in the model aggregation. The formula for calculating the weights is as follows:
[0079]
[0080] Among them, w i (t) is the weight of client i at time t. Ti (t) represents the trust score of client i at time t. N is the total number of clients. This process normalizes the trust scores so that the sum of the weights equals 1. The higher the trust score of a client, the greater its weight, which ensures that high-trust clients contribute more to the global model while the impact of malicious clients is effectively restricted.
[0081] After obtaining the weights of each client, the system performs weighted aggregation on the model updates of all clients to generate a new global model. The specific formula is as follows:
[0082]
[0083] where G(t + 1) is the global model at time t + 1. g i (t) is the model update uploaded by client i at time t. w i (t) is the weight of client i.
[0084] Through this weighted aggregation process, the contribution ratio of each client to the global model can be flexibly adjusted according to the trust score of the client, thereby effectively reducing the impact of malicious clients in model updates. This weighted aggregation mechanism ensures the robustness and stability of the system under different attack scenarios.
[0085] In the embodiments of the present invention, the malicious client is included in each of the clients.
[0086] As an alternative implementation, the method of performing weighted aggregation on each client based on the adjusted trust score to obtain the global model may include:
[0087] Determining the weights of each client based on the adjusted trust score;
[0088] Performing weighted aggregation on each client based on the weights to obtain the global model.
[0089] Please refer to Figure 5 and Figure 6 , Figure 5 which schematically shows a comparison diagram of the defense effects of the poisoning defense method for federated learning and the FLDetector method in the embodiments of the present invention on ER@5 on the ML-100k dataset; Figure 6 which schematically shows a comparison diagram of the defense effects of the poisoning defense method for federated learning and the FLDetector method in the embodiments of the present invention on ER@5 on the ML-1M dataset.
[0090] As Figure 5As shown in the figure, on the ML-100k dataset, the method of the present invention is used to detect model poisoning attacks by malicious clients. In the experiment, the effectiveness of using the defense strategy of the present invention was compared with that of the existing FLDetector defense mechanism. Through the ER@5 metric during the iterative training process, it can be observed that after using the defense strategy of the present invention, the proportion of malicious recommended items in the top 5 items of the recommendation list decreased significantly. In the first 25 iterations, the proportion of malicious recommended items rapidly decreased from nearly 1.0 to about 0.1, and remained at a low level in subsequent iterations until it fluctuated slightly after the 150th iteration. In contrast, the proportion of malicious recommended items of FLDetector remained at a high level close to 1.0 throughout the iterative process. The experimental results show that the method of the present invention can effectively suppress malicious updates, prevent malicious recommended items from appearing in the recommendation list on a large scale, and significantly improve the defense effect and system robustness.
[0091] As Figure 6 shown, on the ML-1M dataset, for more complex sparse data, the effectiveness of the method of the present invention was further verified. The experimental results are shown in the figure, which shows the performance of the defense strategy in a sparse data environment. In the first 50 iterations, the defense strategy of the present invention successfully reduced the proportion of malicious recommended items from 1.0 to about 0.2. Although this proportion increased somewhat during subsequent iterations, it always remained below 0.8, while FLDetector had a proportion of malicious recommended items close to 1.0 throughout the iterative process. This result shows that in scenarios with high data complexity and sparsity, the method of the present invention can still effectively suppress malicious updates and significantly reduce the proportion of malicious recommended items, and its defense effect is better than traditional methods, demonstrating the robustness and flexibility of the method in complex scenarios.
[0092] It can be seen that on recommendation system datasets such as ML-100k and ML-1M, the embodiments of the present invention showed significant defense effects in the experiment. Compared with traditional defense methods, the frequency of malicious recommended items appearing in the Top-N recommendation list decreased significantly, and the overall robustness and security of the system were improved by more than 30%, demonstrating the effectiveness of the method.
[0093] The embodiments of the present invention can enhance the ability to identify malicious clients: by introducing multi-modal anomaly detection technology, the system can comprehensively analyze the model updates and behavioral data uploaded by clients, no longer relying on a single feature dimension, thus greatly improving the recognition accuracy of malicious clients. Compared with traditional methods, the present invention can significantly reduce the risk of false positives and false negatives when dealing with scenarios with high data sparsity or complex client behaviors, enabling the system to more accurately identify potential malicious clients.
[0094] The embodiments of the present invention use a dynamic trust management mechanism: The adaptive trust management system in the present invention can dynamically adjust its trust score according to the historical performance of the client and the current anomaly detection results. In the face of complex attack scenarios, the system can respond flexibly, weaken the impact of malicious clients on the global model, and enhance the flexibility and effectiveness of the defense. By continuously adjusting the weight ratio of the clients, the system can effectively suppress the influence of malicious clients and maintain the stability of the global model.
[0095] The embodiments of the present invention use a flexible noise injection mechanism: During the global model aggregation process, the dynamic noise injection mechanism proposed in the present invention can flexibly adjust the noise injection intensity according to the attack intensity and model stability. This can effectively disrupt the forged model updates uploaded by malicious clients and ensure the security and robustness of the global model. Compared with the fixed noise injection method, the dynamic noise injection mechanism is more flexible, can adapt to different types and intensities of attacks, and ensures that the defense effect does not affect the model performance.
[0096] The embodiments of the present invention use a multi-level defense framework: By combining multi-modal anomaly detection, adaptive trust management, and dynamic noise injection technologies, the present invention constructs a multi-level defense framework that can cope with various complex attack patterns. Especially in dealing with high-sparsity data scenarios and complex client behavior patterns, this framework can provide a stable defense effect and prevent the negative impact of malicious behavior on the global model.
[0097] The embodiments of the present invention can adapt to multi-domain applications: The multi-level poisoning defense method proposed in the present invention is particularly suitable for federated learning application scenarios in fields such as recommendation systems, finance, and healthcare. In these fields, the sparsity and complexity of data are relatively high, and traditional defense methods are difficult to cope with. The multi-level defense mechanism of the present invention can not only improve the security of the system but also effectively reduce the damage of malicious clients to the system and ensure the performance and stability of the global model.
[0098] The embodiments of the present invention can improve the security and robustness of the global model: Through the multi-level defense strategy of multi-modal anomaly detection, adaptive trust management, and dynamic noise injection, the present invention significantly enhances the robustness and security of the global model. In complex attack scenarios, the system can quickly identify and respond to the forged updates uploaded by malicious clients, ensure that the global model is not disturbed, and maintain the high accuracy and stability of the model.
[0099] The present invention can effectively improve the ability of the federated learning system to cope with complex poisoning attacks through multi-level defense mechanisms such as multi-modal anomaly detection, adaptive trust management, and noise injection. Compared with the traditional single-dimensional anomaly detection method, the present invention can accurately detect malicious clients in more complex and data-sparse scenarios, and flexibly adjust the trust score and noise intensity, thereby improving the adaptability and robustness of the defense, and further enhancing the security of the global model.
[0100] Exemplary device
[0101] After introducing the method of the exemplary embodiment of the present invention, next, reference is made to Figure 2 A poisoning defense device for federated learning according to an exemplary embodiment of the present invention will be described. The device includes:
[0102] A combining unit 201, configured to combine the model update data and client behavior data uploaded by each client to obtain multi-modal features corresponding to each client;
[0103] In an embodiment of the present invention, the model update data is the updated data after the client's training, and the client behavior data includes at least the upload frequency and data sparsity information.
[0104] In an embodiment of the present invention, the composition formula of the multi-modal feature is:
[0105] v i (t)=[g i (t),b i (t)];
[0106] Wherein, v i (t) represents the multi-modal feature, g i (t) represents the model update data of client i at time t, and b i (t) represents the client behavior data of client i at time t.
[0107] A detection unit 202, configured to perform anomaly detection on the multi-modal features of each client to obtain an anomaly detection result;
[0108] An adjustment unit 203, configured to adjust the trust score of each client based on the anomaly detection result to obtain an adjusted trust score;
[0109] In an embodiment of the present invention, the calculation formula of the adjusted trust score is:
[0110] T i (t + 1)=T i (t)×(1 - λ×α i (t));
[0111] Among them, T i (t + 1) represents the adjusted trust score of client i, and T i (t) represents the trust score of client i before adjustment, λ represents the adjustment coefficient, and α i (t) represents the degree of abnormality of client i at time t.
[0112] The injection unit 204 is used to inject adaptive noise into the target client whose adjusted trust score is lower than the preset score to obtain a malicious client; wherein, the adaptive noise is generated based on the anomaly detection result;
[0113] In the embodiment of the present invention, the formula for injecting adaptive noise into the target client is:
[0114] g noisy (t) = g test (t) + ∈(t) × n(t);
[0115] Among them, g test (t) represents the malicious client, g test (t) represents the target client, ∈(t) represents the noise intensity coefficient of the adaptive noise, and n(t) represents the adaptive noise at time t.
[0116] The aggregation unit 205 is used to perform weighted aggregation on each client based on the adjusted trust score to obtain a global model; wherein, the malicious client is included in each client.
[0117] As an optional implementation manner, the way that the aggregation unit 205 performs weighted aggregation on each client based on the adjusted trust score to obtain a global model can specifically be:
[0118] Determine the weights of each client based on the adjusted trust score;
[0119] Perform weighted aggregation on each client based on the weights to obtain a global model.
[0120] The present invention can effectively improve the ability of the federated learning system to cope with complex poisoning attacks through multi-modal anomaly detection, adaptive trust management, noise injection and other multi-level defense mechanisms. Compared with the traditional single-dimensional anomaly detection method, the present invention can accurately detect malicious clients in more complex and data-sparse scenarios, and flexibly adjust the trust score and noise intensity, thereby improving the adaptability and robustness of the defense, and further enhancing the security of the global model.
[0121] Exemplary medium
[0122] After introducing the methods and apparatuses of the exemplary embodiments of the present invention, next, reference is made to Figure 3 to describe the computer-readable storage medium of the exemplary embodiments of the present invention. Please refer to Figure 3 , which shows that the computer-readable storage medium is an optical disc 30, on which a computer program (i.e., a program product) is stored. When the computer program is run by a processor, it will implement the steps described in the above method embodiments. For example, the model update data and client behavior data uploaded by each client are combined to obtain the multimodal features corresponding to each client; anomaly detection is performed on the multimodal features of each client to obtain an anomaly detection result; based on the anomaly detection result, the trust scores of each client are adjusted to obtain adjusted trust scores; adaptive noise is injected into the target client whose adjusted trust score is lower than the preset score to obtain a malicious client; based on the adjusted trust scores, each client is weighted and aggregated to obtain a global model. The specific implementation manners of each step will not be repeated here.
[0123] It should be noted that examples of the computer-readable storage medium may also include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory, or other optical and magnetic storage media, which will not be elaborated here one by one.
[0124] Exemplary computing device
[0125] After introducing the methods, apparatuses, and media of the exemplary embodiments of the present invention, next, reference is made to Figure 4 a computing device for poisoning defense in federated learning of the exemplary embodiments of the present invention.
[0126] Figure 4 The block diagram of an exemplary computing device 40 suitable for implementing the embodiments of the present invention is shown. The computing device 40 may be a computer system or a server. Figure 4 The shown computing device 40 is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present invention.
[0127] As Figure 4 shown, the components of the computing device 40 may include, but are not limited to: one or more processors or processing units 401, a system memory 402, and a bus 403 connecting different system components (including the system memory 402 and the processing unit 401).
[0128] Computing device 40 typically includes a variety of computer system readable media. These media can be any available media that can be accessed by computing device 40, including volatile and non-volatile media, removable and non-removable media.
[0129] System memory 402 can include computer system readable media in the form of volatile memory, such as random access memory (RAM) 4021 and / or cache memory 4022. Computing device 40 can further include other removable / non-removable, volatile / non-volatile computer system storage media. By way of example only, ROM 4023 can be used to read and write on non-removable, non-volatile magnetic media ( Figure 4 not shown, commonly referred to as a "hard disk drive"). Although not shown in Figure 4 a disk drive for reading and writing on a removable non-volatile disk (such as a "floppy disk") and an optical disk drive for reading and writing on a removable non-volatile optical disk (such as a CD-ROM, DVD-ROM or other optical media) can be provided. In these cases, each drive can be connected to bus 403 through one or more data media interfaces. System memory 402 can include at least one program product having a set (such as at least one) of program modules configured to perform the functions of the embodiments of the present invention.
[0130] A program / utility 4025 having a set (at least one) of program modules 4024 can be stored in, for example, system memory 402, and such program modules 4024 include but are not limited to: an operating system, one or more application programs, other program modules, and program data, and the implementation of a network environment may be included in each or some combination of these examples. Program modules 4024 generally perform the functions and / or methods in the embodiments described in the present invention.
[0131] Computing device 40 can also communicate with one or more external devices 404 (such as a keyboard, pointing device, display, etc.). Such communication can be carried out through an input / output (I / O) interface 405. And, computing device 40 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN) and / or a public network, such as the Internet) through a network adapter 406. As Figure 4 shown, network adapter 406 communicates with other modules (such as processing unit 401, etc.) of computing device 40 through bus 403. It should be understood that although Figure 4 not shown in, other hardware and / or software modules can be used in conjunction with computing device 40.
[0132] The processing unit 401 executes various functional applications and data processing by running the programs stored in the system memory 402. For example, it combines the model update data and client behavior data uploaded by each client to obtain the multimodal features corresponding to each client; performs anomaly detection on the multimodal features of each client to obtain the anomaly detection results; adjusts the trust scores of each client based on the anomaly detection results to obtain the adjusted trust scores; injects adaptive noise into the target clients whose adjusted trust scores are lower than the preset scores to obtain malicious clients; and performs weighted aggregation on each client based on the adjusted trust scores to obtain the global model. The specific implementation manners of each step will not be repeated here. It should be noted that although several units / modules or sub-units / sub-modules of the poisoning defense device for federated learning are mentioned in the above detailed description, this division is merely exemplary and not mandatory. In fact, according to the embodiments of the present invention, the features and functions of two or more units / modules described above can be embodied in one unit / modules. Conversely, the features and functions of one unit / modules described above can be further divided into multiple unit / modules for embodiment.
[0133] In the description of the present invention, it should be noted that the terms "first", "second", and "third" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance.
[0134] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described system, device, and unit can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0135] In several embodiments provided by the present invention, it should be understood that the disclosed system, device, and method can be implemented in other ways. The device embodiments described above are merely illustrative. For example, the division of the units is only a logical functional division, and there may be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection may be through some communication interfaces, and the indirect coupling or communication connection of the device or unit may be in an electrical, mechanical, or other form.
[0136] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0137] In addition, in each embodiment of the present invention, each functional unit may be integrated into a processing unit, or each unit may exist physically alone, or two or more units may be integrated into one unit.
[0138] If the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium executable by a processor. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.
[0139] Finally, it should be noted that the above-mentioned embodiments are only specific implementation manners of the present invention, used to illustrate the technical solutions of the present invention, rather than limiting them. The protection scope of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: any person skilled in the art within the technical scope disclosed by the present invention can still modify the technical solutions described in the foregoing embodiments, or can easily think of changes, or perform equivalent replacements on some of the technical features; and these modifications, changes, or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
[0140] In addition, although the operations of the method of the present invention are described in a specific order in the drawings, this does not require or imply that these operations must be performed in this specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, some steps may be omitted, multiple steps may be combined into one step for execution, and / or one step may be decomposed into multiple steps for execution.
[0141] In an exemplary embodiment, a computer program product is provided, including a computer program, which when executed by a processor implements the steps in the above-mentioned method embodiments.
Claims
1. A poisoning defense method for federated learning, characterized in that: The method comprises: Combine the model update data uploaded by each client with the client behavior data to obtain the multimodal features corresponding to each client; Perform anomaly detection on the multimodal features of each client to obtain anomaly detection results; Adjusting the trust score of each client based on the anomaly detection result to obtain an adjusted trust score; Injecting adaptive noise into the target client whose adjusted trust score is lower than the preset score to obtain a malicious client; wherein the adaptive noise is generated based on the anomaly detection result; Based on the adjusted trust score, each client is weightedly aggregated to obtain a global model; wherein the each client includes the malicious client.
2. The poisoning defense method for federated learning according to claim 1, characterized in that: The model update data is update data after client training, and the client behavior data at least includes upload frequency and data sparsity information.
3. The poisoning defense method for federated learning according to claim 1, characterized in that: The multimodal feature composition formula is: v i (t)=[g i (t),b i (t)]; Among them, v i (t) represents the multimodal feature, g i (t) represents the model update data of client i at time t, b i (t) represents the client behavior data of client i at time t.
4. The poisoning defense method for federated learning according to claim 1, characterized in that: The calculation formula of the adjusted trust score is: T i (t+1)=T i (t)×(1-λ×α i (t)); Among them, T i (t+1) represents the adjusted trust score of client i, T i (t) represents the trust score of client i before adjustment, λ represents the adjustment coefficient, α i (t) represents the abnormality degree of client i at time t.
5. The poisoning defense method for federated learning according to claim 1, characterized in that: The formula for injecting adaptive noise into the target client is: g noisy (t)=g test (t)+∈(t)×n(t); Among them, g test (t) represents the malicious client, g test (t) represents the target client, ∈(t) represents the noise intensity coefficient of the adaptive noise, and n(t) represents the adaptive noise at time t.
6. The poisoning defense method for federated learning according to any one of claims 1 to 5, characterized in that: The weighted aggregation of each client based on the adjusted trust score to obtain a global model includes: Determining a weight of each client based on the adjusted trust score; The clients are weightedly aggregated based on the weights to obtain a global model.
7. A poisoning defense device for federated learning, characterized in that: The device comprises: A combining unit, used to combine the model update data uploaded by each client with the client behavior data to obtain multimodal features corresponding to each client; A detection unit, used to perform anomaly detection on the multimodal features of each client to obtain anomaly detection results; An adjustment unit, configured to adjust the trust score of each client based on the anomaly detection result to obtain an adjusted trust score; An injection unit, configured to inject adaptive noise into a target client whose adjusted trust score is lower than a preset score, to obtain a malicious client; wherein the adaptive noise is generated based on the anomaly detection result; An aggregation unit is used to perform weighted aggregation on each client based on the adjusted trust score to obtain a global model; wherein the each client includes the malicious client.
8. A computing device, comprising: at least one processor, memory, and input-output unit; The memory is used to store a computer program, and the processor is used to call the computer program stored in the memory to execute the method according to any one of claims 1 to 6.
9. A computer-readable storage medium comprising instructions, which, when executed on a computer, causes the computer to execute the method according to any one of claims 1 to 6.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Federal learning security and privacy method oriented to user behaviors
CN118013574A
Target-free model poisoning attack dynamic joint learning defense framework based on historical information
CN118094566A