Federal Learning Model Training Method and System Based on Differential Privacy Image Noise Addition

By dynamically adjusting the privacy budget and selecting clients with different data distributions in federated learning model training, the problem of low image recognition rate in the prior art is solved, and the effect of improving image recognition accuracy while protecting privacy is achieved.

CN119849603BActive Publication Date: 2025-07-01NAT UNIV OF DEFENSE TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510330136.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2025-07-01
Estimated Expiration
2045-03-20

AI Technical Summary

Technical Problem

The existing differential privacy image noise-added method uses the same privacy budget during the training process, resulting in a significant reduction in the model training effect and affecting the final recognition accuracy.

Method used

The federated learning model training method based on differential privacy is adopted. Before each training, a different privacy budget is used to process the local image training data of the client, and a suitable client with different data distributions is selected to participate in federated learning.

Benefits of technology

While ensuring user privacy, the image recognition rate is improved, and the training effect and recognition accuracy of the model are improved by dynamically adjusting the noise increase intensity and selecting the appropriate client.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119849603B_ABST
    Figure CN119849603B_ABST
Patent Text Reader

Abstract

The present invention discloses a method and system for training a federated learning model based on differential privacy image noise addition. The method includes: S1: Initialize the evaluation network, the target network, and hyperparameters; S2: Initialize the global model and its parameters; S3: Obtain the selected clients and the privacy budget; S4: The selected clients perform local training and upload the perturbed gradients to the central server; S5: The central server aggregates the perturbed gradients of the clients to obtain the updated global model and the reward corresponding to the current state; S6: Obtain the next state of the federated learning and update the evaluation network and the target network; S7: Repeat S3 to S6 until the set global iteration number is reached; S8: Update the exploration rate and repeat S2 to S7 until the set federated learning number is reached. The present invention proposes a dynamic differential privacy method in combination with the federated learning framework, which can improve the image recognition rate while ensuring user privacy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of data privacy protection, and particularly relates to a method and system for training a federated learning model based on differential privacy image noise addition. Background Art

[0002] With the rapid development of artificial intelligence technology, image recognition has been widely applied in many fields such as security monitoring, medical diagnosis, and autonomous driving. However, in practical applications, image data often contains sensitive information of users, such as facial features, geographical locations, etc. Directly using these raw data for model training may lead to serious privacy leakage problems. To address this challenge, differential privacy (DP), as a powerful privacy protection mechanism, has been introduced into machine learning, which can effectively protect user data privacy without sacrificing model performance.

[0003] Previous differential privacy image noise addition methods used the same privacy budget for noise addition to training image data each time to protect user privacy. However, the noise may significantly reduce the training effect of the model, thereby affecting the final recognition accuracy. Therefore, how to improve the image recognition rate while ensuring privacy has become an urgent problem to be solved. Summary of the Invention

[0004] To solve the above problems existing in the prior art, the present invention provides a method and system for training a federated learning model based on differential privacy image noise addition. The technical problems to be solved by the present invention are realized through the following technical solutions:

[0005] The present invention provides a method for training a federated learning model based on differential privacy image noise addition, including:

[0006] S1: Initialize the evaluation network, the target network, and related hyperparameters;

[0007] S2: Initialize the global model and its parameters of the federated learning system on the central server, and broadcast the global model to all clients;

[0008] S3: Obtain the selected clients and the allocated privacy budget according to the current state of the federated learning system and the target network;

[0009] S4: Train the local model using the local dataset on the selected clients, and upload the perturbed gradients to the central server;

[0010] S5: Aggregate the perturbed gradients from the selected clients on the central server to obtain the updated global model and the reward corresponding to the current state;

[0011] S6: Update the evaluation network and the target network;

[0012] S7: Repeat S3 to S6 until the global iteration number set by one round of federated learning is reached n ;

[0013] S8: Update the exploration rate and repeat S2 to S7 until the set number of federated learning rounds is reached E 。

[0014] Another aspect of the present invention provides a federated learning model training system based on differential privacy image noise addition, including a central server and a plurality of clients connected to the central server, for executing the federated learning model training method based on differential privacy image noise addition described in any one of the above embodiments.

[0015] Compared with the prior art, the beneficial effects of the present invention are as follows:

[0016] The federated learning model training method based on differential privacy image noise addition of the present invention processes the local image training data of the client using different privacy budgets before each training, and selects appropriate clients with different data distributions to participate in federated learning. While ensuring user privacy, it improves the image recognition rate, and specifically has the following advantages:

[0017] (1) Collaborative training under the federated learning framework: Combining the advantages of federated learning, a distributed training system is constructed, allowing multiple clients to independently train models locally and synchronize local updates to the central server through secure aggregation. During this process, the data of all participants remains local and is not uploaded to the central server (cloud), thus reducing the risk of data leakage.

[0018] (2) Efficient privacy protection: A dynamic differential privacy method is adopted, and by adding noise to image pixels, the risk of leaking image data from the model gradient due to inference attacks is reduced, further strengthening the privacy protection of user data.

[0019] (3) Optimized noise addition strategy: According to the sensitivity of the image content and the image data distribution, the noise addition intensity is dynamically adjusted to ensure minimizing the impact on the model performance while protecting privacy. Specifically, the present invention designs an intelligent noise generation algorithm that can adaptively select appropriate noise parameters (i.e., privacy budgets), ensuring both the effectiveness of privacy protection and the accuracy of image recognition.

[0020] (4) Enhanced image recognition performance: By introducing techniques such as multi-task learning and transfer learning, not only the model performance of individual clients is improved, but also knowledge sharing between different clients is promoted, enhancing the image recognition ability of the entire system. Especially for small-sample or low-quality images, the method of the present invention can obtain better generalization performance through global collaboration.

[0021] (5) Flexible adaptation to application scenarios: It is applicable to a variety of image recognition tasks, such as face recognition, object detection, medical image analysis, etc., and is particularly suitable for fields with strict privacy protection requirements. In addition, the method and system can also flexibly adjust the privacy protection level according to the requirements of specific application scenarios to achieve a balance between performance and privacy.

[0022] The present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Description of the Drawings

[0023] Figure 1 is a flowchart of a federated learning model training method based on differential privacy image noise addition provided by an embodiment of the present invention;

[0024] Figure 2 is a detailed flowchart of a federated learning model training method based on differential privacy image noise addition provided by an embodiment of the present invention. Detailed Embodiments

[0025] In order to further elaborate on the technical means and effects adopted by the present invention to achieve the intended invention purpose, a federated learning model training method and system based on differential privacy image noise addition proposed according to the present invention will be described in detail below with reference to the accompanying drawings and specific embodiments.

[0026] The foregoing and other technical contents, features, and effects of the present invention will be clearly presented in the following detailed description in conjunction with the accompanying drawings. Through the description of the specific embodiments, a more in-depth and specific understanding of the technical means and effects adopted by the present invention to achieve the intended purpose can be obtained. However, the accompanying drawings are only for reference and illustration, and are not used to limit the technical solution of the present invention.

[0027] It should be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant is intended to cover non-exclusive inclusion, so that an article or device comprising a series of elements includes not only those elements but also other elements not expressly listed. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the article or device comprising said element.

[0028] Embodiment 1

[0029] Please refer to Figure 1 and Figure 2 , the embodiment of the present invention provides a federated learning model training method based on differential privacy image noise addition, and the federated learning model training method includes:

[0030] S1: Initialize the evaluation network, the target network and related hyperparameters.

[0031] Specifically, step S1 of this embodiment includes:

[0032] S1.1: Randomly initialize the parameters of the evaluation network and the parameters of the target network to be equal parameters, that is, initialize the parameters of the evaluation network and the parameters of the target network to the same value. and the parameters of the target network to the same value. and the parameters of the target network to the same value.

[0033] S1.2: Initialize related hyperparameters, and the related hyperparameters include a discount factor , a soft update parameter , an exploration rate , a minimum exploration rate , an exploration rate decay factor , a learning rate of the evaluation network and a replay buffer . Preferably, the initial value of the exploration rate can be taken as 1, and the value of the minimum exploration rate can be taken as 0.01 - 0.1.

[0034] S2: Initialize the global model and its parameters of the federated learning system on the central server, and broadcast the global model to all clients.

[0035] Specifically, a federated learning system is constructed, including a central server and N clients. The number of clients can be set according to actual needs and is not limited here.

[0036] Furthermore, the clients need to initialize the local model and training parameters of federated learning. Each client needs to initialize a local training dataset containing multiple images of the target class and annotate the targets of each image.

[0037] It should be noted that according to the characteristics of federated learning, the entire federated learning process is divided into time slots, and each time slot represents the round of global iteration, that is, the aggregation round of the round. Due to the limitation of communication bandwidth, at most N clients are selected from the set of clients each time for global iteration, and privacy budgets are allocated.

[0038] S3: According to the current state of the federated learning system and the target network, obtain the selected clients and the allocated privacy budgets.

[0039] Furthermore, a decimal is randomly generated within the range of (0, 1), and the value of the decimal is compared with the value of the exploration rate ; if the value of the decimal is less than the value of the exploration rate , then an action for the th global iteration in this federated learning is randomly generated, where indicates whether client is selected in the th global iteration. If so, , otherwise , indicates the privacy budget allocated to client in the th global iteration, represents the set of clients. When the value of the decimal is less than the value of the exploration rate , privacy budgets are randomly allocated. For example, in the first round, the initial value of the exploration rate is taken as 1, and the randomly generated decimal must be less than the initial value of the exploration rate . Therefore, an action for the first round is randomly generated, where indicates whether client is selected in the first round. If so, , otherwise , represents the client selected in the first round Allocated privacy budget

[0040] If the value of the decimal is greater than or equal to the exploration rate , obtain the selected client and the allocated privacy budget according to the current state and the target network. Specifically, input the current state into the target network , and the target network outputs multiple probabilities according to the current state, the number of the probabilities is equal to the number of the actions, use the Top-k technique to select the top actions corresponding to the largest probabilities , and take the client corresponding to the current action as the selected client, where represents the local loss function value of the client at the -th global iteration, and represents the remaining overall privacy budget of the client at the -th global iteration.

[0041] It should be noted that the number of probabilities output by the target network is equal to the number of actions. For example, there are 10 clients, and each client has 10 different levels of privacy budgets, then there are 100 different tuple pairs. Each tuple pair includes a client number and a privacy budget, so the number of probabilities is 100, that is, each probability corresponds to a tuple pair.

[0042] S4: Train the local model using the local dataset at the selected client and upload the perturbed gradient to the central server.

[0043] Step S4 of this embodiment specifically includes:

[0044] S4.1: The selected client obtains the current global model and the allocated privacy budget , and assigns the parameters of the global model to the local model, where represents the local model on the -th client.

[0045] S4.2: Select a predetermined number of local image training data from the local image training dataset, generate differential privacy noise of the corresponding degree using the Gaussian mechanism according to the allocated privacy budget and add it to the local image training data to obtain the noise-added local image training data:

[0046] ;

[0047] Among them, represents the pixel value of the m th row and n th column in the current local image training data, represents the pixel value of the m th row and n th column in the locally noisy image training data, represents Gaussian noise that satisfies a Gaussian distribution with a mean of 0 and a variance of .

[0048] S4.3: Use the locally noisy image training data to train the local model on the current client to obtain a local loss value and the corresponding perturbation gradient , and upload the perturbation gradient to the central server.

[0049] S4.4: The client obtains the current remaining overall privacy budget according to the allocated privacy budget :

[0050] ;

[0051] Among them, represents the initial overall privacy budget of the client . To simulate a real environment where different users have different privacy requirements, at the beginning of federated learning, each client has its own initial overall privacy budget represents the privacy budget allocated by the client in the m th global iteration.

[0052] S5: Aggregate the perturbation gradients from the selected clients on the central server to obtain an updated global model and the reward corresponding to the current state.

[0053] This step specifically includes:

[0054] S5.1: The central server aggregates the perturbation gradients from all selected clients to obtain an updated global model :

[0055] ,

[0056] Among them, represents the global model in the th global iteration, represents the The global model in the sub - global iteration, is the learning rate, is the total number of local image training data in the selected clients, represents the number of local image training data of the th client,

[0057] S5.2: The central server obtains the reward corresponding to the current state:

[0058] ,

[0059] wherein, represents the reward in the th global iteration, , is a fixed hyper - parameter, that is, is the proportionality coefficient, which belongs to the hyper - parameters, and increases linearly with the excess value of the overall privacy budget.

[0060] S6: Obtain the next state of federated learning and update the evaluation network and the target network.

[0061] Step S6 of this embodiment includes:

[0062] S6.1: Switch the federated learning system to the next state and store the tuple into the replay buffer wherein, respectively represent the state, action and reward of the federated learning system in the th global iteration, represents the state of the federated learning system in the th global iteration.

[0063] S6.2: Randomly sample tuples b from the replay buffer as samples, and use the random gradient descent method to train and update the parameters of the evaluation network according to the discount factor and the learning rate of the evaluation network to obtain the updated evaluation network.

[0064] Specifically, judge whether the number of tuples stored in the replay buffer is greater than or equal to the preset sampling number b, if so, randomly sample from the replay buffer and b tuples as samples, and according to the discount factor and the evaluation network learning rate use the stochastic gradient descent method to train and update the parameters of the evaluation network to obtain the updated evaluation network; if not, do not train and update the evaluation network and keep the current evaluation network unchanged. In practice, b is set according to actual needs. For example, it can take values such as 16, 32, 64, 128, etc.

[0065] S6.3: Update the target network parameters according to the soft update principle: , where represents the soft update parameter.

[0066] S7: Repeat steps S3 to S6 until the set global iteration number n is reached.

[0067] Specifically, return to step S3, randomly generate a decimal within the range (0, 1), and compare the value of this decimal with the exploration rate ; if the value of this decimal is less than the current exploration rate , randomly generate an action , where represents whether the client is selected in the round. If so, , otherwise , represents the round in which the selected client is allocated the privacy budget; if the value of the decimal is greater than or equal to the exploration rate , obtain the selected client and the allocated privacy budget according to the current state and the target network. The specific process can be seen in step S3 and will not be elaborated here. After the above steps, the updated global network, evaluation network, and target network after the th global iteration can be obtained. Repeating the iteration can obtain the th iteration of the global network.

[0068] S8: Update the exploration rate and repeat steps S2 to S7 until the set number of federated learning times E is reached.

[0069] Specifically, after n times of global iteration in one federated learning, judge the exploration rate Whether the preset exploration rate minimum value is reached , if so, keep the exploration rate unchanged, if not, then use the exploration rate decay factor to update the exploration rate and obtain the updated exploration rate:

[0070] ;

[0071] Among them, represents the updated exploration rate.

[0072] The exploration rate can be expressed in the following specific mathematical form:

[0073] .

[0074] It should be noted that during the execution of the above method, the parameter E (number of federated learning times) actually represents the number of times federated learning is repeatedly executed. For example E = 100, indicating that federated learning has been executed 100 times. The reason for repeated execution is to provide enough samples for the training of the evaluation network . And the parameter n represents the number of global iterations for each federated learning. For example n = 200, indicating that 200 global iterations are executed for each federated learning. In the early stage when the exploration rate value is relatively large, and are mostly randomly generated to explore possible situations in the federated learning environment and provide sample training for the evaluation network . After that, the exploration rate decreases continuously as the number of federated learning executions increases until it decreases to the preset exploration rate minimum value . At the end (i.e., when federated learning is executed for the E th time), and are almost all generated by the target network . At this time, and are the desired client selection and privacy budget allocation strategies.

[0075] After training is completed, the global network after the last federated learning has the best recognition performance. Therefore, the trained global model can be used to recognize the input image to obtain the recognition result.

[0076] Another aspect of the present invention also provides a federated learning model training system based on differential privacy image noise addition, including a central server and a plurality of clients connected to the central server, for the federated learning model training method based on differential privacy image noise addition.

[0077] Combined with the federated learning framework, the present invention proposes a dynamic differential privacy method, which processes image data with different privacy budgets before each training and selects appropriate clients with different data distributions to participate in federated learning, improving the image recognition rate while ensuring user privacy, and specifically having the following advantages:

[0078] (1) Collaborative training under the federated learning framework: Combining the advantages of federated learning, a distributed training system is constructed, allowing multiple clients to independently train models on local data and synchronizing local updates to the central server through secure aggregation. During this process, the data of all participants remains local and will not be uploaded to the central server (cloud), thus reducing the risk of data leakage.

[0079] (2) Efficient privacy protection: Adopting a dynamic differential privacy method, by adding noise to image pixels, the risk of leaking image data from the model gradients due to inference attacks is reduced, further strengthening the privacy protection of user data.

[0080] (3) Optimized noise addition strategy: Dynamically adjust the noise addition intensity according to the sensitivity of the image content and the image data distribution to ensure minimizing the impact on the model performance while protecting privacy. Specifically, the present invention designs an intelligent noise generation algorithm that can adaptively select appropriate noise parameters (i.e., privacy budgets), ensuring both the effectiveness of privacy protection and the accuracy of image recognition.

[0081] (4) Enhanced image recognition performance: By introducing techniques such as multi-task learning and transfer learning, not only the model performance of a single client is improved, but also the knowledge sharing between different clients is promoted, enhancing the image recognition ability of the entire system. Especially for small-sample or low-quality images, this method can obtain better generalization performance through global collaboration.

[0082] (5) Flexible adaptation to application scenarios: Applicable to a variety of image recognition tasks, such as face recognition, object detection, medical image analysis, etc., especially suitable for those fields with strict requirements for privacy protection. In addition, this method and system can also flexibly adjust the privacy protection level according to the needs of specific application scenarios to achieve a balance between performance and privacy.

[0083] The above content is a further detailed description of the present invention in combination with specific preferred embodiments. It cannot be determined that the specific implementation of the present invention is only limited to these descriptions. For those of ordinary skill in the technical field to which the present invention pertains, without departing from the concept of the present invention, several simple deductions or substitutions can still be made, and all should be regarded as belonging to the protection scope of the present invention.

Claims

1. A federated learning model training method based on differential privacy image noising, characterized in that: include: S1: Initialize the evaluation network, target network and related hyperparameters; S2: Initialize the global model and its parameters of the federated learning system on the central server, and broadcast the global model to all clients; S3: Get the selected clients and the allocated privacy budget based on the current state of the federated learning system and the target network; S4: training the local model using the local data set on the selected client, and uploading the perturbation gradient to the central server; S5: Aggregating the perturbation gradients from the selected clients at the central server to obtain an updated global model and a reward corresponding to the current state; S6: updating the evaluation network and the target network; S7: Repeat S3 to S6 until the global iteration number set by federated learning is reached. n ; S8: Update the exploration rate and repeat S2 to S7 until the set number of federated learning is reached. E , The S1 includes: S1.1: The network will be evaluated Parameters and the target network Parameters Randomly initialized to equal parameters; S1.2: Initialize relevant hyperparameters, including discount factors , Soft Update Parameters , Exploration Rate , minimum exploration rate , exploration rate decay factor , evaluate the network learning rate and replay buffer , The S3 includes: A random decimal is generated in the range (0,1), and the value of the decimal is compared with the exploration rate 's values ​​for comparison; If the decimal value is less than the exploration rate The value of , then randomly generates the first The action of the global iteration ,in, Represents the client In the Is it selected in the global iteration? If so, ,otherwise , Represents the client In the The privacy budget allocated in the global iteration, Represents a collection of clients; If the value of the decimal is greater than or equal to the exploration rate , the current state Input to the target network In the target network Output multiple probabilities according to the current state, the number of probabilities is equal to the number of actions, and the largest forward probability is selected using the Top-k technique. The actions corresponding to the probability , the current action The corresponding client is taken as the selected client, where Represents the client In the The local loss function value in the global iteration, Represents the client In the The total privacy budget remaining in the global iteration.

2. The method for training a federated learning model based on differential privacy image noising according to claim 1, characterized in that: The S4 includes: S4.1: The selected client obtains the current global model and the allocated privacy budget , and the global model Assign the parameters of to the local model; S4.2: Select a predetermined amount of local image training data from the local image training dataset, based on the allocated privacy budget A Gaussian mechanism is used to generate differential privacy noise of a corresponding degree and added to the local image training data to obtain the noisy local image training data: ; in, Indicates the number of the current local image training data m Line n The pixel value of the column, Represents the number of local image training data after adding noise m Line n The pixel value of the column, It means that the mean is 0 and the variance is Gaussian noise with Gaussian distribution; S4.3: Using the noised local image training data to train the local model on the current client Perform training and get the local loss value and the corresponding perturbation gradient , and the perturbation gradient Uploading to the central server; S4.4: The client receives the allocated privacy budget Get the current remaining overall privacy budget : ; in, Represents the client The initial overall privacy budget is Represents the client In the m The privacy budget allocated in the global iteration.

3. The method for training a federated learning model based on differential privacy image noising according to claim 2, characterized in that: The S5 includes: S5.1: The central server aggregates the perturbation gradients from all selected clients to obtain an updated global model : ; in, Indicates The global model in the global iteration, represents the global model in the tth global iteration, is the learning rate, Indicates the total number of local image training data in the selected client. Indicates The number of local image training data of each client, Indicates the number of selected clients; S5.2: The central server obtains the reward corresponding to the current state: ; in, , To fix the hyperparameters, is the proportionality coefficient.

4. The method for training a federated learning model based on differential privacy image noising according to claim 3, characterized in that: The S6 includes: S6.1: Switch the federated learning system to the next state And the tuple Stored to the replay buffer Among them, They represent the execution of the federated learning system The state, action, and reward of the global iteration, Indicates that the federated learning system executes The state of the next global iteration; S6.2: From the replay buffer Randomly select b Tuples As a sample, and according to the discount factor and evaluate the network learning rate The evaluation network is evaluated using the stochastic gradient descent method. The parameters of the network are trained and updated to obtain an updated evaluation network; S6.3: Update the parameters of the target network according to the soft update principle: .

5. According to the federated learning model training method based on differential privacy image noising according to claim 4, S6.2 comprises: Determine the replay buffer Tuples stored in Is the number greater than or equal to the preset extraction number? b , if so, then from the replay buffer Randomly select b Tuples As a sample, and according to the discount factor and evaluate the network learning rate The evaluation network is evaluated using the stochastic gradient descent method. The parameters of the training are updated to obtain an updated evaluation network; if not, the evaluation network is kept The parameters remain unchanged.

6. The method for training a federated learning model based on differential privacy image noising according to claim 1, characterized in that: Updates to exploration rate, including: After completing a federated learning n After global iterations, determine the exploration rate Whether the preset minimum exploration rate is reached , if so, keep the exploration rate unchanged, if not, then use the exploration rate decay factor Exploration Rate Update and get the updated exploration rate: ; in, represents the updated exploration rate.

7. A federated learning model training system based on differential privacy image noising, characterized in that: It comprises a central server and a plurality of clients connected to the central server, and is used to execute the federated learning model training method based on differential privacy image noising as described in any one of claims 1 to 6.