Robust privacy federal learning method based on homomorphic evaluation

By using technical means such as homomorphic evaluation and malicious judges detection in federated learning, the problems of robustness and privacy security in the face of malicious attacks are solved, and the encryption gradient quality evaluation and system robustness are improved.

CN119940481AActive Publication Date: 2025-05-06NANJING UNIV OF POSTS & TELECOMM
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510414991.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-05-06
Estimated Expiration
2045-04-03

AI Technical Summary

Technical Problem

Existing federated learning technologies are difficult to ensure the robustness and privacy of the system when facing malicious attacks, especially the problem of difficult evaluating the quality of encryption gradients during the aggregation process.

Method used

A robust privacy federated learning method based on homomorphic evaluation is adopted to protect data privacy through threshold Paillier homomorphic encryption, and a quality evaluation method for encryption gradient "homomorphic evaluation" is designed. At the same time, a malicious judges detection algorithm is introduced to screen out malicious judges to ensure the robustness of the system.

Benefits of technology

It effectively solves the problem that encryption gradient quality is difficult to evaluate during the aggregation process, enhances the robustness and privacy and security of the system, is suitable for a wider range of practical scenarios, and improves the quality of the global model.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119940481A_ABST
    Figure CN119940481A_ABST
Patent Text Reader

Abstract

The invention provides a robust privacy federated learning method based on homomorphic evaluation, and designs four indexes of privacy, availability, robustness and efficiency by integrating the defects of an existing scheme so as to comprehensively measure a federated learning scheme. The privacy is used for measuring the defense capability of the scheme on privacy threats; evaluating the performance of the model under the condition of no security threat; the robustness reflects the resistance of the scheme to security threats; the efficiency focuses on the performance of the model in the aspects of time efficiency, calculation overhead and the like. The scheme of the invention shows significant advantages in four index aspects of privacy, availability, robustness and efficiency, and can effectively solve the problem that the encryption gradient quality is difficult to evaluate in the aggregation process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security applications, and specifically relates to a robust privacy federated learning method based on homomorphic evaluation. Background Art

[0002] With the rapid development of Internet technology, machine learning and artificial intelligence are increasingly used in finance, medicine, education, transportation, basic science and other fields. However, conducting machine learning research requires the collection and processing of a large amount of data, which often contains sensitive privacy information and may involve multiple institutions or countries. Due to the risk of data leakage during transmission and learning, and with the increasing awareness of privacy protection among individuals and institutions, data owners are often reluctant to contribute their private data, resulting in the increasingly serious phenomenon of "data islands". In addition, countries have gradually introduced and improved laws and regulations related to user data privacy security, which has exacerbated this phenomenon. Faced with such a reality, federated learning is seen as an effective solution. By collecting models trained locally by each participant rather than raw data, federated learning overcomes the "data island" phenomenon to a certain extent while protecting user data privacy.

[0003] However, many research works have shown that even federated learning has many threats. We will conduct a systematic analysis of threats in federated learning based on the CIA triplet (integrity, availability, confidentiality) in the field of information security. Integrity ensures that the data has not been tampered with during the training process and that the participants follow the protocol to execute the algorithm; availability ensures that the final model obtained through training has high performance and can give high-accuracy output for various inputs; confidentiality ensures the security of user data and model information, and prevents sensitive information from being leaked to unauthorized users.

[0004] According to the different impacts on the core security elements in the CIA triplet, potential threats in federated learning can be divided into privacy threats and security threats: Privacy threats undermine confidentiality in federated learning. Malicious servers or participants steal the gradient information of other participants during the learning process to infer or reconstruct the original data, resulting in privacy leakage; Security threats undermine integrity and availability. The main security threats in federated learning include poisoning attacks. Attackers interfere with the federated learning process by tampering with training data or manipulating local models, poisoning the global model to reduce model performance or insert backdoors.

[0005] In order to solve the above problems, the existing technologies are as follows: Technical comparison with CN114862416B "A cross-platform credit evaluation method in a federated learning environment" 1. CN114862416B uses homomorphic encryption to encrypt the local model to protect data security during data transmission. The server receives data from all parties and uses the federated average as data aggregation. Its characteristic is that the ciphertext can be decrypted to obtain the plaintext result without direct access to the plaintext. This scheme of encrypting the local model, aggregating and decrypting the global model can only ensure the privacy of the system but not the robustness of the system. It cannot resist poisoning attacks from malicious clients and can only work under the security assumption that all participants are semi-honest. This study proposes a federated learning scheme Fed-HA that takes into account both privacy and robustness. It uses threshold Paillier homomorphic encryption to protect the privacy and security of data, and designs a quality assessment method for encrypted gradients, "homomorphic evaluation", which effectively solves the problem of difficult evaluation of the quality of encrypted gradients during the aggregation process, ensures the robustness of the system when facing malicious attackers, and is suitable for a wider range of practical scenarios. At the same time, it improves the incentives for participants who actively participate in learning, which helps to improve the quality of the global model.

[0006] Second, CN114862416B uses traditional additive homomorphic encryption, which has only a single public key and a single secret key. Although it can ensure that data is not eavesdropped during transmission, if a malicious attacker disguises himself as a normal client to participate in federated learning, the system's secret key will be leaked, and the attacker can use the secret key to steal the privacy information of other normal clients. The threshold homomorphic encryption scheme used in this research scheme has multiple different partial keys. During decryption, each decryptor uses his partial key to generate the corresponding decryption share. Decryption can only be completed when the number of correct decryption shares exceeds the specified threshold, which can prevent a single attacker or several attackers from conspiring to disguise themselves as normal clients to steal privacy.

[0007] Technical comparison with patent CN114491616A "Federated learning method and application based on blockchain and homomorphic encryption" 1. Patent CN114491616A combines blockchain, homomorphic encryption and federated learning, introduces the decentralized characteristics of blockchain into federated learning, reduces the potential risk of single point failure, and introduces trust mechanism and scoring mechanism through the accounting function of blockchain. The account client measures the contribution of participating clients based on the prediction accuracy of the public evaluation data set to encourage participants to upload high-quality parameters. This requires the collection of a public, high-quality, and sufficiently rich evaluation data set, which may not be feasible in practice. This study divides the participants other than the server into calculators and judges. The judges are responsible for using the "homomorphic evaluation" method to score the encrypted gradients uploaded by the calculators using their local evaluation data sets, and then screen out potential malicious judges through the malicious judge detection algorithm, and obtain the score of each calculator based on the scores of the remaining benign judges, and finally perform weighted aggregation based on the scores. This study does not rely on a public data set collected in advance, but uses the local data sets of each judge to measure the quality of the gradient of the calculator, while not leaking the privacy of any judge or calculator.

[0008] Second, the scoring mechanism in patent CN114491616A can eliminate low-quality clients and malicious attackers. However, in the initial stage, there is no means to detect potential malicious attackers. Once multiple attackers conspire to attack federated learning and an attacker is selected as the account client, it will pose a great threat to the security of the system, thereby affecting the quality of the global model. This study uses a malicious judge detection algorithm. After the judges evaluate the computer, the scores of each judge on each computer are collected and analyzed, and abnormal scoring results are screened out, ensuring that the client's score is not manipulated by the attacker, maintaining system security, and improving robustness.

[0009] Technical comparison with patent CN116596561A "Energy-using enterprise credit evaluation method, system and equipment based on vertical federated learning" 1. Patent CN116596561A uses vertical federated learning to establish a credit evaluation model for energy-consuming enterprises, analyzes the intrinsic correlation between power grid and partner data, calculates scores through encryption and privacy computing, and uses Softmax regression method and homomorphic encryption to predict future scores while protecting data privacy, which can expand data labels, enrich data pools, and ensure privacy security. Vertical federated learning is suitable for scenarios where the participants have the same samples or the same user groups, but each participant has different characteristics. In this case, through vertical federated learning, joint modeling can be achieved while ensuring data privacy. This research plan is built on the infrastructure of horizontal federated learning, and introduces modules such as a scoring mechanism based on comprehensive reputation value, a judge selection algorithm, a threshold homomorphic encryption method, a quality assessment method "homomorphic evaluation" of encrypted gradients, and a malicious judge detection algorithm, thereby achieving the unity of privacy, availability, robustness and efficiency in federated learning. Horizontal federated learning is suitable for scenarios where the participants have the same sample set, but each participant has different characteristics. In this scenario, horizontal federated learning can be jointly trained based on their respective data characteristics without directly exchanging data.

[0010] Second, the patent CN116596561A aims to propose a credit evaluation method for energy-consuming enterprises and build a credit evaluation model for energy-consuming enterprises. It mainly focuses on energy enterprises such as electricity and power grids, and belongs to the field of power market trading technology. This study involves the fields of computer technology and network security application technology. The Fed-HA scheme proposed in this study is a general privacy-preserving robust federated learning scheme. It is applicable to any learning task in any horizontal federated learning scenario where the model architecture is compatible with the homomorphic evaluation method, and has a wide range of applications in data analysis, computer vision and other fields. Summary of the invention

[0011] To solve the above technical problems, the present invention proposes a robust privacy federated learning method based on homomorphic evaluation. This scheme shows significant advantages in the four indicators of privacy, availability, robustness and efficiency, and can effectively solve the problem of difficulty in evaluating the quality of encrypted gradients during the aggregation process.

[0012] To achieve the above object, the technical solution adopted by the present invention is: The present invention provides a robust privacy federated learning method based on homomorphic evaluation, and the specific steps are as follows: S1 initialization phase: Server initializes global model , and for each user Initialize comprehensive reputation value , the key generation center generates public and private keys and distributes them; S2 collaborative training phase; The system iteratively executes the robust aggregation algorithm and updates the global model, comprehensive reputation value, and user historical score after each round of aggregation. Each participant performs their respective duties and collaborates to complete the corresponding global round until the global round reaches the set maximum value. E Or reach the stopping condition, and finally output a high-performance global model M .

[0013] As a further improvement of the present invention, in the initialization phase of step S1, the specific steps are as follows: Assume that there is User clients participate in federated learning, and their user set , a server O And a third-party key generation center participates in federated learning. In the initialization phase, the server initializes the global model , and for each user Initialize comprehensive reputation value , the key generation center generates the public key And the private key collection And distribute keys, public keys Public, to any user , which obtains part of the private key .

[0014] As a further improvement of the present invention, in step S2, the collaborative training phase, the specific steps are as follows: Note that the server initializes the global model as , No. The global model of the wheel is , for each user participating in federated learning, use The digital serial number between them corresponds one to one, using the serial number Indicates the user corresponding to this serial number. During the federated learning process, users will be divided into calculators or judges. For a calculator, its user serial number is used. To represent himself, for a judge, use his user number To represent the comprehensive reputation value sequence of all clients on its behalf , the client's historical score matrix ,user In the The score of the round is ,lie in The matrix Line List; 2.1. Identity division: users are divided into two identities: calculators and judges, who play different roles in federated learning; 2.2. Local model training: The computer uses its local data set to perform local model training to obtain local gradients, which are then encrypted and uploaded to the server. 2.3. Model evaluation: The judges conduct homomorphic evaluation on the encrypted gradients submitted by the calculator and upload the homomorphic evaluation results; 2.4. Malicious judge detection: The scores of each judge are obtained based on the homomorphic evaluation results uploaded by the judges, and malicious judges are screened out based on this, and the rest of the judges are considered benign; 2.5. Comprehensive scoring: The scores of each calculator are obtained by combining the homomorphic evaluation results of all benign judges; 2.6. Global gradient aggregation: perform weighted average of the encrypted gradients uploaded by each calculator according to their scores, and decrypt them to obtain the global gradient; 2.7. Information update: Calculate the comprehensive reputation value of each user and update the historical score matrix and comprehensive reputation value sequence of all users.

[0015] As a further improvement of the present invention, step 2.1 identity division, the specific steps are as follows: The server selects users according to the judge selection algorithm based on comprehensive reputation value. Divide into A calculator and Judges , the set of calculators is denoted as , the judges collectively record ; The Beta distribution is a continuous probability distribution defined on the interval [0,1], and its probability density function is as follows: ; in is a parameter and , assuming that you need to Thompson sampling is used to sample out , for any user , let the number of normal and abnormal behaviors be and , construct the corresponding Beta distribution probability density function , then based on Generate a random number , sort and take The largest number is obtained and the corresponding participant is selected. The Thompson sampling process is expressed as follows: ; in , Gather for the chosen ones; Then build a judge selection algorithm; In the judge selection algorithm, the number of normal and abnormal behaviors in Thompson sampling is and Extended to the field of positive real numbers, and respectively called well-behaved exponents and malignancy index , the calculation formula is: ; in Is a user In the Round score; When the judge selection algorithm is executed, the benignity index of all users is first calculated. Malignancy Index , statistics show , and then apply Thompson sampling to select the judges set : ; in is the total number of users, is the number of judges, then the set of calculators .

[0016] As a further improvement of the present invention, step 2.2 local model training, the specific steps are as follows: Calculator Download the global model of the previous round , and use it as input for local training, and then use its local dataset Take the layered training method to learn and get the local gradient , then the calculator Use part of its private key to parse the local gradient After Paillier homomorphic encryption, the encrypted gradient is obtained , upload it to the server.

[0017] As a further improvement of the present invention, step 2.3 model evaluation, the specific steps are as follows: Now assume that a certain original model The number of parameter update layers required in , original model The network parameters are expressed as: ; in , Indicates the layer whose parameters need to be updated. The weight matrix corresponding to the layer, Indicates the layer whose parameters need to be updated. The bias vector corresponding to the layer; Suppose there is a piece of data for homomorphic evaluation ,in Represents the input vector and data label respectively. If used To the original model The gradient of is evaluated homomorphically, and the parameter update strategy of layered training is adopted, with one layer of parameters updated each time; Assume that the layer of the global model update parameters in a certain round of learning is layer, and the encrypted gradient uploaded by the evaluated client is ,in They are the corresponding The weight and bias of the layer, then the homomorphic evaluation network corresponding to this user is represented as: ; go through Before Layer forward propagation obtains , through the After layer The output vector of the encrypted layer, this process can be expressed as: ; After decryption, we get: ; Continue forward propagation through the remaining Layer Acquisition Output , compared with the labels of the original data That is, the homomorphic evaluation of the parameters submitted by this user on this data is completed; Homomorphic evaluation is implemented based on an evaluation data set. The definition of homomorphic evaluation on the data set and the calculation formula for measuring the evaluation results will be given; For an evaluation dataset ,in For the first Items of data, For the The labels of the data are based on the evaluation dataset. The given set of homomorphic evaluations is represented as a set of pairs of numbers: ; in , is the data label, since is a vector, can be converted into a one-hot vector, and and The cross entropy function between the converted one-hot vectors reflects the degree of deviation, so the average cross entropy function value of each pair in the homomorphic evaluation set is defined as the evaluation result: ; in is the dimension of each data in the dataset, That is The average cross entropy function of each pair in is: The larger the The worse the evaluation is, the and the original model Gradient The process of performing homomorphic evaluation is expressed as: ; The model evaluation steps are as follows: First, each judge collects the updated parameters of all the calculators and establishes a corresponding homomorphic evaluation network. Encrypted gradient The homomorphic evaluation network established is , judges Using its local dataset The data in the network are passed through the homomorphic evaluation network one by one Get the encrypted layer output: ; Then the judges These encrypted layer outputs are uploaded to the server, which aggregates the total The output of the group encryption layer is then organized for collaborative decryption. After decryption, forward propagation continues through the homomorphic evaluation network after the encryption layer to obtain a set of output vector pairs: ; in Refers to the dataset The The label vector of the data. Local Datasets The Homomorphic Evaluation Network The output vector after The server then calculates the homomorphic evaluation results based on these vector pairs and stores them in the matrix used to store homomorphic evaluation results In the calculation formula of the homomorphic evaluation result, .

[0018] As a further improvement of the present invention, step 2.4. Malicious judge detection, the specific steps are as follows: In one round of learning, each judge will The vector of homomorphic evaluation results given by the judges can be regarded as a Weidian, such as judges The homomorphic evaluation result vector , each dimension of the vector represents the homomorphic evaluation result given by this judge to a certain computer; For point , the distance between the homomorphic evaluation result vectors is defined as: ; Judges of Neighbor Set Pointing to The distance between the homomorphic evaluation results vectors is the smallest For a set of points, , define its sharing The neighbor set is: ; Then define The SNN similarity between the homomorphic evaluation result vectors is: ; Judges SNN similarity Neighbor Set Pointing to The SNN with the highest similarity of the homomorphic evaluation result vector points, then The density at can be defined as: ; When executing the malicious judge detection algorithm, first input the homomorphic evaluation result set , extract the evaluation result sequence given by each judge, and then establish two point sets , respectively represent the initial point set and the current point set. After the initialization is completed Contains the evaluation result sequence given by all judges, Empty for judges , find out its Neighbor Set The element with the largest density value ,like The density ratio at If it is small, Move to Otherwise, it does not move. This operation is run once for each judge. Repeat the above steps until no point moves in a round. Then the termination condition is reached. At this time, all points move to their corresponding local highest density point, which is called the local center point. Finally, all judges who move to the same local center point will be classified into the same cluster, and the cluster with the largest number of elements will be taken as the benign judge set. ; After obtaining the benign judges set, in order to remove discrete points, set a threshold , for a judge , if its density is less than , then it is determined as discrete points and transform them from Finally, each judge needs to be scored according to the analysis results. For any judge, its score is the sum of the SNN similarities between the judges in the benign judge set and it: ; After normalization, we get the scores of all judges in this round: ; Therefore, the malicious judge detection steps are as follows: after collecting all the homomorphic evaluation results, call the malicious judge detection algorithm to identify the evaluation result vectors of these judges to eliminate possible malicious judges, and return the scores of each judge to measure the performance of each judge in this round of learning. The set of benign judges that pass the detection algorithm is recorded as ,and .

[0019] As a further improvement of the present invention, step 2.5. Comprehensive scoring, the specific steps are as follows: The score of each calculator is obtained by combining the evaluations of each benign judge. The calculation method is as follows: ; in Representative judges For calculators The evaluation opinions, It is the judges' opinions on the calculator. The weighted comprehensive result of the opinions of the judges is the comprehensive reputation value of each good judge. , Is a calculator The score of this round is then normalized: ; Highest score The number of operators will be selected as benign operators, and their set is .

[0020] As a further improvement of the present invention, step 2.6. global gradient aggregation, the specific steps are as follows: Only collection The encrypted gradients submitted by the benign calculators in will be used for global aggregation, and after weighted aggregation, the encrypted global gradients of this round are obtained: ; in Is a calculator The comprehensive reputation value of Is a calculator The score for this round, is a constant used to measure the ratio of the importance of the calculator's performance in this round to its historical performance. The encrypted global gradient is the result of the weighted average of each encrypted gradient based on these two indicators; Then, the server organizes collaborative decryption to obtain the global gradient , and update it accordingly The parameters of the corresponding layer in the current round are obtained .

[0021] As a further improvement of the present invention, step 2.7. Information update, the specific steps are as follows: Each calculator and judge receives a score for this round of learning. Next, the historical score matrix is ​​updated based on the scores of each user. and comprehensive reputation value sequence ,user Comprehensive reputation value is the sum of their model scores from each previous round, plus a time decay factor ; ; After the comprehensive reputation value is updated, users whose reputation value is too low during multiple rounds of learning will be identified as malicious attackers by the server and kicked out of the system.

[0022] Compared with the prior art, the present invention has the following advantages and beneficial effects: 1) A quality assessment method for encrypted gradients, "Homomorphic Assessment" (HA), is proposed, which effectively solves the problem that the quality of encrypted gradients is difficult to assess during the aggregation process. In the federated learning process, users are divided into judges and calculators based on their past performance, who are responsible for generating gradients for local training and scoring the quality of gradients, respectively. This method can filter out malicious gradients submitted by attackers without destroying data privacy, thus ensuring the privacy and robustness of the system; 2) Adaptive improvements are made to the training process of servers and users, and a parameter update strategy compatible with the homomorphic evaluation method, "layered training", is proposed. Since homomorphic evaluation uses threshold Paillier homomorphic encryption, in order to adapt to the additive homomorphism and mixed multiplicative homomorphism of threshold Paillier homomorphic encryption, this strategy only updates one layer of the model in each training, and trains and updates the learnable parameters in the model layer by layer, so that this solution can be applied to most common network structures; 3) A malicious judge detection method based on shared nearest neighbor (SNN) similarity clustering is proposed. This method can screen out possible malicious judges based on the evaluation opinions collected by the server, and obtain the score of the calculator by combining the scoring opinions of benign judges, thereby discarding low-quality gradients. Finally, the benign calculator is selected based on the score, and its gradient will participate in the global aggregation, and the aggregation weight is positively correlated with the score; 4) A privacy-robust aggregation scheme based on homomorphic assessment, Fed-HA (Federated Learning with Homomorphic Assessment), was proposed, and a federated learning system based on this scheme was implemented. Fed-HA comprehensively applies the encrypted gradient quality assessment method HA, the parameter update strategy of layered training, and the malicious judge detection method based on SNN similarity clustering. It combines privacy, availability, robustness and efficiency, and does not require additional assumptions about servers or users, and can adapt to most practical scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 It is a flowchart of the robust privacy federated learning method based on homomorphic evaluation provided by module 1 of the present invention; Figure 2 It is a schematic diagram of the parameter update strategy of "layered training" in the present invention; Figure 3 This is the test experiment result 1 of the malicious judge detection algorithm provided by module 5 of the present invention on the MNIST data set; Figure 4 This is the second test result of the malicious judge detection algorithm provided by module 5 of the present invention on the MNIST data set; Figure 5 This is a comparison experiment diagram of the Fed-HA solution and other solutions facing label flipping attacks; Figure 6 This is a comparison experiment diagram of the Fed-HA solution and other solutions facing scaling attacks; Figure 7 This is a comparison experiment chart of the Fed-HA solution and other solutions when facing Gaussian attacks. DETAILED DESCRIPTION

[0024] The present invention is further described in detail below in conjunction with the accompanying drawings and specific embodiments: Example 1: A robust privacy federated learning method based on homomorphic evaluation Module 1; This module 1 provides an overall framework for robust privacy federated learning methods based on homomorphic evaluation, including: The initial global model is , No. The global model of the wheel is For each user participating in federated learning, we use The numbers between them correspond to each other one by one. In the following, we use the serial number Indicates the user corresponding to this serial number. During the federated learning process, users will be divided into calculators or judges. For a calculator, we use its user serial number To represent themselves, for a judge, we use their user number To represent itself. The comprehensive reputation value sequence of all users is , the user's historical score matrix is ,user In the The score of the round is ,lie in The matrix Line List In the initialization phase, the server initializes the global model , and for each user Initialize comprehensive reputation value , the key generation center generates public and private keys and distributes them; in the collaborative training phase, the system iteratively executes the robust aggregation algorithm and updates the global model, comprehensive reputation value, and user historical scores after each round of aggregation. Each user performs their respective duties and collaborates to complete the corresponding global round until the global round reaches the set maximum value. Or reach the stopping condition, and finally output a high-performance global model .

[0025] The comparison experiment of the robust privacy federated learning method Fed-HA based on homomorphic evaluation and other schemes in the face of label flipping attack, scaling attack and Gaussian attack is shown in the figure below. Figure 5 , Figure 6 , Figure 7 shown.

[0026] Module 2; This module 2 provides a robust aggregation method that focuses on privacy protection, such as Figure 1 As shown, including: Division phase: The server divides users into A calculator and Judges , the set of calculators and judges are denoted as and .

[0027] Local model training phase: Calculator Download the global model of the previous round , and use it as input for local training, and then use its local dataset Take the layered training method to learn and get the local gradient .

[0028] Local update upload phase: calculator right After encryption, the encrypted gradient is obtained , upload it to the server.

[0029] Model evaluation stage: Each judge collects the updated parameters of all the calculators and establishes a corresponding homomorphic evaluation network. Encrypted gradient The homomorphic evaluation network established is . Judges Using its local dataset The data in the Get the encrypted layer output: ; Evaluation and decryption phase: The server summarizes the total The output of the group encryption layer is then organized for collaborative decryption. After decryption, forward propagation continues through the homomorphic evaluation network after the encryption layer to obtain a set of output vector pairs: ; in Refers to the dataset The The label vector of the data. Refers to the dataset The Homomorphic Evaluation Network The server then calculates the homomorphic evaluation results based on these vectors and stores them in the matrix used to store homomorphic evaluation results. The calculation formula of the homomorphic evaluation result is: ; Malicious judge detection stage: After collecting all the evaluation data, it is necessary to identify the evaluations of these judges to eliminate possible malicious judges. The malicious judge detection algorithm will be introduced in Module 5. The set of benign judges that pass the detection algorithm is ,and ,At the same time, the malicious judge detection algorithm returns the score of each judge.

[0030] Scoring stage: The evaluation of each benign judge is combined to obtain the score of each calculator. The calculation method is as follows: ; in Representative judges For calculators The evaluation opinions, It is the judges' opinions on the calculator. The weighted comprehensive result of the opinions of the judges is the comprehensive reputation value of each good judge. , Is a calculator Then we need to normalize the score: ; Highest score The number of operators will be selected as benign operators, and their set is ; Global gradient aggregation phase: only the collection The updated gradients submitted by the benign calculators in will be used for global aggregation. The encrypted global gradient of this round is: ; in Is a calculator The comprehensive reputation value of is a constant used to measure the ratio of the importance of the calculator's current performance to its historical performance. The encrypted global gradient is the result of the weighted average of each encrypted gradient based on these two indicators.

[0031] Model decryption phase: Servers organize collaborative decryption to obtain global gradients , and update it accordingly The parameters of the corresponding layer in the current round are obtained . So far This round of federated learning ends.

[0032] Reputation update phase: At this point, each calculator and judge has obtained a score for this round of learning. Next, the user's historical score matrix is ​​updated based on the score. and the user's comprehensive reputation sequence .user Comprehensive reputation value is the sum of their model scores from each previous round, plus a time decay factor ; ; After the comprehensive reputation value is updated, users whose reputation value is too low during multiple rounds of learning will be identified as malicious attackers by the server and kicked out of the system.

[0033] Module 3; This module 3 provides homomorphic evaluation methods, including: Homomorphic evaluation is the core part of the robust aggregation module in this scheme. Its process is as follows: First, according to the encrypted gradient submitted by a user, the parameters of the corresponding position of the previous round of global model are updated. The updated model is called the homomorphic evaluation network (HAnet). Since the gradient is encrypted, the parameters of the corresponding position of the homomorphic evaluation network are also in the ciphertext state. Next, a set of plaintext data for evaluation is input into the homomorphic evaluation network. Using the properties of homomorphic encryption, the plaintext data can output the ciphertext result after passing through the homomorphic evaluation network. By comparing the decrypted homomorphic evaluation network output and the corresponding data label, the user's verification result on this data can be obtained.

[0034] In order to further clarify the specific process of homomorphic evaluation, we will use mathematical expressions to analyze its mechanism. In common neural network models, each layer can be divided into two categories: one does not contain learnable parameters, such as pooling layers, DropOut layers, activation function layers, and batch normalization layers; the other contains learnable parameters, including linear layers and convolutional layers. Now assume that a certain model The total number of layers that need parameter updates in , The network parameters are expressed as: ; in They represent the layers that need parameter update. The weight matrix and bias vector corresponding to the layer; Suppose there is a piece of data for homomorphic evaluation ,in Represents the input vector and data label respectively. If used Come to The gradient of is evaluated homomorphically, and the parameter update strategy of layered training is adopted. The schematic diagram of layered training is as follows Figure 2 As shown, the number of layers of parameters updated each time is one layer; Assume that the layer of the global model update parameters in a certain round of learning is layer, and the encrypted gradient uploaded by the evaluated client is ,in They are the corresponding The weight and bias of the layer, then the homomorphic evaluation network corresponding to this user is represented as: ; go through Before Layer forward propagation obtains , through the After layer The output vector of the encrypted layer, this process can be expressed as: ; After decryption, we get: ; Continue forward propagation through the remaining Layer Acquisition Output , compared with the labels of the original data That is, the homomorphic evaluation of the parameters submitted by this user on this data is completed; The above is a homomorphic evaluation of a single piece of data. Homomorphic evaluation is implemented based on an evaluation data set. The definition of homomorphic evaluation on the data set and the calculation formula for measuring the evaluation results will be given; For an evaluation dataset ,in For the first Items of data, For the The labels of the data are based on the evaluation dataset. The given set of homomorphic evaluations is represented as a set of pairs of numbers: ; in , is the data label, since is a vector, can be converted into a one-hot vector, and and The cross entropy function between the converted one-hot vectors reflects the degree of deviation, so the average cross entropy function value of each pair in the homomorphic evaluation set is defined as the evaluation result: ; in is the dimension of each data in the dataset, That is The average cross entropy function of each pair in is: The larger the The worse the evaluation is, the and the original model Gradient The process of performing homomorphic evaluation is expressed as: ; Module 4; This module 4 provides the judge selection algorithm, including: Before introducing the judge selection algorithm, we first introduce the prerequisite knowledge: Beta distribution and Thompson sampling. Beta distribution is a continuous probability distribution defined on the interval [0,1], and its probability density function is as follows: ; in is a parameter and , assuming that you need to Thompson sampling is used to sample out , for any user , let the number of normal and abnormal behaviors be and , construct the corresponding Beta distribution probability density function , then based on Generate a random number , sort and take The largest number is selected and the corresponding participant is selected. The above Thompson sampling process is expressed as follows: ; in , Gather for the chosen ones; We then built our judge selection algorithm based on this; In the judge selection algorithm, the number of normal and abnormal behaviors in Thompson sampling is and Extended to the field of positive real numbers, and respectively called well-behaved exponents and malignancy index , the calculation formula is: ; in Is a user In the Round score; When the judge selection algorithm is executed, the benignity index of all users is first calculated. Malignancy Index , statistics show , and then apply Thompson sampling to select the judges set : ; The set of calculators .

[0035] Module 5; This module 5 provides a malicious judge detection algorithm, including: In one round of learning, each judge will The vector of homomorphic evaluation results given by the judges can be regarded as a Weidian, such as judges The homomorphic evaluation result vector , each dimension of the vector represents the homomorphic evaluation result given by this judge to a certain computer; For point , the distance between the homomorphic evaluation result vectors is defined as: ; Judges of Neighbor Set Pointing to The distance between the homomorphic evaluation results vectors is the smallest For a set of points, , define its sharing The neighbor set is: ; Then define The SNN similarity between the homomorphic evaluation result vectors is: ; Judges SNN similarity Neighbor Set Pointing to The SNN with the highest similarity of the homomorphic evaluation result vector points, then The density at can be defined as: ; When executing the malicious judge detection algorithm, first input the homomorphic evaluation result set , extract the evaluation result sequence given by each judge, and then establish two point sets , respectively represent the initial point set and the current point set. After the initialization is completed Contains the evaluation result sequence given by all judges, Empty for judges , find out its Neighbor Set The element with the largest density value ,like The density ratio at If it is small, Move to Otherwise, it does not move. This operation is run once for each judge. Repeat the above steps until no point moves in a round. Then the termination condition is reached. At this time, all points move to their corresponding local highest density point, which is called the local center point. Finally, all judges who move to the same local center point will be classified into the same cluster, and the cluster with the largest number of elements will be taken as the benign judge set. ; After obtaining the benign judges set, in order to remove discrete points, set a threshold , for a judge , if its density is less than , then it is determined as discrete points and transform them from Finally, each judge needs to be scored according to the analysis results. For any judge, its score is the sum of the SNN similarities between the judges in the benign judge set and it: ; After normalization, we get the scores of all judges in this round: ; The test results of the malicious judge detection algorithm on the MNIST dataset are as follows: Figure 3 , Figure 4 shown.

[0036] The above description is only a preferred embodiment of the present invention and does not constitute any other form of limitation to the present invention. Any modification or equivalent change made based on the technical essence of the present invention still falls within the scope of protection required by the present invention.

Claims

1. A robust privacy federated learning method based on homomorphic evaluation, the specific steps are as follows, characterized in that: S1 initialization phase: Server initializes global model , and for each user Initialize comprehensive reputation value , the key generation center generates public and private keys and distributes them; S2 collaborative training phase; The system iteratively executes the robust aggregation algorithm and updates the global model, comprehensive reputation value, and user's historical score after each round of aggregation. Each participant performs their respective duties and collaborates to complete the corresponding global round until the global round reaches the set maximum value. E Or reach the stopping condition, and finally output a high-performance global model M .

2. The robust privacy federated learning method based on homomorphic evaluation according to claim 1, characterized in that: Step S1: Initialization phase. The specific steps are as follows: Assume that there is User clients participate in federated learning, and their user set , a server O And a third-party key generation center participates in federated learning. In the initialization phase, the server initializes the global model , and for each user Initialize comprehensive reputation value , the key generation center generates the public key And the private key collection And distribute keys, public keys Public, to any user , which obtains part of the private key .

3. The robust privacy federated learning method based on homomorphic evaluation according to claim 1, characterized in that: Step S2 is the collaborative training phase, and the specific steps are as follows: Note that the server initializes the global model as , No. The global model of the wheel is , for each user participating in federated learning, use The digital serial number between them corresponds one to one, using the serial number Indicates the user corresponding to this serial number. During the federated learning process, users will be divided into calculators or judges. For a calculator, its user serial number is used. To represent himself, for a judge, use his user number To represent itself, the comprehensive reputation value sequence of all users is , the user's historical score matrix is ,user In the The score of the round is ,lie in The matrix Line List; 2.

1. Identity division: users are divided into two identities: calculators and judges, who play different roles in federated learning; 2.

2. Local model training; The computer uses its local data set to train the local model to obtain the local gradient, encrypts the local gradient and uploads it to the server; 2.

3. Model evaluation; The judges perform homomorphic evaluation on the encrypted gradients submitted by the calculator and upload the homomorphic evaluation results; 2.

4. Malicious judge detection: The scores of each judge are obtained based on the homomorphic evaluation results uploaded by the judges, and malicious judges are screened out based on this, and the rest of the judges are considered benign; 2.

5. Comprehensive scoring: The scores of each calculator are obtained by combining the homomorphic evaluation results of all benign judges; 2.

6. Global gradient aggregation; The encrypted gradients uploaded by each calculator are weighted averaged according to their scores, and then decrypted to obtain the global gradient; 2.

7. Information update: Calculate the comprehensive reputation value of each user and update the historical score matrix and comprehensive reputation value sequence of all users.

4. The robust privacy federated learning method based on homomorphic evaluation according to claim 3 is characterized by: Step 2.1 Identity division, the specific steps are as follows: The server selects users according to the judge selection algorithm based on comprehensive reputation value. Divide into A calculator and Judges , the set of calculators is denoted as , the judges collectively record ; The Beta distribution is a continuous probability distribution defined on the interval [0,1], and its probability density function is as follows: ; in is a parameter and , assuming that you need to Thompson sampling is used to sample out , for any user , let the number of normal and abnormal behaviors be and , construct the corresponding Beta distribution probability density function , then based on Generate a random number , sort and take The largest number is obtained and the corresponding participant is selected. The Thompson sampling process is expressed as follows: ; in , Gather for the chosen ones; Then build a judge selection algorithm; In the judge selection algorithm, the number of normal and abnormal behaviors in Thompson sampling is and Extended to the field of positive real numbers, and respectively called well-behaved exponents and malignancy index , the calculation formula is: ; in Is a user In the Round score; When the judge selection algorithm is executed, the benignity index of all users is first calculated. Malignancy Index , statistics show , and then apply Thompson sampling to select the judges set : ; in is the total number of users, is the number of judges, then the set of calculators .

5. The robust privacy federated learning method based on homomorphic evaluation according to claim 4, characterized in that: Step 2.2 Local model training, the specific steps are as follows: Calculator Download the global model of the previous round , and use it as input for local training, and then use its local dataset Take the layered training method to learn and get the local gradient , then the calculator Use part of its private key to parse the local gradient After Paillier homomorphic encryption, the encrypted gradient is obtained , upload it to the server.

6. The robust privacy federated learning method based on homomorphic evaluation according to claim 5, characterized in that: Step 2.3 Model evaluation, the specific steps are as follows: Now assume that a certain original model The number of parameter update layers required in , original model The network parameters are expressed as: ; in , respectively represent the layers that need parameter update The weight matrix and bias vector corresponding to the layer, Indicates the layer whose parameters need to be updated. The weight matrix corresponding to the layer, Indicates the layer whose parameters need to be updated The bias vector corresponding to the layer; Suppose there is a piece of data for homomorphic evaluation ,in Represents the input vector and data label respectively. If used To the original model The gradient of is evaluated homomorphically, and the parameter update strategy of layered training is adopted, with one layer of parameters updated each time; Assume that the layer of the global model update parameters in a certain round of learning is layer, and the encrypted gradient uploaded by the evaluated client is ,in They are the corresponding The weight and bias of the layer, then the homomorphic evaluation network corresponding to this user is represented as: ; go through Before Layer forward propagation obtains , through the After layer The output vector of the encrypted layer, this process can be expressed as: ; After decryption, we get: ; Continue forward propagation through the remaining Layer Acquisition Output , compared with the labels of the original data That is, the homomorphic evaluation of the parameters submitted by this user on this data is completed; Homomorphic evaluation is implemented based on an evaluation data set. The definition of homomorphic evaluation on the data set and the calculation formula for measuring the evaluation results will be given; For an evaluation dataset ,in For the first Items of data, For the The labels of the data are based on the evaluation dataset. The given set of homomorphic evaluations is represented as a set of pairs of numbers: ; in , is the data label, since is a vector, can be converted into a one-hot vector, and and The cross entropy function between the converted one-hot vectors reflects the degree of deviation, so the average cross entropy function value of each pair in the homomorphic evaluation set is defined as the evaluation result: ; in is the dimension of each data in the dataset, That is The average cross entropy function of each pair in is: The larger the The worse the evaluation is, the and the original model Gradient The process of performing homomorphic evaluation is expressed as: ; The model evaluation steps are as follows: First, each judge collects the updated parameters of all the calculators and establishes a corresponding homomorphic evaluation network. Encrypted gradient The homomorphic evaluation network established is , judges Using its local dataset The data in the network are passed through the homomorphic evaluation network one by one Get the encrypted layer output: ; Then the judges These encrypted layer outputs are uploaded to the server, which aggregates the total The output of the group encryption layer is then organized for collaborative decryption. After decryption, forward propagation continues through the homomorphic evaluation network after the encryption layer to obtain a set of output vector pairs: ; in Refers to the dataset The The label vector of the data. Local Datasets The Homomorphic Evaluation Network The output vector after The server then calculates the homomorphic evaluation results based on these vector pairs and stores them in the matrix used to store homomorphic evaluation results In the calculation formula of the homomorphic evaluation result, 。 7. The robust privacy federated learning method based on homomorphic evaluation according to claim 6, characterized in that: Step 2.

4. Malicious judge detection. The specific steps are as follows: In one round of learning, each judge will The vector of homomorphic evaluation results given by the judges can be regarded as a Weidian, such as judges The homomorphic evaluation result vector , each dimension of the vector represents the homomorphic evaluation result given by this judge to a certain computer; For point , the distance between the homomorphic evaluation result vectors is defined as: ; Judges of Neighbor Set Pointing to The distance between the homomorphic evaluation results vectors is the smallest For a set of points, , define its sharing The neighbor set is: ; Then define The SNN similarity between the homomorphic evaluation result vectors is: ; Judges SNN similarity Neighbor Set Pointing to The SNN with the highest similarity of the homomorphic evaluation result vector points, then The density at can be defined as: ; When executing the malicious judge detection algorithm, first input the homomorphic evaluation result set , extract the evaluation result sequence given by each judge, and then establish two point sets , respectively represent the initial point set and the current point set. After the initialization is completed Contains the evaluation result sequence given by all judges, Empty for judges , find out its Neighbor Set The element with the largest density value ,like The density ratio at If it is small, Move to Otherwise, it does not move. This operation is run once for each judge. Repeat the above steps until no point moves in a round. Then the termination condition is reached. At this time, all points move to their corresponding local highest density point, which is called the local center point. Finally, all judges who move to the same local center point will be classified into the same cluster, and the cluster with the largest number of elements will be taken as the benign judge set. ; After obtaining the benign judges set, in order to remove discrete points, set a threshold , for a judge , if its density is less than , then it is determined as discrete points and transform them from Finally, each judge needs to be scored according to the analysis results. For any judge, its score is the sum of the SNN similarities between the judges in the benign judge set and it: ; After normalization, we get the scores of all judges in this round: ; Therefore, the malicious judge detection steps are as follows: after collecting all the homomorphic evaluation results, call the malicious judge detection algorithm to identify the evaluation result vectors of these judges to eliminate possible malicious judges, and return the scores of each judge to measure the performance of each judge in this round of learning. The set of benign judges that pass the detection algorithm is recorded as ,and .

8. The robust privacy federated learning method based on homomorphic evaluation according to claim 7, characterized in that: Step 2.

5. Comprehensive scoring. The specific steps are as follows: The score of each calculator is obtained by combining the evaluations of each benign judge. The calculation method is as follows: ; in Representative judges For calculators The evaluation opinions, It is the judges' opinions on the calculator. The weighted comprehensive result of the opinions of the judges is the comprehensive reputation value of each good judge. , Is a calculator The score of this round is then normalized: ; Highest score The number of operators will be selected as benign operators, and their set is .

9. The robust privacy federated learning method based on homomorphic evaluation according to claim 8, characterized in that: Step 2.

6. Global gradient aggregation, the specific steps are as follows: Only collection The encrypted gradients submitted by the benign calculators in will be used for global aggregation, and after weighted aggregation, the encrypted global gradients of this round are obtained: ; in Is a calculator The comprehensive reputation value of Is a calculator The score for this round, is a constant used to measure the ratio of the importance of the calculator's performance in this round to its historical performance. The encrypted global gradient is the result of the weighted average of each encrypted gradient based on these two indicators; Then, the server organizes collaborative decryption to obtain the global gradient , and update it accordingly The parameters of the corresponding layer in the current round are obtained .

10. The robust privacy federated learning method based on homomorphic evaluation according to claim 3, characterized in that: Step 2.

7. Information update. The specific steps are as follows: Each calculator and judge receives a score for this round of learning. Next, the historical score matrix is ​​updated based on the scores of each user. and comprehensive reputation value sequence ,user Comprehensive reputation value is the sum of their model scores from each previous round, plus a time decay factor ; ; After the comprehensive reputation value is updated, users whose reputation value is too low during multiple rounds of learning will be identified as malicious attackers by the server and kicked out of the system.

Citation Information

Patent Citations

  • Federal learning method and application based on block chain and homomorphic encryption

    CN114491616A

  • A cross-platform credit evaluation method in a federated learning environment

    CN114862416B

  • Energy consumption enterprise credit evaluation method, system and equipment based on longitudinal federal learning

    CN116596561A

  • Privacy protectable information safety calculation realization method based on homomorphic encryption mechanism

    CN106161405A

  • Private data protection method and system based on homomorphic encryption and federated learning

    CN119513919A