A Robust Privacy-Preserving Federated Learning Method Based on Homomorphic Evaluation

By using technical means such as homomorphic evaluation and malicious judges detection in federated learning, the problem of malicious attacks and encryption gradient quality assessment in federated learning is solved, achieving higher robustness and privacy security.

CN119940481BActive Publication Date: 2025-06-20NANJING UNIV OF POSTS & TELECOMM
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510414991.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-06-20
Estimated Expiration
2045-04-03

AI Technical Summary

Technical Problem

Existing federated learning technologies are difficult to ensure the robustness and privacy of the system when facing malicious attacks, especially the problem of difficult evaluating the quality of encryption gradients during the aggregation process.

Method used

A robust privacy federated learning method based on homomorphic evaluation is adopted to protect data privacy through threshold Paillier homomorphic encryption, and a quality evaluation method for encryption gradient "homomorphic evaluation" is designed, and a malicious judge detection algorithm is introduced to screen potential malicious judges.

Benefits of technology

It effectively solves the problem that the quality of encryption gradients is difficult to evaluate during the aggregation process, ensures the robustness of the system when facing malicious attacks, and improves the quality of the global model and the privacy and security of user data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119940481B_ABST
    Figure CN119940481B_ABST
Patent Text Reader

Abstract

The present invention provides a robust privacy-preserving federated learning method based on homomorphic evaluation. Considering the deficiencies of existing solutions, four metrics, namely privacy, usability, robustness, and efficiency, are designed to comprehensively measure federated learning solutions. Privacy measures the defense ability of the solution against privacy threats; usability evaluates the performance of the model in the absence of security threats; robustness reflects the resistance ability of the solution to security threats; and efficiency focuses on the performance of the model in terms of time efficiency and computational overhead. The solution of the present invention shows significant advantages in the four metrics of privacy, usability, robustness, and efficiency, and can effectively solve the problem of difficult evaluation of the quality of encrypted gradients during the aggregation process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of network security applications, and particularly relates to a robust privacy-preserving federated learning method based on homomorphic evaluation. Background Art

[0002] With the rapid development of Internet technology, machine learning and artificial intelligence are increasingly widely used in fields such as finance, healthcare, education, transportation, and basic sciences. However, conducting machine learning research requires collecting and processing a large amount of data, which usually contains sensitive privacy information and may involve multiple institutions or countries. Due to the risk of data leakage during transmission and learning, and with the increasing awareness of personal and institutional privacy protection, data owners are often reluctant to contribute their private data, resulting in the increasingly serious phenomenon of "data silos". In addition, countries have gradually introduced and improved laws and regulations related to user data privacy and security, which has further exacerbated this phenomenon. Faced with such a reality, federated learning is regarded as an effective solution. By collecting the models trained locally by each participant instead of the original data, federated learning overcomes the "data silos" phenomenon to a certain extent while protecting user data privacy.

[0003] However, many research works have shown that even federated learning has various threats. We will systematically analyze the threats in federated learning based on the CIA triad (integrity, availability, confidentiality) in the field of information security. Integrity ensures that the data is not tampered with during the training process and that the participants follow the protocol to execute the algorithm; availability ensures that the final model obtained through training has high performance and can give high-accuracy outputs for various inputs; confidentiality ensures the security of user data and model information and prevents sensitive information from being leaked to unauthorized users.

[0004] According to the different impacts on the core security elements in the CIA triad, the potential threats in federated learning can be divided into privacy threats and security threats: Privacy threats undermine the confidentiality in federated learning. Malicious servers or participants steal the gradient information of other participants during the learning process to infer or reconstruct the original data, resulting in privacy leakage; Security threats undermine integrity and availability. The main security threats in federated learning include poisoning attacks. Attackers interfere with the federated learning process by tampering with the training data or manipulating the local models to poison the global model, reducing the model performance or inserting backdoors.

[0005] To solve the above problems, the current existing technologies are as follows:

[0006] Technical comparison with CN114862416B "A cross-platform credit evaluation method in a federated learning environment"

[0007] 1. CN114862416B uses homomorphic encryption to encrypt the local model to protect data security during data transmission. It uses federated averaging to aggregate data received from all parties through the server. Its feature is that it can obtain the plaintext result after decrypting the ciphertext without directly accessing the plaintext. This solution of aggregating and decrypting the encrypted local model to obtain the global model can only ensure the privacy of the system but cannot guarantee the robustness of the system. It cannot resist poisoning attacks from malicious clients and can only work under the security assumption that all participants are semi-honest. This study proposes a federated learning scheme Fed-HA that takes into account both privacy and robustness. It uses threshold Paillier homomorphic encryption to protect the privacy and security of data and designs a quality evaluation method for encrypted gradients, "homomorphic evaluation", which effectively solves the problem of difficult evaluation of the quality of encrypted gradients during the aggregation process, guarantees the robustness of the system against malicious attackers, is applicable to a wider range of actual scenarios, and at the same time improves the incentives for participants who actively participate in learning, which helps to improve the quality of the global model.

[0008] 2. Traditional additive homomorphic encryption is used in CN114862416B, which has only a single public key and a single private key. Although it can ensure that data is not eavesdropped during transmission, if a malicious attacker disguises as a normal client to participate in federated learning, the system's private key will be leaked, and then this attacker can use the private key to steal the privacy information of the remaining normal clients. In contrast, the threshold homomorphic encryption scheme used in this study's solution has multiple different partial private keys. When decrypting, each decryptor uses its partial private key to generate the corresponding decryption share, and decryption can only be completed when the number of correct decryption shares exceeds the specified threshold, which can prevent a single attacker or several attackers from colluding to disguise as normal clients to steal privacy.

[0009] Technical comparison with the patent CN114491616A "Federated Learning Method and Application Based on Blockchain and Homomorphic Encryption"

[0010] 1. Patent CN114491616A combines blockchain, homomorphic encryption, and federated learning. It introduces the decentralized feature of blockchain into federated learning, reducing the potential risk of single-point failure. Additionally, through the accounting function of blockchain, a trust mechanism and a scoring mechanism are introduced. The ledger client measures the contribution of participating clients based on the prediction accuracy of the public evaluation dataset to encourage participants to upload high-quality parameters. This requires collecting a public, high-quality, and highly data-rich evaluation dataset, which may not be feasible in practice. In this study, the participants other than the server are divided into calculators and judges. The judges are responsible for using the "homomorphic evaluation" method to score the encrypted gradients uploaded by the calculators using their local evaluation datasets. Then, potential malicious judges are screened out through a malicious judge detection algorithm, and the scores of each calculator are comprehensively obtained based on the scores of the remaining benign judges. Finally, weighted aggregation is performed based on the scores. This study does not rely on a pre-collected public dataset but uses the local datasets of each judge to measure the quality of the calculators' gradients without revealing the privacy of any judge or calculator.

[0011] 2. The scoring mechanism in patent CN114491616A can eliminate low-quality clients and malicious attackers. However, in the initial stage, there is no means to detect potential malicious attackers. Once multiple attackers collude to attack federated learning and an attacker is selected as the ledger client, it will pose a great threat to the security of the system, thus affecting the quality of the global model. In this study, through the malicious judge detection algorithm, after the judges evaluate the calculators, the scores of each judge for each calculator are collected and analyzed to filter out abnormal scoring results, ensuring that the scores of the clients are not manipulated by attackers, maintaining system security, and improving robustness.

[0012] Technical comparison with patent CN116596561A "Energy-using enterprise credit evaluation method, system, and device based on vertical federated learning"

[0013] 1. Patent CN116596561A uses vertical federated learning to establish an energy - using enterprise credit evaluation model, analyzes the internal correlation between power grid and partner data, calculates scores through encryption and privacy - preserving computing, and uses the Softmax regression method and homomorphic encryption to predict future scores while protecting data privacy. It can expand data tags, enrich the data pool, and ensure privacy security. Vertical federated learning is applicable to scenarios where the samples between participants are the same or have the same user group, but each participant holds different features. In this case, through vertical federated learning, joint modeling can be carried out on the premise of ensuring data privacy. This research plan is based on the infrastructure of horizontal federated learning and introduces modules such as a scoring mechanism based on comprehensive credit values, a judge selection algorithm, a threshold homomorphic encryption method, a quality evaluation method for encrypted gradients "homomorphic evaluation", and a malicious judge detection algorithm, achieving the unity of privacy, availability, robustness, and efficiency in federated learning. Horizontal federated learning is applicable to scenarios where participants have the same sample set, but each participant holds different features. In this scenario, horizontal federated learning can perform joint training based on their respective data features without directly exchanging data.

[0014] 2. Patent CN116596561A aims to propose an energy - using enterprise credit evaluation method, construct an energy - using enterprise credit evaluation model, mainly focusing on energy enterprises such as power and power grids, belonging to the technical field of power market transactions. And this research involves the fields of computer technology and network security application technology. The Fed - HA scheme proposed in this research is a general privacy - preserving and robust federated learning scheme, which is applicable to any learning task compatible with the model architecture and homomorphic evaluation method in the scenario of horizontal federated learning, and has a wide range of application spaces in fields such as data analysis and computer vision. Summary of the Invention

[0015] To solve the above - mentioned technical problems, the present invention proposes a robust privacy - preserving federated learning method based on homomorphic evaluation. This scheme shows significant advantages in four indicators: privacy, availability, robustness, and efficiency, and can effectively solve the problem of difficult evaluation of the quality of encrypted gradients during the aggregation process.

[0016] To achieve the above - mentioned purpose, the technical solution adopted by the present invention is:

[0017] The present invention provides a robust privacy - preserving federated learning method based on homomorphic evaluation, and the specific steps are as follows:

[0018] S1 Initialization stage:

[0019] The server initializes the global model and initializes the comprehensive credit value for each user ​, the key generation center generates the public key and the private key and performs key distribution;

[0020] S2 Collaborative training stage;

[0021] The system iteratively executes the robust aggregation algorithm and updates the global model, the comprehensive reputation value, and the historical scores of users after each round of aggregation. Each participant performs its respective duties and collaborates to complete the corresponding global rounds until the global rounds reach the set maximum value E or the stop condition is reached, and finally a high-performance global model is output M .

[0022] As a further improvement of the present invention, in the initialization stage of step S1, the specific steps are as follows:

[0023] Assume there are user clients participating in federated learning, and its user set , a server O and a third-party key generation center participate in federated learning. In the initialization stage, the server initializes the global model , and for each user initializes the comprehensive reputation value , the key generation center generates the public key and the private key set and performs key distribution. The public key is made public. For any user , it obtains a partial private key .

[0024] As a further improvement of the present invention, in the collaborative training stage of step S2, the specific steps are as follows:

[0025] Denote the global model initialized by the server as , and the global model of the th round as . For each user participating in federated learning, use the sequence of numbers between to correspond to it one by one. Use the serial number to represent the user corresponding to this serial number. During the federated learning process, users will be divided into calculators or judges. For a certain calculator, use its user serial number to represent itself. For a certain judge, use its user serial number to represent itself. The sequence of comprehensive reputation values of all clients , the historical score matrix of the client , the score of user in the th round is , located at the th row of the Row Column;

[0026] 2.1. Identity division; users are divided into two identities, calculators and judges, who perform different duties in federated learning;

[0027] 2.2. Local model training; the calculator uses its local dataset to train the local model to obtain local gradients, encrypts the local gradients, and uploads them to the server;

[0028] 2.3. Model evaluation; the judge performs homomorphic evaluation on the encrypted gradients submitted by the calculator and uploads the homomorphic evaluation results;

[0029] 2.4. Malicious judge detection; obtain the scores of each judge based on the homomorphic evaluation results uploaded by the judge, and filter out malicious judges based on this. The remaining judges are regarded as benign;

[0030] 2.5. Comprehensive scoring; obtain the scores of each calculator by synthesizing the homomorphic evaluation results of all benign judges;

[0031] 2.6. Global gradient aggregation; perform weighted averaging on the encrypted gradients uploaded by each calculator according to their scores, and decrypt to obtain the global gradient;

[0032] 2.7. Information update; calculate the comprehensive reputation value of each user, and update the historical score matrix and comprehensive reputation value sequence of all users.

[0033] As a further improvement of the present invention, for step 2.1 identity division, the specific steps are as follows:

[0034] The server divides the user set into calculators and judges , the calculator set is denoted as , the judge set is denoted as ;

[0035] The beta distribution is a continuous probability distribution defined on the interval [0,1], and its probability density function is as follows:

[0036] ;

[0037] where are parameters and , assuming that it is necessary to sample from users using Thompson sampling, for any user , let the number of its normal and abnormal behaviors be and , construct the corresponding beta distribution probability density function , and then based on generate a random number , after sorting, take the largest numbers and select the corresponding participants. The Thompson sampling process is expressed as follows:

[0038] ;

[0039] where , is the set of selected persons;

[0040] Then construct the judge selection algorithm;

[0041] In the judge selection algorithm, the number of normal and abnormal behaviors in Thompson sampling is and extended to the positive real number domain and are respectively called the benign index and the malignant index , and the calculation formula is:

[0042] ;

[0043] where is the score of user in the round;

[0044] When the judge selection algorithm is executed, first count the benign index and the malignant index of all users, and the statistics obtain , then apply Thompson sampling to select the judge set :

[0045] ;

[0046] where is the total number of users, is the number of judges, then the set of calculators .

[0047] As a further improvement of the present invention, step 2.2 local model training, the specific steps are as follows:

[0048] The calculator downloads the global model of the previous round , and uses it as the input for local training, and then uses its local dataset to learn in a hierarchical training manner to obtain the local gradient , and then the calculator uses its partial private key for the local gradient After performing Paillier homomorphic encryption, the encrypted gradient is obtained. Upload it to the server.

[0049] As a further improvement of the present invention, in step 2.3 model evaluation, the specific steps are as follows:

[0050] Now assume a certain original model The number of parameter update layers required in the original model is represented as:

[0051] ;

[0052] Where , represents the weight matrix corresponding to the th layer in the layer that requires parameter update, represents the bias vector corresponding to the th layer in the layer that requires parameter update;

[0053] Suppose there is a piece of data for homomorphic evaluation , where represent the input vector and data label respectively. If is used to perform homomorphic evaluation on the gradient of the original model , a parameter update strategy of hierarchical training is adopted, and the number of layers for updating parameters each time is one layer;

[0054] Suppose that in a certain round of learning, the layer for updating the parameters of the global model is the th layer, and the encrypted gradient uploaded by the evaluated client is , where are the parts of the weight and bias corresponding to the th layer in the gradient respectively. Then the homomorphic evaluation network corresponding to this user is represented as:

[0055] ;

[0056] After forward propagation through the first layers, is obtained. After passing through the th layer, the output vector of the encryption layer is obtained. This process can be represented as:

[0057] ;

[0058] After decryption, it is obtained:

[0059] ;

[0060] Continue the forward propagation through the remaining layers to obtain the output , and compare it with the label of the original data That is, the homomorphic evaluation of the parameters submitted by this user on this piece of data is completed;

[0061] Homomorphic evaluations are all implemented based on an evaluation dataset. The definition of the homomorphic evaluation on the dataset will be given, as well as the calculation formula for measuring the evaluation results;

[0062] For an evaluation dataset , where is the th piece of data, is the label of the th piece of data, then the set of homomorphic evaluations given based on the evaluation dataset is represented as a set composed of several pairs:

[0063] ;

[0064] where , is the data label. Since is a vector, can be converted into a one-hot vector, and and the converted one-hot vector, the cross-entropy function reflects their deviation degree. Therefore, the average cross-entropy function value of each pair in the homomorphic evaluation set is defined as the evaluation result:

[0065] ;

[0066] where is the dimension of each piece of data in the dataset, is the average cross-entropy function of each pair in , the larger is, the worse the evaluation of is. The process of homomorphic evaluation of the gradient based on the evaluation dataset and the original model is expressed as:

[0067] ;

[0068] The model evaluation steps are as follows:

[0069] First, each judge collects the updated parameters of all calculators respectively and establishes the corresponding homomorphic evaluation network. According to the calculators​ Encrypted gradient The established homomorphic evaluation network is The judge uses the data in its local dataset and passes the data in it one by one through the homomorphic evaluation network to obtain the output of the encryption layer:

[0070] ;

[0071] Then the judge uploads these encryption layer outputs to the server, and the server aggregates these groups of encryption layer outputs, and then organizes collaborative decryption. After decryption, it continues to forward propagate through the part of the homomorphic evaluation network after the encryption layer to obtain the set of output vector pairs:

[0072] ;

[0073] where refers to the label vector of the th data in the dataset , and the output vector of the th data in the local dataset after passing through the homomorphic evaluation network ;

[0074] Then, the server calculates the homomorphic evaluation result based on these vector pairs and stores it in the matrix for storing the homomorphic evaluation result. The calculation formula for the homomorphic evaluation result is:

[0075] .

[0076] As a further improvement of the present invention, step 2.4. Malicious judge detection is specifically as follows:

[0077] In one round of learning, each judge performs homomorphic evaluation on computers. The vector composed of the homomorphic evaluation results given by this judge can be regarded as a -dimensional point. For example, the homomorphic evaluation result vector of judge , and each dimension of the vector represents the homomorphic evaluation result given by this judge to a certain computer;

[0078] For the point , define the distance between its homomorphic evaluation result vectors as:

[0079] ;

[0080] Judge 's Neighbor set Refers to the set composed of the points with the smallest distance between the homomorphic evaluation result vectors of For its shared neighbor set is defined as:

[0081] ;

[0082] Then the SNN similarity between the homomorphic evaluation result vectors of is defined as:

[0083] ;

[0084] The judge 's SNN similarity neighbor set refers to the set composed of the points with the highest SNN similarity to the homomorphic evaluation result vectors of Then the density at can be defined as:

[0085] ;

[0086] When executing the malicious judge detection algorithm, first input the homomorphic evaluation result set , extract the evaluation result sequences given by each judge from it, and then establish two point sets , representing the initial point set and the current point set respectively. After initialization is completed contains all the evaluation result sequences given by the judges, is empty. For the judge , find the element with the largest density value in its neighbor set . If the density value at is smaller than the density value at , then move to . Otherwise, do not move. Such an operation is performed for each judge once, and the above steps are repeated iteratively until no point moves in a certain round, then the termination condition is reached. At this time, all points move to their corresponding local density highest points, and this point is called the local center point. Finally, all judges who move to the same local center point will be grouped into the same cluster, and the cluster with the largest number of elements will be taken as the set of benign judges ;

[0087] After obtaining the set of benign judges, in order to remove the discrete points, set a threshold . For a certain judge , if its density is less than , then it is determined that is a discrete point and it is deleted from . Finally, it is necessary to score each judge according to the analysis results. For any judge, its score is the sum of the SNN similarities between the judges in the set of good judges and it:

[0088] ;

[0089] After normalization, the scores of all judges in this round are obtained:

[0090] ;

[0091] Therefore, the malicious judge detection step is as follows: After collecting all the homomorphic evaluation results, call the malicious judge detection algorithm to identify the evaluation result vectors of these judges to eliminate possible malicious judges, and return the scores of each judge to measure the performance of each judge in this round of learning. Denote the set of good judges passing the detection algorithm as , and .

[0092] As a further improvement of the present invention, step 2.5. Comprehensive scoring, the specific steps are as follows:

[0093] Obtain the scores of each calculator by comprehensively evaluating the good judges. The calculation method is as follows:

[0094] ;

[0095] Among them represents the evaluation opinion of judge on calculator , is the result of weighted synthesis of the opinions of each judge on calculator . The weight coefficient is the comprehensive credibility value of each good judge , is the score of calculator in this round, and then the score is normalized:

[0096] ;

[0097] The calculators with the highest scores will be selected as good calculators, and their set is .

[0098] As a further improvement of the present invention, step 2.6. Global gradient aggregation, the specific steps are as follows:

[0099] Only the set The encrypted gradients submitted by benign calculators in it will be used for global aggregation, and after weighted aggregation, the encrypted global gradients for this round will be obtained:

[0100] ;

[0101] Among them is the comprehensive reputation value of the calculator , is the score of the calculator in this round, is a constant used to measure the ratio of the importance of the calculator's performance in this round to its historical performance. The encrypted global gradient is the result of weighted averaging of each encrypted gradient based on these two metrics;

[0102] Then, the server organizes collaborative decryption to obtain the global gradient , and updates the parameters of the corresponding layer in to obtain the global model for this round

[0103] As a further improvement of the present invention, step 2.7. Information update is specifically as follows:

[0104] Each calculator and judge has obtained the score of this round of learning. Next, according to the scores of each user, the historical score matrix and the comprehensive reputation value sequence are updated. The comprehensive reputation value of user is the sum of the model scores of each previous round of theirs, plus the time decay factor ;

[0105] ;

[0106] After updating the comprehensive reputation value, users in a state of too low reputation value in multiple rounds of learning will be identified as malicious attackers by the server and kicked out of the system.

[0107] Compared with the prior art, the present invention has the following advantages and beneficial effects:

[0108] 1) A quality evaluation method for encrypted gradients, "Homomorphic Assessment" (HA), is proposed, effectively solving the problem of difficult quality evaluation of encrypted gradients during the aggregation process. During the federated learning process, according to the past performance of users, they are divided into judges and calculators, who are respectively responsible for locally training to generate gradients and scoring the gradient quality. This method can screen out malicious gradients submitted by attackers without compromising data privacy, ensuring the privacy and robustness of the system;

[0109] 2) Adaptively improve the training process between the server and users, and propose a parameter update strategy - "layered training" that is compatible with the homomorphic evaluation method. Since the homomorphic evaluation uses threshold Paillier homomorphic encryption, in order to adapt to the additive homomorphic property and mixed multiplicative homomorphic property of threshold Paillier homomorphic encryption, this strategy only updates one layer of the model in each training, and layer by layer trains and updates the learnable parameters in the model, so that this solution can be applied to most common network structures;

[0110] 3) Propose a malicious judge detection method based on Shared Nearest Neighbor (SNN) similarity clustering. This method can screen out possible malicious judges according to the evaluation opinions collected by the server, and comprehensively obtain the scores of the calculators based on the scoring opinions of the benign judges, so as to discard low-quality gradients. Finally, benign calculators are selected according to the scores, and their gradients will participate in the global aggregation, and the aggregation weight is positively correlated with the score;

[0111] 4) Propose a privacy-robust aggregation scheme Fed-HA (Federated Learning with Homomorphic Assessment) based on homomorphic evaluation, and implement a federated learning system based on this scheme. Fed-HA comprehensively applies the encrypted gradient quality evaluation method HA, the parameter update strategy of layered training, and the malicious judge detection method based on SNN similarity clustering, and has privacy, availability, robustness and efficiency, and does not require additional assumptions about the server or users, and can adapt to the vast majority of actual scenarios. Brief Description of the Drawings

[0112] Figure 1 It is a schematic flowchart of the robust privacy federated learning method based on homomorphic evaluation provided by Module 1 of the present invention;

[0113] Figure 2 It is a schematic diagram of the parameter update strategy of "layered training" in the present invention;

[0114] Figure 3 It is the first test experimental result of the malicious judge detection algorithm provided by Module 5 of the present invention on the MNIST dataset;

[0115] Figure 4 It is the second test experimental result of the malicious judge detection algorithm provided by Module 5 of the present invention on the MNIST dataset;

[0116] Figure 5 It is a comparison experimental graph when the Fed-HA scheme and other schemes face label flipping attacks respectively;

[0117] Figure 6It is a comparison experiment diagram when the Fed-HA scheme and other schemes face scaling attacks respectively;

[0118] Figure 7 It is a comparison experiment diagram when the Fed-HA scheme and other schemes face Gaussian attacks respectively. Specific implementation manner

[0119] The present invention will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners:

[0120] Embodiment 1: A robust privacy federated learning method based on homomorphic evaluation

[0121] Module 1;

[0122] This Module 1 provides an overall framework for a robust privacy federated learning method based on homomorphic evaluation, including:

[0123] Denote the initial global model as , and the global model of the th round as . For each user participating in federated learning, we use the numerical serial numbers between to correspond to them one by one according to their joining order. In the following text, we use the serial number to represent the user corresponding to this serial number. During the federated learning process, users will be divided into calculators or judges. For a certain calculator, we use its user serial number to represent itself. For a certain judge, we use its user serial number to represent itself. The comprehensive credit value sequence of all users is , the historical score matrix of users is , and the score of user in the th round is , which is located in the matrix at the th row and the th column

[0124] In the initialization stage, the server initializes the global model , and initializes the comprehensive credit value for each user . The key generation center generates the public key and private key and conducts key distribution; in the collaborative training stage, the system iteratively executes the robust aggregation algorithm and updates the global model, comprehensive credit value, and historical scores of users after each round of aggregation. Each user performs its respective duties and collaborates to complete the corresponding global rounds until the global rounds reach the set maximum value or the stop condition is reached, and finally a high-performance global model is output.

[0125] The comparison experiment graphs of the robust privacy-preserving federated learning method Fed-HA based on homomorphic evaluation and other schemes when facing label flipping attack, scaling attack, and Gaussian attack are as Figure 5 , Figure 6 , Figure 7 shown.

[0126] Module 2;

[0127] This module 2 provides a robust aggregation method that emphasizes privacy protection, as Figure 1 shown, including:

[0128] Partitioning stage: The server divides users into computers and judges according to the judge selection algorithm based on the comprehensive reputation value (see Module 4). The sets of computers and judges are denoted as and respectively.

[0129] Local model training stage: The computer downloads the global model of the previous round and uses it as the input for local training. Then, it uses its local dataset to learn in a hierarchical training manner to obtain the local gradient .

[0130] Local update and upload stage: The computer encrypts to obtain the encrypted gradient and uploads it to the server.

[0131] Model evaluation stage: Each judge collects the updated parameters of all computers and establishes a corresponding homomorphic evaluation network. Specifically, the homomorphic evaluation network established according to the encrypted gradient of the computer is . The judge uses the data in its local dataset to pass through one by one to obtain the encrypted layer output:

[0132] ;

[0133] Evaluation and decryption stage: The server aggregates these groups of encrypted layer outputs, then organizes collaborative decryption, and continues forward propagation through the part after the encrypted layer of the homomorphic evaluation network after decryption to obtain the set of output vector pairs:

[0134] ;

[0135] Among them refers to the label vector of the th data in the dataset, refers to the output vector after the th data in the dataset passes through the homomorphic evaluation network ; then, the server calculates the homomorphic evaluation result based on these vectors and stores it in the matrix for storing the homomorphic evaluation result. The calculation formula for the homomorphic evaluation result is:

[0136] ;

[0137] Malicious reviewer detection stage: After collecting all the evaluation data, it is necessary to identify the evaluations of these reviewers to eliminate possible malicious reviewers. The malicious reviewer detection algorithm will be introduced in Module 5. The set of benign reviewers obtained through the detection algorithm is , and , and at the same time, the malicious reviewer detection algorithm returns the scores of each reviewer.

[0138] Scoring stage: The scores of each calculator are obtained by synthesizing the evaluations of each benign reviewer. The calculation method is as follows:

[0139] ;

[0140] Among them represents the evaluation opinion of reviewer on calculator , is the result of weighted synthesis of the opinions of each reviewer on calculator , and the weight coefficient is the comprehensive credibility value of each benign reviewer, is the score of calculator in this round. Then we need to normalize the scores:

[0141] ;

[0142] The calculators with the highest scores will be selected as benign calculators, and their set is ;

[0143] Global gradient aggregation stage: Only the updated gradients submitted by the benign calculators in the set will be used for global aggregation. The encrypted global gradient in this round is:

[0144] ;

[0145] Among them is the calculator The comprehensive reputation value is a constant used to measure the ratio of the importance of the current performance and historical performance of the calculator. The encrypted global gradient is the result of weighted averaging of each encrypted gradient based on these two metrics.

[0146] Model decryption stage: The server organizes collaborative decryption to obtain the global gradient , and updates according to it the parameters of the corresponding layer in to obtain the global model of this round . Thus, the

[0147] round of federated learning ends. Reputation value update stage: At this time, each calculator and judge has obtained the scores of this round of learning. Next, update the user's historical score matrix and the sequence of the user's comprehensive reputation values . The comprehensive reputation value of user is the sum of the model scores of each previous round, plus the time decay factor

[0148] ;

[0149] After updating the comprehensive reputation value, users with too low reputation values in multiple rounds of learning will be identified as malicious attackers by the server and kicked out of the system.

[0150] Module 3;

[0151] This module 3 provides a homomorphic evaluation method, including:

[0152] Homomorphic evaluation is the core part of the robust aggregation module in this scheme, and its process is as follows: First, according to the encrypted gradient submitted by a certain user, update the parameters of the corresponding position of the global model in the previous round, and call the updated model the homomorphic evaluation network (HAnet). Since the gradient is encrypted, the parameters of the corresponding position of the homomorphic evaluation network are also in ciphertext state. Next, input a set of plaintext data for evaluation into the homomorphic evaluation network. Using the properties of homomorphic encryption, the plaintext data can output ciphertext results after passing through the homomorphic evaluation network. By comparing the decrypted output of the homomorphic evaluation network and the corresponding data labels, the verification result of this user on this data can be obtained.

[0153] To further clarify the specific process of homomorphic evaluation, the following will use a mathematical expression to analyze its mechanism. In a common neural network model, each layer can be divided into two categories: one category does not contain learnable parameters, such as pooling layers, DropOut layers, activation function layers, and batch normalization layers; the other category contains learnable parameters, including linear layers and convolutional layers, etc. Now assume a certain model The total number of layers that require parameter update is , The network parameters are represented as:

[0154] ;

[0155] Among them respectively represent the weight matrix and bias vector corresponding to the th layer in the layers that require parameter update;

[0156] Suppose there is a piece of data for homomorphic evaluation , among which respectively represent the input vector and data label. If is used to perform homomorphic evaluation on the gradient, and a parameter update strategy of hierarchical training is adopted. The schematic diagram of hierarchical training is as shown in Figure 2 , and the number of layers for which the parameters are updated each time is one layer;

[0157] Suppose that in a certain round of learning, the layer for which the global model updates the parameters is the th layer, and the encrypted gradient uploaded by the evaluated client is , among which are respectively the parts of the weight and bias corresponding to the th layer in the gradient. Then the homomorphic evaluation network corresponding to this user is represented as:

[0158] ;

[0159] After passing through the first layers through forward propagation, we get . After passing through the th layer, we get the output vector of the encryption layer. This process can be represented as:

[0160] ;

[0161] After decryption, we get:

[0162] ;

[0163] Continue forward propagation through the remaining layers to obtain the output . Comparing with the label of the original data, the homomorphic evaluation of the parameters submitted by this user on this piece of data is completed;

[0164] The above is the homomorphic evaluation of a single piece of data. Homomorphic evaluations are all implemented based on an evaluation dataset. The definition of the homomorphic evaluation on the dataset and the calculation formula for measuring the evaluation results will be given;

[0165] For an evaluation dataset , where is the th piece of data, is the label of the th piece of data, then the set of homomorphic evaluations given based on the evaluation dataset is represented as a set consisting of several pairs:

[0166] ;

[0167] where , is the data label. Since is a vector, can be converted into a one-hot vector, and the cross-entropy function between and the one-hot vector converted from reflects their deviation degree, so the average cross-entropy function value of each pair in the homomorphic evaluation set is defined as the evaluation result:

[0168] ;

[0169] where is the dimension of each piece of data in the dataset, is exactly the average cross-entropy function of each pair in The larger is, the worse the evaluation of is. The process of homomorphic evaluation of the gradient based on the evaluation dataset and the original model

[0170] is represented as:

[0171] Module 4;

[0172] This module 4 provides a jury selection algorithm, including:

[0173] Before introducing the jury selection algorithm, we first introduce the prerequisite knowledge: beta distribution and Thompson sampling. The beta distribution is a continuous probability distribution defined on the interval [0,1], and its probability density function is as follows:

[0174] ;

[0175] where ​is a parameter and , assuming that it is necessary to sample users using Thompson sampling to sample ones. For any user , let the number of normal and abnormal behaviors be and , construct the corresponding beta distribution probability density function , and then generate a random number based on . After sorting, take the largest numbers and select the corresponding participants. The above Thompson sampling process is expressed as follows:

[0176] ;

[0177] where , is the set of selected persons;

[0178] Then we construct a judge selection algorithm based on this;

[0179] In the judge selection algorithm, the number of normal and abnormal behaviors in Thompson sampling and are extended to the positive real number domain and are respectively called the benign index and the malignant index , and the calculation formula is:

[0180] ;

[0181] where is the score of user in the round;

[0182] When the judge selection algorithm is executed, first count the benign indexes and malignant indexes of all users, and the statistics obtained are . Then apply Thompson sampling to select the judge set :

[0183] ;

[0184] Then calculate the set of calculators .

[0185] Module 5;

[0186] This module 5 provides a malicious judge detection algorithm, including:

[0187] In one round of learning, each judge A homomorphic evaluation was performed by a number of evaluators. The vector composed of the homomorphic evaluation results given by this evaluator can be regarded as a -dimensional point. For example, the homomorphic evaluation result vector of evaluator . Each dimension of the vector represents the homomorphic evaluation result given by this evaluator to a certain calculator;

[0188] For point , define the distance between its homomorphic evaluation result vectors as:

[0189] ;

[0190] The -nearest neighbor set of evaluator refers to the set composed of the points with the smallest distance between the homomorphic evaluation result vectors of . For , define its shared -nearest neighbor set as:

[0191] ;

[0192] Then define the SNN similarity between the homomorphic evaluation result vectors of as:

[0193] ;

[0194] The -SNN similarity -nearest neighbor set of evaluator refers to the set composed of the points with the highest SNN similarity between the homomorphic evaluation result vectors of . Then the density at

[0195] can be defined as:

[0196] When executing the malicious evaluator detection algorithm, first input the homomorphic evaluation result set , extract the evaluation result sequences given by each evaluator from it, and then establish two point sets , which represent the initial point set and the current point set respectively. After initialization is completed, contains all the evaluation result sequences given by the evaluators, and is empty. For evaluator , find the element -nearest neighbor set with the largest density value . If the density value at is smaller than the density value at , then Move to this position, otherwise do not move. Such an operation is performed once for each judge, and the above steps are repeated iteratively until no points move in a certain round, then the termination condition is reached. At this time, all points move to the local density highest point corresponding to them, and this point is called the local center point. Finally, all judges who move to the same local center point will be grouped into the same cluster, and the cluster with the largest number of elements will be taken as the set of good judges ;

[0197] After obtaining the set of good judges, in order to remove discrete points, a threshold is set. For a certain judge , if its density is less than , then it is determined that is a discrete point and it is deleted from . Finally, each judge needs to be scored according to the analysis result. For any judge, its score is the sum of the SNN similarities between the judge in the set of good judges and it:

[0198] ;

[0199] After normalization, the scores of all judges in this round are obtained:

[0200] ;

[0201] The test experimental results of the malicious judge detection algorithm on the MNIST dataset are as Figure 3 , Figure 4 shown.

[0202] The above is only a preferred embodiment of the present invention, and it is not any other form of limitation to the present invention. Any modification or equivalent change made according to the technical essence of the present invention still belongs to the scope protected by the present invention.

Claims

1. A robust privacy federated learning method based on homomorphic evaluation, the specific steps are as follows, characterized in that: S1 initialization phase: Server initializes global model , and for each user Initialize comprehensive reputation value , the key generation center generates public and private keys and distributes them; Step S1: Initialization phase. The specific steps are as follows: Assume that there is User clients participate in federated learning, and their user set , a server O And a third-party key generation center participates in federated learning. In the initialization phase, the server initializes the global model , and for each user Initialize comprehensive reputation value , the key generation center generates the public key And the private key collection And distribute keys, public keys Public, to any user , which obtains part of the private key ; S2 collaborative training phase; The system iteratively executes the robust aggregation algorithm and updates the global model, comprehensive reputation value, and user's historical score after each round of aggregation. Each participant performs their respective duties and collaborates to complete the corresponding global round until the global round reaches the set maximum value. E Or reach the stopping condition, and finally output a high-performance global model M; Step S2 is the collaborative training phase, and the specific steps are as follows: Note that the server initializes the global model as , No. The global model of the wheel is , for each user participating in federated learning, use The digital serial number between them corresponds one to one, using the serial number Indicates the user corresponding to this serial number. During the federated learning process, users will be divided into calculators or judges. For a calculator, its user serial number is used. To represent himself, for a judge, use his user number To represent itself, the comprehensive reputation value sequence of all users is , the user's historical score matrix is ,user In the The score of the round is ,lie in The matrix Line List; 2.

1. Identity division: users are divided into two identities: calculators and judges, who play different roles in federated learning; 2.

2. Local model training; The computer uses its local data set to train the local model to obtain the local gradient, encrypts the local gradient and uploads it to the server; 2.

3. Model evaluation; The judges perform homomorphic evaluation on the encrypted gradients submitted by the calculator and upload the homomorphic evaluation results; 2.

4. Malicious judge detection: The scores of each judge are obtained based on the homomorphic evaluation results uploaded by the judges, and malicious judges are screened out based on this, and the rest of the judges are considered benign; 2.

5. Comprehensive scoring: The scores of each calculator are obtained by combining the homomorphic evaluation results of all benign judges; 2.

6. Global gradient aggregation; The encrypted gradients uploaded by each calculator are weighted averaged according to their scores, and then decrypted to obtain the global gradient; 2.

7. Information update: Calculate the comprehensive reputation value of each user and update the historical score matrix and comprehensive reputation value sequence of all users.

2. The robust privacy federated learning method based on homomorphic evaluation according to claim 1, characterized in that: Step 2.1 Identity division, the specific steps are as follows: The server selects users according to the judge selection algorithm based on comprehensive reputation value. Divide into A calculator and Judges , the set of calculators is denoted by , the judges gathered and recorded ; The Beta distribution is a continuous probability distribution defined on the interval [0,1], and its probability density function is as follows: ; in is a parameter and , assuming that you need to Thompson sampling is used to sample out , for any user , let the number of normal and abnormal behaviors be and , construct the corresponding Beta distribution probability density function , then based on Generate a random number , sort and take The largest number is obtained and the corresponding participant is selected. The Thompson sampling process is expressed as follows: ; in , Gather for the chosen ones; Then build a judge selection algorithm; In the judge selection algorithm, the number of normal and abnormal behaviors in Thompson sampling is and Extended to the field of positive real numbers, and respectively called well-behaved exponents and malignancy index , the calculation formula is: ; in Is a user In the Round score; When the judge selection algorithm is executed, the benignity index of all users is first calculated. Malignancy Index , statistics show , and then apply Thompson sampling to select the judges set : ; in is the total number of users, is the number of judges, then the set of calculators .

3. The robust privacy federated learning method based on homomorphic evaluation according to claim 2, characterized in that: Step 2.2 Local model training, the specific steps are as follows: Calculator Download the global model of the previous round , and use it as input for local training, and then use its local dataset Take the layered training method to learn and get the local gradient , then the calculator Use part of its private key to parse the local gradient After Paillier homomorphic encryption, the encrypted gradient is obtained , upload it to the server.

4. The robust privacy federated learning method based on homomorphic evaluation according to claim 3 is characterized by: Step 2.3 Model evaluation, the specific steps are as follows: Now assume that a certain original model The number of parameter update layers required in , original model The network parameters are expressed as: ; in , respectively represent the layers that need parameter update The weight matrix and bias vector corresponding to the layer, Indicates the layer whose parameters need to be updated The weight matrix corresponding to the layer, Indicates the layer whose parameters need to be updated. The bias vector corresponding to the layer; Suppose there is a piece of data for homomorphic evaluation ,in Represents the input vector and data label respectively. If used To the original model The gradient of is evaluated homomorphically, and the parameter update strategy of layered training is adopted, with one layer of parameters updated each time; Assume that the layer of the global model update parameters in a certain round of learning is layer, and the encrypted gradient uploaded by the evaluated client is ,in They are the corresponding The weight and bias of the layer, then the homomorphic evaluation network corresponding to this user is represented as: ; go through Before Layer forward propagation obtains , through the After layer The output vector of the encrypted layer, this process can be expressed as: ; After decryption, we get: ; Continue forward propagation through the remaining Layer Acquisition Output , compared with the labels of the original data That is, the homomorphic evaluation of the parameters submitted by this user on this data is completed; Homomorphic evaluation is implemented based on an evaluation data set. The definition of homomorphic evaluation on the data set and the calculation formula for measuring the evaluation results will be given; For an evaluation dataset ,in For the first Items of data, For the The labels of the data are based on the evaluation dataset. The given set of homomorphic evaluations is represented as a set of pairs of numbers: ; in , is the data label, since is a vector, can be converted into a one-hot vector, and and The cross entropy function between the converted one-hot vectors reflects the degree of deviation, so the average cross entropy function value of each pair in the homomorphic evaluation set is defined as the evaluation result: ; in is the dimension of each data in the dataset, That is The average cross entropy function of each pair in is: The larger the The worse the evaluation is, the and the original model Gradient The process of performing homomorphic evaluation is expressed as: ; The model evaluation steps are as follows: First, each judge collects the updated parameters of all the calculators and establishes a corresponding homomorphic evaluation network. Encrypted gradient The homomorphic evaluation network established is , judges Using its local dataset The data in the network are passed through the homomorphic evaluation network one by one Get the encrypted layer output: ; Then the judges These encrypted layer outputs are uploaded to the server, which aggregates the total The output of the group encryption layer is then organized for collaborative decryption. After decryption, forward propagation continues through the homomorphic evaluation network after the encryption layer to obtain a set of output vector pairs: ; in Refers to the dataset The The label vector of the data. Local Datasets The Homomorphic Evaluation Network The output vector after The server then calculates the homomorphic evaluation results based on these vector pairs and stores them in the matrix used to store homomorphic evaluation results In the calculation formula of the homomorphic evaluation result, 。 5. The robust privacy federated learning method based on homomorphic evaluation according to claim 4, characterized in that: Step 2.

4. Malicious judge detection. The specific steps are as follows: In one round of learning, each judge will The vector of homomorphic evaluation results given by the judges can be regarded as a Weidian, such as judges The homomorphic evaluation result vector , each dimension of the vector represents the homomorphic evaluation result given by this judge to a certain computer; For point , the distance between the homomorphic evaluation result vectors is defined as: ; Judges of Neighbor Set Pointing to The distance between the homomorphic evaluation results vectors is the smallest For a set of points, , define its sharing The neighbor set is: ; Then define The SNN similarity between the homomorphic evaluation result vectors is: ; Judges SNN similarity Neighbor Set Pointing to The SNN with the highest similarity of the homomorphic evaluation result vector points, then The density at can be defined as: ; When executing the malicious judge detection algorithm, first input the homomorphic evaluation result set , extract the evaluation result sequence given by each judge, and then establish two point sets , respectively represent the initial point set and the current point set. After the initialization is completed Contains the evaluation result sequence given by all judges, Empty for judges , find out its Neighbor Set The element with the largest density value ,like The density ratio at If it is small, Move to Otherwise, it does not move. This operation is run once for each judge. Repeat the above steps until no point moves in a round. Then the termination condition is reached. At this time, all points move to their corresponding local highest density point, which is called the local center point. Finally, all judges who move to the same local center point will be classified into the same cluster, and the cluster with the largest number of elements will be taken as the benign judge set. ; After obtaining the benign judges set, in order to remove discrete points, set a threshold , for a judge , if its density is less than , then it is determined as discrete points and transform them from Finally, each judge needs to be scored according to the analysis results. For any judge, its score is the sum of the SNN similarities between the judges in the benign judge set and it: ; After normalization, we get the scores of all judges in this round: ; Therefore, the malicious judge detection steps are as follows: after collecting all the homomorphic evaluation results, call the malicious judge detection algorithm to identify the evaluation result vectors of these judges to eliminate possible malicious judges, and return the scores of each judge to measure the performance of each judge in this round of learning. The set of benign judges that pass the detection algorithm is recorded as ,and .

6. The robust privacy federated learning method based on homomorphic evaluation according to claim 5, characterized in that: Step 2.

5. Comprehensive scoring. The specific steps are as follows: The score of each calculator is obtained by combining the evaluations of each benign judge. The calculation method is as follows: ; in Representative judges For calculators The evaluation opinions, It is the judges' opinions on the calculator. The weighted comprehensive result of the opinions of the judges is the comprehensive reputation value of each good judge. , Is a calculator The score of this round is then normalized: ; Highest score The number of operators will be selected as benign operators, and their set is .

7. The robust privacy federated learning method based on homomorphic evaluation according to claim 6, characterized in that: Step 2.

6. Global gradient aggregation, the specific steps are as follows: Only collection The encrypted gradients submitted by the benign calculators in will be used for global aggregation, and after weighted aggregation, the encrypted global gradients of this round are obtained: ; in Is a calculator The comprehensive reputation value of Is a calculator The score for this round, is a constant used to measure the ratio of the importance of the calculator's performance in this round to its historical performance. The encrypted global gradient is the result of the weighted average of each encrypted gradient based on these two indicators; Then, the server organizes collaborative decryption to obtain the global gradient , and update it accordingly The parameters of the corresponding layer in the current round are obtained .

8. The robust privacy federated learning method based on homomorphic evaluation according to claim 7, characterized in that: Step 2.

7. Information update. The specific steps are as follows: Each calculator and judge receives a score for this round of learning. Next, the historical score matrix is ​​updated based on the scores of each user. and comprehensive reputation value sequence ,user Comprehensive reputation value is the sum of their model scores from each previous round, plus a time decay factor ; ; After the comprehensive reputation value is updated, users whose reputation value is too low during multiple rounds of learning will be identified as malicious attackers by the server and kicked out of the system.

Citation Information

Patent Citations

  • Federal learning method and application based on block chain and homomorphic encryption

    CN114491616A

  • A cross-platform credit evaluation method in a federated learning environment

    CN114862416B

  • Energy consumption enterprise credit evaluation method, system and equipment based on longitudinal federal learning

    CN116596561A

  • Privacy protectable information safety calculation realization method based on homomorphic encryption mechanism

    CN106161405A

  • Private data protection method and system based on homomorphic encryption and federated learning

    CN119513919A