Privacy protection machine learning optimization method and system based on Kalman filter

By using Kalman filters to filter gradient and model parameter noise in machine learning optimization methods, combined with momentum update technology, the problems of slow training speed and poor convergence accuracy are solved, and a more efficient and stable model training process is achieved.

CN119940568APending Publication Date: 2025-05-06INFORMATION CENT OF YUNNAN POWER GRID CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411839446.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-13
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In machine learning optimization methods based on differential privacy, there are problems such as slow training speed and poor convergence accuracy, especially under the overshoot problem caused by momentum update technology.

Method used

The gradient information is filtered and scaled by Kalman filter, combined with the momentum update method, and the overshoot noise in the model parameters is filtered using the Kalman filter with system variance attenuated Kalman filter to achieve more accurate and stable gradient estimation and model parameter update.

Benefits of technology

It effectively alleviates the gradient fluctuations and overshoot problems during model training, improves the convergence speed and final accuracy of the model, and significantly improves the training efficiency and convergence accuracy of the model while ensuring the degree of privacy protection remains unchanged.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119940568A_ABST
    Figure CN119940568A_ABST
Patent Text Reader

Abstract

The invention discloses a privacy protection machine learning optimization method and system based on a Kalman filter, and relates to the technical field of data security. Comprising the following steps: randomly extracting L samples from a training set, and calculating gradient information corresponding to each sample; cutting the gradient of each sample, adding Gaussian noise and averaging; filtering and scaling the noise-added gradient information by using a Kalman filter; performing momentum accumulation and gradient descent based on the momentum coefficient; filtering overshoot noise in model parameters by using a Kalman filter of a system variance attenuation coefficient; and circularly executing the steps until the model converges. Gradient information is filtered through the Kalman filter, the gradient fluctuation problem in the model training process is relieved, the overshoot problem caused by momentum updating is solved by introducing a momentum updating method and combining the Kalman filter with system variance attenuation, and through the synergistic effect of the two Kalman filters, the model training efficiency is improved. And the model efficiency and precision are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data security technology, and in particular to a privacy protection machine learning optimization method and system based on a Kalman filter. Background Art

[0002] With the development of the Internet and the era of big data, machine learning, as a powerful data analysis tool, has been widely used in various fields, greatly promoting the development of various industries. However, traditional machine learning algorithms often need to access individual raw data, which is bound to bring the risk of privacy leakage. The leakage of private information may lead to problems such as exposure of personal information and identity theft. In addition, it may also lead to the leakage of commercial secrets, which will bring huge economic losses to enterprises and organizations. Therefore, it is crucial to ensure that user privacy information will not be leaked while using user information for modeling. In this context, differential privacy technology, as a powerful privacy protection method, has attracted the attention of researchers because of its rigorous mathematical proof. The stochastic gradient descent method based on differential privacy can effectively hide the sensitive information of individuals by adding Gaussian noise to the model gradient during the training process, thereby protecting the privacy of individuals. However, although differential privacy has many advantages in protecting privacy, there are problems such as slow training speed and poor convergence accuracy in the training process of the model. To address the problem of slow training rate, the momentum update technology can be introduced to speed up the training rate of the model, but this technology will bring overshoot problems and affect the convergence of the model. Kalman filters can filter Gaussian noise in linear dynamic systems, thereby achieving the optimal estimate of the system state. In data publishing scenarios based on differential privacy, Kalman filters are often used to filter the added differential privacy noise. This method can improve the utility of data while ensuring that the degree of privacy protection remains unchanged, achieving a better privacy-utility trade-off. However, there are few studies on Kalman filtering in the gradient descent process. Therefore, it is of great practical significance to conduct optimization research on privacy-preserving machine learning based on Kalman filters. Summary of the invention

[0003] In view of the problems existing in the prior art, the present invention is proposed.

[0004] Therefore, the problem to be solved by the present invention is how to better achieve the trade-off between privacy and utility in a machine learning optimization method based on differential privacy. By utilizing the property of the Kalman filter that can filter noise in a dynamic system containing noise, it is used to filter the Gaussian noise contained in the gradient, making the gradient more accurate and stable, thereby improving the final utility of the model. At the same time, in response to the overshoot problem caused by momentum update, the Kalman filter is further used to filter the overshoot noise in the model parameters, so that the model can converge stably in the later stage of convergence.

[0005] In order to solve the above technical problems, the present invention provides the following technical solutions:

[0006] In a first aspect, an embodiment of the present invention provides a privacy-preserving machine learning optimization method based on a Kalman filter, which includes randomly extracting L samples from a training set and calculating gradient information corresponding to each sample;

[0007] Clip the gradient of each sample, add Gaussian noise and average;

[0008] Use Kalman filter to filter and scale the noisy gradient information;

[0009] Momentum accumulation and gradient descent based on momentum coefficient;

[0010] A Kalman filter with a system variance attenuation coefficient is used to filter out overshoot noise in the model parameters;

[0011] The above steps are repeated until the model converges.

[0012] As a preferred solution of the privacy-preserving machine learning optimization method based on the Kalman filter of the present invention, wherein: L samples are randomly selected from the training set, and the gradient information corresponding to each sample is calculated as:

[0013]

[0014] Among them, the samples required for this step of gradient calculation are selected through random sampling technology to control the contribution of a single sample to the comprehensive gradient.

[0015] As a preferred solution of the privacy-preserving machine learning optimization method based on the Kalman filter of the present invention, the gradient clipping for each sample is expressed as:

[0016]

[0017] Among them, C is the clipping coefficient, which is used to limit the proportion of a single sample in the gradient, thereby controlling the sensitivity of the method;

[0018] The addition of Gaussian noise and averaging is expressed as:

[0019]

[0020] Among them, σ is the noise variance, which is used to ensure that the training process meets differential privacy protection.

[0021] As a preferred solution of the privacy protection machine learning optimization method based on Kalman filter described in the present invention, the filtering of the noisy gradient information using Kalman filter is expressed as:

[0022]

[0023] Among them, the use of Kalman filter can effectively filter out random sampling noise and differential privacy noise.

[0024] As a preferred solution of the privacy-preserving machine learning optimization method based on the Kalman filter of the present invention, the momentum accumulation based on the momentum coefficient is expressed as:

[0025]

[0026] Among them, α is the momentum coefficient;

[0027] Use the momentum coefficient to accumulate the momentum of the filtered gradient, and use the momentum update method to accelerate the training process;

[0028] The gradient descent is expressed as:

[0029] θ t+1 ←θ t +V t+1

[0030] Perform gradient descent based on the latest momentum information.

[0031] As a preferred solution of the privacy protection machine learning optimization method based on Kalman filter of the present invention, the overshoot noise in the Kalman filter filtering model parameters using the system variance attenuation coefficient is expressed as:

[0032]

[0033] Among them, η is the system attenuation coefficient, and the Kalman filter is used to filter the overshoot noise in the model parameters.

[0034] As a preferred solution of the privacy-preserving machine learning optimization method based on Kalman filter of the present invention, wherein: the looping of the above steps until the model converges includes:

[0035] The above steps are executed repeatedly. After each round, the effect of the current model is evaluated based on the test set to determine whether the training termination conditions are met.

[0036] In a second aspect, an embodiment of the present invention provides a privacy-preserving machine learning optimization system based on a Kalman filter, which includes a gradient calculation module, a filtering optimization module, an overshoot noise processing module, and a monitoring and evaluation module;

[0037] The gradient calculation module is used to randomly extract L samples from the training set, calculate the gradient information corresponding to each sample, clip the gradient of each sample and add Gaussian noise;

[0038] A filtering optimization module, for filtering and scaling the noisy gradient information using a first Kalman filter, and performing momentum accumulation and gradient descent based on a momentum coefficient;

[0039] An overshoot noise processing module is used to filter the overshoot noise in the model parameters using a second Kalman filter based on the system variance attenuation coefficient, and cyclically execute the above steps until the model converges;

[0040] The monitoring and evaluation module is used to monitor and evaluate the gradient accuracy, convergence speed and privacy protection level during model training in real time.

[0041] In a third aspect, an embodiment of the present invention provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: when the computer program instructions are executed by the processor, the steps of the privacy-preserving machine learning optimization method based on the Kalman filter as described in the first aspect of the present invention are implemented.

[0042] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program instructions are executed by a processor, the steps of the privacy-preserving machine learning optimization method based on the Kalman filter as described in the first aspect of the present invention are implemented.

[0043] The beneficial effects of the present invention are as follows: the privacy-preserving machine learning optimization method based on Kalman filter provided by the present invention filters gradient information by using Kalman filter, thereby effectively alleviating the gradient fluctuation problem in the model training process, improving the accuracy and stability of the gradient, and accelerating the convergence speed of the model under the premise of ensuring differential privacy protection; by introducing the momentum update method and combining the Kalman filter with system variance attenuation, the overshoot problem caused by the momentum update is effectively solved, and the stability of the model parameters is ensured while accelerating the model training, thereby improving the final convergence accuracy; through the synergistic effect of the two Kalman filters, while ensuring that the degree of privacy protection remains unchanged, the training efficiency and convergence accuracy of the model are significantly improved, and a better privacy-utility trade-off is achieved, providing a more efficient and stable optimization solution for machine learning applications based on differential privacy. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0045] Figure 1 Flowchart of the optimization method for privacy-preserving machine learning based on Kalman filter;

[0046] Figure 2 The first improvement point of the privacy-preserving machine learning optimization method based on the Kalman filter is the gradient change graph during the model training process;

[0047] Figure 3 This is a diagram of the gradient filtering sub-algorithm framework of the privacy-preserving machine learning optimization method based on the Kalman filter;

[0048] Figure 4 This is the framework diagram of the overshoot filter algorithm of the privacy-preserving machine learning optimization method based on the Kalman filter;

[0049] Figure 5 This is a complete algorithm framework diagram of the privacy-preserving machine learning optimization method based on the Kalman filter. DETAILED DESCRIPTION

[0050] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the accompanying drawings.

[0051] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0052] Secondly, the term "one embodiment" or "embodiment" as used herein refers to a specific feature, structure, or characteristic that may be included in at least one implementation of the present invention. The term "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor does it refer to a separate or selective embodiment that is mutually exclusive with other embodiments.

[0053] Example 1

[0054] Reference Figure 1 to Figure 5 , which is the first embodiment of the present invention, and provides a privacy-preserving machine learning optimization method based on a Kalman filter, comprising:

[0055] S1, randomly select L samples from the training set and calculate the gradient information corresponding to each sample;

[0056] In the embodiment of the present application, L samples are randomly selected from the training set, and the gradient information corresponding to each sample is calculated as:

[0057]

[0058] Among them, the samples required for this step of gradient calculation are selected through random sampling technology to control the contribution of a single sample to the comprehensive gradient.

[0059] S2, clips the gradient of each sample, adds Gaussian noise and averages it;

[0060] Furthermore, the gradient of each sample is clipped, and the calculated gradient is clipped in order to control the influence of a single sample on the overall gradient. The clipping coefficient C is set, and the following operations are performed:

[0061]

[0062] Among them, C is the clipping coefficient, which is used to limit the proportion of a single sample in the gradient, thereby controlling the sensitivity of the method.

[0063] In the embodiment of the present application, the adding of Gaussian noise and averaging is expressed as adding Gaussian noise to the clipped gradient and calculating the average value:

[0064]

[0065] Among them, σ is the noise variance, which is used to ensure that the training process meets differential privacy protection.

[0066] S3, using a Kalman filter to filter and scale the noisy gradient information;

[0067] In the embodiment of the present application, the use of a Kalman filter to filter the noisy gradient information is expressed as:

[0068]

[0069] Among them, the use of Kalman filter can effectively filter out random sampling noise and differential privacy noise.

[0070] It should be noted that the first Kalman filter is used to filter the gradient information after adding noise. This step effectively reduces the impact of random sampling noise and differential privacy noise, and improves the accuracy and stability of the gradient. Since the filtered gradient is more accurate, it can be appropriately expanded to increase the training rate.

[0071] S4, accumulate momentum based on the momentum coefficient and perform gradient descent;

[0072] In the embodiment of the present application, the momentum accumulation based on the momentum coefficient is expressed as:

[0073]

[0074] Among them, α is the momentum coefficient;

[0075] Use the momentum coefficient to accumulate the momentum of the filtered gradient, and use the momentum update method to accelerate the training process. Although this step speeds up the training rate, it also introduces the overshoot problem;

[0076] The gradient descent is expressed as:

[0077] θ t+1 ←θ t +V t+1

[0078] Perform gradient descent based on the latest momentum information.

[0079] S5, using the Kalman filter with system variance attenuation coefficient to filter the overshoot noise in the model parameters;

[0080] In the embodiment of the present application, the overshoot noise in the Kalman filter filtering model parameters using the system variance attenuation coefficient is expressed as:

[0081]

[0082] Among them, η is the system attenuation coefficient, and the Kalman filter is used to filter the overshoot noise in the model parameters.

[0083] It should be noted that in order to solve the overshoot problem caused by momentum update, the second Kalman filtering process uses a Kalman filter with exponential decay of system variance to filter the model parameters. This step can effectively filter out the overshoot noise in the model parameters, thereby alleviating the negative impact of the overshoot problem on the model training process.

[0084] S6, repeat the above steps until the model converges.

[0085] In an embodiment of the present application, the looping of the above steps until the model converges includes:

[0086] The above steps are executed repeatedly. After each round, the effect of the current model is evaluated based on the test set to determine whether the training termination conditions are met.

[0087] It should be noted that after each round of training, the test set is used to evaluate the performance of the current model until a preset termination condition is reached. The termination condition in this embodiment may be that the maximum number of iterations is reached, or the improvement in model performance is less than a preset threshold.

[0088] It should be noted that the first improvement of the present invention is to model the gradient change process in the machine learning optimization method based on differential privacy as a linear system containing noise. The process is as follows:

[0089] r(t+1)=A(t)r(t)+w(t)

[0090] Among them, r(t+1) represents the global gradient at the t+1th gradient descent, and w(t) is the noise that causes gradient fluctuations. The noise consists of two parts, namely w(t) = σ sgd +σ dp , where σ sgd is the noise caused by random sampling, and σ dp The noise added to the model gradient is to satisfy differential privacy. Based on this, the Kalman filter can filter noise in linear systems to filter the noise in the gradient, making the gradient more accurate and stable, thereby accelerating the convergence rate and accuracy of the model.

[0091] The second improvement of the present invention is to introduce a momentum update optimization method to accelerate the model training process, help it break through the local optimum, and model the model parameter change process during the momentum update process to address the overshoot problem caused by the momentum update method. The specific process is as follows:

[0092]

[0093] From the above formula, it can be obtained that the model parameter change process based on the momentum update optimization method is a linear process with exponential noise decay. In order to better fit this process, the system variance of the Kalman filter is also exponentially decayed. The Kalman filter with exponential decay of system variance can be used to filter the overshoot noise in the model parameters, thereby alleviating the impact of the overshoot problem on the model update process in the later stage of model convergence, thereby accelerating the convergence of the model and improving the convergence accuracy. Combining the above two methods, a privacy-preserving machine learning optimization method based on Kalman filtering is formed.

[0094] In summary, the present invention uses the Kalman filter to act on the system noise and overshoot noise respectively, thereby effectively alleviating the gradient fluctuation problem and momentum overshoot problem in the model optimization process. While greatly accelerating the model convergence rate, it improves the final accuracy of the model and better realizes the privacy-utility trade-off.

[0095] Furthermore, this embodiment also provides a privacy-preserving machine learning optimization system based on a Kalman filter, including a gradient calculation module, a filtering optimization module, an overshoot noise processing module, and a monitoring and evaluation module;

[0096] The gradient calculation module is used to randomly extract L samples from the training set, calculate the gradient information corresponding to each sample, clip the gradient of each sample and add Gaussian noise;

[0097] A filtering optimization module, for filtering and scaling the noisy gradient information using a first Kalman filter, and performing momentum accumulation and gradient descent based on a momentum coefficient;

[0098] An overshoot noise processing module is used to filter the overshoot noise in the model parameters using a second Kalman filter based on the system variance attenuation coefficient, and cyclically execute the above steps until the model converges;

[0099] The monitoring and evaluation module is used to monitor and evaluate the gradient accuracy, convergence speed and privacy protection level during model training in real time.

[0100] This embodiment also provides a computer device, which is suitable for the privacy-preserving machine learning optimization method based on the Kalman filter, and includes a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute computer-executable instructions to implement the privacy-preserving machine learning optimization method based on the Kalman filter proposed in the above embodiment.

[0101] The computer device may be a terminal, and the computer device includes a processor, a memory, a communication interface, a display screen and an input device connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be achieved through WIFI, an operator network, NFC (near field communication) or other technologies. The display screen of the computer device may be a liquid crystal display screen or an electronic ink display screen, and the input device of the computer device may be a touch layer covering the display screen, or a key, trackball or touchpad provided on the housing of the computer device, or an external keyboard, touchpad or mouse, etc.

[0102] This embodiment also provides a storage medium on which a computer program is stored. When the program is executed by a processor, the privacy-preserving machine learning optimization method based on the Kalman filter proposed in the above embodiment is implemented.

[0103] In summary, the privacy-preserving machine learning optimization method based on Kalman filter provided by the invention effectively alleviates the gradient fluctuation problem in the model training process by filtering gradient information through the Kalman filter, improves the accuracy and stability of the gradient, and accelerates the convergence speed of the model while ensuring differential privacy protection; by introducing the momentum update method and combining the Kalman filter with system variance attenuation, the overshoot problem caused by the momentum update is effectively solved, and the stability of the model parameters is ensured while accelerating the model training, thereby improving the final convergence accuracy; through the synergistic effect of the two Kalman filters, while ensuring that the degree of privacy protection remains unchanged, the training efficiency and convergence accuracy of the model are significantly improved, and a better privacy-utility trade-off is achieved, providing a more efficient and stable optimization solution for machine learning applications based on differential privacy.

[0104] Example 2

[0105] Reference Figure 1 to Figure 5 , which is the second embodiment of the present invention, and provides a privacy-preserving machine learning optimization method based on a Kalman filter, comprising:

[0106] Since the two improvements of the present invention are based on the Kalman filter, the update process of the Kalman filter is first described. The Kalman filter is applicable to the following dynamic linear system:

[0107] r(t+1)=A(t)r(t)+w(t)

[0108] Wherein, A(t) is the state transfer matrix, w(t) is the system variance, r(t+1) is the system state at the t+1th timestamp, in the first improvement of the present invention, the system state is the gradient, and in the second improvement, the system state is the model parameter. The measurement model observes the system through the following process:

[0109] x i (t) = H i (t)r(t)+v i (t)

[0110] Among them, v i (t) is the observation noise, which satisfies the normal distribution N(0,R t ), in the first improvement of the present invention, the noise is the fluctuation noise of the gradient, while in the second improvement, the noise is the overshoot noise in the model.

[0111] The specific update steps of the Kalman filter are as follows:

[0112] A1: Calculate the Kalman coefficient based on the prior variance and observation proportion.

[0113] K(t)=P(t)H T (R+HP(t)H T ) -1

[0114] Among them, P i (t) is the prior variance, H is the observation proportion;

[0115] A2: Optimal estimation of the system based on Kalman coefficient and prior estimation:

[0116]

[0117] Where K(t) is the Kalman coefficient, is a priori estimate;

[0118] A3: Update the posterior variance of the Kalman filter based on the prior variance and the observed noise variance:

[0119] M(t)=P(t)-P(t)H T (R+HP(t)H T ) -1 HP(t);

[0120] A4: Update the prior variance based on the posterior variance, state transfer matrix and system variance:

[0121] P(t+1)=AM(t)A T +Q(t);

[0122] A5: Update the system's prior estimate based on the state transfer matrix:

[0123]

[0124] A6: Perform system variance reduction:

[0125] Q(t+1)=ηQ(t);

[0126] A7: Loop through A1 to A6 until the system converges.

[0127] The above is the complete update process of the Kalman filter, wherein η in step A6 represents the system variance attenuation coefficient. In the first improvement point of the present invention, η=1, and in the second improvement point, since the system variance needs to decay exponentially, η∈(0,1).

[0128] like Figure 2The figure shows the gradient change diagram of the first improvement point of the present invention in the model training process, which contains three different gradients. DPSGD is the gradient change process using a machine learning optimization method based on differential privacy, BGD is the global gradient of each step, and KFGrad is the gradient filtered by a Kalman filter based on the DPSGD gradient. From the information in the figure, it can be seen that the change of the global gradient is very stable, which is similar to a linear transformation process, which proves the validity of the assumption of the present invention.

[0129] The DPSGD gradient satisfies the following equation due to the influence of Gaussian noise and random sampling noise:

[0130] g dpsgd =g BGD +σ sgd +σ dp

[0131] Among them, g BGD is the global gradient, representing the true value of the gradient, and σ sgd and σ dp They are Gaussian noise added to satisfy differential privacy and random noise caused by random sampling. According to the change trend of DPSGD in Figure 1, it can be concluded that the DPSGD gradient has obvious jitter, but because both noises are unbiased, the overall change trend is the same as BGD. It is this fluctuation that causes the machine learning optimization process based on differential privacy to generally have the problem of slow convergence speed and poor convergence accuracy.

[0132] The KFGrad gradient is filtered using a Kalman filter based on the gradient linear transformation assumption, so the gradient becomes smoother and more accurate, which also proves the accuracy and effectiveness of the assumptions of the present invention.

[0133]

[0134] like Figure 3 The figure shows the framework diagram of the first improvement point of the present invention. The method as a whole consists of three parts: DPSGD module, KFGrad module and update module. The specific process is as follows:

[0135] S101: Randomly extract L samples from the training set and calculate the gradient information corresponding to each sample:

[0136]

[0137] S102: Gradient g calculated for each sample t (x i ), gradient clipping is performed based on the clipping coefficient C:

[0138]

[0139] Add the corresponding Gaussian noise to the gradient of each sample and average them:

[0140]

[0141] S103: Momentum accumulation based on momentum coefficient:

[0142]

[0143] Among them, α is the momentum coefficient;

[0144] S104: Gradient descent based on the latest momentum:

[0145] θ t+1 ←θ t +V t+1 ;

[0146] S105: Using Kalman filter to filter overshoot noise in model parameters based on system variance attenuation coefficient

[0147]

[0148] Where η is the system attenuation coefficient, θ t+1 Filter model parameters for Kalman filter;

[0149] S106: The above steps are executed repeatedly until the model converges.

[0150] The key steps of the second improvement point of the present invention are step S103 and step S105, wherein step 103 introduces a momentum update method to accelerate the model optimization process based on differential privacy, but this method also causes an overshoot problem. In order to solve the impact of the overshoot problem, step S105 uses a Kalman filter with exponential decay of the system variance to filter the gradient information in the model parameters, thereby alleviating the impact of the overshoot problem in the machine learning training process.

[0151] like Figure 3 As shown, the present invention combines the above two improvements to generate a privacy-preserving machine learning optimization method based on a Kalman filter. The specific process is as follows:

[0152] S201: Randomly extract L samples from the training set and calculate the gradient information corresponding to each sample:

[0153]

[0154] S202: For each sample, the gradient is calculated and clipped based on the clipping coefficient:

[0155]

[0156] Add the corresponding Gaussian noise to the gradient of each sample and average them:

[0157]

[0158] Where C is the crop factor, g t (x i ) is the gradient information;

[0159] S203: Accumulate momentum based on momentum coefficient:

[0160]

[0161] Among them, α is the momentum coefficient;

[0162] S204: Gradient descent based on the latest momentum:

[0163] θ t+1 ←θ t +V t+1 ;

[0164] S205: Using a Kalman filter to filter out overshoot noise in the model parameters based on the system variance attenuation coefficient:

[0165]

[0166] Where η is the system attenuation coefficient, θ t+1 Filter model parameters for Kalman filter;

[0167] S206: Execute the above steps repeatedly until the model converges

[0168] The key steps of the second improvement point of the present invention are step S203 and step S205, wherein step S203 introduces a momentum update method to accelerate the model optimization process based on differential privacy, but this method also causes an overshoot problem. In order to solve the impact of the overshoot problem, step S205 uses a Kalman filter with exponential decay of the system variance to filter the gradient information in the model parameters, thereby alleviating the impact of the overshoot problem in the machine learning training process.

[0169] like Figure 5 As shown, the present invention combines the above two improvements to generate a privacy-preserving machine learning optimization method based on the Kalman filter.

[0170] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A privacy-preserving machine learning optimization method based on Kalman filter, characterized in that: include, Randomly extract L samples from the training set and calculate the gradient information corresponding to each sample; Clip the gradient of each sample, add Gaussian noise and average; Use Kalman filter to filter and scale the noisy gradient information; Momentum accumulation and gradient descent based on momentum coefficient; A Kalman filter with a system variance attenuation coefficient is used to filter out overshoot noise in the model parameters; The above steps are repeated until the model converges.

2. The privacy-preserving machine learning optimization method based on Kalman filter according to claim 1, characterized in that: The method randomly extracts L samples from the training set and calculates the gradient information corresponding to each sample as follows: Among them, the samples required for this step of gradient calculation are selected through random sampling technology to control the contribution of a single sample to the comprehensive gradient.

3. The privacy-preserving machine learning optimization method based on Kalman filter according to claim 2, characterized in that: The clipping of the gradient for each sample is expressed as: Among them, C is the clipping coefficient, which is used to limit the proportion of a single sample in the gradient, thereby controlling the sensitivity of the method; The addition of Gaussian noise and averaging is expressed as: Among them, σ is the noise variance, which is used to ensure that the training process meets differential privacy protection.

4. The privacy-preserving machine learning optimization method based on Kalman filter according to claim 3, characterized in that: The use of the Kalman filter to filter the noisy gradient information is expressed as: Among them, the use of Kalman filter can effectively filter out random sampling noise and differential privacy noise.

5. The privacy-preserving machine learning optimization method based on Kalman filter according to claim 4, characterized in that: The momentum accumulation based on the momentum coefficient is expressed as: Among them, α is the momentum coefficient; Use the momentum coefficient to accumulate the momentum of the filtered gradient, and use the momentum update method to accelerate the training process; The gradient descent is expressed as: i t+1 ←θ t +V t+1 Perform gradient descent based on the latest momentum information.

6. The privacy-preserving machine learning optimization method based on Kalman filter according to claim 5, characterized in that: The Kalman filter filtering overshoot noise in the model parameters using the system variance attenuation coefficient is expressed as: Among them, η is the system attenuation coefficient, and the Kalman filter is used to filter the overshoot noise in the model parameters.

7. The privacy-preserving machine learning optimization method based on Kalman filter according to claim 6, characterized in that: The loop executes the above steps until the model converges, including: The above steps are executed repeatedly. After each round, the effect of the current model is evaluated based on the test set to determine whether the training termination conditions are met.

8. A privacy-preserving machine learning optimization system based on a Kalman filter, based on the privacy-preserving machine learning optimization method based on a Kalman filter according to any one of claims 1 to 7, characterized in that: It also includes a gradient calculation module, a filtering optimization module, an overshoot noise processing module, and a monitoring and evaluation module; The gradient calculation module is used to randomly extract L samples from the training set, calculate the gradient information corresponding to each sample, clip the gradient of each sample and add Gaussian noise; A filtering optimization module, for filtering and scaling the noisy gradient information using a first Kalman filter, and performing momentum accumulation and gradient descent based on a momentum coefficient; An overshoot noise processing module is used to filter the overshoot noise in the model parameters using a second Kalman filter based on the system variance attenuation coefficient, and cyclically execute the above steps until the model converges; The monitoring and evaluation module is used to monitor and evaluate the gradient accuracy, convergence speed and privacy protection level during model training in real time.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the privacy-preserving machine learning optimization method based on the Kalman filter are implemented in any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the privacy-preserving machine learning optimization method based on a Kalman filter according to any one of claims 1 to 7 are implemented.