Collaborative distributed learning defense method and system based on cloud side end
By layering the parameter difference of edge devices and clustering in the cloud edge-end collaborative distributed learning system, the computing device trust score and weight values are solved, and the existing defense methods have large detection granularity, single detection scale and large computing overhead are achieved, and more fine-grained malicious device detection and more efficient computing overhead are achieved.
Patent Information
- Application Number
- CN202510054925.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-14
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2045-01-14
AI Technical Summary
The existing cloud edge-end collaborative distributed learning defense methods have large detection granularity, single detection scale and excessive computational overhead cost, which cannot effectively identify fine-grained attacks and efficiently handle model updates of a large number of edge-end devices.
By layering the parameter difference of each edge device according to the hierarchical structure of the network model in the cloud server, clustering using paired cosine distances and Euclidean distances, generating a benign set, computing the trust score and weight values of each edge device, and aggregating and updating the global model parameters based on these weight values.
It realizes finer-grained malicious device detection, diversified detection scales, and dynamic and flexible weighting methods, which reduces the computing overhead of cloud servers and improves the efficiency and scalability of the system.
Smart Images

Figure CN119945761A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer system technology, and in particular to a cloud-edge-based collaborative distributed learning defense method and system. Background Art
[0002] In the cloud-edge collaborative distributed learning system, there are multiple edge devices and a cloud server. Each edge device has a local training dataset. In each communication, the cloud server distributes the global model in the cloud to the edge devices; then, each edge device uses its local training dataset to fine-tune the global model to train a model, called a local model, and submits the local model update to the cloud server; finally, the cloud server generates a new global model by aggregating the local model updates of the edge devices using an aggregation rule.
[0003] In a collaborative distributed learning system between cloud and edge, some edge devices may take malicious actions to affect the training of the global model by modifying their local data or parts of the model. This attack is called poisoning attacks. Poisoning attacks are generally divided into two categories: data poisoning attacks and model poisoning attacks. Data poisoning attacks aim to pollute the training data and thus destroy the global model. Malicious edge devices can cause damage to the global model by modifying, adding, or deleting samples in the local training data set. The other type is model poisoning attacks, which can be further divided into untargeted attacks and targeted attacks, also known as backdoor attacks, depending on the attack target. In untargeted attacks, malicious edge devices directly manipulate model updates, causing the accuracy of the global model to drop significantly. In contrast, targeted attacks are more covert. Malicious edge devices modify local data and manipulate model updates to cause the global model to perform abnormally on specific target test samples (i.e., predict the target label set by the attacker), while the accuracy of other non-target samples remains unchanged.
[0004] The cloud-edge-based collaborative distributed learning defense method aims to exclude malicious model updates from the central server by adopting appropriate defense methods when facing limited malicious edge devices. The current defense methods can be summarized into five categories: distance-based, parameter-based, sign-flip-based, inversion-based, and principal component analysis-based.
[0005] Distance-based defense methods identify malicious devices by detecting the distance difference between local model updates, where the distance includes l1 norm, l2 norm, cosine distance, etc. However, distance-based defense methods are vulnerable to customized attacks designed for distance, which makes the defense ineffective. On the other hand, different distance scales are suitable for different scenarios, but no one scale can adapt to all situations.
[0006] Parameter-based defense methods identify potential malicious devices by performing a more detailed analysis of the parameters updated by the local model. However, parameter-based defense methods, on the one hand, lead to higher computational costs, especially when there are a large number of devices, the computing process of the cloud server may become a bottleneck. On the other hand, identifying malicious devices only by analyzing the parameters updated by the local model may not fully reflect the behavior of the device, allowing the malicious device to evade detection.
[0007] The symbol-based defense method distinguishes between benign and malicious devices based on the symbols updated by the local model. However, the limitation of the symbol-based defense method is that attackers can often take advantage of its characteristics and actively flip the symbols to achieve the attack effect.
[0008] Inversion-based defense methods aim to invert potential triggers in each category and use adversarial training to eliminate backdoor tasks in the global model. However, the computational overhead of inverting triggers in inversion-based defense methods is extremely high, and the adversarial training cost is high. In addition, it has poor flexibility and attackers can adjust the position of triggers in real time to launch attacks.
[0009] The defense method based on principal component analysis reduces the dimension of high-dimensional model parameters through techniques such as eigenvalue decomposition or singular value decomposition, and then analyzes the reduced parameters to identify and exclude malicious devices. The limitation of the defense method based on principal component analysis is that it is easily interfered by the bait model. The attacker can make the bait model show greater anomalies on the principal component, so that the real malicious model can evade detection.
[0010] Existing defense methods detect malicious devices through a variety of methods based on distance, parameters, sign flipping, inversion, and principal component analysis. However, they mainly have the following problems: Problem 1: The detection granularity of the defense method is large and cannot effectively identify fine-grained attackers. Problem 2: The detection scale used by the defense method is single and cannot comprehensively identify the differences between model updates. Problem 3: The computational overhead is high, and cloud servers and edge devices cannot support methods with high computational overhead. Summary of the invention
[0011] The present invention provides a collaborative distributed learning defense method and system based on cloud-edge, which solves the technical problem that the existing defense methods have too large detection granularity, a single detection scale and too high computational overhead cost.
[0012] In order to solve the above technical problems, the present invention provides a cloud-edge-based collaborative distributed learning defense method, comprising the steps of:
[0013] S1. In each communication round, the cloud server broadcasts the parameters of the global model to n edge devices;
[0014] S2. Each edge device initializes the received parameters of the global model as its own parameters and updates its own parameters based on the local data set;
[0015] S3, each edge device sends the difference between its updated parameters and the parameters of the global model to the cloud server;
[0016] S4. The cloud server calculates the weight value of each edge device based on the received parameter differences of the n edge devices;
[0017] S5. Based on the weight value of each edge device and the parameter difference uploaded by each edge device, the parameters of the global model are updated in an aggregated manner.
[0018] Furthermore, the step S4 specifically includes the steps of:
[0019] S41, the cloud server divides the parameter difference uploaded by each edge device into L layers according to the hierarchical structure of the network model;
[0020] S42, respectively calculate the pairwise cosine distance and pairwise Euclidean distance of the parameter difference of each layer of n edge devices, and obtain n pairwise cosine distance and pairwise Euclidean distance of the parameter difference of each layer. 2 pairwise cosine distances and n 2 pairwise Euclidean distances;
[0021] S43, respectively for each layer parameter difference n 2 pairwise cosine distances and n 2 Cluster the pairwise Euclidean distances to obtain the corresponding cosine distance clusters and Euclidean distance clusters;
[0022] S44, taking the edge device sets corresponding to the cluster with the largest number of devices in the cosine distance clustering cluster and the Euclidean distance clustering cluster of each layer of parameter differences as candidate benign sets, and taking the intersection of the two candidate benign sets as the benign set of the parameter differences of this layer;
[0023] S45, calculating the trust score of each edge device based on the benign set of parameter differences at each layer;
[0024] S46. Calculate a weight value for each edge device based on the trust score of each edge device.
[0025] Furthermore, in step S45, the trust score of the edge device i It is a binary classification definition, which is 1 when the edge device i is in the benign set of layer l, otherwise it is 0. β is a positive factor greater than 1, i = 1, 2, …, n.
[0026] Furthermore, β is an integer.
[0027] Furthermore, in step S46, in the current round t, the weight value of edge device i is
[0028] Furthermore, in step S5, the parameter w of the global model t Updated to w t-1 Represents the parameters of the global model before updating.
[0029] Further, in step S42, the paired cosine distance between edge device i and edge device j in the tth round and the lth layer is and represents the parameter difference of layer l calculated by edge devices i and j in round t, <·,·> represents the inner product, ‖·‖ 2 Represents the L2 norm of the vector, j=1,2,…,n.
[0030] Furthermore, in step S42, the pairwise Euclidean distance between edge device i and edge device j in the tth round and the lth layer is
[0031] Furthermore, in step S43, the K-means clustering method is used to cluster the n values of the parameter differences of each layer. 2 pairwise cosine distances and n 2 The clustering is performed based on pairwise Euclidean distances.
[0032] The present invention also provides a cloud-edge-based collaborative distributed learning defense system, the key of which is that it includes a cloud server and n edge devices, and the cloud server and the n edge devices learn according to the cloud-edge-based collaborative distributed learning defense method.
[0033] The present invention provides a cloud-edge-based collaborative distributed learning defense method and system. In the learning process of the cloud server and n edge devices, after receiving the parameter difference of the n edge devices, the cloud server calculates the weight value of each edge device based on the parameter difference, and then updates the parameters of the global model based on the weight value and parameter difference of each edge device. The present invention layers the parameter difference uploaded by each edge device according to the hierarchical structure of the network model, and then clusters and generates a benign set, so as to detect malicious edge devices from the granularity of the layer space, and the detection granularity is finer; cosine and Euclidean distance are used as two measurement scales to detect malicious edge devices in each layer, and the detection scales are diverse; different weights are assigned to different layers and weight values are assigned to different edge devices, and the weighting method is more dynamic and flexible; the running time of the cloud server is only linearly related to the model parameters, and the calculation overhead cost is low. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 This is an architecture diagram of an existing cloud-edge-based collaborative distributed learning system provided by an embodiment of the present invention;
[0035] Figure 2 It is a flow chart of a cloud-edge-based collaborative distributed learning defense method and system provided by an embodiment of the present invention;
[0036] Figure 3 is a specific process example diagram of step S41 to step S44 provided in an embodiment of the present invention;
[0037] Figure 4 It is a specific process example diagram of steps S4 to S5 provided in an embodiment of the present invention. DETAILED DESCRIPTION
[0038] The following specifically illustrates the implementation mode of the present invention in conjunction with the accompanying drawings. The embodiments are provided for illustrative purposes only and cannot be understood as limiting the present invention. The accompanying drawings are provided for reference and illustration only and do not constitute a limitation on the scope of patent protection of the present invention, because many changes can be made to the present invention without departing from the spirit and scope of the present invention.
[0039] The existing collaborative distributed learning system architecture based on cloud-edge is as follows: Figure 1 As shown in the figure, the system includes a cloud server and n edge devices. A local model is deployed in each edge device, and a global model is deployed in the cloud server. The local model and the global model use the same model architecture. The learning process between the cloud server and the n edge devices is mainly divided into four steps:
[0040] ① In each communication round t, the cloud server transmits the parameters w of the global model through the network t-1 Broadcast to n edge devices.
[0041] ② Each edge device i (i = 1, 2, ..., n) first uses the received global model parameters w t-1 Parameters of its own local model To initialize, Then perform E rounds of iterative training. In each round of training, their local training data set will be divided into several batches according to the batch size N. The set of these batches is recorded as B. For each batch b∈B, perform stochastic gradient descent to update the parameters of the local model:
[0042]
[0043] Where t represents the current communication round, η is the learning rate used in training, is the average gradient of edge device i on batch b in the current iteration.
[0044] ③ When the edge device completes local training, the local model is updated through the network Sent to the server, denoted as
[0045] ④The cloud server obtains a new global model through specific aggregation algorithms such as average aggregation.
[0046]
[0047] exist Figure 1 Based on this, the present invention designs a collaborative distributed learning defense method based on cloud-edge, an example of which is as follows Figure 2 As shown, the steps include:
[0048] S1. In each communication round t, the cloud server sets the parameters w of the global model t-1 Broadcast to n edge devices;
[0049] S2, each edge device i (i = 1, 2, ..., n) receives the parameters w of the global model t-1 Initialize to own parameters And adjust its own parameters based on the local data set Make updates;
[0050] S3, each edge device i updates its own parameters and the parameter w of the global model t-1 The difference between Send to cloud server;
[0051] S4: The cloud server receives the parameter difference of n edge devices. to Calculate the weight value of each edge device;
[0052] S5. Based on the weight value of each edge device and the parameter difference uploaded by each edge device, the parameters of the global model are updated in an aggregated manner.
[0053] Compared with steps ① to ④, the cloud-edge-based collaborative distributed learning defense method designed by the present invention has improvements in steps S4 and S5.
[0054] Specifically, step S4 specifically includes the steps of:
[0055] S41, the cloud server uploads the parameter difference uploaded by each edge device according to the hierarchical structure of the network model It is divided into L (≥2) layers;
[0056] S42, respectively calculate the pairwise cosine distance and pairwise Euclidean distance of the parameter difference of each layer of n edge devices, and obtain n pairwise cosine distance and pairwise Euclidean distance of the parameter difference of each layer. 2 pairwise cosine distances and n 2 pairwise Euclidean distances;
[0057] S43, respectively for each layer parameter difference n 2 pairwise cosine distances and n 2 Cluster the pairwise Euclidean distances to obtain the corresponding cosine distance clusters and Euclidean distance clusters;
[0058] S44, taking the edge device sets corresponding to the cluster with the largest number of devices in the cosine distance clustering cluster and the Euclidean distance clustering cluster of each layer of parameter differences as candidate benign sets, and taking the intersection of the two candidate benign sets as the benign set of the parameter differences of this layer;
[0059] S45, calculating the trust score of each edge device based on the benign set of parameter differences at each layer;
[0060] S46. Calculate a weight value for each edge device based on the trust score of each edge device.
[0061] In step S41, for non-directional attacks, the attacker aims to significantly reduce the accuracy of the global model. The essence of non-directional attacks is to use carefully designed models to produce significant deviations in the aggregated model before and after the attack. Compared with benign models, these carefully designed models have larger angular deviations, which indicates that they are likely to threaten the collaborative distributed learning system of the cloud-edge. Therefore, in order to detect and mitigate these deviations, the parameter difference uploaded by the edge device is obtained. to Finally, the cloud server layers the model according to its structure.
[0062] For ease of understanding, this embodiment uses an example in which the number of edge devices is 3 and the number of layers of each edge device is 3 to illustrate the specific process of step S41 to step S44.
[0063] exist Figure 3 In the example, assume that edge device 3 is attacked (marked in red), specifically the third layer of its local model is attacked (marked in red), then the third layer parameter difference uploaded by it has a problem, but these cloud servers are not aware of it. After the collaborative distributed learning defense method based on cloud-edge, the third layer parameter difference should be completely eliminated.
[0064] In step S42, the parameter difference of each layer of edge device i ( to ), this embodiment uses paired cosine distance to identify malicious edge devices of non-directional attacks, and paired Euclidean distance to identify malicious edge devices of directional attacks.
[0065] The cloud server calculates the pairwise cosine distance between all local model updates at each layer using the following formula:
[0066]
[0067] in, and represents the parameter difference of layer l calculated by edge devices i and j in round t, j = 1, 2, …, n. <·,·> represents the inner product, ‖·‖ 2 Represents the L2 norm of the vector, also known as the Euclidean distance. represents the cosine distance between edge device i and edge device j at layer l in round t. This metric helps identify abnormal updates that may perform attacks by measuring the angular difference of parameter differences at each layer from different edge devices. Subsequently, the cloud server iteratively calculates the parameter difference of each layer of n edge devices using formula (3) to The pairwise cosine distance between exist Figure 3 In the example, the pairwise cosine distances of the three edge devices in the first layer are Paired cosine distances of three edge devices at the second layer Paired cosine distances of three edge devices at the third layer Each layer has 9 cosine distance values.
[0068] For backdoor model poisoning attacks, attackers usually adopt two types of attack strategies. The first type of attack strategy is to train a backdoor model with high attack impact, which is very different from the benign model. In this case, the attacker usually uses data with a high poison data rate (PDR) or consumes a large number of local training cycles. i represents the clean dataset of edge device i, represents the contaminated data set, then the merged poisoned data set D′ i The PDR is given by the following formula:
[0069]
[0070] Here, || represents the size of the data set.
[0071] Another class of attack strategies is to train weaker backdoor models through data with low PDR, but they can increase their contribution to the aggregate model by enlarging local model parameters.
[0072] For backdoor attacks, no matter what strategy is used, the Euclidean distance is significantly different from the Euclidean distance updated by the benign model. Therefore, in order to reduce the impact of backdoor attacks, this embodiment uses the following formula to calculate the pairwise Euclidean distance of the parameter difference of each layer of n edge devices:
[0073]
[0074] in, represents the Euclidean distance between edge device i and edge device j at the lth layer of the tth round. Pairwise Euclidean distance can capture richer features and subtle differences, thus enabling more detailed and meticulous detection of anomalies. Similar to the way of calculating pairwise cosine distance, the cloud server iteratively uses formula (5) to calculate the pairwise Euclidean distance between the parameter differences of n edge devices in each layer, denoted as exist Figure 3 In the example, the pairwise Euclidean distances of the three edge devices in the first layer are Pairwise Euclidean distances of three edge devices at the second layer Pairwise Euclidean distances of three edge devices at the third layer Each layer has 9 Euclidean distance values.
[0075] In step S43, after the server calculates the pairwise cosine distance and pairwise Euclidean distance of each layer, the server clusters the pairwise cosine distance and pairwise Euclidean distance of each layer through the K-means clustering algorithm to detect malicious layers. Since most edge devices in the cloud-edge collaborative distributed learning system are benign, the cluster with more devices in the clustering results is regarded as a set of benign devices, that is, a candidate benign set. In other words, each layer has two pairs of cosine distances C t(l) and pairwise Euclidean distance E t(l) The generated candidate benign set. Figure 3 In the example, the first layer consists of pairwise cosine distances C t(1) and pairwise Euclidean distance E t(1) The generated candidate benign sets are represented as [2,3] and [1,3], where 1, 2, and 3 refer to edge devices 1, 2, and 3, respectively. The second layer consists of pairwise cosine distances C t(2) and pairwise Euclidean distance E t(2) The generated candidate benign sets are denoted as [1,3] and [1,3] respectively. The third layer consists of pairwise cosine distance C t(3) and pairwise Euclidean distance E t(3) The generated candidate benign sets are denoted as [1,2,3] and [1,2] respectively.
[0076] In order to comprehensively evaluate the edge devices of each layer, the intersection of the two candidate benign sets of each layer is taken as the benign set of this layer. Figure 3 In the example, the benign set of the first layer is [3], the benign set of the second layer is [1,3], and the benign set of the third layer is [1,2]. After the above steps, it can be seen that the benign set [1,2] of the third layer does not include edge device 3, so the third layer parameter difference of edge device 3 is successfully eliminated.
[0077] Step S45 uses a layer-based depth and benign set dynamic scoring strategy to calculate the trust score of each edge device. Step S46 uses a dynamic aggregation method based on the trust score to calculate the weight value of each edge device. Figure 4 Based on Figure 3Flowchart corresponding to step S45 and step S46. Generally speaking, deeper layers in the model are more important than shallower layers, because in neural network models, such as DNN (Deep Neural Network), shallow layers usually learn low-level features, such as edges and textures, while deep layers combine these features to learn more complex high-level concepts, such as objects and their parts. Therefore, deeper layers are generally more important to the performance of the model than shallower layers. At the same time, although the output layer may be the most important layer, the filtering results of other layers cannot be ignored because attackers can successfully attack the model by attacking other layers. Therefore, this embodiment considers the parameters of all layers and dynamically scores them according to the depth of the layers. The deeper the layer, the higher the score when it is selected as benign. The scoring rules for edge device i are as follows:
[0078]
[0079] Among them, Score i represents the trust score of edge device i, is a binary classification definition. When edge device i is in the benign set of layer l, it is 1, otherwise it is 0. β is a positive factor greater than 1. When β is greater than 1, the deeper the layer, the more important it is. For ease of calculation, β is an integer. Finally, malicious edge devices are screened out by the trust score of each edge device.
[0080] exist Figure 4 In the example, the value of β is set to 2. For edge device 1 (child node 1, corresponding to 1 in the benign set), the trust score Using the same calculation formula, the trust score Score of edge device 2 (child node 2, corresponding to 2 in the benign set) is 2 =β 3 =8, the trust score of edge device 3 (child node 3, corresponding to 3 in the benign set) 3 =β 1 +β 2 =2+4=6.
[0081] In step S46, after obtaining the trust score of each edge device, this embodiment adopts a dynamic model aggregation strategy based on dynamic scores, and first calculates the weight value of each edge device. This embodiment uses the following formula to calculate the weight value of terminal device i
[0082]
[0083] Finally, in step S5, the traditional federated averaging algorithm averages all edge devices, which ignores the contribution of each edge device to the model. This project uses the trust score of each edge device as the weighted value, and the larger the score, the higher the weight, to reflect the importance of the edge device with greater contribution. The parameter update method of the global model is as follows:
[0084]
[0085] in, Update the local model parameters of edge device i in round t, w t is the parameter of the cloud server after round t aggregation.
[0086] Based on the above method, an embodiment of the present invention also provides a cloud-edge-based collaborative distributed learning defense system, which includes a cloud server and n edge devices. The cloud server and the n edge devices learn according to the above cloud-edge-based collaborative distributed learning defense method.
[0087] In summary, the embodiment of the present invention provides a collaborative distributed learning defense method and system based on cloud-edge devices. In the learning process between the cloud server and n edge devices, after receiving the parameter difference of the n edge devices, the cloud server calculates the weight value of each edge device based on the parameter difference, and then updates the parameters of the global model based on the weight value and parameter difference of each edge device. The present invention stratifies the parameter difference uploaded by each edge device according to the hierarchical structure of the network model, and then clusters and generates a benign set, so as to detect malicious edge devices from the granularity of the layer space, and the detection granularity is finer; cosine and Euclidean distance are used as two measurement scales to detect malicious edge devices in each layer, and the detection scales are diverse; different weights are assigned to different layers and weight values are assigned to different edge devices, and the weighting method is more dynamic and flexible; the running time of the cloud server is only linearly related to the model parameters, and the computational overhead cost is low.
[0088] The above embodiments are preferred implementation modes of the present invention, but the implementation modes of the present invention are not limited to the above embodiments. Any other changes, modifications, substitutions, combinations, and simplifications that do not deviate from the spirit and principles of the present invention should be equivalent replacement methods and are included in the protection scope of the present invention.
Claims
1. A collaborative distributed learning defense method based on cloud-edge, characterized in that: Includes steps: S1. In each communication round, the cloud server broadcasts the parameters of the global model to n edge devices; S2. Each edge device initializes the received parameters of the global model as its own parameters and updates its own parameters based on the local data set; S3, each edge device sends the difference between its updated parameters and the parameters of the global model to the cloud server; S4. The cloud server calculates the weight value of each edge device based on the received parameter differences of the n edge devices; S5. Based on the weight value of each edge device and the parameter difference uploaded by each edge device, the parameters of the global model are updated in an aggregated manner.
2. According to claim 1, a cloud-edge-based collaborative distributed learning defense method is characterized in that: The step S4 specifically comprises the following steps: S41, the cloud server divides the parameter difference uploaded by each edge device into L layers according to the hierarchical structure of the network model; S42, respectively calculate the pairwise cosine distance and pairwise Euclidean distance of the parameter difference of each layer of n edge devices, and obtain n pairwise cosine distance and pairwise Euclidean distance of the parameter difference of each layer. 2 pairwise cosine distances and n 2 pairwise Euclidean distances; S43, respectively for each layer parameter difference n 2 pairwise cosine distances and n 2 Cluster the pairwise Euclidean distances to obtain the corresponding cosine distance clusters and Euclidean distance clusters; S44, taking the edge device sets corresponding to the cluster with the largest number of devices in the cosine distance clustering cluster and the Euclidean distance clustering cluster of each layer of parameter differences as candidate benign sets, and taking the intersection of the two candidate benign sets as the benign set of the parameter differences of this layer; S45, calculating the trust score of each edge device based on the benign set of parameter differences at each layer; S46. Calculate a weight value of each edge device based on the trust score of each edge device.
3. The cloud-edge-based collaborative distributed learning defense method according to claim 2 is characterized in that: In step S45, the trust score of edge device i It is a binary classification definition, which is 1 when the edge device i is in the benign set of layer l, otherwise it is 0. β is a positive factor greater than 1, i = 1, 2, …, n.
4. The cloud-edge-based collaborative distributed learning defense method according to claim 3 is characterized in that: β is an integer.
5. The cloud-edge-based collaborative distributed learning defense method according to claim 4 is characterized in that: In step S46, in the current round t, the weight value of edge device i is 6. The cloud-edge-based collaborative distributed learning defense method and system according to claim 5, characterized in that: In step S5, the parameter w of the global model t Updated to w t-1 Represents the parameters of the global model before updating.
7. A cloud-edge-based collaborative distributed learning defense method according to any one of claims 1 to 6, characterized in that: In step S42, the pairwise cosine distance between edge device i and edge device j in the tth round and the lth layer is and It represents the parameter difference of the lth layer calculated by the edge devices i and j in the tth round, <·,·> represents the inner product, ‖·‖2 represents the L2 norm of the vector, and j=1,2,…,n.
8. The cloud-edge-based collaborative distributed learning defense method according to claim 7, characterized in that: In step S42, the pairwise Euclidean distance between edge device i and edge device j in the tth round and the lth layer is 9. The cloud-edge-based collaborative distributed learning defense method according to claim 8, characterized in that: In step S43, the K-means clustering method is used to cluster the n values of the parameter differences of each layer. 2 pairwise cosine distances and n 2 The clustering is performed based on pairwise Euclidean distances.
10. A cloud-edge-based collaborative distributed learning defense system, characterized by: It includes a cloud server and n edge devices, and the cloud server and the n edge devices learn according to the cloud-edge-based collaborative distributed learning defense method described in any one of claims 1 to 9.
Citation Information
Patent Citations
End-side cloud architecture-based distributed federated learning security defense method and application
CN114448601A
Distributed scrap steel detection method and system based on hierarchical fine-grained fusion federated learning
CN116524309A
Robustness federated learning method based on client defense
CN117035056A
Defense method for cluster federated learning attack, terminal and storage medium
CN117424754A
Ubiquitous computing power resource allocation method, device, equipment, medium and program
CN118708365A
Cited By
Security federal learning method based on multimode structure detection
CN120875087A