Data heterogeneous federation learning model reasoning method and related device
By proposing a data heterogeneous federated learning model inference method in data heterogeneous federated learning, the problem of low data utilization rate and difficulty in adapting to dynamic changes on the client model is solved, and the accuracy of inference is achieved and the demand for global model retraining is reduced.
Patent Information
- Application Number
- CN202411892485.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-20
- Publication Date
- 2025-05-13
AI Technical Summary
In data heterogeneous federated learning, the data utilization rate of the client model is low, making it difficult to effectively utilize heterogeneous data and adapt to dynamic changes, resulting in low accuracy and requires expensive training.
A data heterogeneous federated learning model inference method is proposed. Through feature extraction, encryption, transmission and decryption of query distance, a query data point set is constructed, nearest neighbor data points are selected and confidence calculation is performed to achieve the inference result.
On the premise of protecting the privacy of data characteristics, enhance the inference ability of the client model, reduce the need for global model retraining, and improve the inference accuracy.
Smart Images

Figure CN119990306A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of artificial intelligence technology, and in particular to a data heterogeneous federated learning model reasoning method and related devices. Background Art
[0002] This section is intended to provide a background or context to the embodiments of the disclosure that are recited in the claims. No description herein is admitted to be prior art by inclusion in this section.
[0003] Heterogeneous data federated learning is a distributed machine learning technology that allows multiple clients to collaboratively train models while protecting data privacy. In this learning model, the data owned by each client may differ significantly in quantity, type, distribution, or quality, that is, the data is heterogeneous; through heterogeneous data federated learning, a shared model can be trained using global data resources without sharing the original data, thereby improving the generalization ability and accuracy of the model.
[0004] However, in the related art, the client model has low data utilization, and it is difficult for the client model to effectively utilize heterogeneous data and adapt to dynamic changes, resulting in low accuracy and requiring expensive retraining. Summary of the invention
[0005] In view of this, the purpose of the present disclosure is to propose a data heterogeneous federated learning model reasoning method and related devices, which can at least solve one of the technical problems in the related technology to a certain extent.
[0006] Based on the above purpose, the first aspect of the exemplary embodiment of the present disclosure provides a data heterogeneous federated learning model reasoning method, which is applied to a first client, and the method includes:
[0007] Determine the data to be inferred, and perform feature extraction based on the data to be inferred to obtain a first feature graph;
[0008] Encrypting the first feature map to obtain a first encrypted feature map;
[0009] transmitting the first encrypted feature map to at least one second client so that the at least one second client generates a first encrypted query distance;
[0010] Receive at least one first encrypted query distance sent by the at least one second client, and construct a query data point set based on the at least one first encrypted query distance; decrypt the first encrypted query distance to obtain at least one decrypted query distance; select the query data point set based on the at least one decrypted query distance to obtain at least one neighbor data point;
[0011] A confidence calculation is performed on the at least one neighboring data point to obtain an inference result.
[0012] A data heterogeneous federated learning model reasoning method, applied to a second client, the method comprising:
[0013] Determine a second feature graph and differential privacy noise, receive a first encrypted feature graph transmitted by a first client, and perform homomorphic encryption distance calculation on the second feature graph and the differential privacy noise based on the first encrypted feature graph to obtain a first encrypted query distance;
[0014] The first encrypted query distance is transmitted to the first client, so that the first client decrypts the first encrypted query distance based on a private key and selects a neighboring data point.
[0015] Based on the same inventive concept, a second aspect of the exemplary embodiment of the present disclosure provides a data heterogeneous federated learning model reasoning device, which is applied to a first client, and the device includes:
[0016] A first feature map determining module is configured to determine the data to be inferred, perform feature extraction based on the data to be inferred, and obtain a first feature map;
[0017] A first encrypted feature map determining module is configured to encrypt the first feature map to obtain a first encrypted feature map;
[0018] A first encrypted feature map transmission module, configured to transmit the first encrypted feature map to at least one second client, so that the at least one second client generates a first encrypted query distance;
[0019] The neighbor data point determination module is configured to receive at least one first encrypted query distance sent by the at least one second client, construct a query data point set based on the at least one first encrypted query distance; decrypt the first encrypted query distance to obtain at least one decrypted query distance; select the query data point set based on the at least one decrypted query distance to obtain at least one neighbor data point;
[0020] The inference result determination module is configured to perform confidence calculation on the at least one neighboring data point to obtain an inference result.
[0021] A data heterogeneous federated learning model reasoning device, applied to a second client, comprising:
[0022] An encrypted query distance determination module is configured to determine a second feature graph and differential privacy noise, receive a first encrypted feature graph transmitted by a first client, and perform homomorphic encryption distance calculation on the second feature graph and the differential privacy noise based on the first encrypted feature graph to obtain a first encrypted query distance;
[0023] The encrypted query distance transmission module is configured to transmit the first encrypted query distance to the first client, so that the first client decrypts the first encrypted query distance based on a private key and selects a neighboring data point.
[0024] Based on the same inventive concept, a third aspect of the exemplary embodiment of the present disclosure provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the method described in the first aspect is implemented.
[0025] From the above, it can be seen that the data heterogeneous federated learning model reasoning method and related devices provided by the embodiments of the present disclosure are applied to a first client, and the method includes: determining the data to be inferred, performing feature extraction based on the data to be inferred, and obtaining a first feature map; encrypting the first feature map to obtain a first encrypted feature map; transmitting the first encrypted feature map to at least one second client, so that the at least one second client generates a first encrypted query distance; receiving at least one first encrypted query distance sent by the at least one second client, and constructing a query data point set based on the at least one first encrypted query distance; decrypting the first encrypted query distance to obtain at least one decrypted query distance; selecting the query data point set based on the at least one decrypted query distance to obtain at least one neighboring data point; performing confidence calculation on the at least one neighboring data point to obtain an inference result.
[0026] A data heterogeneous federated learning model reasoning method is applied to a second client, the method comprising: determining a second feature graph and differential privacy noise, receiving a first encrypted feature graph transmitted by a first client, performing homomorphic encryption distance calculation on the second feature graph and the differential privacy noise based on the first encrypted feature graph, and obtaining a first encrypted query distance; transmitting the first encrypted query distance to the first client, so that the first client decrypts the first encrypted query distance based on a private key and selects neighboring data points. The present disclosure can construct a privacy-preserving feature graph query mechanism, enhance the client model reasoning capability under the premise of protecting data feature privacy, and reduce the need for global model retraining. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] In order to more clearly illustrate the technical solutions in the present disclosure or related technologies, the drawings required for use in the embodiments or related technical descriptions are briefly introduced below. Obviously, the drawings described below are only embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0028] Figure 1 A schematic diagram of an application scenario of a data heterogeneous federated learning model reasoning method provided by an exemplary embodiment of the present disclosure;
[0029] Figure 2 A flowchart of a data heterogeneous federated learning model reasoning method provided by an exemplary embodiment of the present disclosure applied to a first client;
[0030] Figure 3 A flowchart of a data heterogeneous federated learning model reasoning method provided by an exemplary embodiment of the present disclosure applied to a second client;
[0031] Figure 4 An application scenario embodiment diagram of a data heterogeneous federated learning model reasoning method provided by an exemplary embodiment of the present disclosure;
[0032] Figure 5 A structural schematic diagram of a data heterogeneous federated learning model inference device provided by an exemplary embodiment of the present disclosure applied to a first client;
[0033] Figure 6 A structural schematic diagram of a data heterogeneous federated learning model inference device provided by an exemplary embodiment of the present disclosure applied to a second client;
[0034] Figure 7 A schematic diagram of the hardware structure of an electronic device for reasoning about a data heterogeneous federated learning model provided for an exemplary embodiment of the present disclosure. DETAILED DESCRIPTION
[0035] It is understandable that before using the technical solutions disclosed in the embodiments of this application, the type, scope of use, usage scenarios, etc. of the personal information involved in this application should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.
[0036] For example, in response to receiving an active request from a user, a prompt message is sent to the user to clearly prompt the user that the operation requested to be performed will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, application, server, or storage medium that performs the operation of the technical solution of the present application according to the prompt message.
[0037] As an optional but non-limiting implementation, in response to receiving an active request from the user, the prompt information may be sent to the user in the form of a pop-up window, in which the prompt information may be presented in text form. In addition, the pop-up window may also carry a selection control for the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0038] It is understandable that the above notification and the process of obtaining user authorization are merely illustrative and do not constitute a limitation on the implementation method of the present application. Other methods that meet relevant laws and regulations may also be applied to the implementation method of the present application.
[0039] It is understandable that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and relevant provisions.
[0040] In order to make the purpose, technical solutions and advantages of the present disclosure more clear, the principles and spirit of the present disclosure will be described with reference to several exemplary embodiments. It should be understood that these embodiments are provided only to enable those skilled in the art to better understand and implement the present disclosure, and are not intended to limit the scope of the present disclosure in any way. On the contrary, these embodiments are provided to make the present disclosure more thorough and complete, and to fully convey the scope of the present disclosure to those skilled in the art.
[0041] It should be understood herein that any number of elements in the drawings is for illustration rather than limitation, and any naming is only for distinction rather than having any limiting meaning.
[0042] It should be noted that, unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present disclosure should be understood by people with ordinary skills in the field to which the present disclosure belongs. The "first", "second" and similar words used in the embodiments of the present disclosure do not represent any order, quantity or importance, but are only used to distinguish different components. "Including" or "comprising" and similar words mean that the elements or objects appearing in front of the word cover the elements or objects listed after the word and their equivalents, without excluding other elements or objects. "Connecting" or "connected" and similar words are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly. The article "one" or "a" before an element does not exclude the existence of multiple such elements.
[0043] The principle and spirit of the present disclosure are explained in detail below with reference to several representative embodiments of the present disclosure.
[0044] As described in the background technology, in the related art, the client model has low data utilization rate, and it is difficult for the client model to effectively utilize heterogeneous data and adapt to dynamic changes, resulting in low accuracy and requiring expensive retraining. Specifically:
[0045] Federated learning is a distributed machine learning technology that allows multiple clients (such as mobile devices or distributed servers) to collaboratively train models while maintaining data privacy and security. This technology can address the need to fully utilize large amounts of data scattered across different clients for model training while protecting user privacy. In federated learning, model parameters are updated and aggregated between clients instead of directly transmitting data, thereby reducing the risk of data leakage and reducing dependence on centralized data centers. This approach is particularly suitable for scenarios with strict requirements on data privacy, such as healthcare, financial services, and other fields.
[0046] Data heterogeneous federated learning is an extension of federated learning. It targets situations where there are significant differences in data distribution among the various clients participating in learning, namely data heterogeneity. Since clients may have data samples of different characteristics, different scales, or even different orders of magnitude, traditional federated learning algorithms face challenges in model training and reasoning, as the model may favor clients with large amounts of data or rich features. Data heterogeneous federated learning aims to solve this problem of uneven data distribution through special algorithm design, such as weighted aggregation, personalized learning and other strategies, to improve the generalization ability and fairness of the model, ensure that the data of each client can contribute to the global model, and protect data privacy at the same time.
[0047] However, in related technologies, the data owned by each client have significant differences in characteristics, distribution and quality, and the amount of data may be unbalanced, which makes the model training of a single client limited to the characteristics of local data and difficult to learn the complete distribution and complexity of global data. In addition, the dynamic changes and updates of data further aggravate the model degradation problem.
[0048] Moreover, in a data-heterogeneous federated learning environment, the data distribution of the client may change over time, making the original model unable to accurately reflect the new data features, resulting in a decline in model performance. Since the data of each client is heterogeneous, the model cannot obtain a complete view of the global data during training, making it difficult to adapt to changes in local data. In addition, the communication and computing resources in federated learning are limited, and frequent retraining of the global model is not only costly but also inefficient.
[0049] In summary, in existing technical practices, client models often face the problem of insufficient data utilization, and it is difficult to fully integrate diverse data and flexibly respond to the continuous evolution of data. These limitations reduce the accuracy of the model and often require costly global model retraining to capture the characteristics of new client data.
[0050] In order to solve the above problems, the present disclosure provides a data heterogeneous federated learning model reasoning method and related device solutions, which specifically include:
[0051] A data heterogeneous federated learning model reasoning method, applied to a first client, includes: determining data to be inferred, performing feature extraction based on the data to be inferred, and obtaining a first feature map; encrypting the first feature map to obtain a first encrypted feature map; transmitting the first encrypted feature map to at least one second client, so that the at least one second client generates a first encrypted query distance; receiving at least one first encrypted query distance sent by the at least one second client, and constructing a query data point set based on the at least one first encrypted query distance; decrypting the first encrypted query distance to obtain at least one decrypted query distance; selecting the query data point set based on the at least one decrypted query distance to obtain at least one neighboring data point; and performing confidence calculation on the at least one neighboring data point to obtain an inference result.
[0052] A data heterogeneous federated learning model reasoning method, applied to a second client, includes: determining a second feature graph and differential privacy noise, receiving a first encrypted feature graph transmitted by a first client, performing homomorphic encryption distance calculation on the second feature graph and the differential privacy noise based on the first encrypted feature graph to obtain a first encrypted query distance; transmitting the first encrypted query distance to the first client, so that the first client decrypts the first encrypted query distance based on a private key and selects neighboring data points. The present disclosure designs a homomorphically encrypted feature graph query method based on global data features and ciphertext query schemes such as neighbor queries to correct model reasoning deviations; at the same time, the client can be used to update data, improve the client's reasoning ability, and reduce the need for retraining the global model. Under the protection of privacy technology, the client performs a ciphertext query and matches it with the feature graph pre-stored in the client, which not only enhances the client's reasoning accuracy, but also effectively guarantees the client's data privacy.
[0053] After introducing the basic principles of the present disclosure, various non-limiting embodiments of the present disclosure are described in detail below.
[0054] refer to Figure 1 , which is a schematic diagram of an application scenario of the data heterogeneous federated learning model reasoning method provided by the exemplary embodiment of the present disclosure.
[0055] This application scenario includes a first client 101 and a second client 102. The first client 101 and the second client 102 may be connected via a wired or wireless communication network to achieve data interaction.
[0056] The first client 101 and the second client 102 may be electronic devices with data transmission and multimedia input / output functions close to the user side, including but not limited to desktop computers, mobile phones, mobile computers, tablet computers, media players, smart wearable devices, personal digital assistants (PDAs) or other electronic devices capable of implementing the above functions. The electronic device may include a processor and a display screen with a touch input function, the display screen is used to present a graphical user interface, the graphical user interface can display an application interface, and the processor is used to process application data, generate a graphical user interface, and control the display of the graphical user interface on the display screen.
[0057] In some exemplary embodiments, the data heterogeneous federated learning model reasoning method can be run on the first client 101 or the second client 102.
[0058] When the data heterogeneous federated learning model reasoning method is run on the first client 101 and the second client 102 , the second client 102 is used to provide the data heterogeneous federated learning model reasoning service to the user of the first client 101 .
[0059] The first client 101 determines the data to be inferred, and the first client 101 performs feature extraction based on the data to be inferred to obtain a first feature graph;
[0060] The first client 101 encrypts the first feature map to obtain a first encrypted feature map;
[0061] The first client 101 transmits the first encrypted feature map to at least one second client 102, so that the at least one second client 102 generates a first encrypted query distance;
[0062] The first client 101 receives at least one first encrypted query distance sent by the at least one second client 102, and the first client 101 constructs a query data point set based on the at least one first encrypted query distance; the first client 101 decrypts the first encrypted query distance to obtain at least one decrypted query distance; the first client 101 selects the query data point set based on the at least one decrypted query distance to obtain at least one neighbor data point;
[0063] The first client 101 performs confidence calculation on the at least one neighboring data point to obtain an inference result;
[0064] The second client 102 determines a second feature graph and differential privacy noise, the second client 102 receives the first encrypted feature graph transmitted by the first client 101, and the second client 102 performs homomorphic encryption distance calculation on the second feature graph and the differential privacy noise based on the first encrypted feature graph to obtain a first encrypted query distance;
[0065] The second client 102 transmits the first encrypted query distance to the first client 101, so that the first client 101 decrypts the first encrypted query distance based on a private key and selects a neighboring data point.
[0066] It should be noted that the above application scenarios are only shown to facilitate understanding of the spirit and principle of the present disclosure, and the embodiments of the present disclosure are not limited in this respect. On the contrary, the embodiments of the present disclosure can be applied to any applicable scenario.
[0067] refer to Figure 2 , a data heterogeneous federated learning model reasoning method is applied to a first client, and the method comprises the following steps:
[0068] Step S210: determine the data to be inferred, perform feature extraction based on the data to be inferred, and obtain a first feature map.
[0069] During implementation, determine the data to be inferred:
[0070] As a specific example, refer to Figure 4 , the user can determine the data to be inferred through the inference client (first client) by voice input, text input or video input.
[0071] In the above exemplary embodiment, a method for determining the data to be inferred is introduced. Next, a method for obtaining the first feature map is introduced:
[0072] In a specific implementation, feature extraction is performed based on the data to be inferred to obtain a first feature map:
[0073] The first client uses the feature extraction layer of traditional machine learning models such as support vector machine (SVM), decision tree, random forest, etc. to extract features of the inference data to obtain a first feature map. The first client uses autoencoders to learn effective encoding of the data to be inferred, and the output of its encoding layer can be used as the first feature map, or the first client uses a model with an attention mechanism to extract the inference data to obtain the first feature map.
[0074] As a specific example, refer to Figure 3The embodiment diagram includes: one inference client (first client) and three non-inference clients (second clients), wherein when the user inputs the data to be inferred x in the inference client req When the inference client r has a data size of D r =|X r |, the inference client performs local queries and can utilize the feature extraction layers of the local model For local data X r Get the inference client feature map (first client feature map)
[0075] Step S220: encrypt the first feature map to obtain a first encrypted feature map.
[0076] In a specific implementation, the method of encrypting the first feature map to obtain the first encrypted feature map includes:
[0077] Following the above exemplary embodiments, refer to Figure 4 , the inference client generates a homomorphically encrypted public key pk and broadcasts the public key to each non-inference client, where the public key pk is used to encrypt the feature map of the inference client, thereby obtaining the first encrypted feature map
[0078] In the above exemplary embodiment, a method for obtaining the first encrypted feature map is introduced. Below, before encrypting the first feature map, the method further includes:
[0079] Determine a public key and a private key, wherein the public key is used to encrypt the first feature map; the private key is used to decrypt the first encrypted query distance; and transmit the public key to the at least one second client.
[0080] In a specific implementation, a public key and a private key are determined, and the public key is used to encrypt the first feature map:
[0081] Following the above exemplary embodiments, refer to Figure 4 , the inference client (first client) generates a pair of homomorphically encrypted public key pk and private key sk.
[0082] In a specific implementation, the public key is transmitted to the at least one second client in the following manner:
[0083] Following the above exemplary embodiments, refer to Figure 4 , the inference client (first client) broadcasts the public key to each non-inference client (second client).
[0084] Step S230: Transmit the first encrypted feature map to at least one second client, so that the at least one second client generates a first encrypted query distance.
[0085] In a specific implementation, the first encrypted feature map is transmitted to at least one second client in the following manner:
[0086] Following the above exemplary embodiments, refer to Figure 4 ,The inference client regards the encrypted feature map extracted by the model as a query point, generates a k-nearest neighbor query request for it, and broadcasts the request to each non-inference client. At the same time, the inference client also performs the query locally.
[0087] Step S240, receiving at least one first encrypted query distance sent by the at least one second client, and constructing a query data point set based on the at least one first encrypted query distance; decrypting the first encrypted query distance to obtain at least one decrypted query distance; selecting the query data point set based on the at least one decrypted query distance to obtain at least one neighboring data point.
[0088] In a specific implementation, at least one first encrypted query distance sent by the at least one second client is received, and a query data point set is constructed based on the at least one first encrypted query distance:
[0089] Following the above exemplary embodiments, refer to Figure 4 , the inference client receives the first encrypted query distance [[Dis]] sent by each non-inference client (second client), and constructs the query data point set Poi=([[Dis]],Y r ), where each data point set contains the homomorphic encryption distance and the label corresponding to the feature map of the non-inference client; this label is determined by comparing the similarity between the activation of the feature map in the model and the predefined category label, and the label with the highest similarity is usually selected as the category label Y of the feature map r .
[0090] In a specific implementation, the first encrypted query distance is decrypted to obtain at least one decrypted query distance:
[0091] Following the above exemplary embodiments, refer to Figure 4 , the inference client uses the private key to decrypt the query distance Dis r ←EN([[Dis r ]],sk). Specifically: the inference client uses its private key to decrypt the encrypted query distance received from the non-inference client. This process is completed through the decryption operation of the homomorphic encryption scheme, namely Dis r ←EN([[Dis r]],sk), where sk is the private key of the inference client.
[0092] In a specific implementation, the query data point set is selected based on the at least one decrypted query distance to obtain at least one neighboring data point:
[0093] Following the above exemplary embodiments, refer to Figure 4 , the inference client obtains the k query data points Poi with the smallest distance Tk =([[Dis Tk ]],Y Tk ). Specifically: The inference client first uses its private key to decrypt the encrypted query distance received from the non-inference client to obtain the actual query distance. Then, the inference client selects the k data points with the smallest distance based on these decrypted query distances. These data points together with the corresponding feature map category labels Y Tk Constitutes the set of neighboring data points Poi Tk =([[Dis Tk ]],Y Tk ) for the subsequent reasoning enhancement process. This step ensures that the reasoning client can focus on the data points most relevant to the query request to improve the accuracy of model reasoning.
[0094] Step S250: Calculate the confidence of the at least one neighboring data point to obtain an inference result.
[0095] In this exemplary embodiment, the confidence calculation is performed on the at least one neighboring data point to obtain an inference result, including:
[0096] The at least one neighboring data point is mapped to obtain a query mapping function; the query mapping function is standardized to obtain a query confidence; and the query confidence is weighted and fused to obtain the inference result.
[0097] In a specific implementation, the at least one neighboring data point is mapped to obtain a query mapping function:
[0098] Following the above exemplary embodiments, refer to Figure 4 , the inference client uses the mapping function f between distance and category confidence r (·) Design the distance-confidence decreasing curve mapping function to obtain Dis Tk Mapping value. Specifically: The inference client uses the mapping function f between distance and category confidence r (·) Design a distance-confidence decreasing curve mapping function, by taking the distance Dis of the neighboring data points as TkInput into the mapping function, calculate the corresponding mapping value, and obtain the confidence of each category. The mapping function usually adopts a decreasing form to ensure that the points with smaller distances have higher corresponding confidence, and then obtain the final confidence value of each category through standardization, so as to more accurately reflect the relative importance of data points in the inference process.
[0099] In specific implementation, the query mapping function is standardized to obtain the query confidence:
[0100] Following the above exemplary embodiment, the mapping value of category v is calculated and standardized to obtain the confidence As shown in the formula:
[0101]
[0102] Among them, category c refers to one of the specific categories or labels that a data point may belong to in a classification task. In the context of machine learning and pattern recognition, especially in the application scenarios of federated learning, data sets are usually divided into multiple mutually exclusive categories, such as "cat", "dog", "car", etc. Each category represents a specific attribute or attribute group of the data. Category c is used to distinguish these different attributes or attribute groups and serves as the target of model reasoning and prediction. The reasoning client calculates the confidence of each category by analyzing the feature maps of neighboring data points and the corresponding category labels, and then generates an inference result.
[0103] In specific implementation, the query confidence is weighted and integrated to obtain the inference result:
[0104] Following the above exemplary embodiments, refer to Figure 3 , get the confidence of all categories to get the query result y r , weighted fusion with the inference result of the model in the inference client, and calculate the inference enhancement result y, as shown in the formula.
[0105]
[0106] Among them, α is a weight parameter, which is used to control the contribution ratio of the global model inference result and query confidence in the final inference result; x req The data to be inferred; is the local model f J The weight of .
[0107] This enables effective use of global heterogeneous data during reasoning, and the reasoning client obtains more accurate reasoning results.
[0108] refer to Figure 3 , a data heterogeneous federated learning model reasoning method is applied to a second client, and the method comprises the following steps:
[0109] Step S310: determine a second feature graph and differential privacy noise, receive a first encrypted feature graph transmitted by a first client, and perform homomorphic encryption distance calculation on the second feature graph and the differential privacy noise based on the first encrypted feature graph to obtain a first encrypted query distance.
[0110] In specific implementation, the method of determining the second feature map is:
[0111] The second client uses the feature extraction layer of traditional machine learning models such as support vector machine (SVM), decision tree, random forest, etc. to obtain the second feature map, and the second client uses autoencoders to learn effective encoding of data, and the output of its encoding layer can be used as the second feature map, or the second client uses a model with an attention mechanism to extract the second feature map.
[0112] In the above exemplary embodiment, a method for determining the second feature map is introduced. Next, a method for obtaining differential privacy noise is introduced:
[0113] In this exemplary embodiment, the method of obtaining differential privacy noise includes:
[0114] Performing distance measurement on the second feature map to obtain local sensitivity; and quantifying the local sensitivity to obtain the differential privacy noise.
[0115] In a specific implementation, the distance measurement is performed on the second feature map to obtain the local sensitivity:
[0116] Following the above exemplary embodiments, refer to Figure 4 , each non-inference client uses methods such as Euclidean distance and cosine distance to calculate the distance between its local feature map and the feature maps of other non-inference clients, and selects the maximum value from the calculated distances as the local sensitivity Δf of the current data set.
[0117] In a specific implementation, the local sensitivity is quantified to obtain the differential privacy noise:
[0118] Following the above exemplary embodiments, refer to Figure 4 , each non-inference client calculates the differential privacy noise δ for each distance, and the size of the differential privacy noise is determined by the local sensitivity. Specifically: According to the requirements of differential privacy, the non-inference client calculates the scale parameter b of the noise, which is usually related to the local sensitivity Δf and the privacy budget parameter c, and the calculation formula is The non-inference client extracts random noise δ from a Laplace distribution with a scale parameter of b. Laplace distribution is a distribution commonly used in differential privacy because its heavy-tailed property allows the added noise to protect privacy without having too much impact on the results.
[0119] In the above exemplary embodiment, a method for obtaining differential privacy noise is introduced. Next, a method for obtaining the first encrypted query distance is introduced:
[0120] In this exemplary embodiment, performing distance calculation on the second feature graph and the differential privacy noise based on the first encrypted feature graph to obtain a first encrypted query distance includes:
[0121] Receive the public key transmitted by the first client, encrypt the second feature map based on the public key to obtain a second encrypted feature map; perform homomorphic encryption calculation on the first encrypted feature map and the second encrypted feature map to obtain a second encrypted query distance; add the differential privacy noise to the second encrypted query distance to obtain the first encrypted query distance.
[0122] In a specific implementation, a method of receiving a public key transmitted by the first client, and encrypting the second feature map based on the public key to obtain a second encrypted feature map is as follows:
[0123] Following the above exemplary embodiments, refer to Figure 4 , each non-inference client receives the public key transmitted by the inference client, and encrypts the local feature map through the public key to obtain a second encrypted feature map.
[0124] In a specific implementation, the first encrypted feature graph and the second encrypted feature graph are homomorphically encrypted to obtain the second encrypted query distance:
[0125] Following the above exemplary embodiments, refer to Figure 4 , execute the query request of the inference client in parallel in each non-inference client, calculate the query point and the local encrypted feature map (second client feature map) The homomorphic encryption distance between r ]]. Specifically, the inference client generates a query request that contains a feature map (query point) encrypted with its public key. The inference client broadcasts the encrypted query request to all non-inference clients. After each non-inference client receives the query request, it starts to process the request. The non-inference client uses its local homomorphic encryption library to process the encrypted data. The non-inference client calculates the homomorphic encryption distance between the query point and each encrypted feature map stored locally. This calculation takes advantage of the characteristics of homomorphic encryption, allowing arithmetic operations to be performed directly on encrypted data without decrypting the data.
[0126] In a specific implementation, the differential privacy noise is added to the second encrypted query distance to obtain the first encrypted query distance:
[0127] The second client adds differential privacy noise to the second encrypted query distance to obtain the first encrypted query distance.
[0128] In the above exemplary embodiment, a method of performing homomorphic encryption distance calculation on the second feature graph and the differential privacy noise based on the first encrypted feature graph to obtain the first encrypted query distance is introduced. The following further introduces a method of adding the differential privacy noise to the second encrypted query distance to obtain the first encrypted query distance:
[0129] In this exemplary embodiment, the differential privacy noise is added to the second encrypted query distance to obtain the first encrypted query distance, including:
[0130] The differential privacy noise is encrypted based on the public key to obtain encrypted differential privacy noise; and the encrypted differential privacy noise is added to the second encrypted query distance to obtain the first encrypted query distance.
[0131] In a specific implementation, the differential privacy noise is encrypted based on the public key to obtain the encrypted differential privacy noise:
[0132] Following the above exemplary embodiments, refer to Figure 4 , each non-inference client encrypts the differential privacy noise with the public key sent from the inference client to obtain the encrypted differential privacy noise [[δ]].
[0133] In a specific implementation, the encrypted differential privacy noise is added to the second encrypted query distance to obtain the first encrypted query distance:
[0134] Following the above exemplary embodiments, refer to Figure 4 , the non-reasoning client uses the public key of the reasoning client to homomorphically encrypt the noise and add it to the homomorphic encryption distance [[Dis r ]]=[[Dis′ r ]]+[[δ]]. Specifically: In this scheme, the non-reasoning client first uses the public key provided by the reasoning client to homomorphically encrypt the differential privacy noise δ extracted from the Laplace distribution to obtain [[δ]], ensuring that the encrypted noise can be homomorphically encrypted with the previously calculated distance [[Dis′ r ]]Directly perform arithmetic operations and then add the encrypted noise to these distances to obtain the final encrypted distance [[Dis r ]]=[[Dis′ r ]]+[[δ]], this process is carried out entirely in a homomorphic encryption environment to maintain the privacy and security of the data.
[0135] Based on the above exemplary embodiments, this solution combines homomorphic encryption and differential privacy technologies to protect client data privacy while enhancing the client model reasoning capabilities in a data heterogeneous federated learning environment, effectively improving the reasoning accuracy and reducing the need for global model retraining, thereby optimizing the performance and efficiency of federated learning while ensuring data security and privacy.
[0136] It should be noted that the method of the embodiment of the present disclosure can be performed by a single device, such as a computer or a server. The method of the present embodiment can also be applied in a distributed scenario and completed by multiple devices cooperating with each other. In the case of such a distributed scenario, one of the multiple devices can only perform one or more steps in the method of the embodiment of the present disclosure, and the multiple devices will interact with each other to complete the described method.
[0137] It should be noted that the above describes some embodiments of the present disclosure. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the above embodiments and still achieve the desired results. In addition, the processes depicted in the accompanying drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0138] Based on the same inventive concept, corresponding to any of the above-mentioned embodiment methods, the present disclosure also provides a data heterogeneous federated learning model reasoning device.
[0139] refer to Figure 5 The data heterogeneous federated learning model reasoning device is applied to the first client and includes:
[0140] A first feature map determining module 510 is configured to determine data to be inferred, perform feature extraction based on the data to be inferred, and obtain a first feature map;
[0141] A first encrypted feature map determining module 520 is configured to encrypt the first feature map to obtain a first encrypted feature map;
[0142] A first encrypted feature map transmission module 530, configured to transmit the first encrypted feature map to at least one second client, so that the at least one second client generates a first encrypted query distance;
[0143] The neighbor data point determination module 540 is configured to receive at least one first encrypted query distance sent by the at least one second client, construct a query data point set based on the at least one first encrypted query distance; decrypt the first encrypted query distance to obtain at least one decrypted query distance; select the query data point set based on the at least one decrypted query distance to obtain at least one neighbor data point;
[0144] The inference result determination module 550 is configured to perform confidence calculation on the at least one neighboring data point to obtain an inference result.
[0145] In this exemplary embodiment, the first feature map determination module 510 is specifically configured as follows:
[0146] The data to be inferred is determined, and features are extracted based on the data to be inferred to obtain a first feature map.
[0147] In this exemplary embodiment, the first encryption feature map determination module 520 is specifically configured as follows:
[0148] Determine a public key and a private key, the public key is used to encrypt the first feature map, the private key is used to decrypt the first encrypted query distance, transmit the public key to the at least one second client, encrypt the first feature map, and obtain a first encrypted feature map.
[0149] In this exemplary embodiment, the first encrypted feature map transmission module 530 is specifically configured as follows:
[0150] The first encrypted feature map is transmitted to at least one second client, so that the at least one second client generates a first encrypted query distance.
[0151] In this exemplary embodiment, the neighboring data point determination module 540 is specifically configured as follows:
[0152] Receive at least one first encrypted query distance sent by the at least one second client, and construct a query data point set based on the at least one first encrypted query distance; decrypt the first encrypted query distance to obtain at least one decrypted query distance; select the query data point set based on the at least one decrypted query distance to obtain at least one neighboring data point.
[0153] In this exemplary embodiment, the reasoning result determination module 550 is specifically configured as follows:
[0154] The at least one neighboring data point is mapped to obtain a query mapping function, the query mapping function is standardized to obtain a query confidence, and the query confidence is weighted and fused to obtain the inference result.
[0155] refer to Figure 6 The data heterogeneous federated learning model reasoning device is applied to the second client and includes:
[0156] The encrypted query distance determination module 610 is configured to determine the second feature graph and the differential privacy noise, receive the first encrypted feature graph transmitted by the first client, and perform homomorphic encryption distance calculation on the second feature graph and the differential privacy noise based on the first encrypted feature graph to obtain a first encrypted query distance;
[0157] The encrypted query distance transmission module 620 is configured to transmit the first encrypted query distance to the first client, so that the first client decrypts the first encrypted query distance based on a private key and selects a neighboring data point.
[0158] In this exemplary embodiment, the encrypted query distance determination module 610 is specifically configured as follows:
[0159] Determine a second feature map, perform distance measurement on the second feature map to obtain local sensitivity, quantify the local sensitivity to obtain the differential privacy noise, receive a first encrypted feature map transmitted by a first client, receive a public key transmitted by the first client, encrypt the second feature map based on the public key to obtain a second encrypted feature map, perform homomorphic encryption calculation on the first encrypted feature map and the second encrypted feature map to obtain a second encrypted query distance, encrypt the differential noise based on the public key to obtain encrypted differential privacy noise, and add the encrypted differential privacy noise to the second encrypted query distance to obtain the first encrypted query distance.
[0160] In this exemplary embodiment, the encrypted query distance transmission module 620 is specifically configured as follows:
[0161] The first encrypted query distance is transmitted to the first client, so that the first client decrypts the first encrypted query distance based on a private key and selects a neighboring data point.
[0162] For the convenience of description, the above device is described by dividing it into various modules according to its functions. Of course, when implementing the present disclosure, the functions of each module can be implemented in the same or multiple software and / or hardware.
[0163] The device of the above embodiment is used to implement the corresponding data heterogeneous federated learning model inference method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be repeated here.
[0164] Based on the same inventive concept, corresponding to any of the above-mentioned embodiments and methods, the present disclosure also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the data heterogeneous federated learning model reasoning method described in any of the above embodiments is implemented.
[0165] Figure 7 A more specific schematic diagram of the hardware structure of an electronic device provided in this embodiment is shown, and the device may include: a processor 1010, a memory 1020, an input / output interface 1030, a communication interface 1040, and a bus 1050. The processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040 are connected to each other through the bus 1050 in the device.
[0166] The processor 1010 can be implemented by a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of this specification.
[0167] The memory 1020 may be implemented in the form of ROM (Read Only Memory), RAM (Random Access Memory), static storage device, dynamic storage device, etc. The memory 1020 may store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented by software or firmware, the relevant program codes are stored in the memory 1020 and are called and executed by the processor 1010.
[0168] The input / output interface 1030 is used to connect the input / output module to realize information input and output. The input / output module can be configured in the device as a component (not shown in the figure), or it can be externally connected to the device to provide corresponding functions. The input device may include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device may include a display, a speaker, a vibrator, an indicator light, etc.
[0169] The communication interface 1040 is used to connect a communication module (not shown) to realize communication interaction between the device and other devices. The communication module can realize communication through a wired mode (such as USB, network cable, etc.) or a wireless mode (such as mobile network, WIFI, Bluetooth, etc.).
[0170] The bus 1050 includes a path that transmits information between the various components of the device (eg, the processor 1010, the memory 1020, the input / output interface 1030, and the communication interface 1040).
[0171] It should be noted that, although the above device only shows the processor 1010, the memory 1020, the input / output interface 1030, the communication interface 1040 and the bus 1050, in the specific implementation process, the device may also include other components necessary for normal operation. In addition, it can be understood by those skilled in the art that the above device may also only include the components necessary for implementing the embodiments of the present specification, and does not necessarily include all the components shown in the figure.
[0172] The electronic device of the above embodiment is used to implement the corresponding data heterogeneous federated learning model inference method in any of the above embodiments, and has the beneficial effects of the corresponding method embodiment, which will not be repeated here.
[0173] Those skilled in the art will appreciate that the embodiments of the present disclosure may be implemented as a system, method, or computer program product. Therefore, the present disclosure may be specifically implemented in the following forms, namely: complete hardware, complete software (including firmware, resident software, microcode, etc.), or a combination of hardware and software, generally referred to herein as a "circuit," "module," or "system." In addition, in some embodiments, the present disclosure may also be implemented in the form of a computer program product in one or more computer-readable media, which contains computer-readable program code.
[0174] Any combination of one or more computer-readable media may be used. A computer-readable medium may be a computer-readable signal medium or a computer-readable storage medium. A computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples (non-exhaustive examples) of computer-readable storage media may include, for example: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this document, a computer-readable storage medium may be any tangible medium containing or storing a program that may be used by or in combination with an instruction execution system, device or device.
[0175] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, which carry computer-readable program code. Such propagated data signals may take a variety of forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. Computer-readable signal media may also be any computer-readable medium other than a computer-readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device.
[0176] The program code embodied on the computer readable medium may be transmitted using any appropriate medium, including but not limited to wireless, wireline, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0177] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages or a combination thereof, including object-oriented programming languages such as Java, Smalltalk, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0178] It should be understood that each box in the flowchart and / or block diagram and the combination of boxes in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer or other programmable data processing device to produce a machine, and these computer program instructions are executed by a computer or other programmable data processing device to produce a device that implements the functions / operations specified in the boxes in the flowchart and / or block diagram.
[0179] These computer program instructions may also be stored in a computer-readable medium that enables a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable medium produce a product that includes an instruction device that implements the functions / operations specified in the blocks in the flowchart and / or block diagram.
[0180] Computer program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device so that a series of operational steps are performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby enabling the instructions executed on the computer or other programmable device to provide a process for implementing the functions / operations specified in the blocks in the flowchart and / or block diagram.
[0181] In addition, although the operations of the disclosed method are described in a particular order in the accompanying drawings, this does not require or imply that the operations must be performed in this particular order, or that all the operations shown must be performed to achieve the desired results. On the contrary, the steps depicted in the flow chart can be performed in a different order. Additionally or alternatively, some steps can be omitted, multiple steps can be combined into one step, and / or one step can be decomposed into multiple steps.
[0182] The flowchart and block diagram in the accompanying drawings illustrate the possible architecture, functions and operations of the system, method and computer program product according to various embodiments of the present application. Wherein, each box in the flowchart or block diagram can represent a module, a program segment, or a part of the code, and the above-mentioned module, program segment, or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram or flowchart, and the combination of boxes in the block diagram or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0183] It should be noted that, although several modules or units of the equipment for action execution are mentioned in the above detailed description, this division is not mandatory. In fact, according to the embodiments of the present application, the features and functions of two or more modules or units described above can be embodied in one module or unit. On the contrary, the features and functions of one module or unit described above can be further divided into being embodied by multiple modules or units.
[0184] Those skilled in the art should understand that the discussion of any of the above embodiments is merely illustrative and is not intended to imply that the scope of the present application (including the claims) is limited to these examples. In line with the concept of the present application, the technical features in the above embodiments or different embodiments may be combined, the steps may be implemented in any order, and there are many other variations of the different aspects of the embodiments of the present application as described above, which are not provided in detail for the sake of simplicity.
[0185] In addition, to simplify the description and discussion, and in order not to make the embodiments of the present application difficult to understand, the known power supply / ground connection with the integrated circuit (IC) chip and other components may or may not be shown in the provided drawings. In addition, the device can be shown in the form of a block diagram to avoid making the embodiments of the present application difficult to understand, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform to be implemented in the embodiments of the present application (that is, these details should be fully within the scope of understanding of those skilled in the art). In the case of elaborating specific details (e.g., circuits) to describe exemplary embodiments of the present application, it is obvious to those skilled in the art that the embodiments of the present application can be implemented without these specific details or when these specific details are changed. Therefore, these descriptions should be considered to be illustrative rather than restrictive.
[0186] Although the present application has been described in conjunction with specific embodiments of the present application, many replacements, modifications and variations of these embodiments will be apparent to those skilled in the art from the foregoing description. For example, other memory architectures (e.g., dynamic RAM (DRAM)) may use the embodiments discussed.
[0187] The embodiments of the present application are intended to cover all such substitutions, modifications and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present application should be included in the scope of protection of the present application.
[0188] Although the spirit and principle of the present disclosure have been described with reference to several specific embodiments, it should be understood that the present disclosure is not limited to the disclosed specific embodiments, and the division of various aspects does not mean that the features in these aspects cannot be combined to benefit, and such division is only for the convenience of expression. The present disclosure is intended to cover various modifications and equivalent arrangements included in the spirit and scope of the attached claims. The scope of the attached claims conforms to the broadest interpretation, thereby including all such modifications and equivalent structures and functions.
Claims
1. A data heterogeneous federated learning model reasoning method, characterized in that: Applied to the first client, including: Determine the data to be inferred, and perform feature extraction based on the data to be inferred to obtain a first feature graph; Encrypting the first feature map to obtain a first encrypted feature map; transmitting the first encrypted feature map to at least one second client so that the at least one second client generates a first encrypted query distance; Receive at least one first encrypted query distance sent by the at least one second client, and construct a query data point set based on the at least one first encrypted query distance; decrypt the first encrypted query distance to obtain at least one decrypted query distance; select the query data point set based on the at least one decrypted query distance to obtain at least one neighbor data point; A confidence calculation is performed on the at least one neighboring data point to obtain an inference result.
2. The method according to claim 1, characterized in that Before encrypting the first feature map, the method further includes: Determining a public key and a private key, wherein the public key is used to encrypt the first feature map; The private key is used to decrypt the first encrypted query distance; The public key is transmitted to the at least one second client.
3. The method according to claim 1, characterized in that Calculating the confidence of the at least one neighboring data point to obtain an inference result includes: Mapping the at least one neighboring data point to obtain a query mapping function; Normalizing the query mapping function to obtain query confidence; The query confidences are weighted and fused to obtain the inference result.
4. A data heterogeneous federated learning model reasoning method, characterized in that: Applied to the second client, including: Determine a second feature graph and differential privacy noise, receive a first encrypted feature graph transmitted by a first client, and perform homomorphic encryption distance calculation on the second feature graph and the differential privacy noise based on the first encrypted feature graph to obtain a first encrypted query distance; The first encrypted query distance is transmitted to the first client, so that the first client decrypts the first encrypted query distance based on a private key and selects a neighboring data point.
5. The method according to claim 4, characterized in that Before determining the second feature map and the differential privacy noise, the method further includes: Performing distance measurement on the second feature map to obtain local sensitivity; The local sensitivity is quantified to obtain the differential privacy noise.
6. The method according to claim 4, characterized in that The performing distance calculation on the second feature graph and the differential privacy noise based on the first encrypted feature graph to obtain a first encrypted query distance includes: Receiving a public key transmitted by the first client, and encrypting the second feature map based on the public key to obtain a second encrypted feature map; Performing homomorphic encryption calculation on the first encrypted feature graph and the second encrypted feature graph to obtain a second encrypted query distance; The differential privacy noise is added to the second encrypted query distance to obtain the first encrypted query distance.
7. The method according to claim 6, characterized in that The adding the differential privacy noise to the second encrypted query distance to obtain the first encrypted query distance includes: Encrypting the differential privacy noise based on the public key to obtain encrypted differential privacy noise; The encrypted differential privacy noise is added to the second encrypted query distance to obtain the first encrypted query distance.
8. A data heterogeneous federated learning model reasoning device, characterized in that: Applied to the first client, including: A first feature map determining module is configured to determine the data to be inferred, perform feature extraction based on the data to be inferred, and obtain a first feature map; A first encrypted feature map determining module is configured to encrypt the first feature map to obtain a first encrypted feature map; A first encrypted feature map transmission module, configured to transmit the first encrypted feature map to at least one second client, so that the at least one second client generates a first encrypted query distance; The neighbor data point determination module is configured to receive at least one first encrypted query distance sent by the at least one second client, construct a query data point set based on the at least one first encrypted query distance; decrypt the first encrypted query distance to obtain at least one decrypted query distance; select the query data point set based on the at least one decrypted query distance to obtain at least one neighbor data point; The inference result determination module is configured to perform confidence calculation on the at least one neighboring data point to obtain an inference result.
9. A data heterogeneous federated learning model reasoning device, characterized in that: Applied to the second client, including: An encrypted query distance determination module is configured to determine a second feature graph and differential privacy noise, receive a first encrypted feature graph transmitted by a first client, and perform homomorphic encryption distance calculation on the second feature graph and the differential privacy noise based on the first encrypted feature graph to obtain a first encrypted query distance; The encrypted query distance transmission module is configured to transmit the first encrypted query distance to the first client, so that the first client decrypts the first encrypted query distance based on a private key and selects a neighboring data point.
10. An electronic device, characterized in that: The method comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the method according to any one of claims 1 to 7 is implemented.