Robust federated learning method and system based on chaotic encryption and dual-server enabling

By introducing chaotic encryption and dual-server detection modes in federated learning, edge nodes are allowed to encrypt using different initial values, and filtering Byzantine nodes through reputation segmentation mechanism, the problem of large computing overhead and no support for different initial value encryption in the existing technology is solved, and efficient privacy protection and Byzantine robustness are achieved.

CN119995819AActive Publication Date: 2025-05-13HARBIN UNIV OF SCI & TECH

Patent Information

Application Number
CN202411646576.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-11-18
Publication Date
2025-05-13
Estimated Expiration
2044-11-18

AI Technical Summary

Technical Problem

The existing federated learning privacy protection method has high computational overhead, and the method of using chaotic encryption to protect federated learning privacy does not support edge nodes to use different initial values ​​to encrypt, making it difficult to defend against Byzantine attacks while protecting privacy.

Method used

A robust federated learning method with chaotic encryption and dual-server empowerment is proposed, allowing edge nodes to perform chaotic encryption using different initial values, and filter Byzantine edge nodes through dual-server detection mode and reputation scoring mechanism.

Benefits of technology

Lightweight privacy leak protection and Byzantine robustness are achieved, reducing computational overhead, improving testing accuracy, and showing high robustness in the face of Byzantine attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995819A_ABST
    Figure CN119995819A_ABST
Patent Text Reader

Abstract

The invention discloses a robust federated learning method and system based on chaotic encryption and dual-server enabling, and belongs to the technical field of data security. The method is provided for solving the problems that an existing federated learning privacy protection method is generally high in calculation overhead, and an existing method for protecting federated learning privacy by using chaotic encryption does not support edge nodes to encrypt by using different initial values. According to the technical key points, edge nodes are allowed to encrypt local model parameters by using different initial values, the characteristic of mutual offset exists between ciphertexts, and a result in a plaintext form can be obtained after aggregation; secondly, constructing a dual-server detection mode, and performing layered detection on a local model; and finally, providing a reputation sub-mechanism, performing reputation evaluation on the edge nodes according to a detection result, filtering Byzantine edge nodes, and aggregating local model parameters of honest edge nodes. Security analysis shows that the method can effectively prevent privacy leakage of edge nodes; experimental results show that under Byzantine attack, the test accuracy of the method is averagely 18.33% higher than that of a baseline scheme, and compared with homomorphic encryption methods such as CKKS and BFV, the time overhead is at least reduced by 69.8%, and privacy protection and Byzantine robustness can be efficiently considered. The method is suitable for fault diagnosis of the rolling bearing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a robust federated learning method and system, and belongs to the technical field of data security. Background Art

[0002] In the digital age, data has gradually become an important means of production. [1] As a powerful engine for mining data value, artificial intelligence has achieved rapid development in recent years, and the data generated by user devices has also exploded. According to a report released by Statista, the number of IoT devices in use in 2025 will reach 30.9 billion. [2] By then, the amount of data generated daily will increase significantly compared to now, and how to protect the privacy information in it has become a hot topic. In addition, in the process of data circulation and sharing, attacks and leaks occur frequently, such as the user information leak incident on Facebook in 2019, in which more than 50 million private information was illegally downloaded. [3] Privacy issues are receiving increasing attention from all parties, and data sharing is becoming increasingly difficult, which has led to the emergence of data silos.

[0003] Federated Learning [4] Federated Learning (FL) has emerged as a solution to data silos. Different from traditional machine learning methods, federated learning is an efficient decentralized machine learning framework consisting of remote clients and aggregation servers. Users can upload local models for multi-party collaboration, which not only avoids uploading large amounts of data but also alleviates privacy issues.

[0004] However, there are still two problems that need to be solved in federated learning. The first problem is that the user's model information is still at risk of being leaked. [5-6] To address the problem of privacy leakage, a variety of solutions have been proposed: differential privacy [7-8] , Homomorphic encryption [9-10] and Chaos Encryption [11-12] The scheme based on differential privacy protects the privacy of users by adding random noise, but sacrifices the test accuracy to achieve high efficiency; the scheme based on homomorphic encryption uses complex cryptographic methods, which ensures the test accuracy of the global model, but has high computational overhead; the scheme based on chaotic encryption and image encryption scheme

[13] The core idea of ​​​​the proposed method is similar to that of , which uses chaotic sequences to cover up the user's privacy information. However, since users use the same initial value to generate chaotic sequences, the degree of privacy protection is limited. Therefore, how to design a secure and efficient federated learning privacy protection method is the first problem to be solved in this paper.

[0005] The second problem is that federated learning under privacy protection is vulnerable to Byzantine attacks. [14-15]Byzantine users may pollute training data or randomly generate model parameters, causing the server aggregation to obtain incorrect results, thereby destroying the performance of the global model. Most existing defense solutions compare the distance between models. [16-17] , calculate reputation and similarity [18-19] Or use generative adversarial networks to complete the test set

[20] Methods such as ciphertext and ciphertext can be used to filter out Byzantine users. However, ciphertext is not analyzable in the case of privacy protection. For example, after homomorphic encryption, the model parameters completely lose the digital features of the plaintext form, which makes the Byzantine defense scheme difficult to implement. Therefore, the second problem that needs to be solved is to protect user privacy while taking Byzantine robustness into account.

[0006] In recent years, some schemes have been proposed to achieve privacy protection in federated learning using chaotic encryption methods. However, such schemes require users to use the same initial value for chaotic encryption, which is not suitable for scenarios with Byzantine users.

[0007] At present, many encryption methods have been proposed to achieve privacy protection in federated learning, but few use encryption methods based on chaotic systems to protect model parameters. Because chaotic sequences have good pseudo-random properties, most existing schemes use chaotic systems to encrypt images. For example, reference

[13] proposes to combine Chen hyperchaotic system with DNA coding technology to encrypt images, aiming to improve the diversity of coding and the anti-attack ability of ciphertext. However, encryption methods based on chaotic systems can also be used to achieve privacy protection in federated learning. Reference

[11] proposes to use chaotic sequences generated by chaotic systems to scramble model parameters. Reference

[12] proposes to combine chaotic encryption methods with homomorphic encryption technology to achieve dual protection of model information.

[0008] In addition, users in federated learning may be malicious. To address this problem, many researchers have proposed some defense schemes. The main defense ideas can be classified into three categories: 1) Behavior-based defense. This type of defense scheme filters Byzantine users by analyzing the similarity between local models, calculating the user's reputation value, or comparing the threshold of local model updates. Reference

[16] proposed the Krum method, where the server calculates the norm distance between the local models of each user and selects the model with the smallest distance score as the global model. Reference

[17] proposed the FABA method, which discards some gradients with a large distance from the average gradient and selects the remaining gradients to calculate the global model. Reference

[18] proposed the SSPA mechanism, which uses the Beta distribution to evaluate the user's reputation score and filters Byzantine users based on the threshold. Reference

[19] proposed using the cosine similarity between models to calculate the node's credibility and filter Byzantine users whose credibility is lower than the threshold. Reference

[20] proposed using a generative adversarial network to generate a test set on the server side and filter users whose test scores are lower than the threshold. Reference

[21] proposed a detection method based on matrix mapping. The server constructs a mapping matrix and obtains the Softmax layer probability distribution of the user's local model, and filters Byzantine users based on the probability distribution. 2) Clustering-based defense. This method performs cluster analysis on model parameters to identify and filter Byzantine users. Reference

[22] proposed a heterogeneous quantitative security aggregation method. Users are divided into groups according to their communication capabilities, and local models are divided into segments. Finally, the global model is updated based on the grouping and segmentation strategy and the repeated median regression strategy. Reference

[23] proposed a robust aggregation method poly. First, the cosine similarity between users is calculated, and then the GMM clustering method is used to divide users into different clusters. Clusters with average similarity higher than the threshold are filtered out. Finally, the median aggregation method is used to update the global model between the remaining clusters. Reference

[24] proposed a gradient clustering method. PCA dimensionality reduction is performed on the local model parameters uploaded by users. After PCA dimensionality reduction, the local model parameters of Byzantine users show completely different results from those of honest users. They can be divided into different clusters through K-means clustering. In order to produce better results after the user's local model parameters are reduced in dimension, the reference

[25] uses the KCPA dimensionality reduction method instead of the PCA dimensionality reduction method, and uses K-means clustering to distinguish Byzantine users. The improved strategy has a better defense effect against poisoning attacks. 3) Defense based on the model itself. This type of method mainly defends the model itself. The reference

[26] proposes a method for trimming abnormal parameters to defend against Byzantine attacks by trimming model parameters whose update amplitude exceeds the threshold. The reference

[27] proposes a joint trimming method that aims to delete abnormal neurons, constrain neuron weights and fine-tune the model.

[0009] In recent years, some scholars have solved the privacy leakage and robustness problems of federated learning. Reference

[28] proposed a federated learning method that combines homomorphic encryption and anomaly detection technology. It uses homomorphic encryption technology to protect the user's local model information and filters Byzantine users based on the detection method of the normal distribution 3-sigma principle. Reference

[29] also filters malicious models based on the distance between models. Users upload their local model parameters to edge nodes through secret sharing technology. The edge nodes calculate the Euclidean distance between models based on the secret share. Finally, the blockchain filters the Byzantine users and updates the global model. Different from the distance-based detection method, reference

[30] proposed a federated learning method PEMFL that combines homomorphic encryption and cosine similarity. It uses homomorphic encryption technology to protect model information, performs similarity calculation on ciphertext and filters Byzantine users. Reference

[31] proposed the PBFL method, which uses fully homomorphic encryption technology to protect the user's local model information, cosine similarity to identify and filter Byzantine users, and blockchain to improve transparency, but it may bring huge computational overhead. Reference

[32] proposed a lightweight federated learning method that uses differential privacy technology to protect model information, evaluates the credibility of the current state based on the node's past performance, and filters Byzantine users based on credibility. In order to achieve privacy protection and robust aggregation more flexibly, reference

[33] proposed the SecureFL method, which uses the joint calculation of SP servers and CS servers and several cryptographic protocols for robust aggregation. Reference

[34] proposed the LSFL method, in which users split the model parameters and transmit them to two servers respectively. The two servers collaborate to filter the model parameters of Byzantine users and aggregate the model parameters of honest users. However, LSFL only selects k local models based on similarity to update the global model, and the local models of a small number of honest users may be discarded.

[0010] Therefore, there is an urgent need to solve the problem that the local models of a small number of honest users are discarded and the problem that the existing method of using chaotic encryption to protect the privacy of federated learning does not support users using different initial values ​​for encryption. Summary of the invention

[0011] The technical problems to be solved by the present invention are:

[0012] In view of the fact that the existing methods for protecting the privacy of federated learning generally have high computational overhead, and the problem that the existing methods for protecting the privacy of federated learning using chaotic encryption do not support the encryption of edge nodes using different initial values, the present invention proposes a robust federated learning method and system with chaotic encryption and dual-server empowerment. This method integrates the chaotic encryption scheme with the robust aggregation scheme, and can deal with the problems of privacy leakage and Byzantine attacks in a lightweight manner.

[0013] The technical solution adopted by the present invention to solve the above technical problems is: content of the certificate of right.

[0014] The present invention has the following technical effects:

[0015] The method of the present invention integrates the chaotic encryption scheme with the robust aggregation scheme, which can deal with the problems of privacy leakage and Byzantine attacks in a lightweight manner, and effectively solves the problem that the existing methods for protecting the privacy of federated learning generally have high computational overhead, and the existing methods for protecting the privacy of federated learning using chaotic encryption do not support edge nodes using different initial value encryption.

[0016] Federated learning technology can solve the problem of data islands, but it still faces two challenges: one is that local model parameters in plain text may leak the privacy of edge nodes; the other is that it is difficult to defend against Byzantine attacks while protecting privacy. The present invention proposes a robust federated learning method empowered by chaotic encryption and dual-server mechanism (A Robust Federated Learning Method Empowered by Chaotic Encryption and Dual-Server Mechanism, CDRFL) to solve the above problems. The method of the present invention is a chaotic encryption strategy suitable for federated learning, which allows edge nodes to encrypt local model parameters using different initial values, and there is a mutual cancellation feature between ciphertexts, and the results in plain text can be obtained after aggregation; secondly, a dual-server detection mode is constructed to perform hierarchical detection on local models; finally, a reputation scoring mechanism is proposed to evaluate the reputation of edge nodes according to the detection results, filter Byzantine edge nodes, and aggregate the local model parameters of honest edge nodes. Security analysis shows that the proposed method can effectively prevent privacy leakage of edge nodes; experimental results show that under Byzantine attack, the test accuracy of the proposed method is 18.33% higher than that of the baseline scheme on average, and compared with homomorphic encryption methods such as CKKS and BFV, the time overhead is reduced by at least 69.8%, which can effectively balance privacy protection and Byzantine robustness. The present invention is suitable for fault diagnosis of rolling bearings. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] Figure 1 This is an example diagram of the DBSCAN method; Figure 2 This is the architecture diagram of the dual-server federated learning system; Figure 3 Example graph of exchanging random numbers for edge nodes; Figure 4 An example diagram for constructing a chaotic parameter model; Figure 5 Flow chart of the robust federated learning method for chaotic encryption and dual-server empowerment; Figure 6 This is a convergence comparison curve for the CWRU bearing dataset and the CIFAR-10 dataset; Figure 7 This is a bar chart comparing the test accuracy of the CWRU bearing dataset and the CIFAR-10 dataset; Figure 8 This is the test accuracy graph of different schemes under free-rider attack; Fig. 9The test accuracy graph of different schemes under label flipping attack; Fig.10 It is the credit score change curve of edge nodes; Fig.11 Comparison of the test accuracy of CDRFL and FedAvg under free-rider attack; Fig.12 This is the test accuracy graph of CDRFL and FedAvg under label flipping attack; Fig.13 A bar chart showing the time consumption for a single training run of different methods in the IID scenario of the CWRU bearing dataset. DETAILED DESCRIPTION

[0018] Combined with Figures 1 to 13 , the implementation of the robust federated learning method of chaotic encryption and dual-server empowerment of the present invention is described as follows:

[0019] 1 The present invention proposes a chaotic encryption and dual-server enabled robust federated learning method. Different from the existing chaotic encryption method, the innovation of the proposed method lies in that the edge node can use different initial values ​​to perform chaotic encryption on the local model and successfully integrate robust aggregation with chaotic encryption. The contributions of the present invention are as follows:

[0020] (1) A chaotic encryption strategy suitable for federated learning is proposed. This strategy uses the elements of the chaotic sequence to replace the model parameters to construct a new model, and adds or subtracts the constructed model from the local model to blur the model information. As the encrypted model aggregates, the constructed models cancel each other out internally, and finally the aggregated result in plain text can be obtained;

[0021] (2) A dual-server detection strategy for Byzantine edge nodes is proposed. First, the local model of the edge node is detected by the joint calculation of two non-collusive servers. Then, the proposed reputation score mechanism is used to screen the Byzantine edge nodes and expand the punishment of Byzantine edge nodes. Finally, only the model parameters of honest edge nodes are aggregated to ensure the fairness of federated learning.

[0022] (3) Through security analysis and experiments, it is proved that the proposed method can effectively deal with malicious attacks and privacy leakage problems. It can filter out malicious models while protecting the privacy information of edge nodes, effectively taking into account the security and robustness of federated learning.

[0023] 2 The commonly used symbols and their meanings in the present invention are shown in Table 1. Table 1 shows the commonly used symbols and their meanings in the present invention.

[0024] Table 1 Symbols and meanings

[0025]

[0026] 3. Description of the relevant technical means in the present invention:

[0027] 3.1 Logistic Chaotic System

[0028] Logistic mapping is one of the most commonly used chaotic systems, and its difference equation expression is shown in formula (1):

[0029] x n+1 =f(x n ,μ)=μx n (1-x n ) (1)

[0030] Where: x n ∈(0,1), μ is the system parameter, when μ∈[3.569945,4], after a certain number of iterations, the Logistic map enters a chaotic state. In short, the Logistic map in a chaotic state can generate a sequence that is both random and highly sensitive to the initial conditions based on an initial value.

[0031] 3.2 DBSCAN Clustering Method

[0032] DBSCAN is a density clustering method that does not require the number of clusters to be specified in advance. It can determine the number of clusters based on the data itself and can identify clusters of various shapes. It is also effective even when the amount of data is small. This method mainly relies on two parameters: neighborhood radius (ε) and minimum number of points Through these two parameters, DBSCAN divides data points into three categories: if there are more than points, it is the core point; if the number of points in the ε neighborhood of a point is less than But if it is connected to at least one core point, it is a boundary point; otherwise, it is an outlier. Figure 1 As shown, if Then A, B, and C are core points, D and E are boundary points, and N is an outlier point.

[0033] 3.3 Beta Distribution

[0034] Beta distribution is a continuous probability distribution defined on [0,1]. Its probability density expression is shown in formula (2):

[0035]

[0036] In the formula

[0037]

[0038] Its shape is determined by two parameters, α and β, which can simulate various distribution forms. This study uses the dual-server detection results to assign values ​​to α and β, constructs a probability model of edge node integrity, and designs a reputation scoring mechanism based on Beta distribution.

[0039] 4 Method Overview

[0040] 4.1 System Architecture

[0041] Figure 2 The dual-server federated learning system architecture is shown. The system architecture consists of three types of entities: TP server, SP server, and edge node. The specific role of each entity is:

[0042] (1) TP server: The TP server is responsible for filtering Byzantine nodes and assisting the SP server in updating the global model.

[0043] (2) SP server: The SP server is responsible for aggregating the model parameters of honest edge nodes.

[0044] (3) Edge nodes: Edge nodes are generally equipped with certain computing resources, such as edge servers and smart sensors in the industrial Internet of Things. They are willing to jointly train better models. In the upload phase, edge nodes only upload ciphertexts but not private data.

[0045] 4.2 Threat Target

[0046] The threat targets of the model mainly consider honest and curious TP servers, SP servers and Byzantine nodes.

[0047] (1) Honest and curious SP servers and TP servers: SP servers and TP servers abide by the protocol and do not actively generate errors, but actively and proactively reason about the local data of edge nodes.

[0048] (2) Byzantine nodes: Byzantine nodes refer to edge nodes that are malicious or have been hacked by attackers. In federated learning, Byzantine nodes may damage the performance of the global model by colluding with each other or uploading malicious models. This paper assumes that Byzantine nodes may launch free-rider attacks and label flipping attacks. Free-rider attacks refer to Byzantine nodes that only enjoy the benefits of the global model and do not actively contribute to the trained model. They may randomly generate model parameters and upload them to the server because they do not have the ability to train the model. Label flipping attacks refer to Byzantine nodes maliciously modifying the labels of training data and poisoning the global model with contaminated data.

[0049] 5CDRFL

[0050] In view of the problem that chaotic encryption methods in federated learning are difficult to support edge nodes to use different initial values ​​to perform chaotic encryption on model parameters, and chaotic encryption schemes are difficult to combine with robust aggregation schemes, this paper proposes a robust federated learning method CDRFL that combines chaotic encryption with dual servers. The flowchart is shown in the figure. Figure 5As shown, Section 5.1 mainly explains the chaotic encryption strategy, dual-server detection strategy and reputation score calculation strategy in CDRFL; Section 5.2 gives the complete workflow of CDRFL.

[0051] 5.1 Method design

[0052] (1) Chaotic encryption strategy

[0053] Take edge node P i For example. First, P i Receive the global model w from the SP server global , use local data to train and obtain the local model w i .

[0054] Next, P i Randomly generate a set of random numbers shared To Node P j And from node P j take over P j ∈P and j≠i. After the sharing between edge nodes is completed, P i Available and Two sets of random numbers, taking n=4 as an example, Figure 3 The process of random number sharing between edge nodes is demonstrated.

[0055] If P i by As the initial value of the Logistic chaotic system, the Logistic chaotic system can obtain a set of chaotic sequences through iteration. The elements in the chaotic sequence replace the model parameters in turn to construct a new model, which is called the "chaotic parameter model" and is recorded as Figure 4 The process of building a chaotic parameter model is demonstrated.

[0056] The two sets of random numbers are used to construct corresponding chaotic parameter models according to the above steps, and the local model w is implemented through formulas (4)-(6) i The encryption of is a shape with w i Same, the internal element size is b i Vector.

[0057]

[0058] To facilitate the subsequent detection of Byzantine nodes, P i We also need to calculate a ciphertext B i , as shown in formula (7):

[0059]

[0060] Finally, upload W i To SP server, B i To the TP server. i For example, the specific process of chaotic encryption is shown in method 1:

[0061]

[0062]

[0063] (2) Dual-server detection strategy

[0064] First, the SP server aggregates all encryption models W in the current round i , using the property of mutual cancellation, the average result w of the local model is obtained, as shown in formula (8):

[0065]

[0066] Second, the SP server calculates W i -w and sent to TP server, i∈[1,n].

[0067] Next, the TP server calculates the local model w i The distance d from the average model w i , as shown in formula (9):

[0068]

[0069] Finally, due to i is a vector with the same shape as w i The same, so the TP server layered calculation d i The l2 norm of i (k), k∈[1,K], K is the number of layers of the model. The TP server sets the norms of all edge nodes in the same layer to a set {d1(k),…,d n (k)}, cluster them using the DBSCAN clustering method, output outliers, traverse all layers, and finally identify the local model w i The number of normal and abnormal layers in the.

[0070] (3) Credit score mechanism

[0071] Credit score It consists of three parts: ① Latest score A i : The score determined by the edge node's performance in the current round; ② Historical score N i : The score determined by the performance of the edge node in the past Q rounds; ③ Continuous honesty score h: The score determined by whether the edge node continues to perform honestly, reputation score The calculation method of is shown in formula (10), where q+p+h=1.

[0072]

[0073] Let the expected value of the Beta distribution be the latest score A i , as shown in formulas (11)-(12), where the two shape parameters of the Beta distribution are given by the local model w i Normal number of layers C i and the number of abnormal layers F i Assignment, Much larger than ζ.

[0074]

[0075] A time decay mechanism is used to assist in calculating the historical score N of edge nodes. i , reducing but not ignoring the impact of the past Q round scores on the current round reputation score, the calculation method is shown in formulas (13)-(15):

[0076]

[0077]

[0078] c is a constant, and its value is generally 0.5 to 1. Indicates existence.

[0079] If the edge node behaves honestly in r consecutive rounds, it will receive a reward of h. Finally, the final reputation score is calculated by formula (10): Assuming the threshold is δ, if If the node is a Byzantine edge node, then it is an honest edge node.

[0080] 5.2 Method flow

[0081] ① The edge node downloads the initial model from the SP server;

[0082] ② The edge node uses the local data set to train the local model w i , encrypt the model parameters chaotically, upload W i To SP server, B i To TP server, i∈[1,n];

[0083] ③The SP server aggregates the encryption model W of all edge nodes through formula (8) i , get the average model w;

[0084] ④SP server calculates W i -w, send Wi -w to TP server;

[0085] ⑤TP obtains the local model w according to formula (9) i The distance d from the average model w i , i∈[1,n], hierarchical calculation d i The l2 norm of the same layer is set to a set of {d1(k),…,d n (k)}k∈[1,K], use DBSCAN method to cluster them, identify outliers, and record the local model w i The number of normal and abnormal layers;

[0086] ⑥W i Medium normal layer C i and the number of abnormal layers F i Assigning the shape parameters α and β of the Beta distribution, i∈[1,n], the TP server calculates the reputation score of each edge node. Then determine P i It is a Byzantine edge node;

[0087] ⑦TP server aggregates the ciphertext B of honest edge nodes through formula (16) i , aggregate the results Send to SP server:

[0088]

[0089] ⑧ Encryption model W of SP server aggregating honest edge nodes i , the global model is restored through formulas (17)-(18):

[0090]

[0091] ⑨SP server sends w global To the honest edge nodes.

[0092] Repeat the above steps ②-⑨ until the number of iterations is reached. The specific process is shown in Method 2:

[0093]

[0094]

[0095] 6. Security Analysis

[0096] This section describes in detail the security of the CDRFL method against various potential adversaries and proves the security of the proposed method in an honest and curious model:

[0097] Theorem 1: Chaotic encryption can prevent the leakage of sensitive information at edge nodes.

[0098] Proof: According to the properties of the Logistic chaotic system, when the initial value changes, the chaotic sequences generated by the system will be completely different. Therefore, the initial value sensitivity of the chaotic encryption strategy is analyzed first. Assume that there are Byzantine edge nodes in the system. When the initial value of the edge node changes by 10 -15 -10 -5 infinitesimal changes, the change in the test accuracy of the global model is shown in Table 2:

[0099] Table 2 Influence of the change in the initial value on the test accuracy of the global model

[0100]

[0101] As shown in Table 2, even if the initial value of the chaotic encryption only changes by 10 -15 orders of magnitude, the performance of the global model will also decrease significantly. Because a small change in the initial value will result in completely different chaotic sequences, and the encryption models constructed using these chaotic sequences do not have the property of mutual cancellation. As a result, the server cannot calculate the distance between the local model w i and the average model w, and finally cannot correctly filter out the Byzantine edge nodes, leading to a decrease in the performance of the global model. Therefore, the proposed method has good key sensitivity.

[0102] Similar to the image encryption system, in order to resist brute-force attacks, the chaotic encryption-based scheme must have a sufficiently large key space. If the number of edge nodes in the system is 10 and the initial value uses 15 significant digits, the key space is 10 270 ≈2 897 , when the number of edge nodes increases to 50, the key space can increase to 10 1470 ≈2 4883 . Therefore, the proposed method has good brute-force attack resistance.

[0103] In addition, each edge node only has its own two sets of initial values and cannot infer the initial values of other edge nodes. If M Byzantine edge nodes collude to obtain the initial values of honest edge nodes (M < n), obviously, only when M = n - 1 can the Byzantine edge nodes infer all the initial values of the honest edge nodes. However, this assumption is meaningless and not applicable to the real scenario. In summary, the proposed chaotic encryption strategy can prevent the information leakage of edge nodes.

[0104] Theorem 2: As long as the TP server does not collude with the edge nodes, the dual-server update is secure.

[0105] Proof: Assuming that the attacker will contaminate the TP server, in order to analyze the security of the system, this paper builds a simulator executed in an ideal world to simulate the view of the TP server, that is, the value sent to the TP server by other participants during the execution of the simulated protocol. The ideal view of the TP server can be defined as IDEAL TP =(Bi',(W i -w)'), where, Bi', (W i -w)' is randomly generated by the simulator. In the real world, the realistic view of the TP server is REAL TP =(B i ,W i -w), P i ∈P. Because B i , W i -w internally superimposes a chaotic parameter model, which is generated by a chaotic sequence. The chaotic sequence has pseudo-randomness and can better conceal the model information. Therefore, B i , W i -w and Bi', (W i -w)' is computationally indistinguishable. In summary, the simulator generates a view that is computationally indistinguishable from reality.

[0106] If the attacker will contaminate the SP server, similarly, using the simulation-based security proof method, a simulator executed in the ideal world is constructed. The view of the SP server in the ideal world can be defined as Among them, Wi', Randomly generated by the simulator. The SP's realistic view is Because W i and The chaotic parameter model is superimposed inside, and the chaotic parameter model is generated by a chaotic sequence with pseudo-random properties, so W i , With Wi', Computationally indistinguishable, the simulator generates a view that is computationally indistinguishable from reality. In summary, the TP server and the SP server are ideal executions that are indistinguishable from reality; as long as the TP server does not collude with the edge node, the compromised TP server and SP server cannot infer any private information of the honest edge node.

[0107] 7. Experimentation and Evaluation

[0108] This experiment was conducted on a server with an Intel(R) i5-12600KF CPU, 16GB RAM, and NVIDIA 3070Ti, and was simulated using PyTorch 1.13.0 in Python 3.7.13.

[0109] 7.1 Experimental Setup

[0110] (1) Dataset

[0111] The experiment uses the Case Western Reserve University (CWRU) bearing dataset in the field of fault diagnosis

[37] With the public CIFAR-10 dataset

[38] CDRFL was evaluated.

[0112] CWRU bearing dataset: The CWRU bearing dataset contains four states: normal state, inner ring fault, outer ring fault, and rolling element fault, each with different fault sizes.

[0113] CIFAR-10 dataset: The CIFAR-10 dataset has a total of 50,000 training samples and 10,000 test samples. It is suitable for image classification and contains color images of 10 categories, such as airplanes, cars, cats, etc.

[0114] (2) Data segmentation and hyperparameter setting

[0115] The CWRU bearing dataset and CIFAR-10 dataset are divided using independent and identically distributed (IID) and non-independent and identically distributed (Non-IID) methods. Specifically, IID division: randomly and evenly distribute the training samples of the dataset to each edge node; Non-IID division: divide the training samples of each label into 200 sample blocks, and each edge node randomly extracts 2 sample blocks of two labels, that is, each edge node only has data of 2 labels.

[0116] During the local training process, the network model consists of 3 convolutional layers and 3 fully connected layers. Both the convolutional layers and the fully connected layers use the ReLU function as the activation function. The learning rate of local training is set to 0.01, the SGD momentum is set to 0.9, the number of local iterations is set to 5, the initial assets of the edge nodes are set to 10, and the communication rounds and the number of edge nodes are set to 50.

[0117] (3) Baseline

[0118] ①FedAvg [2] :The edge node uploads the local model, and the server takes the mean to update the global model.

[0119] ② Reference

[12] : The edge nodes use chaotic sequences to scramble parameters and use CKKS homomorphic encryption technology to encrypt model parameters.

[0120] ③Krum

[16] :The edge node uploads the gradient information, the server selects several nearest neighbor edge nodes for each edge node and calculates their average gradient, and selects the smallest average gradient as the final aggregate gradient.

[0121] ④SignSGD

[35] :The edge node uploads the gradient symbol instead of the gradient value. The server accumulates the gradient symbol information of the edge node and obtains the global gradient symbol information. The edge node continues to perform local updates based on the global gradient symbol information.

[0122] ⑤Median

[36] :The edge node uploads its own local model, and the server takes the value to update the global model.

[0123] (4) Attack

[0124] The experiment considers two types of attacks: free-rider attack and label flipping attack. For free-rider attack, it is assumed that the Byzantine edge nodes randomly generate model parameters, and the experiment uses chaotic sequences to simulate randomly generated model parameters; for label flipping attack, it is assumed that the Byzantine edge nodes maliciously modify the labels of training samples to make the model's prediction results wrong.

[0125] 7.2 Fidelity Evaluation

[0126] In order to evaluate the fidelity of the method, the experiment compares CDRFL with the FedAvg method without setting an attacker. In terms of convergence, the experiment calculates the loss values ​​of CDRFL and FedAvg on the CWRU bearing dataset and the CIFAR-10 dataset. Figure 6 As shown in Figure 3, the loss curve of CDRFL converges on the two data sets and is very close to FedAvg. Therefore, CDRFL has good convergence.

[0127] At the same time, in order to evaluate the test accuracy of the global model, the experiment compares FedAvg and CDRFL on two datasets. Figure 7 It can be observed that the test accuracy of CDRFL is almost the same as that of FedAvg. This is because CDRFL uses the proposed chaotic encryption strategy to protect the local model of the edge node, and no noise is introduced during the encryption and aggregation process, so the test accuracy of the global model is not affected. Therefore, in both IID and Non-IID cases, the proposed method has good fidelity.

[0128] 7.3 Safety Assessment

[0129] 7.3.1 Test accuracy of CDRFL under Byzantine attack

[0130] Byzantine attackers want to reduce the overall accuracy of the global model on the test set, so this paper uses the test accuracy of the global model to evaluate the security performance of the method. The experiment compares the test accuracy of CDRFL and FedAvg with 10%-40% Byzantine edge nodes on two data sets. The attack methods are free-rider attack and label flipping attack respectively. Only the IID case is considered when defending against label flipping attack. As shown in Tables 3 and 4, although FedAvg has a high prediction accuracy in the absence of attack, after introducing 10%-40% Byzantine edge nodes, FedAvg's performance has seriously declined, and the test accuracy has dropped to 10.00% at the lowest. The impact of free-rider attack on FedAvg is greater than that of label flipping attack. Under free-rider attack, FedAvg's test accuracy drops by up to 87.87%, while under label flipping attack, it drops by up to 31.41%. After introducing 10%-40% of Byzantine edge nodes, CDRFL's test accuracy is less than 0.92% different from FedAvg without attack, and still maintains a high test accuracy. This is due to CDRFL combining the DBSCAN clustering method with the reputation score mechanism, which can identify abnormal models and effectively filter Byzantine edge nodes. Therefore, compared with FedAvg, CDRFL not only has good privacy protection capabilities, but also has better Byzantine robustness when facing attacks.

[0131] Table 3 Test accuracy of CDRFL and FedAvg under free-rider attack (%)

[0132]

[0133]

[0134] Table 4 Accuracy of CDRFL and FedAvg under label flipping attack (%)

[0135]

[0136] 7.3.2 Robustness Comparison of CDRFL and Baseline Solutions

[0137] To further evaluate the security of CDRFL, the experiment compared the test accuracy of CDRFL with that of the baseline solutions (Krum, Signsgd, Median). The experiment introduced 10-40% of Byzantine edge nodes into CDRFL and the baseline solutions respectively. Figure 8 and Fig. 9It can be seen that the prediction accuracy of CDRFL is generally higher than that of several other baseline schemes, and the accuracy is not affected by the increase in the number of Byzantine edge nodes. For example, in the IID case, when facing free-rider attacks, the test accuracy of CDRFL on the two data sets is 0.77% and 13.55% higher than that of other baseline schemes on average. When facing label flipping attacks, the test accuracy of CDRFL on the two data sets is 1.41% and 18.33% higher than that of other baseline schemes on average. This shows that CDRFL has stronger Byzantine robustness because when the scheme uses the DBSCAN clustering method, the neighborhood radius ε is set to half the median of the edge node norm and the minimum number of data points is This setting makes the abnormal model tend to appear in smaller clusters and helps to distinguish Byzantine edge nodes.

[0138] 7.3.3 Trend of reputation score changes under Byzantine attacks

[0139] The reputation score mechanism is a key part of CDRFL's ability to resist Byzantine attacks. In order to better visualize the reputation score mechanism, the experiment demonstrates the changes in the reputation score for the following two situations: (1) launching attacks only in a certain round; (2) launching attacks continuously. The experiment assumes that the models of edge nodes 1 to 5 have different numbers of abnormal layers, node 6 represents an honest edge node, and the threshold is set to 0.75. Fig.10 As shown in (a), if the Byzantine edge node launches an attack in the third round, the reputation score of the Byzantine edge node will drop sharply after the attack and fall below the threshold. In the subsequent iterations, the edge node remains honest and its reputation score will gradually rise. When the score exceeds the threshold, the edge node will participate in the aggregation again. However, if the Byzantine edge node continues to attack, its reputation score will continue to drop, as shown in Fig.10 As shown in (b), after continuous attacks, the reputation score of the Byzantine edge node will drop below 0.4. Since 10% of the assets of the Byzantine edge node are deducted in each round, when the assets are cleared, the node will be forced to exit the federated learning system. An attack may cause the edge node to be judged as a Byzantine edge node for multiple consecutive rounds, making it unable to participate in aggregation. Therefore, the reputation score mechanism can expand the punishment of the Byzantine edge node and has good defense capabilities against Byzantine attacks.

[0140] 7.4 Efficiency Evaluation

[0141] In terms of efficiency, we first test the convergence speed of CDRFL. The experiment introduces 10-30% of Byzantine edge nodes to CDRFL and FedAvg respectively, such as Fig.11 and Fig.12As shown in the figure, when facing different proportions of Byzantine attacks, the test accuracy of CDRFL is basically the same as FedAvg (no attack) in the same round, that is, the convergence speed of CDRFL test accuracy is similar to that of FedAvg without attack. In short, while taking into account both privacy protection and Byzantine robustness, CDRFL has almost no effect on the convergence speed of the model.

[0142] In order to further study the efficiency of CDRFL, the proposed method is compared with Paillier

[39] 、BFV

[40] and CKKS

[41] The time cost of the encryption method records the time it takes for the edge node to complete a calculation using different encryption methods (encryption, aggregation, decryption). As shown in Table 5, compared with the CKKS, BFV and Paillier encryption methods, the time cost of the proposed chaotic encryption strategy is reduced by 69.8%, 94.8% and 99.7% respectively. Because the proposed method uses chaotic sequences to encrypt the model, the main time consumption lies in the generation of chaotic sequences, which further shows that CDRFL does not bring too much burden to the system when implementing privacy protection.

[0143] Table 5 Time cost of different encryption methods (s)

[0144]

[0145] Finally, in order to intuitively study the training time of CDRFL, the experiment compares the time it takes to complete a training session of the proposed method, FedAvg, and the method in reference [6] on the CWRU bearing dataset IID. Fig.13 As shown in the figure, the time taken by the proposed method to complete a training is similar to that of FedAvg, and much lower than that of the solution in reference [6]. The time overhead of the proposed chaotic encryption strategy is related to the number of edge nodes. Compared with FedAvg, when the number of edge nodes increases from 10 to 40, the average training time of each edge node increases by 0.09s, while the average training time of each edge node in reference [6] is 3.64s more than that of FedAvg. This is because the core of the proposed chaotic encryption strategy lies in the generation of chaotic sequences without using complex cryptographic methods. This also further proves that CDRFL can achieve federated learning privacy protection and Byzantine robustness more efficiently.

[0146] 8. Conclusion

[0147] This paper proposes a robust federated learning method with chaotic encryption and dual-server empowerment. First, the edge nodes perform chaotic encryption on the model parameters. Secondly, a dual-server detection mode is constructed to hierarchically detect the local models of the edge nodes without leaking the privacy information of the edge nodes. Finally, the reputation mechanism is used to filter the Byzantine edge nodes and aggregate the model parameters of the honest edge nodes. The following conclusions are obtained:

[0148] (1) Aiming at the problem that the initial values ​​used by edge nodes in chaotic encryption are the same and single, a chaotic encryption strategy is proposed, which can not only ensure that edge nodes use different initial values ​​for encryption, but also be integrated with the robust aggregation method, and has good initial value sensitivity and key space. -15 The performance of the global model will drop below 10% due to the change of orders of magnitude. The key space increases with the number of edge nodes. When the number of edge nodes is 10, the key space can reach 2 897 , which is much larger than the key space of low-dimensional chaotic encryption scheme.

[0149] (2) A dual-server detection strategy for Byzantine edge nodes is proposed. With the assistance of the SP server, the TP server uses the DBSCAN clustering method to perform model layered detection on the edge nodes and filters the Byzantine edge nodes based on the reputation point mechanism. Experiments show that under Byzantine attacks, the test accuracy of CDRFL on the CWRU bearing dataset is improved by at least 0.89% compared with other baseline schemes, and on the CIFAR-10 dataset, it is improved by at least 13.89%, which improves the robustness of the model to a certain extent.

[0150] (3) A robust federated learning method with chaotic encryption and dual-server empowerment is proposed. The proposed method not only protects the privacy of edge nodes during model aggregation, but also detects and filters Byzantine edge nodes. Compared with CKKS, BFV and Paillier encryption methods, the encryption time overhead of the proposed method is reduced by up to 99.7%, effectively improving the efficiency of privacy protection.

[0151] Although the proposed method takes into account both the privacy protection and Byzantine robustness of federated learning, it does not consider the problem that the server may be subject to single-point attacks. The next step will be to use the blockchain framework for further in-depth research.

[0152] The references cited in the present invention are listed as follows:

[0153] [1] Zhang Zhigang, Yang Dongshu, Wu Hongxia. Research and application of data asset value assessment model [J]. Modern Electronic Technology, 2015, 38(20): [1]

[0154] [2]L.S.Vailshery.(2021).Internet of Things(IoT)—Statistics andFacts.[Online].Available:https: / / www.statista.com / study / 27915 / internet-of-things-iot-statista-dossier /

[0155] [3]Wikipedia.2018.FacebookCambridge Analytica DataScandal. https: / / en.wikipedia.org / wiki / Faceb ook-Cambridge_Analytica%_data_scandal.

[0156] [4]B.McMahan,E.Moore,D.Ramage,S.Hampson,and B.A.y Arcas,“Communication-efficient learning of deep networks from decentralized data,”in Proc.Int.Conf.Artif.Intell.Statist.,A.Singh and X.J.Zhu,Eds.,2017,pp.1273--1282.

[0157] [5]E.Bagdasaryan,A.Veit,Y.Hua,D.Estrin and V.Shmatikov,"How tobackdoor federatedlearning",inProc.Int.Conf.Artif.Intell.Stat.,Jun.2020,pp.2938-2948.

[0158] [6]A.N.Bhagoji,S.Chakraborty,P.Mittal,S.B.Calo,Analyzing FederatedLearning through anAdversarial Lens,2019,pp.634-643.

[0159] [7]H.B.McMahan,D.Ramage,K.Talwar,L.Zhang,Learning DifferentiallyPrivate RecurrentLanguage Models,2018.

[0160] [8] S.Shen, T.Zhu, D.Wu, W.Wang, W.Zhou, From distributed machine learning to federated learning: In the view of data privacy and security, Concurr.Comput.Pract.Exp.34(16)(2022).

[0161] [9] Y.Li, H.Li, G.Xu, T.Xiang, X.Huang, R.Lu, Toward Secure and Privacy-PreservingDistributed Deep Learning in Fog-Cloud Computing, IEEE InternetThings J.7(12)(2020)11460-11472.

[0162]

[10] G.Xu,H.Li,S.Liu,K.Yang,X.Lin,VerifyNet: Secure and VerifiableFederated Learning,IEEE Trans.Inf.Forensics Secur.15(2020)911-926.

[0163]

[11] Z.Zhang, L.Zhang, Q.Li, K.Wang, N.He, T.Gao, Privacy-enhanced momentumfederated learning via differential privacy and chaotic system in industrialCyber–Physical systems, ISATransactions 128(2022)17-31.

[0164]

[12] Zhang Zehui, Li Qingdan, Fu Yao, et al. Adaptive federated deep learning algorithm for non-independent and identically distributed data [J / OL]. Automation: 1-13 [2023-10-16]. DOI: 10.16383 / j.aas.c201018.

[0165]

[13] Zhao Qiao, Li Bo, Xiang Rongrong. Color image encryption algorithm based on chaotic system and dynamic DNA coding [J / OL]. Computer Measurement and Control: 1-12 [2023-10-13]

[0166]

[14] E.Bagdasaryan,A.Veit,Y.Hua,D.Estrin,V.Shmatikov,How To BackdoorFederatedLearning,2020,pp.2938-2948.

[0167]

[15] A.N.Bhagoji,S.Chakraborty,P.Mittal,S.B.Calo,Analyzing FederatedLearning through anAdversarial Lens,2019,pp.634-643.

[0168]

[16] P.Blanchard,E.M.E.Mhamdi,R.Guerraoui,J.Stainer,Machine learningwith adversaries:byzantine tolerant gradient descent,Proceedings ofthe 31stInternational Conference on NeuralInformation Processing Systems,CurranAssociates Inc.,Long Beach,California,USA,2017,pp.118–128.

[0169]

[17] Q.Xia,Z.Tao,Z.Hao,Q.Li,FABA:An Algorithm for Fast Aggregationagainst ByzantineAttacks in Distributed Neural Networks,Twenty-EighthInternational Joint Conference onArtificial Intelligence,2019.

[0170]

[18] T.Chu, García-Recuero,C.Iordanou,G.Smaragdakis,N.Laoutaris,Securing FederatedSensitive Topic Classification against PoisoningAttacks,CoRR abs / 2201.13086(2022).

[0171]

[19] K.Zhai, Q.Ren, J.Wang, C.Yan, Byzantine-robust federated learning viacredibilityassessment on non-IID data, Mathematical Biosciences and Engineering 19(2)(2022)1659-1676.

[0172]

[20] Y. Zhao, J. Chen, J. Zhang, D. Wu, J. Teng, S. Yu, PDGAN: A Novel PoisoningDefenseMethod in Federated Learning Using Generative Adversarial Network, 2020, pp.595-609.

[0173]

[21] Liu Biao, Zhang Fangjiao, Wang Wenxin, et al. Byzantine robust federated learning algorithm based on matrix mapping[J]. Journal of Computer Research and Development, 2021, 58(11): 2416-2429.

[0174]

[22] ARElkordy, ASAvestimehr, HeteroSAg: Secure Aggregation With Heterogeneous Quantization in Federated Learning, IEEE Transactions on Communications 70(4)(2022)2372-2386.

[0175]

[23] Wang Yongkang, Zhai Dihua, Xia Yuanqing. Robust aggregation algorithm against a large number of backdoor clients in federated learning[J]. Chinese Journal of Computers, 2023, 46(06): 1302-1314.

[0176]

[24] V.Tolpegin, S.Truex, MEGursoy, L.Liu, Data PoisoningAttacks AgainstFederated Learning Systems, Springer International Publishing, Cham, 2020, pp.480-501.

[0177]

[25] Y.Zhao,JJChen,JLZhang,D.Wu,M.Blumenstein,S.Yu,Detecting and mitigating poisoning attacks in federated learning using generativeadversarial networks,Concurr.Comput.-Pract.Exp.34(7)(2022)12

[0178]

[26] Z.Sun,P.Kairouz,ATSuresh,HBJAMcMahan,Can You ReallyBackdoor Federated Learning? ,abs / 1911.07963(2019).

[0179]

[27] C. Wu, X. Yang, S. Zhu, P. Mitra, Mitigating Backdoor Attacks in Federated Learning, CoRRabs / 2011.01767(2020).

[0180]

[28] Huang Xiuli, Yu Pengfei, Gao Xianzhou. Secure aggregation method for horizontal federated learning system[J / OL]. Computer Engineering and Applications: 1-13[2023-11-04].

[0181]

[29] Jiang Xiaoyu, Gu Ruichun, Zhang Huan. Research on blockchain-enabled multi-edge secure federated learning model[J / OL]. Computer Application Research: 1-7[2023-10-13].

[0182]

[30] Z. Zhang, N. He, Q. Li, K. Wang, H. Gao, T. Gao, DetectPMFL: Privacy-Preserving Momentum Federated Learning Considering Unreliable Industrial Agents, IEEE Transactions on Industrial Informatics 18(11)(2022)7696-7706.

[0183]

[31] Y.Miao, Z.Liu, H.Li, KKRChoo, RHDeng, Privacy-PreservingByzantine-RobustFederated Learning via Blockchain Systems, IEEETrans.Inf.Forensic Secur.17(2022)2848-2861.

[0184]

[32] Li Haiyang, Guo Jingjing, Liu Jiuzun, et al. Privacy-preserving Byzantine robust federated learning algorithm[J]. Journal of Xidian University, 2023, 50(04): 121-131.

[0185]

[33] M.Hao, H.Li, G.Xu, H.Chen, T.Zhang, Efficient, Private and RobustFederated Learning, Annual Computer Security Applications Conference, Association for Computing Machinery, Virtual Event, USA, 2021, pp.45–60.

[0186]

[34] ZZZhang, LBWu, CGMa, JXLi, J.Wang, Q.Wang, S.Yu, LSFL: ALightweight and Secure Federated Learning Scheme for Edge Computing, IEEETrans.Inf.Forensic Secur.18(2023)365-379.

[0187]

[35] J.Bernstein, Y.-X.Wang, K.Azizzadenesheli, A.Anandkumar, signSGD: Compressed Optimization for Non-Convex Problems, in: D.Jennifer, K.Andreas (Eds.) Proceedings of the 35th International Conference on Machine Learning, PMLR, Proceedings of Machine LearningResearch,2018,pp.560--569.

[0188]

[36] D.Yin,Y.Chen,R.Kannan,P.Bartlett,Byzantine-Robust DistributedLearning:Towards Optimal Statistical Rates,in:D.Jennifer,K.Andreas(Eds.)Proceedings of the 35th International Conference on Machine Learning,PMLR,Proceedings of Machine Learning Research,2018,pp.5650--5659.

[0189]

[37] L.Deng,The MNIST Database of Handwritten Digit Images for MachineLearning Research [Best ofthe Web],IEEE Signal Process.Mag.29(6)(2012)141-142.

[0190]

[38] Krizhevsky A,Nair V,Hinton G.The CIFAR-10dataset[DB / OL].[2023-04-01].https: / / www.cs.toronto.edu / ~kriz / cifar.html

[0191]

[39] P.Paillier,Public-Key Cryptosystems Based on Composite DegreeResiduosity Classes,1999,

[0192] pp.223-238.

[0193]

[40] Z.Brakerski,C.Gentry,V.Vaikuntanathan,(Leveled)fully homomorphicencryption withoutbootstrapping,2012,pp.309-325.

[0194]

[41] J.H.Cheon,A.Kim,M.Kim,Y.S.Song,Homomorphic Encryption forArithmetic ofApproximate Numbers,2017,pp.409-437。

Claims

1. A robust federated learning method with chaotic encryption and dual-server empowerment, characterized by: The implementation process of the method is: ① The edge node downloads the initial rolling bearing fault diagnosis model from the SP server; ② The edge node uses the local rolling bearing dataset to train the local model w i , encrypt the model parameters chaotically, upload W i To SP server, B i To TP server, i∈[1,n]; ③The SP server aggregates the encryption model W of all edge nodes through formula (8) i , get the average model w; Where: w i represents the local model and w represents the average model; ④SP server calculates W i -w, send W i -w to TP server; ⑤TP obtains the local model w according to formula (9) i The distance d from the average model w i , i∈[1,n], hierarchical calculation d i The l2 norm of the same layer is set to a set of {d1(k),…,d n (k)}k∈[1,K], use DBSCAN method to cluster them, identify outliers, and record the local model w i The number of normal and abnormal layers; d i is a vector with the same shape as w i same; ⑥W i Medium normal layer C i and the number of abnormal layers F i Assigning the shape parameters α and β of the Beta distribution, i∈[1,n], the TP server calculates the reputation score of each edge node. Then determine P i It is a Byzantine edge node; ⑦TP server aggregates the ciphertext B of honest edge nodes through formula (16) i , aggregate the results Send to SP server: ⑧ Encryption model W of SP server aggregating honest edge nodes i , the global model is restored through formulas (17)-(18): ⑨SP server sends w global To the honest edge nodes. Repeat the above steps ②-⑨ until the number of iterations is reached.

2. A robust federated learning method with chaotic encryption and dual-server empowerment according to claim 1, characterized in that: In step ②, the chaotic encryption strategy used in the chaotic encryption of model parameters is: For edge node P i First, P i Receive the global model w from the SP server global , using local rolling bearing data to train and obtain the local model w i ; Next, P i Randomly generate a set of random numbers shared To P j And from P j take over P j ∈P and j≠i; after the sharing between edge nodes is completed, P i Available and Two sets of random numbers; If the edge node P i by As the initial value of the Logistic chaotic system, the Logistic chaotic system can obtain a set of chaotic sequences through iteration. The elements in the chaotic sequence replace the model parameters in turn to construct a new model, which is called the "chaotic parameter model" and is recorded as The two sets of random numbers are used to construct corresponding chaotic parameter models according to the above steps, and the local model w is implemented through formulas (4)-(6) i The encryption of is a shape with w i Same, the internal element size is b i The vector of To facilitate the subsequent detection of Byzantine edge nodes, edge node P i We also need to calculate a ciphertext B i , as shown in formula (7): Finally, upload W i To SP server, B i to the TP server.

3. A chaotic encryption and dual-server empowerment robust federated learning method according to claim 2, characterized in that: In step ⑤, TP server layered computing i The l2 norm of i (k), k∈[1,K], K is the number of layers of the model; the TP server sets the norms of all edge nodes in the same layer to a set {d1(k),…,d n (k)}, cluster them using the DBSCAN clustering method, output outliers, traverse all layers, and finally identify the local model w i The number of normal and abnormal layers.

4. A chaotic encryption and dual-server empowerment robust federated learning method according to claim 3, characterized in that: In step ⑥, the credit score mechanism is: Credit score It consists of three parts: ① Latest score A i : The score determined by the edge node's performance in the current round; ② Historical score N i : The score determined by the performance of the edge node in the past Q rounds; ③ Continuous honesty score h: The score determined by whether the edge node continues to perform honestly, reputation score The calculation method of is shown in formula (10), where q+p+h=1; Let the expected value of the Beta distribution be the latest score A i , as shown in formulas (11)-(12), where the two shape parameters of the Beta distribution are given by the local model w i Normal number of layers C i and the number of abnormal layers F i Assignment, ζ+θ=10, θ is much larger than ζ; A time decay mechanism is used to assist in calculating the historical score N of edge nodes. i , reducing but not ignoring the impact of the past Q round scores on the current round reputation score, the calculation method is shown in formulas (13)-(15): If the edge node behaves honestly in r consecutive rounds, it will receive a reward of h. Finally, the final reputation score is calculated by formula (10): Set the threshold to δ, if Then the edge node is judged as a Byzantine edge node, otherwise it is an honest edge node.

5. A chaotic encryption and dual-server enabled robust federated learning system, characterized by: The system has a program module corresponding to the steps of any one of claims 1 to 4 above, and executes the steps in the robust federated learning method with chaotic encryption and dual-server empowerment during operation.

6. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and the computer program is configured to implement the steps of a robust federated learning method for chaotic encryption and dual-server empowerment described in any one of claims 1-4 when called by a processor.

Citation Information

Patent Citations

  • Robust federated learning method for efficient privacy protection

    CN115660050A

  • Byzantine robust federated learning-oriented user data privacy protection system and method

    CN117395067A

  • Rolling bearing fault diagnosis method and system based on cloud-edge collaborative federated model migration

    CN118035893A

  • Wind power prediction system and method based on chaos-homomorphic encryption and federated learning

    CN118381674A

  • Anti-collusion Byzantine robust privacy protection federated learning optimization method

    CN118690406A

Cited By

  • Edge encryption experimental design method for aircraft multidisciplinary optimization design

    CN121118239A