Federal learning-oriented double-server multi-round verifiable security aggregation method

By adopting technical means such as dual-server architecture and separable homomorphic commitment in federated learning, the shortcomings of existing security aggregation solutions in dynamic user participation, model inconsistency attacks and verifiability are solved, and efficient and secure aggregation results verification is achieved.

CN119995826APending Publication Date: 2025-05-13FUJIAN NORMAL UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510134964.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-07
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The existing secure aggregation schemes in federated learning have shortcomings in dynamic user participation, model inconsistency attacks, and verifiability, resulting in poor running performance, vulnerability and inability to effectively verify the aggregation results.

Method used

A multi-round verifiable secure aggregation method based on a dual-server architecture is designed, using separate homomorphic commitments and one-time password book. Through the dual-server architecture and lightweight password primitives, the user-side verification of aggregation results and resistance to model inconsistent attacks is achieved.

Benefits of technology

This solution effectively supports dynamic user participation, resists model inconsistent attacks, and realizes verifiability of aggregation results, reducing computational overhead and communication costs, and improving security and efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995826A_ABST
    Figure CN119995826A_ABST
Patent Text Reader

Abstract

The invention provides a federated learning-oriented dual-server multi-round verifiable security aggregation method, which comprises the following steps that: all users locally use a Masking algorithm to generate an update value after a mask is added, call Enc to generate a mask ciphertext, call a commitment algorithm Commit to generate a separable homomorphic commitment of the update value, and generate a secure aggregation result; sending the value added with the mask and a commitment value related to the random number to an aggregation server, and sending a complete commitment and a ciphertext related to a mask key to an auxiliary aggregation server; then the two servers complete the aggregation task and send an aggregation result to all users; and after the user receives the aggregation result of the two servers, calling UnMasking locally to recover to obtain the aggregation result, then separating a commitment value related to the message by using a separation algorithm Se, then calling a message commitment algorithm PCommit to generate a value only related to the message commitment, and finally comparing whether the two commitment values are equal or not, if the two commitment values are equal, indicating that the aggregation result is correct, and if the two commitment values are not equal, indicating that the aggregation result is correct. Otherwise, if the aggregation result is incorrect, the subsequent training is terminated.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of information security, and in particular relates to a dual-server multi-round verifiable security aggregation method for federated learning. Background Art

[0002] Secure aggregation in federated learning is crucial to protecting user privacy. It ensures that model updates are masked or encrypted and that the server cannot access individual user updates, thereby effectively avoiding model back-propagation attacks. Although current research has made some achievements in multi-round aggregation and communication optimization, it still faces the following key challenges: (i) The dynamic user participation process is complex. Since a complex communication graph needs to be established when users join or exit the training process, the current scheme has poor performance and scalability; (ii) Model inconsistency attacks. Malicious servers may distribute inconsistent model data, thereby launching model inconsistency attacks, posing a serious threat to the privacy of system users; (iii) Poor verifiability. Since most schemes lack an effective verification mechanism, that is, the client cannot effectively verify the correctness of the server-side aggregation, which may cause malicious aggregation servers to return inaccurate or malicious aggregation results. Summary of the invention

[0003] In view of the defects and shortcomings of the above-mentioned prior art, the present invention designs a secure aggregation solution based on a dual-server architecture that supports user-side verification of aggregation results, which not only effectively supports user dynamic participation, but also effectively resists model inconsistency attacks.

[0004] The present invention defines a new cryptographic primitive called separable homomorphic commitment. Usually, a secure separable homomorphic commitment scheme includes five algorithms, namely, the initialization algorithm (Setup), the commitment algorithm (Commit), the separation algorithm (Se), the message commitment algorithm (PCommit), and the opening commitment algorithm (Reveal). The basic structure of each algorithm is as follows:

[0005] 1. Initialization algorithm (Setup): The algorithm inputs the security parameter λ and outputs the public parameter pp.

[0006] 2. Commit algorithm: The algorithm inputs public parameters pp, message m and random number r, and outputs a complete commitment c = (c m ,c r ), where c m is the commitment value associated with the message, c r is the commitment value associated with the random number r.

[0007] 3. Separation algorithm (Se): The algorithm inputs public parameters pp, the complete commitment c and the commitment value c associated with the random number r r , output the commitment value c associated with the message m.

[0008] 4. Message Commitment Algorithm (PCommit): The algorithm inputs public parameters pp and message m, and outputs a commitment value c related to the message m .

[0009] 5. Open commitment algorithm (Reveal): The algorithm inputs public parameters pp, message m, complete commitment value c and random number r. If the commitment value is a valid commitment corresponding to the message, the algorithm returns 1 otherwise it returns 0.

[0010] The above separable homomorphic commitment scheme should have the following two properties:

[0011] 1) Separability: The complete commitment c can be divided into two parts, namely c = (c m ,c r ), where c m is the commitment value associated with the message, c r is the commitment value associated with the random number r.

[0012] 2) Homomorphism: Define the random number space as R and the message space as, we have Commit(m0+m1; r0+r1)=Commit(m0; r0)·Commit(m1; r1) always holds, and the scheme is homomorphic.

[0013] In addition, the present invention also relates to a one-time pad (OTP). Generally, an OTP scheme includes two algorithms: masking and unmasking. Each algorithm is specifically constructed as follows:

[0014] 1. Masking: The algorithm inputs the message x and the mask key k, and outputs the encrypted result after masking.

[0015] 2. UnMasking: The algorithm inputs the encrypted message with a mask added and key k, output message plaintext m.

[0016] Therefore, as a federated learning security aggregation scheme based on dual servers, the present invention generally implements a corresponding architecture that includes four entities: system administrator, user, aggregation server, and auxiliary server. First, the system administrator calls the initialization Setup algorithm to determine the system parameters and distributes them to other entities; all users use the Masking algorithm locally to generate the updated value after adding the mask, call Enc to generate the masked ciphertext, call the commitment algorithm Commit to generate a separable homomorphic commitment of the updated value, send the masked value and the commitment value related to the random number to the aggregation server, and send the complete commitment and the mask key related ciphertext to the auxiliary aggregation server; then the two servers complete the aggregation task and send the aggregation result to all users. After the user receives the aggregation results of the two servers, he calls UnMasking locally to recover the aggregation results, and then uses the separation algorithm Se to separate the commitment value related to the message, and then calls the message commitment algorithm PCommit to generate a value related only to the message commitment, and finally compares whether the two commitment values ​​are equal. If they are equal, it indicates that the aggregation result is correct, otherwise the aggregation result is incorrect, and the user will terminate the subsequent training.

[0017] Due to the dual-server architecture adopted in the present invention, the aggregation results are only visible to users, which effectively avoids model inconsistency attacks initiated by malicious servers; in addition, the separable homomorphic commitment proposed in the present invention combined with the dual-server architecture can realize the correctness verification of the aggregation results, avoiding the risk of malicious aggregation servers returning erroneous results; finally, the present invention only involves lightweight cryptographic primitives, thereby ensuring that the present invention has the characteristics of low computational overhead, low communication cost, etc.

[0018] The purpose of the present invention is to design a secure aggregation solution based on a dual-server architecture, aiming to solve the current problems in the existing secure aggregation, such as complex dynamic user joining, susceptibility to model inconsistency attacks, and unverifiable aggregation results. It ensures that the performance of the federated learning training model is not lost while ensuring that it is independent of the training model. In addition, it effectively reduces the computing overhead and communication cost, and meets the development needs of security, efficiency, and verifiable results.

[0019] The core content of the present invention includes the following four stages:

[0020] 1. System initialization (Setup): In this stage, the system public parameter pp and the specific cryptographic scheme used are determined according to the security parameter λ. Each user generates a private key sk for OTP. i,t , server S1 generates a public-private key pair (sk s ,pk s ) and make the public key public. In the subsequent communication process, the communication between the user and the server will be encrypted by the other party's public key by default.

[0021] 2. Masking and Reporting: User Ui By Masking(x i,t ,sk i,t ) Get the masked update Then U i Call the algorithm Enc(pk s ,sk i,t ) Generate ciphertext CT i,t To achieve verifiability, U i Make a separable homomorphic commitment Commit(x) to the submitted input i,t ,r i,t )=c i,t =(c i,m ,c i,r ), where r i,t is the random number selected when making the commitment, c i,m To update x i,t The associated commitment value, c i,r For i,t The relevant commitment value, finally U i send Send to S0 (CT i,t ,c i,t ) to the secondary server S1.

[0022] 3. Collection and Aggregation: In this phase, the server completes the aggregation task. Specifically, S0 aggregates all user updates. Simultaneous calculation S1 first uses the private key to decrypt and obtain all user mask keys sk i,t = Dec(sk s ,CT i,t ), and then calculate and Finally, S0 and S1 send and (SK t ,C t ) to all users.

[0023] 4. Unmasking and Verification: In this stage, the user calculates and verifies the final aggregation result based on the calculation results returned by S0 and S1. First, user U i Decrypt to get the final updated aggregation result To further verify the correctness of the aggregation results, U i Use the separation algorithm in separable homomorphic commitment to extract the commitment value C related only to the message m =Se(C t ,C r ), then Ui Using the message commitment algorithm Among them, pp c is the public parameter based on the separable homomorphic commitment. Finally, U i verify Is it true? If so, the aggregation result is correct. Otherwise, the aggregation result is wrong. i Terminate further training.

[0024] The technical solution specifically adopted by the present invention to solve the technical problem is:

[0025] A dual-server multi-round verifiably secure aggregation method for federated learning: all users use the Masking algorithm locally to generate masked update values, call Enc to generate masked ciphertext, call the commitment algorithm Commit to generate a separable homomorphic commitment of the update value, send the masked value and the commitment value related to the random number to the aggregation server, and send the complete commitment and the ciphertext related to the mask key to the auxiliary aggregation server; then the two servers complete the aggregation task and send the aggregation result to all users; after the user receives the aggregation results from the two servers, he calls UnMasking locally to restore the aggregation result, and then uses the separation algorithm Se to separate the commitment value related to the message, and then calls the message commitment algorithm PCommit to generate a value only related to the message commitment, and finally compares whether the two commitment values ​​are equal. If they are equal, it indicates that the aggregation result is correct, otherwise the aggregation result is incorrect, and subsequent training is terminated.

[0026] Furthermore, before all users generate the masked update value locally using the Masking algorithm, the system is also initialized: each user generates a private key sk for the one-time password. i,t , assists the aggregation server S1 to generate a public-private key pair (sk s ,pk s ) and make the public key public. In the subsequent communication process, the communication between the user and the server is encrypted by the other party's public key by default.

[0027] Furthermore, all users locally use the Masking algorithm to generate the updated value after adding the mask, call Enc to generate the masked ciphertext, call the commitment algorithm Commit to generate a separable homomorphic commitment of the updated value, send the masked value and the commitment value related to the random number to the aggregation server, and send the complete commitment and the ciphertext related to the masked key to the auxiliary aggregation server. Specifically: User U i By Masking(x i,t ,sk i,t ), where x i,t Update the value of the tth round for the i-th user and get the masked update Then the encryption algorithm Enc(pk s ,sk i,t ) Generate ciphertext CT i,t ; User U i Make a separable homomorphic commitment Commit(x) to the submitted input i,t ,r i,t )=c i,t =(c i,m ,c i,r ), where r i,t is the random number selected when making the commitment, c i,m To update x i,t The associated commitment value, c i,r For i,t The relevant commitment value, the last user U i send To the aggregation server S0, send (CT i,t ,c i,t ) to the secondary aggregation server S1.

[0028] Furthermore, the specific process of the two servers completing the aggregation task and sending the aggregation result to all users is as follows: the aggregation server S0 aggregates all user updates in represents a continuous and commutative group operation; and computes The auxiliary aggregation server S1 first uses the private key to decrypt and obtain the mask key sk of all users i,t = Dec(sk s ,CT i,t ), and then calculate and Finally, the aggregation server S0 and the auxiliary aggregation server S1 send and (SK t ,C t ) to all users.

[0029] Furthermore, after receiving the aggregation results from the two servers, the user locally calls UnMasking to recover the aggregation results, and then uses the separation algorithm Se to separate the commitment value related to the message, and then calls the message commitment algorithm PCommit to generate a value only related to the message commitment, and finally compares whether the two commitment values ​​are equal. If they are equal, it indicates that the aggregation result is correct, otherwise the aggregation result is incorrect, and the subsequent training is terminated. Specifically, the user calculates the final aggregation result based on the calculation results returned by S0 and S1 and verifies: First, user U i Decrypt to get the final updated aggregation result And use the separation algorithm in the separable homomorphic commitment to extract the commitment value C that is only related to the messagem =Se(C t ,C r ), then U i Using the message commitment algorithm Among them, pp c is the public parameter based on separable homomorphic commitment; finally, user U i verify Is it true? If it is true, the aggregation result is correct. Otherwise, the aggregation result is wrong, and subsequent training is terminated.

[0030] Furthermore, the separable homomorphic commitment includes: an initialization algorithm, a commitment algorithm, a separation algorithm, a message commitment algorithm and an open commitment algorithm:

[0031] Initialization algorithm: input security parameter λ, output public parameter pp;

[0032] Commitment algorithm: input public parameter pp, message m and random number r, output complete commitment c = (c m ,c r ), where c m is the commitment value associated with the message, c r is a commitment value associated with the random number r. The two commitment values ​​are separable, and the commitment algorithm is homomorphic.

[0033] Separation algorithm: input public parameter pp, complete commitment c and commitment value c associated with random number r r , output the commitment value c associated with the message m ;

[0034] Message commitment algorithm: input public parameters pp and message m, output commitment value c related to the message m ;

[0035] Open commitment algorithm: input public parameter pp, message m, complete commitment value c and random number r, if the commitment value is a valid commitment corresponding to the message, it returns 1, otherwise it returns 0.

[0036] Furthermore, the one-time pad includes the algorithm steps of masking and demasking:

[0037] Masking: Input message x and the current mask key k, and output the masked encryption result

[0038] Unmask: Enter the masked encrypted message and key k, output message plaintext m.

[0039] Furthermore, the system initialization process also includes: determining the system public parameter pp and the specific cryptographic scheme to be used according to the security parameter λ.

[0040] And, a dual-server multi-round verifiable secure aggregation system for federated learning: it includes at least three entities: users, aggregation servers and auxiliary aggregation servers; all users use the Masking algorithm locally to generate masked update values, call Enc to generate masked ciphertexts, call the commitment algorithm Commit to generate separable homomorphic commitments of the updated values, send the masked values ​​and the commitment values ​​related to the random numbers to the aggregation server, and send the complete commitment and the ciphertext related to the mask key to the auxiliary aggregation server; then the two servers complete the aggregation task and send the aggregation results to all users; after the user receives the aggregation results from the two servers, he calls UnMasking locally to restore the aggregation results, and then uses the separation algorithm Se to separate the commitment values ​​related to the message, and then calls the message commitment algorithm PCommit to generate values ​​only related to the message commitment, and finally compares whether the two commitment values ​​are equal. If they are equal, it indicates that the aggregation result is correct, otherwise the aggregation result is incorrect, and subsequent training is terminated.

[0041] An electronic device comprises a memory, a processor and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the steps of a dual-server multi-round verifiable secure aggregation method for federated learning as described above are implemented.

[0042] A non-transitory computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of a dual-server multi-round verifiable security aggregation method for federated learning as described above.

[0043] Compared with the prior art, the present invention and its preferred embodiments have at least the following advantages:

[0044] 1. Dual-server architecture and support for dynamic user participation. Specifically, the present invention involves two servers, S0 and S1. S0 is responsible for aggregating masked updates, and S1 is responsible for aggregating commitment-related values. The solution in the present invention does not require the establishment of a complex communication graph. When a user joins or leaves, there is no need to re-establish a complex communication graph. After obtaining the server public key, the user can dynamically participate in training.

[0045] 2. Anti-model inconsistency attack and reversal attack. The solution of the present invention can complete secure aggregation, and complete aggregation under the premise that both servers cannot obtain the aggregation results, effectively resisting model inconsistency attacks, and the solution has stronger security.

[0046] 3. The aggregation results are verifiable. In order to save resources, malicious servers may return incorrect aggregation results or send different aggregation results to different users. The present invention allows users to verify whether the aggregation results are correct locally, effectively resisting malicious servers from returning incorrect results.

[0047] Compared with the related prior art in this field such as CN 114696990A "Multi-party computing method, system and related equipment based on fully homomorphic encryption", the present invention aims to realize multi-round secure aggregation of model training and update of each client in federated learning, dynamic user update and verifiable aggregation results. The present invention includes 2 servers and N training participants, there is no data demander, and N participants use the computing resources of 2 servers to complete the secure aggregation of federated learning. The obvious advantages provided include:

[0048] Stronger security: First, when the entities in the present invention interact, the user's plain text information is not involved. Second, the dual servers in the present invention cannot access the final aggregation results, which effectively avoids model inconsistency attacks; finally, the present invention can verify the correctness of the aggregation results, effectively avoiding malicious servers returning incorrect or malicious aggregation results.

[0049] Higher efficiency: The present invention only involves lightweight primitives such as commitment and one-time pad. The performance of the present invention has obvious advantages under the dual-server architecture, especially for clients with limited computing power, as the present invention does not require frequent interactions and calculations. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] The present invention is further described in detail below with reference to the accompanying drawings and specific embodiments:

[0051] Figure 1 The following is the architecture and flow chart of the embodiment of the present invention. DETAILED DESCRIPTION

[0052] In order to make the features and advantages of this patent more obvious and easy to understand, the following embodiments are specifically described in detail as follows:

[0053] It should be noted that the following detailed descriptions are illustrative and are intended to provide further explanation of the present application. Unless otherwise specified, all technical and scientific terms used in this specification have the same meanings as those commonly understood by those skilled in the art to which the present application belongs.

[0054] It should be noted that the terms used herein are only for describing specific embodiments and are not intended to limit the exemplary embodiments according to the present application. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. In addition, it should be understood that when the terms "comprise" and / or "include" are used in this specification, it indicates the presence of features, steps, operations, devices, components and / or combinations thereof.

[0055] In order to facilitate the detailed description of the present invention, the relevant basic concepts are first described in a unified manner.

[0056] 1. Symbols and definitions

[0057] S0: aggregation server.

[0058] S1: Secondary aggregation server.

[0059] (pk s ,sk s ): S_1’s public and private key pair.

[0060] U i : User i, let the number of users participating in each round of training be n,i∈[1,n].

[0061] sk i :U i The private key of

[0062] Continuous and commutative group operations.

[0063] x i,t : The updated value of user i in round t.

[0064] User i updates the local masked value in round t.

[0065] c i,t : The commitment value associated with the message.

[0066] c i,r : Commitment value associated with the random number at the time of commitment.

[0067] Masked aggregation value of round t.

[0068] C r :All c in round t i,r The aggregate value of .

[0069] C m :All c in round t i,m The aggregate value of .

[0070] 2. Dual-server multi-round verifiable secure aggregation scheme for federated learning

[0071] The solution provided by the present invention mainly includes four stages: system initialization (Setup), masking and reporting (Masking and Report), collection and aggregation (Collection and Aggregation), unmasking and verification (Unmasking and Verification), which are as follows:

[0072] 1. System initialization (Setup): In this stage, the system public parameter pp and the specific cryptographic scheme used are determined according to the security parameter λ. Each user generates a private key sk for OTP. i,t, server S1 generates a public-private key pair (sk s ,pk s ) and make the public key public. In the subsequent communication process, the communication between the user and the server will be encrypted by the other party's public key by default.

[0073] 2. Masking and Reporting: User U i By Masking(x i,t ,sk i,t ) Get the masked update Then U i Call the algorithm Enc(pk s ,sk i,t ) Generate ciphertext CT i,t To achieve verifiability, U i Make a separable homomorphic commitment Commit(x) to the submitted input i,t ,r i,t )=c i,t =(c i,m ,c i,r ), where r i,t is the random number selected when making the commitment, c i,m To update x i,t The associated commitment value, c i,r For i,t The relevant commitment value, finally U i send Send to S0 (CT i,t ,c i,t ) to the secondary server S1.

[0074] 3. Collection and Aggregation: In this phase, the server completes the aggregation task. Specifically, S0 aggregates all user updates. Simultaneous calculation S1 first uses the private key to decrypt and obtain all user mask keys sk i,t = Dec(sk s ,CT i,t ), and then calculate and Finally, S0 and S1 send and (SK t ,C t ) to all users.

[0075] 4. Unmasking and Verification: In this stage, the user calculates and verifies the final aggregation result based on the calculation results returned by S0 and S1. First, user Ui Decrypt to get the final updated aggregation result To further verify the correctness of the aggregation results, U i Use the separation algorithm in separable homomorphic commitment to extract the commitment value C related only to the message m =Se(C t ,C r ), then U i Using the message commitment algorithm Among them, pp c is the public parameter based on the separable homomorphic commitment. Finally, U i verify Is it true? If so, the aggregation result is correct. Otherwise, the aggregation result is wrong. i Terminate further training.

[0076] 3. Systematic implementation of a dual-server multi-round verifiable secure aggregation scheme for federated learning

[0077] The typical architecture corresponding to the implementation of this system includes four entities: system administrator, user, server S0, and auxiliary server S1. First, the system administrator calls the initialization Setup algorithm to determine the system parameter pp and distributes the system parameter pp to all other entities (omitted in the figure); all users use the Masking algorithm locally to generate the updated value after adding the mask Then call Enc to generate the masked ciphertext CT i , calling the Commit algorithm to generate a separable homomorphic commitment to the updated value (c i,t ,c i,r ),Will and S0 and S1 send them separately. Then S0 and S1 complete the aggregation and send and (SK t ,C t ) to all users. After receiving the aggregation results of S0 and S1, the user calls UnMasking locally to recover the aggregation result X t , and then use the Se algorithm to separate the commitment value C associated with the message m , call the message commitment algorithm PCommit to generate values ​​only related to the message commitment Final comparison Is it true? If it is true, it means that the aggregation result is correct. Otherwise, the aggregation result is incorrect and the user will terminate the subsequent training.

[0078] Based on the same inventive concept, the present invention also provides a computer device, which includes: one or more processors, and a memory for storing one or more computer programs; the program includes program instructions, and the processor is used to execute the program instructions stored in the memory. The processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. It is the computing core and control core of the terminal, which is used to implement one or more instructions, specifically for loading and executing one or more instructions in a computer storage medium to implement the above method.

[0079] It needs to be further explained that, based on the same inventive concept, the present invention also provides a computer storage medium, on which a computer program is stored, and the computer program is executed by a processor to execute the above method. The storage medium can adopt any combination of one or more computer-readable media. The computer-readable medium can be a computer-readable signal medium or a computer-readable storage medium. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electrical, magnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples (non-exhaustive list) of computer-readable storage media include: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, a computer-readable storage medium can be any tangible medium containing or storing a program, which can be used by an instruction execution system, device or device or used in combination with it.

[0080] In the description of this specification, the description with reference to the terms "one embodiment", "example", "specific example", etc. means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present disclosure. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.

[0081] The above shows and describes the basic principles, main features and advantages of the present disclosure. Those skilled in the art should understand that the present disclosure is not limited by the above embodiments, and the above embodiments and descriptions are only for explaining the principles of the present disclosure. Without departing from the spirit and scope of the present disclosure, the present disclosure may have various changes and improvements, and these changes and improvements fall within the scope of the present disclosure to be protected.

[0082] This patent is not limited to the above-mentioned optimal implementation mode. Anyone can derive various other forms of a dual-server multi-round verifiable security aggregation method for federated learning under the inspiration of this patent. All equal changes and modifications made according to the scope of the patent application of this invention should be covered by this patent.

Claims

1. A dual-server multi-round verifiable secure aggregation method for federated learning, characterized by: All users use the Masking algorithm locally to generate the updated value after adding the mask, call Enc to generate the masked ciphertext, call the commitment algorithm Commit to generate a separable homomorphic commitment of the updated value, send the masked value and the commitment value related to the random number to the aggregation server, and send the complete commitment and the ciphertext related to the mask key to the auxiliary aggregation server; The two servers then complete the aggregation task and send the aggregation results to all users. After receiving the aggregation results from the two servers, the user calls UnMasking locally to recover the aggregation results, and then uses the separation algorithm S e Separate the commitment value related to the message, then call the message commitment algorithm PCommit to generate a value only related to the message commitment, and finally compare whether the two commitment values ​​are equal. If they are equal, it indicates that the aggregation result is correct. Otherwise, the aggregation result is incorrect, and subsequent training is terminated.

2. The dual-server multi-round verifiable secure aggregation method for federated learning according to claim 1, characterized in that: Before all users generate the updated value after adding the mask locally using the Masking algorithm, the system is also initialized: each user generates a private key sk for the one-time password i,t , assists the aggregation server S1 to generate a public-private key pair (sk s , pk s ) and make the public key public. In the subsequent communication process, the communication between the user and the server is encrypted by the other party's public key by default.

3. The dual-server multi-round verifiable secure aggregation method for federated learning according to claim 2, characterized in that: All users use the Masking algorithm locally to generate the updated value after adding the mask, call Enc to generate the masked ciphertext, call the commitment algorithm Commit to generate a separable homomorphic commitment of the updated value, send the masked value and the commitment value related to the random number to the aggregation server, and send the complete commitment and the ciphertext related to the mask key to the auxiliary aggregation server. Specifically: User U i By Masking(x i,t ,sk i,t ), where x i,t Update the value of the tth round for the i-th user and get the masked update Then the encryption algorithm Enc(pk s ,sk i,t ) Generate ciphertext CT i,t ; User U i Make a separable homomorphic commitment Commit(x) to the submitted input i,t , r i,t )=c i,t =(c i,m , c i,r ), where r i,t is the random number selected when making the commitment, c i,m To update x i,t The associated commitment value, c i,r For i,t The relevant commitment value, the last user U i send To the aggregation server S0, send (CT i,t , c i,t ) to the secondary aggregation server S1.

4. The dual-server multi-round verifiable secure aggregation method for federated learning according to claim 3, characterized in that: The specific process of the two servers completing the aggregation task and sending the aggregation results to all users is as follows: Aggregation server S0 aggregates all user updates where ⊙ represents a continuous and commutative group operation; and computes The auxiliary aggregation server S1 first uses the private key to decrypt and obtain the mask key sk of all users i,t = Dec(sk s , CT i,t ), and then calculate and Finally, the aggregation server S0 and the auxiliary aggregation server S1 send and (SK t , C t ) to all users.

5. The dual-server multi-round verifiable secure aggregation method for federated learning according to claim 4, characterized in that: After receiving the aggregated results from the two servers, the user locally calls UnMasking to recover the aggregated results, and then uses the separation algorithm S e Separate the commitment value related to the message, then call the message commitment algorithm PCommit to generate a value related only to the message commitment, and finally compare whether the two commitment values ​​are equal. If they are equal, it means that the aggregation result is correct. Otherwise, the aggregation result is incorrect, and the subsequent training is terminated. Specifically: the user calculates the final aggregation result based on the calculation results returned by S0 and S1 and verifies: First, user U i Decrypt to get the final updated aggregation result And use the separation algorithm in the separable homomorphic commitment to extract the commitment value C that is only related to the message m =Se(C t , C r ), then U i Using the message commitment algorithm Among them, pp c is the public parameter based on separable homomorphic commitment; finally, user U i verify Is it true? If it is true, the aggregation result is correct. Otherwise, the aggregation result is wrong, and subsequent training is terminated.

6. The dual-server multi-round verifiable secure aggregation method for federated learning according to claim 1, characterized in that: The separable homomorphic commitment includes: initialization algorithm, commitment algorithm, separation algorithm, message commitment algorithm and open commitment algorithm: Initialization algorithm: input security parameter λ, output public parameter pp; Commitment algorithm: input public parameter pp, message m and random number r, output complete commitment c = (c m , c r ), where c m is the commitment value associated with the message, c r is a commitment value associated with the random number r. The two commitment values ​​are separable, and the commitment algorithm is homomorphic. Separation algorithm: input public parameter pp, complete commitment c and commitment value c associated with random number r r , output the commitment value c associated with the message m ; Message commitment algorithm: input public parameters pp and message m, output commitment value c related to the message m ; Open commitment algorithm: input public parameter pp, message m, complete commitment value c and random number r, if the commitment value is a valid commitment corresponding to the message, it returns 1, otherwise it returns 0.

7. The dual-server multi-round verifiable secure aggregation method for federated learning according to claim 2, characterized in that: The one-time pad includes the algorithm steps of masking and unmasking: Masking: Input message x and the current mask key k, and output the masked encryption result Unmask: Enter the masked encrypted message and key k, output message plaintext m.

8. The dual-server multi-round verifiable secure aggregation method for federated learning according to claim 2, characterized in that: The system initialization process also includes: determining the system public parameter pp and the specific cryptographic scheme to be used according to the security parameter λ.

9. A dual-server multi-round verifiable secure aggregation system for federated learning, characterized by: It includes at least three entities: users, aggregation servers, and auxiliary aggregation servers. All users use the Masking algorithm locally to generate the updated value after adding the mask, call Enc to generate the masked ciphertext, call the commitment algorithm Commit to generate a separable homomorphic commitment of the updated value, send the masked value and the commitment value related to the random number to the aggregation server, and send the complete commitment and the ciphertext related to the mask key to the auxiliary aggregation server. The two servers then complete the aggregation task and send the aggregation results to all users; after the user receives the aggregation results from the two servers, he calls UnMasking locally to restore the aggregation results, and then uses the separation algorithm Se to separate the commitment value related to the message, and then calls the message commitment algorithm PCommit to generate a value only related to the message commitment. Finally, compare whether the two commitment values ​​are equal. If they are equal, it indicates that the aggregation result is correct. Otherwise, the aggregation result is incorrect, and subsequent training is terminated.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the steps of a dual-server multi-round verifiable security aggregation method for federated learning are implemented as described in any one of claims 1-8.