Privacy federal learning system based on model robustness filter
By adopting hybrid and layered strategies to detect backdoor attacks in federated learning systems and protecting privacy with verifiable secret sharing and zero-knowledge proof technologies, the problems of poor robustness and privacy leakage in existing federated learning systems are solved, achieving secure aggregation and efficient privacy protection.
Patent Information
- Application Number
- CN202411849112.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-16
- Publication Date
- 2025-05-16
AI Technical Summary
The existing federated learning system is poorly robust, difficult to defend against model poisoning attacks against tail data, and difficult to defend against poisoning, Byzantine and privacy attacks at the same time.
A privacy federated learning system based on model robustness filters is adopted, combining hybrid and hierarchical strategies to detect backdoor attacks, and ensuring that participants’ privacy data is not leaked through verifiable secret sharing and zero-knowledge proof technologies.
Effectively defend against backdoor attacks, improve the robustness of federated learning systems, ensure the privacy of participant data, and achieve secure aggregation.
Smart Images

Figure CN120017252A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to a privacy federated learning system based on a model robustness filter, and belongs to the technical field of machine learning. Background Art
[0002] With the development of mobile Internet, cloud computing and big data technology, data plays a huge role, and data security and privacy have become the focus of attention, covering data content privacy, decision model privacy, data weight privacy and other aspects. In recent years, data security threat incidents have occurred frequently, and the problem of data privacy being easily leaked and security being difficult to guarantee has become increasingly prominent. On the one hand, data privacy and security protection is becoming increasingly strict. On the other hand, data flow is restricted and difficult to share, which greatly limits the role of data value. The real dilemma of "data islands" and "privacy protection" has become a problem for many industries.
[0003] Federated learning technology provides a solution to the above problems. Federated learning technology is an emerging artificial intelligence technology and one of the mainstream technologies of privacy computing. In a federated learning system, data is dispersed among participants for local training. After uploading local parameters, the server aggregates the results and updates the model. Federated learning technology has the advantages of model parameter protection and joint modeling optimization. However, federated learning technology also has certain defects. Malicious participants can make it difficult for the global model to converge by arbitrarily generating aggregate parameters to achieve the purpose of destroying model training. They can even tamper with the data set, such as modifying uncommon tail data in category A and changing the labels of these tail data to category B. While the accuracy of the global model on the main task is not affected, the accuracy of tail data of type A being misclassified as type B is greatly improved, achieving the purpose of injecting a backdoor into the global model. In addition, when the local model submitted by the participant is exposed, the attacker can infer whether a sample has been trained based on the local model, or even reconstruct the data used for training.
[0004] Based on the above situation, how to provide good defense performance against poisoning attacks, Byzantine attacks, and privacy attacks at the same time has always been an important research issue in secure federated learning. On the one hand, it is necessary to check whether the submitted local model is benign and defend against model poisoning attacks without compromising privacy. On the other hand, it is also necessary to aggregate the checked models in a secure way to avoid Byzantine attacks and privacy leakage during the aggregation process. Therefore, it is necessary to solve the technical problems of the poor robustness of the existing federated learning system and the difficulty in defending against poisoning attacks on tail data models. Summary of the invention
[0005] The purpose of this invention is to solve the technical problems of existing federated learning systems, such as poor robustness and difficulty in defending against poisoning attacks on tail data models. A privacy federated learning system based on a model robustness filter is creatively proposed to prevent the privacy data of participants from being leaked while defending against model poisoning.
[0006] This system uses two strategies: hybrid and hierarchical. The hybrid strategy compares the differences in the distance and direction of the model, and the hierarchical strategy checks the direction differences of the model at different layers. The combination of the two strategies can effectively detect backdoor attacks and improve the robustness of the federated learning system. By using verifiable secret sharing and zero-knowledge proof technology, it ensures that participants will not leak any information about local model updates during aggregation, achieving secure aggregation and ensuring the privacy of participants' data.
[0007] In order to achieve the above object, the present invention provides the following technical solutions.
[0008] A privacy federated learning system based on model robustness filter, including:
[0009] Step 1: The server initializes the list of all participants U and the list of benign participants U B List U with malicious actors M In list U, each participant generates a key pair (pk, sk) for encryption and decryption, and sends the public key pk to the server. sk represents the private key. The server uses the initial model to train the initial global model. A unique number i is generated for each participant to distinguish different participants. The server will {(i,pk i )} i∈U Distribute to all participants.
[0010] Step 2: Start the jth round of training, and distribute the global model to the server The n participants participating in the federated learning computation are from UU M , each participant has a local dataset D i The global model of the training distribution Get local model Through local model and global model Computational model update
[0011] Step 3: Each participant uses the zero-knowledge proof algorithm Bulletproof and Sigma protocol to calculate the Euclidean norm threshold t according to the pre-determined Euclidean norm threshold t. e , generate the Euclidean distance range proof; according to the hierarchical cosine similarity threshold t c, generate cosine similarity range proofs for each layer of the model update and send all proofs to the server.
[0012] The server verifies all proofs and adds the participants whose Euclidean distance range proofs have been successfully verified to the benign participant list U B In the middle; sort the n participants according to the verification pass rate of the hierarchical cosine similarity range proof, and remove the least number of participants from U B Removed.
[0013] The server will complete the list of benign participants U B Broadcast to all participants.
[0014] Step 4: Each participant uses a verifiable secret sharing algorithm to update the model θ i j Generate n secret shares. After encrypting the shares with the corresponding participants' public keys, send them to the server along with all the generated commitments. After receiving the shares, the server forwards them to the specific participants.
[0015] Step 5: Each participant decrypts the honest list U B The secret shares sent by all participants in the aggregation are aggregated to obtain the global secret share i And send it to the server.
[0016] The server selects k bits from all participants and uses the secret recovery algorithm to get the global model update θ j After that, the legality of the global model update is verified. If the verification passes, proceed to step 6; if the verification fails, proceed to step 7.
[0017] Step 6: The server uses the global model from the previous round and the global model update θ j Add together to get the global model of this round And distribute it to all participants. After distribution, proceed to step 10.
[0018] Step 7: The server verifies the global secret shares submitted by the selected k participants and asks the participant C who failed to verify u Provide the proof. At the same time, the server sends the participant the commitment required in step 4 to generate the corresponding proof.
[0019] Step 8: Participant C is asked to provide proof u Verify all secret shares from other participants. For participant C that fails verification v Generate a certificate and send it to the server.
[0020] Step 9: The server performs two verifications:
[0021] I: Verify C u proof of;
[0022] II: Verification C v The secret share.
[0023] If verification I passes but verification II fails, the server will C v Join the malicious actor list U M Otherwise, C u Join the malicious actor list U M . Return to step 5 and re-aggregate.
[0024] Step 10: Return to step 2 until a fixed number of training rounds is reached or the global model converges.
[0025] Furthermore, in step 1, each participant uses the ElGamal algorithm KeyGen(λ)→(pk,sk) which is resistant to chosen plaintext attacks, where λ is a security parameter and (pk,sk) is the generated key pair. The specific process is as follows:
[0026] G is a polynomial time algorithm with input 1 λ , output a group The order of the group is a prime number q of length λ bits. Let g be a generator of this group. Randomly pick pk=(g,g sk ), (pk, sk) constitute a key pair, where pk is the public key and sk is the private key.
[0027] On this basis, the encryption algorithm Enc(pk,m)→c, where m represents plaintext and c represents encrypted ciphertext, is as follows:
[0028] c=(pk r ,g r *m)
[0029] Among them, r is a random number,
[0030] The decryption algorithm Dec(sk,c)→m′, where m′ represents the decrypted plaintext and c′ represents the ciphertext, is as follows:
[0031]
[0032] Among them, the form is a -b The calculation of means calculating a in the corresponding group b The inverse element.
[0033] Furthermore, in step 3, the zero-knowledge proof algorithm Bulletproof is used to generate the model update θ ij The range proof includes the Euclidean distance range proof and the hierarchical cosine similarity range proof. The details are as follows:
[0034] Each client needs to generate a zero-knowledge proof circuit, and the calculations for proof and verification are represented by arithmetic circuits containing only addition gates and multiplication gates. The floating-point numbers in the model parameters are converted into fixed-point numbers, and the decimal part is represented by a fixed number of bits.
[0035] The Euclidean distance range proof requires the use of zero-knowledge proof and Sigma protocol. The Sigma protocol is responsible for proving the correlation between the parameter and its square, and the zero-knowledge proof is responsible for proving the following inequality:
[0036] ‖θ‖2≤t e
[0037] This inequality is equivalent to where θ represents the model update, represented by a vector of length k (x1,…,x k ) indicates that t e represents the Euclidean norm threshold. i and x i 2 Use the Sigma protocol MulSigma(x,y)→(r,c″) to associate them. The specific content of the function is as follows:
[0038] calculate Where (m1, m2, r1, r2, r3) are random numbers. Calculate the challenge factor e, e = Hash (g||h||c1||c2||c3||c4). Finally, check and The correctness of the two equations. The c″ returned by the function is the value of x 2 is a commitment, r is the blinding factor of the commitment.
[0039] Then x i and x i 2 The correlation is expressed by MulSigma(x i ,x i ) function to bind and get c″ i and r i .
[0040] Zero-knowledge proof of Euclidean distance Indicates that comm is Commitment, π norm is the generated proof result. The verification process uses Norm2Verify(min,max,π norm )→True / False.
[0041] At this point, the verification process of the Euclidean distance range proof verifies the correctness of the zero-knowledge proof and checks the equation The legal realization of A generator in that is different from g.
[0042] The layered cosine similarity range proof requires calculating the cosine similarity for each layer of parameters in the model update and the global model separately, and proving the following inequality:
[0043] θ l *w l ≥t c *(‖θ l ‖2*‖w l ‖2),l∈[1,L]
[0044] Among them, L represents the number of layers of the model, θ l represents the lth layer parameter updated by the model, w l Represents the lth layer parameters of the global model. θ l and w l are transformed into vectors of length k (x1,…,x k ) and (y1,…,y k ), then the inner product of two vectors is calculated by MulSigma(x i ,y i ) binding.
[0045] Zero-knowledge proof of cosine similarity Indicates that comm is The promise, is the generated proof result. The verification process uses express.
[0046] At this point, the verification process of the hierarchical cosine similarity range proof can be verified by verifying the correctness of the zero-knowledge proof and checking the equation legitimacy realization.
[0047] Furthermore, the verifiable secret sharing generation algorithm VSSGen(s,n,k)→{(s i ,t i )} i∈[1,n] , where s is the secret, n is the number of participants, and k is the minimum number of people required to recover the secret. i ,t i )} i∈[1,n] are the generated n secret shares, as follows:
[0048] Choose two different large prime numbers p and q and q|(p-1), the cyclic group The order of is q, which is For two different generators No one knows log g A specific value of h. For another integer group of order q Any participant will give his secret share Distribute as follows:
[0049] The participants generate two polynomials of degree up to k-1:
[0050] F(x)=s+F1x+…+F k-1 x k-1
[0051] G(x)=t+G1x+…+G k-1 x k-1
[0052] Among them, F i , G i is a random number generated by the participant,
[0053] Furthermore, the specific process of each participant aggregating the global secret share in step 5 is as follows:
[0054] For each participant C v , Participant C u Receive the ciphertext sent by it and decrypt it to get the secret share (s v,u ,t v,u )=Dec(sk u ,c). After that, C u List U for all honest people B The secret shares sent by the participants are calculated and Get the global secret share (S) of a parameter in the global model update u ,T u ). u Represents participant C u The aggregate secret share, T u Represents participant C u The aggregate blinding factor secret share of .
[0055] Each participant C u To aggregate all l parameters of the model, we need to get the global secret share u .
[0056] Furthermore, in step 5, the server uses the secret recovery algorithm VSSRec(k,{s i ,t i} i∈[1,k] )→(s,t), and get the global model update θ j , the specific process is as follows:
[0057] The contents of the secret recovery algorithm are:
[0058]
[0059] Where s represents the recovered secret, s i represents the secret recovered by the i-th participant.
[0060] For each parameter updated by the global model, the server randomly selects the honest list U B The global secret shares submitted by k participants (S i ,T i ) is restored, and the calculation method is as follows:
[0061] (X,R)=VSSRec(k,{S i ,T i} i∈[1,k] )
[0062] Where X represents a parameter for global model update, and R represents the blinding factor committed to X. i represents the aggregate secret share of participant i, T i represents the aggregate blinding factor secret share of participant i.
[0063] Furthermore, in step 5, the server verifies the legitimacy of the global model update. This verification process uses the function The specific process is as follows:
[0064] For each parameter updated by the global model, the server checks whether the following equation holds:
[0065]
[0066] Among them, E0 represents each participant’s commitment to updating the parameters of the local model, g X represents the group calculation result of the global model update parameter X, h R represents the group calculation result of the blinding factor R, g X h R A commitment representing a parameter of the global model update. If the equality holds, VerifyParam() returns True, indicating that the global model update is legal; if the equality does not hold, VerifyParam() returns False, indicating that the global model update is illegal.
[0067] Furthermore, in step 6, the formula for calculating the global model of this round is as follows:
[0068] w g j =w g j-1 +θ j
[0069] Further, in step 7, the server verifies the global secret share algorithm, and this verification process uses the function The specific process is as follows:
[0070] For each participant's global secret share, the server checks whether the following equation holds:
[0071]
[0072] in, Indicates all U B The multiplication of the polynomial coefficients of the participants in Represents participant C u The group calculation result of the aggregated secret share is Represents participant C u The group calculation result of the aggregate blinding factor secret share is, For participant C u The aggregate secret share S u The promise, represents a commitment to the coefficients of a polynomial, where F i The i-th coefficient of the polynomial F(x), G i The i-th coefficient of the polynomial G(x).
[0073] Furthermore, in steps 8 and 9, the participant secret share algorithm is verified. This verification process uses the function VerifyClient((E0,…,E k-1 ) v ,s v,u ,t v,u )→True / False, the specific process is as follows:
[0074] Participant C u For each other participant C received v The secret share checks whether the following equation holds:
[0075]
[0076] in, represents the result of calculating the secret share sent by participant v to u on the group, Represents the result of calculating the secret share of the blinding factor sent by participant v to u on the group.
[0077] Furthermore, in step 8, participant C u Generate C using Sigma protocol v Proof of correct decryption of secret shares, using DecSimga(pk,sk,m,c)→π dec represents the protocol, where π dec Represents the generated proof. The specific process is as follows:
[0078] The public key is represented by the tuple (g,h)=pk, and the ciphertext is represented by the tuple (c1,c2)=c. Calculate A = g a , B=(c2*m -1 ) a , calculate the challenge factor e = Hash(g||h||m||c||A||B) and z = x*e+a, and generate proof π dec =(m,A,B,z). Among them,
[0079] Further, in step 9, the Sigma protocol proves WerifyDec(π dec ,c,pk), the verification process checks whether the following two equations hold:
[0080] g e *A=g z
[0081] c1 e *b=(c2*m -1 ) z
[0082] Among them, g z Represents the calculation result of the intermediate calculation z of the challenge factor e on the group.
[0083] Beneficial Effects
[0084] Compared with the prior art, the present invention has the following advantages:
[0085] The present invention uses two model checking strategies, hybrid and hierarchical, to prevent the malicious model of the attacker from contaminating the global model, effectively defend against backdoor attacks, and improve the robustness of federated learning; the zero-knowledge proof technology is used to complete the proof and verification of the model checking method, so that the verification process will not expose any information about the local model of the participants except Euclidean distance and hierarchical cosine similarity; Pedersen verifiable secret sharing is used to complete aggregation without exposing the local model of the participants, thereby realizing privacy aggregation; the Sigma protocol is used to effectively eliminate Byzantine attackers in the aggregation process and complete the correct aggregation of the global model. BRIEF DESCRIPTION OF THE DRAWINGS
[0086] Figure 1 A diagram of the system and threat model of the present invention;
[0087] Figure 2 It is a schematic diagram of the system implementation flow of the present invention. DETAILED DESCRIPTION
[0088] The technical solution of the present invention is described in detail and completely below in conjunction with the accompanying drawings.
[0089] like Figure 1 As shown, the scenario of the embodiment of the present invention is a federated learning system, which includes a server and multiple clients. The server distributes the global model to the participants. After receiving the global model, each participant performs local training with private data. After the training is completed, the local update is submitted to the server, and the server completes the aggregation. The server is honest but curious. The server will strictly execute each step of the federated learning process, but will be curious about the parameters and private data submitted by the participants. Each participant uses a client. The participants are divided into honest participants and attackers. Honest participants will strictly execute each step of federated learning. The attacker will try to use attack methods to launch attacks, including but not limited to model poisoning attacks and data poisoning attacks that inject backdoors into the global model, obtain the private data of other participants, and prevent the global model from converging. The attack method used by the attacker is implemented by the following simulated attack method: the attacker uses the Projected Gradient Descent (PGD) method to implant a backdoor into the global model for the tail data in the data set; the attacker attempts to read and crack the private data such as local parameters of other participants; the attacker randomly generates parameters for aggregation.
[0090] Before each round of training begins, the server randomly selects a fixed number of participants from all participants to conduct this round of federated learning. In order to simulate the scenario of federated learning being attacked, there are one or more clients controlled by the attacker to attack in each round. In addition to the clean data set, the attacker also includes a poisonous data set generated by himself. These poisonous data are uncommon data in the clean data set, and the labels are changed to other categories.
[0091] like Figure 2 As shown, the process of using the present invention to defend against attacks and solve the problem in this scenario is as follows:
[0092] Step 1: The server initializes a list of all participants U and a list of benign participants U B List U with malicious actors M Each participant in U generates a key pair (pk, sk) for encryption and decryption, and sends the public key pk to the server. The server uses the initial model to train the initial global model. A unique number i is generated for each participant to distinguish different participants. The server will {(i,pk i )} i∈U Distributed to all participants. The encryption and decryption algorithm used by each participant is the ElGamal algorithm KeyGen(λ)→(pk,sk) that can resist chosen plaintext attacks, where λ is the security parameter and (pk,sk) is the generated key pair. The specific process is as follows:
[0093] G is a polynomial time algorithm with input 1 λ , output a group The order of the group is a prime number q of length λ bits, and let g be a generator of this group. pk=(g,g sk ), (pk, sk) constitute a key pair, where pk is the public key and sk is the private key.
[0094] On this basis, the encryption algorithm Enc(pk,m)→c, where m represents plaintext and c represents encrypted ciphertext, the specific contents are as follows:
[0095] c=(pk r ,g r *m)
[0096] in, is a random number.
[0097] The decryption algorithm is Dec(sk,c)→m, where m represents the decrypted plaintext and c represents the ciphertext. The specific contents are as follows:
[0098]
[0099] Among them, the form is a -b The calculation of means calculating a in the corresponding group b The inverse element.
[0100] Step 2: Start the jth round of training, and distribute the global model to the server The n participants participating in the federated learning computation are from UU M , each participant has a local dataset D i The global model of the training distribution Get local model Through local model and global model Computational model update
[0101] Step 3: Each participant uses the zero-knowledge proof algorithm bulletproof and Sigma protocol to calculate the value of the Euclidean norm threshold t according to the predetermined Euclidean norm threshold t.e Generate Euclidean distance range proof, according to the hierarchical cosine similarity threshold t c =0 Generate cosine similarity range proofs for each layer of the model update and send all proofs to the server. The server verifies all proofs and adds the participants who have successfully verified the Euclidean distance range proof to the benign participant list U B In the middle; sort the n participants according to the verification pass rate of the hierarchical cosine similarity range proof, and remove the least number of participants from U B The server will complete the list of benign participants U B Broadcast to all participants.
[0102] Use the zero-knowledge proof algorithm Bulletproof to generate the model update θ i j The range proof includes the Euclidean distance range proof and the hierarchical cosine similarity range proof. The specific process is as follows:
[0103] Each client needs to generate a zero-knowledge proof circuit, and the proof and verification calculations are represented by arithmetic circuits containing only addition gates and multiplication gates. The floating-point numbers in the model parameters are converted into fixed-point numbers, and the decimal part is represented by a fixed number of bits.
[0104] The Euclidean distance range proof requires the use of zero-knowledge proof and Sigma protocol. The Sigma protocol is responsible for proving the correlation between the parameter and its square, and the zero-knowledge proof is responsible for proving the following inequality:
[0105] ‖θ‖2≤t e
[0106] This inequality is equivalent to where θ represents the model update, which can be a vector of length k (x1,…,x k ) represents. Every pair of x i and x i 2 It can be associated with the Sigma protocol MulSigma(x,y)→(r,c′), the specific content of the function is as follows:
[0107] calculate Among them (m1,m2,r1,r2,r3) are random numbers. Calculate the challenge factor e = Hash(g||h||c1||c2||c3||c4). Finally check and The correctness of the two equations. The function returns c′ for x 2 is a commitment, r is the blinding factor of the commitment.
[0108] Then x i and x i2 The correlation can be expressed by MulSigma(x i ,x i ) function to bind and get c′ i and r i .
[0109] Zero-knowledge proof of Euclidean distance Indicates that comm is Commitment, π norm is the generated proof result. The verification process uses Norm2Verify(min,max,π norm )→True / False.
[0110] At this point, the verification process of the Euclidean distance range proof can be verified by verifying the correctness of the zero-knowledge proof and checking the equation legitimacy realization.
[0111] The layered cosine similarity range proof requires calculating the cosine similarity for each layer of parameters in the model update and the global model separately, and proving the following inequality:
[0112] θ l *w l ≥0,l∈[1,L]
[0113] Among them, L represents the number of layers of the model, θ l represents the lth layer parameter updated by the model, w l Represents the lth layer parameters of the global model. θ l and w l can be transformed into vectors of length k (x1,…,x k ) and (y1,…,y k ), then the inner product of two vectors can be expressed by MulSigma(x i ,y i ) binding.
[0114] Zero-knowledge proof of cosine similarity Indicates that comm is The promise, is the generated proof result. The verification process uses express.
[0115] At this point, the verification process of the hierarchical cosine similarity range proof can be verified by verifying the correctness of the zero-knowledge proof and checking the equation legitimacy realization.
[0116] Step 4: Each participant uses a verifiable secret sharing algorithm to update the model θi j Generate n secret shares. The details are as follows:
[0117] Verifiable Secret Sharing Generation Algorithm VSSGen(s,n,k)→{(s i ,t i )} i∈[1,n] , where s is the secret, n is the number of participants, and k is the minimum number of people required to recover the secret. i ,t i )} i∈[1,n] are the n secret shares generated.
[0118] Choose two different large prime numbers p and q and q|(p-1), the cyclic group The order of is q, which is For two different generators No one knows log g A specific value of h. For another integer group of order q Any participant can add his or her secret share Distribute as follows.
[0119] The participants generate two polynomials of degree up to k-1:
[0120] F(x)=s+F1x+…+F k-1 x k-1
[0121] G(x)=t+G1x+…+G k-1 x k-1
[0122] in, is a random number generated by the participant.
[0123] Finally, the participants generate commitments and send it to the server. At the same time, the participants calculate s i =F(i),t i =G(i),i={1,…,n}, and {(s i ,t i )} i∈[1,n] Encryption Enc(pk i ,{(s i ,t i )} i∈[1,n] ) and then sent to the server, the server sends i Forward the corresponding ciphertext.
[0124] Step 5: Each participant decrypts the honest list U BThe secret shares sent by all participants in the aggregation are aggregated to obtain the global secret share i And send it to the server. The aggregation process is as follows:
[0125] For each participant C v , Participant C u Receive the ciphertext sent by it and decrypt it to get the secret share (s v,u ,t v,u )=Dec(sk u ,c). Then C u List U for all honest people B The secret shares sent by the participants are calculated and Get the global secret share (S) of a parameter in the global model update u ,T u ).
[0126] Each participant C u It is necessary to aggregate all l parameters of the model to obtain the global secret share u .
[0127] The server selects k bits from all participants and uses the secret recovery algorithm to get the global model update θ j Finally, verify the legitimacy of the global model update.
[0128] The server uses the secret recovery algorithm VSSRec(k,{s i ,t i} i∈[1,k] )→(s,t) is as follows:
[0129]
[0130] For each parameter updated by the global model, the server randomly selects the honest list U B The global secret shares submitted by k participants (S i ,T i ) is calculated as follows:
[0131] (X,R)=VSSRec(k,{S i ,T i} i∈[1,k] )
[0132] Among them, X represents a parameter of the global model update, and R represents the blinding factor committed to X.
[0133] The server verifies the legitimacy of global model updates using functions The specific process is as follows:
[0134] For each parameter updated by the global model, the server checks whether the following equation holds:
[0135]
[0136] If the equation holds true, VerifyParam() returns True, indicating that the global model update is legal, and then proceed to step 6; if the equation does not hold true, VerifyParam() returns False, indicating that the global model update is illegal, and then proceed to step 7.
[0137] Step 6: The server uses the global model from the previous round and the global model update θ j Add together to get the global model of this round And distribute it to all participants. After distribution, proceed to step 10.
[0138] Step 7: The server verifies the global secret shares submitted by the selected k participants and asks the participant C who failed to verify u Provide the proof, and the server will send the participant a commitment to step 4 required to generate the corresponding proof.
[0139] The server verifies the global secret share algorithm using a function The specific process is as follows:
[0140] For each participant's global secret share, the server checks whether the following equation holds:
[0141]
[0142] in
[0143] Step 8: Participant C is asked to provide proof u Verify all secret shares from other participants, for participant C that failed verification v Generate a certificate and send it to the server.
[0144] Verify the secret share algorithm process of the participants using the function VerifyClient((E0,…,E k-1 ) v ,s v,u ,t v,u )→True / False, the specific process is as follows:
[0145] Participant C u For each other participant C received v The secret share checks whether the following equation holds:
[0146]
[0147] Participant C u Generate C using Sigma protocol v Proof of correct decryption of secret shares, using DecSimga(pk,sk,m,c)→π dec represents the protocol, where π dec Represents the generated proof. The specific process is as follows:
[0148] The public key is represented by the tuple (g,h)=pk, and the ciphertext is represented by the tuple (c1,c2)=c. Calculate A = g a , B=(c2*m -1 ) a , calculate the challenge factor e = Hash (g||h||m||c||A||B) and z = x*e+a. Then the generated proof π dec =(m,A,B,z).
[0149] Step 9: The server performs two verifications:
[0150] (1) Verify C u Proof of VerifyDec(π dec ,c,pk), the verification process checks whether the following two equations hold:
[0151] g e *A=g z
[0152] c1 e *b=(c2*m -1 ) z
[0153] (2) Verify C v The secret share.
[0154] If verification (1) passes but verification (2) fails, the server will C v Join the malicious actor list U M Otherwise, C u Join the malicious actor list U M . Return to step 5 and re-aggregate.
[0155] Step 10: Return to step 2 until a fixed number of training rounds is reached or the global model converges.
[0156] The attacker will use the PGD method in step 2 to implant a backdoor into the global model, with the aim of making the accuracy of the global model on the clean test set basically unaffected, but greatly improving the accuracy of misclassification of tail data. The present invention uses two model checking strategies, hybrid and hierarchical, so that the attacker's local model with a backdoor will not affect the global model, effectively defending against the attacker's model poisoning backdoor attack.
[0157] In order to interfere with the aggregation of the global model, the attacker will send forged secret shares, such as some random numbers, to other participants in step 4. In step 4 of the present invention, participants need to submit Pedersen commitments to secret sharing verification parameters, where the commitment to the secret is required to be the same as the commitment used for model checking in step 3. Pedersen commitments are computationally bound, and a probabilistic polynomial-time adversary finds a solution that satisfies g x h t =g x′ h t′ The probability of x′ where ∧x≠x′ is negligible. Therefore, the attacker cannot tamper with the secret parameter value corresponding to the commitment. In step 4, the participants also need to generate a secret share of the parameters, and Pedersen can verify that the secret share is computationally correct. A probabilistic polynomial-time adversary finds a parameter of size k that satisfies The probability of S1 and S2 being different is negligible. Therefore, the attacker cannot generate a secret share that is different from the secret parameters without being discovered. In step 8, the honest participant will submit a proof of "receiving an incorrect secret share" to the server using the Sigma protocol. The Sigma protocol is perfect and complete, so when an incorrect secret share is received from a malicious participant, the proof submitted by the honest participant will be accepted by the server.
[0158] In order to interfere with the aggregation of the global model, the attacker will submit an erroneous global secret share in step 5. In step 4 of the present invention, the participants aggregate multiple secret shares to generate a global secret share and send it to the server. Pedersen verifies that the secret share is computationally correct. A probabilistic polynomial time adversary finds a size k that satisfies The probability of S1 and S2 is negligible. Therefore, the attacker cannot generate a global secret share that can be verified and interfere with aggregation.
[0159] In order to disrupt the aggregation, the attacker will forge the proof in step 8. The Sigma protocol is reliable. A probabilistic polynomial-time adversary finds a e *A=g z ∧c1 e *b=(c2*m′ -1 )z |c1=h t ,c2=mg t ,m≠m′}, the probability of m′ is negligible. Therefore, the attacker cannot submit a wrong proof to the server.
[0160] The non-interactive zero-knowledge proof Bulletproof used in step 3 has the SHVZK property, so no information about the model parameters will be leaked during the model checking phase. Pedersen verifiable secret sharing has perfect privacy and will not leak information about the model parameters when there are less than k attackers colluding. The Sigma protocol also has the SHVZK property, so the private key information of the participants will not be leaked. The ElGamal encryption scheme used in data transmission can resist chosen plaintext attacks, so that the secret share of the local model update can only be obtained by the corresponding participant, and the participant cannot recover the secret itself because he cannot obtain other secret shares. Based on these schemes, the present invention ensures the privacy security of the participants.
[0161] In summary, the present invention is a complete secure federated learning system that defends against model poisoning attacks, effectively improves the robustness of federated learning, and ensures that the privacy of participants is not leaked, thereby achieving secure aggregation.
[0162] The above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by a person skilled in the art within the technical scope disclosed by the present invention should be included in the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A privacy federated learning system based on model robustness filter, characterized in that: include: Step 1: The server initializes the list of all participants U and the list of benign participants U B List U with malicious actors M ; In list U, each participant generates a key pair (pk, sk) used for encryption and decryption, sends the public key pk to the server, and sk represents the private key; The server uses the initial model to train the initial global model A unique number i is generated for each participant to distinguish different participants; the server will {(i, pk i )} i∈U Distribute to all participants; Step 2: Start the jth round of training, and distribute the global model to the server The n participants participating in the federated learning computation are from UU M , each participant has a local dataset D i The global model of the training distribution Get local model Through local model and global model Computational model update Step 3: Each participant uses the zero-knowledge proof algorithm Bulletproof and Sigma protocol to calculate the Euclidean norm threshold t according to the pre-determined Euclidean norm threshold t. e , generate the Euclidean distance range proof; according to the hierarchical cosine similarity threshold t c , generate cosine similarity range proofs for each layer of the model update and send all proofs to the server; The server verifies all proofs and adds the participants whose Euclidean distance range proofs have been successfully verified to the benign participant list U B In the middle; sort the n participants according to the verification pass rate of the hierarchical cosine similarity range proof, and remove the least number of participants from U B Removed; The server will complete the list of benign participants U B Broadcast to all participants; Step 4: Each participant uses a verifiable secret sharing algorithm to update the model θ i j Generate n secret shares; encrypt the shares with the corresponding participants’ public keys and send them to the server along with all the generated commitments; after receiving the shares, the server forwards them to the specific participants; Step 5: Each participant decrypts the honest list U B The secret shares sent by all participants in the aggregation are aggregated to obtain the global secret share i And send it to the server; The server selects k bits from all participants and uses the secret recovery algorithm to get the global model update θ j After that, verify the legitimacy of the global model update; if the verification passes, proceed to step 6; if the verification fails, proceed to step 7; Step 6: The server uses the global model from the previous round Add the global model update θj to get the global model And distribute it to all participants; after distribution, proceed to step 10; Among them, the formula of this round of global model is as follows: w g j =w g j-1 +θ j Step 7: The server verifies the global secret shares submitted by the selected k participants and asks the participant C who failed to verify u Provide proof; at the same time, the server sends the participant the commitment required in step 4 to generate the corresponding proof; Step 8: Participant C is asked to provide proof u Verify all secret shares from other participants; for participant C that fails verification v Generate a certificate and send it to the server; Step 9: The server performs two verifications: I: Verify C u proof of; II: Verification C v of secret share; If verification I passes but verification II fails, the server will C v Join the malicious actor list U M Otherwise, C u Join the malicious actor list U M ; Return to step 5 and re-aggregate; Step 10: Return to step 2 until a fixed number of training rounds is reached or the global model converges.
2. A privacy federated learning system based on model robustness filter as claimed in claim 1, characterized in that: In step 1, each participant uses the ElGamal algorithm KeyGen(λ)→(pk, sk) that is resistant to chosen plaintext attacks, where λ is a security parameter and (pk, sk) is the generated key pair, as follows: G is a polynomial time algorithm with input 1 λ , output a group The order of the group is a prime number q of length λ bits; let g be a generator of this group; randomly select pk=(g,g sk ), (pk, sk) constitute a key pair, where pk is the public key and sk is the private key; On this basis, the encryption algorithm Enc(pk, m)→c, where m represents plaintext and c represents encrypted ciphertext, is as follows: c=(pk r ,g r *m) Among them, r is a random number, The decryption algorithm Dec(sk, c)→m′, where m′ represents the decrypted plaintext and c′ represents the ciphertext, is as follows: Among them, the form is a -b The calculation of means calculating a in the corresponding group b The inverse element.
3. A privacy federated learning system based on model robustness filter as claimed in claim 1, characterized in that: In step 3, the zero-knowledge proof algorithm Bulletproof is used to generate the model update θ i j The range proofs include the Euclidean distance range proof and the hierarchical cosine similarity range proof, as follows: Each client needs to generate a zero-knowledge proof circuit. The proof and verification calculations are represented by arithmetic circuits containing only addition gates and multiplication gates. The floating-point numbers in the model parameters are converted into fixed-point numbers, and the decimal part is represented by a fixed number of bits. The Euclidean distance range proof requires the use of zero-knowledge proof and Sigma protocol. The Sigma protocol is responsible for proving the correlation between the parameter and its square, and the zero-knowledge proof is responsible for proving the following inequality: ||θ||2≤t e This inequality is equivalent to where θ represents the model update, represented by a vector of length k (x1, ..., x k ) indicates that t e represents the Euclidean norm threshold; each pair of x i and x i 2 Use the Sigma protocol MulSigma(x, y)→(r, c″) to associate them. The specific content of the function is as follows: calculate Where (m1, m2, r1, r2, r3) are random numbers; calculate the challenge factor e, e = Hash (g||h||c1||c2||c3||c4); finally, check and The correctness of both equations; the c″ returned by the function is the value of x 2 Commitment of , r is the blinding factor of the commitment; Then x i and x i 2 The correlation is expressed by MulSigma(x i , x i ) function to bind and get c″ i and r i ; Zero-knowledge proof of Euclidean distance Indicates that comm is Commitment, π norm is the generated proof result; the verification process uses Norm2Verify(min, max, π norm )→True / False indicates; At this point, the verification process of the Euclidean distance range proof verifies the correctness of the zero-knowledge proof and checks the equation The legal realization of a generator in that is different from g; The layered cosine similarity range proof requires calculating the cosine similarity for each layer of parameters in the model update and the global model separately, and proving the following inequality: i l *w l ≥t c *(||θ l ||2*||w l ||2),l∈[1,L] Among them, L represents the number of layers of the model, θ l represents the lth layer parameter updated by the model, w l represents the lth layer parameters of the global model; θ l and w l are transformed into vectors of length k (x1, ..., x k ) and (y1, ..., y k ), then the inner product of two vectors is calculated by MulSigma(x i ,y i ) Binding; Zero-knowledge proof of cosine similarity Indicates that comm is The promise, is the generated proof result; the verification process uses express; At this point, the verification process of the hierarchical cosine similarity range proof is completed by verifying the correctness of the zero-knowledge proof and checking the equation legitimacy realization.
4. A privacy federated learning system based on model robustness filter as claimed in claim 1, characterized in that: In step 4, the verifiable secret sharing generation algorithm VSSGen(s, n, k)→{(s i , t i )) i∈[1,n] , where s is the secret, n is the number of participants, and k is the minimum number of people required to recover the secret. i , t i )) i∈[1,n] are the n secret shares generated, as follows: Choose two different large prime numbers p and q and q|(p-1), the cyclic group The order of is q, which is The only subgroup of No one knows the exact value of loggh; for another integer group of order q Any participant will give his secret share Distribute as follows: The participants generate two polynomials of degree up to k-1: F(x)=s+F1x+…+F k-1 x k-1 G(x)=t+G1x+…+G k-1 x k-1 Among them, F i , G i is a random number generated by the participant, 5. A privacy federated learning system based on model robustness filter as claimed in claim 1, characterized in that: In step 5, the specific process of each participant aggregating the global secret share is as follows: For each participant C v , Participant C u Receive the ciphertext sent by it and decrypt it to get the secret share (s v,u , t v,u )=Dec(sk u , c); then, C u List U for all honest people B The secret shares sent by the participants are calculated and Get the global secret share (S) of a parameter in the global model update u , T u );S u Represents participant C u The aggregate secret share, T u Represents participant C u The aggregate blinding factor secret share of Each participant C u To aggregate all l parameters of the model, we need to get the global secret share u .
6. A privacy federated learning system based on model robustness filter as claimed in claim 1, characterized in that: In step 5, the server uses the secret recovery algorithm VSSRec(k, {s i , t i } i∈[1,k] )→(s, t), and get the global model update θ j , as follows: The contents of the secret recovery algorithm are: Where s represents the recovered secret, s i represents the secret recovered by the i-th participant; For each parameter updated by the global model, the server randomly selects the honest list U B The global secret shares submitted by k participants (S i , T i ) is restored, and the calculation method is as follows: (X,R)=VSSRec(k,{S i ,T i } i∈[1,k] ) Where X represents a parameter of the global model update, R represents the blinding factor committed to X; S i represents the aggregate secret share of participant i, T i represents the aggregate blinding factor secret share of participant i.
7. A privacy federated learning system based on model robustness filter as claimed in claim 1, characterized in that: In step 5, the server verifies the legitimacy of the global model update using the function Indicates, as follows: For each parameter updated by the global model, the server checks whether the following equation holds: Among them, E0 represents each participant’s commitment to updating the parameters of the local model, g X represents the group calculation result of the global model update parameter X, h R represents the group calculation result of the blinding factor R, g X h R A commitment to a parameter representing a global model update; if the equality holds, VerifyParam() returns True, indicating that the global model update is legal; if the equality does not hold, VerifyParam() returns False, indicating that the global model update is illegal.
8. A privacy federated learning system based on model robustness filter as claimed in claim 1, characterized in that: In step 7, the server verifies the global secret share algorithm using the function Indicates, as follows: For each participant's global secret share, the server checks whether the following equation holds: in, Indicates all U B The multiplication of the polynomial coefficients of the participants in Represents participant C u The group calculation result of the aggregated secret share is Represents participant C u The group calculation result of the aggregate blinding factor secret share is, For participant C u The aggregate secret share S u The promise, represents a commitment to the coefficients of a polynomial, where F i The i-th coefficient of the polynomial F(x), G i The i-th coefficient of the polynomial G(x).
9. A privacy federated learning system based on model robustness filter as claimed in claim 1, characterized in that: In step 8 and step 9, the participant secret share algorithm is verified. This verification process uses the function VerifyClient((E0, ..., E k-1 ) v ,s v,u , t v,u )→True / False, the specific process is as follows: Participant C u For each other participant C received v The secret share checks whether the following equation holds: in, represents the result of calculating the secret share sent by participant v to u on the group, Represents the result of calculating the secret share of the blinding factor sent by participant v to u on the group.
10. A privacy federated learning system based on model robustness filter as claimed in claim 1, characterized in that: In step 8, participant C u Generate C using Sigma protocol v Proof of correct decryption of secret shares, using DecSimga(pk, sk, m, c) → π dec represents the protocol, where π dec Represents the generated proof. The specific process is as follows: The public key is represented by the tuple (g, h) = pk, and the ciphertext is represented by the tuple (c1, c2) = c; randomly select Calculate A = g a , B=(c2*m -1 ) a , calculate the challenge factor e = Hash(g||h||m||c||A||B) and z = x*e+a, and generate proof π dec =(m, A, B, z); In step 9, the Sigma protocol verifies that VerifyDec(π dec , c, pk), the verification process checks whether the following two equations hold: g e *A=g z c1 e *b=(c2*m -1 ) z Among them, g z Represents the calculation result of the intermediate calculation z of the challenge factor e on the group.