Federal learning model, medium and method based on split learning and watermarking technology

By adopting split learning and watermarking technology in federated learning, the split learning method splits the federated learning model into client model and server model, and converts the sample labels through an autoencoder, solving the problem of difficult to prevent malicious client models in advance in the existing technology, and achieving the effect of effectively preventing the model from being stolen and verifying the model ownership.

CN120030511APending Publication Date: 2025-05-23HUNAN NORMAL UNIVERSITY
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510099048.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-22
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

It is difficult for existing technology to prevent malicious client models from being stolen in federated learning, and existing model watermarking technology can only be verified after the model is stolen.

Method used

The federated learning model is split into client model and server model by using split learning method, only partial model parameters are provided to the client, and sample labels are converted through the autoencoder, the loss function is determined using the converted label and the prediction results of the server model, and the gradient is backpropagated to prevent malicious clients from stealing the model.

Benefits of technology

Effectively prevent malicious clients from directly stealing and using a complete federated learning model, preventing the model from being stolen by the client, and conveniently verifying the model's ownership rights.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030511A_ABST
    Figure CN120030511A_ABST
Patent Text Reader

Abstract

The invention relates to a federated learning model, medium and method based on split learning and watermarking technology, and the method comprises the steps: a central server trains an auto-encoder, splits the federated learning model into client models and a central server model, carries out the deployment of the client models and the central server model, each client model carries out the prediction of a training sample, and obtains fragmented data; the server model conducts reasoning on the broken data to obtain a prediction label, a self-encoder is used for converting a real label of a sample to obtain a conversion label, loss is calculated and subjected to back propagation to obtain gradients of all layers, the gradient of the first layer is returned to a corresponding client side, then the gradients of the server model are aggregated, and server model parameters are updated; and after each client model is subjected to back propagation to obtain each layer of gradient, each layer of gradient is aggregated to update the client model, and the training processes of the server model and each client model are continuously iterated until the model is converged. The method has the advantages that the malicious client can be effectively prevented from embezzling the model, and the model ownership can be conveniently verified.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of artificial intelligence technology, and in particular to a federated learning model, medium and method based on split learning and watermark technology. Background Art

[0002] Federated learning is a distributed machine learning framework that protects data privacy. The framework consists of two entities: a central server and a client. Multiple clients (which can be mobile devices, personal computers, or servers) are coordinated by a central server to jointly train models while maintaining data locality. The core idea is that in each round of training, each client trains a local model on its own data, and then sends updates to the model (e.g., gradient information or parameter updates) to the central server, which aggregates these updates to generate a global model and sends it back to the client for the next round of training.

[0003] However, since the model training process is very expensive, selfish clients will not participate in the training for free, so the central server needs to motivate the clients to participate by paying them. In this way, the central server naturally becomes the owner of the model. Since the model has significant economic value, the central server must take measures to protect its intellectual property rights. However, the framework of federated learning allows the client to own the structure of the model and fully access the parameter information of the model, which increases the risk.

[0004] Existing technical solutions usually use the model watermark method to verify the ownership of the model, but this method can only be used to verify the ownership of the model after the model is stolen, and cannot prevent the client from stealing the model in advance. For example, in the technical solution disclosed in the Chinese invention patent application with application number CN202211399033.9 and titled "Federated learning method of artificial intelligence model combining homomorphic encryption and model watermarking", during the training process of the model, each client can access all parameters of the global model, and the model owner cannot prevent malicious clients from stealing the model. In the technical solution disclosed in the Chinese invention patent application with application number CN202111182538.5 and titled "Watermark detection method, system and electronic device based on federated learning model", the ownership of the model is detected by judging whether the sample to be detected contains watermark data, but this method can only verify the ownership of the suspicious model after the model is stolen, and cannot prevent malicious clients from stealing the model in advance. Summary of the invention

[0005] The technical problem to be solved by the present invention is: in response to the technical problems existing in the prior art, the present invention provides a federated learning model, medium and method based on split learning and watermarking technology, which can effectively prevent malicious clients from stealing models and verify the ownership of the model.

[0006] In order to solve the above technical problems, the technical solution proposed in the present invention is: a training method of a federated learning model based on split learning and watermark technology, comprising the following steps:

[0007] S1. The central server trains an autoencoder, which is used to convert the label category of the training sample;

[0008] S2. The central server initializes the federated learning model M and splits the federated learning model into client models M C and server model M S ; and the client model M C Deployed on the client, the server model M S Deployed on the central server; the client comprises a normal client and at least one backdoor client;

[0009] S3. The client inputs the client model M with the preset sample X respectively C , the broken data A is output, and the broken data A and the original label Y of the sample X are sent to the central server; the sample input to the normal client is a normal sample; the sample input to the backdoor client is a backdoor sample;

[0010] S4. The central server inputs the fragmented data A into the server model and outputs the prediction result Y′. The autoencoder converts the original label Y to obtain the converted label Y * ; With the predicted result Y′ and the converted label Y * Determine the model loss function, server model M S Back propagation obtains the gradient of each layer of the server model and returns the first layer gradient to the corresponding client model M C ; Client Model M C Back-propagating the first layer gradient to obtain the gradients of each layer of the client model;

[0011] S5. Aggregate the client models M C The corresponding server model M S The gradient of the server model M is updated S , aggregate the client model gradients and update the client model M C ;

[0012] S6. Repeat steps S3 to S5 until the split federated learning converges; then C and server model M S Put together a complete federated learning model M.

[0013] Furthermore, the autoencoder is a symmetric neural network structure including an encoder and a decoder; the autoencoder loss function of the autoencoder is shown in formula (1):

[0014] L 1 =k 1 I 1 (y,y)-k 2 I 2 (y * ,y) (1)

[0015] in,

[0016]

[0017] Where, L 1 is the autoencoder loss function, k 1 , k 2 is the preset adjustment loss hyperparameter, I 1 (y,y) is the cross entropy loss, I 2 (y * ,y) is the mean square error loss, y is the label of all original samples, y i is the i-th original sample label category, y is the output of the autoencoder encoding and decoding all original sample labels y, y i is the self-encoder for the i-th original sample label category y i The output of encoding and decoding, D is the number of normal sample categories, p is the number of backdoor sample categories, y * is the output of the encoder encoding y, is the encoder pair y i Encoded output.

[0018] Furthermore, in step S5, the gradients of each layer of the server model are aggregated as shown in formula (2):

[0019]

[0020] Update Server Model M S As shown in formula (3):

[0021]

[0022] In the formula, is the aggregate gradient of the tth iteration of the server model, N is the number of normal clients, q is the number of backdoor clients, j is the client number, t is the number of training iterations of the federated learning model, is the gradient of the server model at the tth iteration based on the jth client data, are the model parameters of the server model in the t+1th and tth iterations, respectively, SThe learning rate for the preset server model;

[0023] The gradient aggregation of each layer of the client model is shown in formula (4):

[0024]

[0025] Update Server Model M S As shown in formula (5):

[0026]

[0027] In the formula, is the aggregate gradient of the tth iteration of the client model, N is the number of normal clients, q is the number of backdoor clients, j is the client number, t is the number of training iterations of the federated learning model, is the gradient of the client model at the tth iteration based on the jth client data, The client model is the model parameter of the t+1th round and the tth round iteration, η C The default client model learning rate.

[0028] Furthermore, the number of categories of the backdoor samples is 1, the number of the backdoor clients is 1, and the server model learning rate is equal to the client model learning rate.

[0029] Furthermore, the backdoor sample is a random noise sample.

[0030] A federated learning model based on split learning and watermarking technology, wherein the federated learning model is a model trained by any of the methods described above.

[0031] A prediction method of a federated learning model based on split learning and watermarking technology, inputting a sample to be predicted into the federated learning model as described above, obtaining an output result of the federated learning model, and converting the output result through the autoencoder to obtain a prediction result.

[0032] A verification method for a federated learning model based on split learning and watermark technology, as described above, the model owner of the federated learning model inputs a preset backdoor sample into the federated learning model to be verified, obtains the output result of the federated learning model to be verified, and decodes the output result through the decoder to obtain a decoding result, and determines whether the decoding result is consistent with the category of the preset backdoor sample. If they are consistent, it is determined that the model to be verified belongs to the model owner, otherwise it is determined that the model to be verified does not belong to the model owner.

[0033] Furthermore, multiple preset backdoor samples are used as verification samples of the federated learning model to be verified, and the accuracy of whether the categories of the multiple preset backdoor samples are consistent with the decoding results is determined. When the accuracy is greater than a preset threshold, it is determined that the model to be verified belongs to the model owner, otherwise it is determined that the model to be verified does not belong to the model owner.

[0034] A computer storage medium having stored thereon the above-described federated learning model.

[0035] Compared with the prior art, the advantages of the present invention are:

[0036] 1. The technical solution of the present invention adopts a split learning method, so that the client can only obtain part of the model parameters and cannot access the model parameters of the central server. Therefore, the client cannot obtain the complete global federated learning model, which can effectively prevent malicious clients from directly stealing and using the complete federated learning model.

[0037] 2. The technical solution of the present invention converts the original labels of the samples through an autoencoder, determines the loss with the converted labels and the prediction results of the server model, and calculates the gradient by back propagation. The gradient obtained by the client is a pseudo-gradient after conversion, not a real gradient, which can effectively prevent malicious clients from inferring the model parameters of the central server through the gradient reverse, and prevent the model from being stolen by the client. In the model inference stage, only the owner of the correct decoder can decode the inference results of the model to obtain accurate output results, which also effectively prevents the model from being stolen.

[0038] 3. The present invention uses backdoor client and backdoor sample technology to increase the number of sample label types, which can effectively prevent malicious clients from forging autoencoders. On the other hand, it inserts a backdoor into the model so that the model outputs normal labels when predicting normal samples, and outputs backdoor labels when predicting backdoor samples, thereby facilitating verification of the ownership of the model. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] Figure 1 It is a schematic diagram of a flow chart of a specific embodiment of the present invention.

[0040] Figure 2 This is a training principle diagram of a specific embodiment of the present invention.

[0041] Figure 3 This is a schematic diagram of the model reasoning stage of a specific embodiment of the present invention.

[0042] Figure 4 Schematic diagram of the model training process of a specific embodiment of the present invention (taking one round of iteration as an example). DETAILED DESCRIPTION

[0043] The present invention is further described below in conjunction with the accompanying drawings and specific preferred embodiments, but the protection scope of the present invention is not limited thereby.

[0044] A training method of a federated learning model based on split learning and watermarking technology in this embodiment is as follows: Figure 1 , Figure 2 As shown, the following steps are included: S1. The central server trains the autoencoder, which is used to convert the label category of the training sample; S2. The central server initializes the federated learning model M and splits the federated learning model into the client model M C and server model M S ; and the client model M C Deployed on the client, the server model M S Deployed on the central server; the client includes a normal client and at least one backdoor client; S3. The client inputs the client model M with the preset sample X C , the output is the broken data A, and the broken data A and the original label Y of sample X are sent to the central server; the sample input to the normal client is the normal sample; the sample input to the backdoor client is the backdoor sample; S4. The central server inputs the broken data A into the server model, and the output is the predicted result Y′. The autoencoder converts the original label Y to obtain the converted label Y * ; With the predicted result Y′ and the converted label Y * Determine the model loss function, server model M S Back propagation obtains the gradients of each layer of the server model and returns the first layer gradient to the corresponding client model M C ; Client Model M C Back propagate the first layer gradient to obtain the gradients of each layer of the client model; S5. Aggregate each client model M C Corresponding server model M S The gradient of the server model M is updated S , aggregate the client model gradients and update the client model M C ; S6. Repeat steps S3 to S5 until the split federated learning converges; then the client model M C and server model M S The complete federated learning model M is assembled. This embodiment adopts a split learning method so that the client can only obtain part of the model parameters and cannot access the model parameters of the central server. Therefore, the client cannot obtain the complete global federated learning model, which can effectively prevent malicious clients from directly stealing and using the complete federated learning model.

[0045] In this embodiment, if Figure 2As shown, the preferred autoencoder is a symmetric neural network structure including an encoder and a decoder; the autoencoder loss function of the autoencoder is shown in formula (1):

[0046] L 1 =k 1 I 1 (y,y)-k 2 I 2 (y * ,y) (1) Among them,

[0047] Where, L 1 is the autoencoder loss function, k 1 , k 2 is the preset adjustment loss hyperparameter, I 1 (y,y) is the cross entropy loss, I 2 (y * ,y) is the mean square error loss, y is the label of all original samples, y i is the i-th original sample label category, y is the output of the autoencoder encoding and decoding all original sample labels y, y i is the self-encoder for the i-th original sample label category y i The output of encoding and decoding, D is the number of normal sample categories, p is the number of backdoor sample categories, y * is the output of the encoder encoding y, is the encoder pair y i The output of the encoding. The adjustment loss hyperparameter is preferably 0.05 ≥ k 1 ≥0.001, k 2 ≥1, further optimization k 1 =0.01, k 2 =1, of course, it is not limited to the values ​​listed in this embodiment, and the specific value can be adjusted according to the actual situation. It should be noted that the autoencoder in this embodiment converts the original label of the sample, determines the loss by the converted label and the prediction result of the server model, and back-propagates the gradient. The gradient obtained by the client is the pseudo-gradient after conversion, not the real gradient, which can effectively prevent malicious clients from inferring the model parameters of the central server through the gradient reverse, and prevent the model from being stolen by the client. Based on this idea, the autoencoder is not limited to the autoencoder loss function shown in formula (1).

[0048] In this embodiment, in step S5, the gradient aggregation of each layer of the server model is preferably as shown in formula (2):

[0049]

[0050] Update Server Model M SAs shown in formula (3):

[0051]

[0052] In the formula, is the aggregate gradient of the tth iteration of the server model, N is the number of normal clients, q is the number of backdoor clients, j is the client number, t is the number of training iterations of the federated learning model, is the gradient of the server model at the tth iteration based on the jth client data, are the model parameters of the server model in the t+1th and tth iterations, respectively, S is the preset server model learning rate, preferably 0.001≤η S ≤0.1;

[0053] The gradient aggregation of each layer of the client model is shown in formula (4):

[0054]

[0055] Update Server Model M S As shown in formula (5):

[0056]

[0057] In the formula, is the aggregate gradient of the tth iteration of the client model, N is the number of normal clients, q is the number of backdoor clients, j is the client number, t is the number of training iterations of the federated learning model, is the gradient of the client model at the tth iteration based on the jth client data, The client model is the model parameter of the t+1th round and the tth round iteration, η C is the preset client model learning rate, preferably 0.001≤η C ≤0.1.

[0058] In this embodiment, preferably, the number of backdoor sample categories is 1, the number of backdoor clients is 1, and the server model learning rate η is S Equal to the client model learning rate η C The number of backdoor clients is preferably 1, that is, q = 1. Of course, the model owner can set multiple categories of backdoor clients according to needs, that is, q> 1. Further preferably, the backdoor sample is a random noise sample.

[0059] like Figure 2 and 4 As shown, in this embodiment, the client C includes N normal clients C j ,j=1,2,L,N and 1 backdoor client Cbd , the normal client is deployed with a client model, the backdoor client is deployed with a backdoor client, the client is preset with a training sample data set X, and the sample label is Y. The training sample data set of each normal client is recorded as X 1 , X 2 , L, X k , LX N (i.e., the data set of normal samples), the sample labels are recorded as Y 1 , Y 2 , L, Y k LY N , the training sample data set of the backdoor client is recorded as X bd (i.e., the dataset of backdoor samples), the sample label is denoted as Y bd The backdoor sample has nothing to do with the normal sample. The client model M deployed in the client C The training samples of this client are predicted to obtain fragmented data A, where the client model M of the normal client C The predicted output fragmentation data is recorded as A 1 , A 2 , L, A k , LA N , the client model M of the backdoor client C The predicted output fragmentation data is recorded as A bd The client sends the fragmented data and the corresponding sample labels to the central server, and the central server inputs the fragmented data of each client into the server model M S , server model M S The output is the predicted results, recorded as Y 1 ′、Y 2 ′, L, Y k ', LY N ′ and Y bd ′, the central server’s autoencoder encodes the sample labels of each client to obtain the converted labels, which are denoted as Y 1 * , Y 2 * , L, Y k * LY N * and Y bd * The central server calculates the loss of each client's prediction result and converted label through the model loss function. The server model M of the central server S Perform back propagation respectively to calculate the server model M S The gradients of each layer, and the first layer gradients are recorded as G 1,1 , G2,1 LG k,1 LG N,1 and G bd,1 , returned to the corresponding client. The model loss function preferably uses the cross entropy loss function, of course, other loss functions can also be used as the model loss function. 1 The fragmented data and sample labels are in the server model M S Back propagation is performed to obtain the gradient of each layer, where the gradient of a certain layer is denoted as g S,1 , the first layer gradient is recorded as G 1,1 , the first-layer gradient is the gradient of the first layer of the model finally calculated in the back propagation process. After calculating all the gradient data, the central server aggregates the gradients of each layer respectively through the aggregation method shown in formula (2), and then aggregates the server model M through the formula shown in formula (3) S Update to obtain a new round of iterative server model M S Specifically, the central server sets the same number of server models M according to the number of clients. S Each copy performs back propagation to calculate the gradient of each layer, and then aggregates the gradient of each layer to update the server model M S At the same time, after calculating the first-layer gradient, the central server sends the first-layer gradient to each client, and the client model M of each client C Back propagation is performed on the first layer gradient to calculate each client model M C The gradients of each layer are aggregated by the aggregation method shown in formula (4), and the client model M is aggregated by the method shown in formula (5). C Specifically, an independent aggregation server can be set up to collect the client models M C The gradient information of each layer is aggregated and sent to the client, and the client updates the client model M C ; The central server can also assume the role of aggregation server. S and client model M C After that, one iteration of the federated learning model training is completed. The above iterative training process is continued until the model converges, and then the server model M S and client model M C The complete federated learning model is assembled to complete the training process of the federated learning model. It should be noted that in addition to the above specific implementation methods, the client model of each client can also be sent to a central server or aggregation server or other server device, and the server performs the reverse transmission, aggregation and update process of the client model, and distributes the updated client model to each client to complete the update of the client model.

[0060] This embodiment is a federated learning model based on split learning and watermarking technology. The federated learning model is a model trained by any of the above methods.

[0061] The prediction method of a federated learning model based on split learning and watermarking technology in this embodiment includes inputting a sample to be predicted into the above federated learning model, obtaining the output result of the federated learning model, and converting the output result through an autoencoder to obtain a prediction result. This embodiment converts the original label of the sample through an autoencoder, determines the loss with the converted label and the prediction result of the server model, and back-propagates and calculates the gradient. The gradient obtained by the client is a pseudo-gradient after conversion, not a real gradient, which can effectively prevent malicious clients from inferring the model parameters of the central server through the gradient reverse, and prevent the model from being stolen by the client. In the model reasoning stage, only the owner of the correct decoder can decode the reasoning result of the model to obtain an accurate output result, which also effectively prevents the model from being stolen.

[0062] A prediction method of a federated learning model based on split learning and watermarking technology in this embodiment is as follows: Figure 3 As shown, the model owner of the above federated learning model inputs the to-be-verified federated learning model with the preset backdoor sample, obtains the output result of the to-be-verified federated learning model, and decodes the output result through the decoder to obtain the decoding result, and determines whether the decoding result is consistent with the category of the preset backdoor sample. If they are consistent, the to-be-verified model is determined to belong to the model owner, otherwise, the to-be-verified model is determined not to belong to the model owner. The federated model owner can easily remotely verify whether the to-be-verified federated learning model belongs to the model owner through the backdoor sample.

[0063] In this embodiment, it is further preferred to use multiple preset backdoor samples as verification samples of the federated learning model to be verified, and determine whether the categories of the multiple preset backdoor samples are consistent with the decoding results. When the accuracy is greater than a preset threshold, it is determined that the model to be verified belongs to the model owner, otherwise it is determined that the model to be verified does not belong to the model owner.

[0064] This embodiment uses backdoor client and backdoor sample technology to increase the number of sample label types, which can effectively prevent malicious clients from forging autoencoders. On the other hand, a backdoor is inserted into the model so that the model outputs normal labels when predicting normal samples, and outputs backdoor labels when predicting backdoor samples, thereby facilitating verification of the ownership of the model.

[0065] A computer storage medium of this embodiment stores the above federated learning model.

[0066] The above is only a preferred embodiment of the present invention, and does not limit the present invention in any form. Although the present invention has been disclosed as a preferred embodiment, it is not intended to limit the present invention. Therefore, any simple modification, equivalent change and modification made to the above embodiment according to the technical essence of the present invention without departing from the content of the technical solution of the present invention shall fall within the scope of protection of the technical solution of the present invention.

Claims

1. A training method for a federated learning model based on split learning and watermarking technology, characterized in that: The steps include: S1. The central server trains an autoencoder, which is used to convert the label category of the training sample; S2. The central server initializes the federated learning model M and splits the federated learning model into client models M C and server model M S ; and the client model M C Deployed on the client, the server model M S Deployed on the central server; the client comprises a normal client and at least one backdoor client; S3. The client inputs the client model M with the preset sample X respectively C , the broken data A is output, and the broken data A and the original label Y of the sample X are sent to the central server; the sample input to the normal client is a normal sample; the sample input to the backdoor client is a backdoor sample; S4. The central server inputs the fragmented data A into the server model and outputs the prediction result Y′. The autoencoder converts the original label Y to obtain the converted label Y * ; With the predicted result Y′ and the converted label Y * Determine the model loss function, server model M S Back propagation obtains the gradient of each layer of the server model and returns the first layer gradient to the corresponding client model M C ; Client Model M C Back-propagating the first layer gradient to obtain the gradients of each layer of the client model; S5. Aggregate the client models M C The corresponding server model M S The gradient of the server model M is updated S , aggregate the client model gradients and update the client model M C ; S6. Repeat steps S3 to S5 until the split federated learning converges; then C and server model M S Put together a complete federated learning model M.

2. The training method of the federated learning model based on split learning and watermarking technology according to claim 1 is characterized in that: The autoencoder is a symmetrical neural network structure including an encoder and a decoder; the autoencoder loss function of the autoencoder is shown in formula (1): L1=k1I1(y,y)-k2I2(y * ,and) (1) in, Where L1 is the autoencoder loss function, k1 and k2 are preset adjustment loss hyperparameters, I1(y,y) is the cross entropy loss, and I2(y * ,y) is the mean square error loss, y is the label of all original samples, y i is the i-th original sample label category, y is the output of the autoencoder encoding and decoding all original sample labels y, y i is the self-encoder for the i-th original sample label category y i The output of encoding and decoding, D is the number of normal sample categories, p is the number of backdoor sample categories, y * is the output of the encoder encoding y, is the encoder pair y i Encoded output.

3. The training method of the federated learning model based on split learning and watermarking technology according to claim 1 or 2, characterized in that: In step S5, The gradient aggregation of each layer of the server model is shown in formula (2): Update Server Model M S As shown in formula (3): In the formula, is the aggregate gradient of the tth iteration of the server model, N is the number of normal clients, q is the number of backdoor clients, j is the client number, t is the number of training iterations of the federated learning model, is the gradient of the server model at the tth iteration based on the jth client data, are the model parameters of the server model in the t+1th and tth iterations, respectively, S The learning rate for the preset server model; The gradient aggregation of each layer of the client model is shown in formula (4): Update Server Model M S As shown in formula (5): In the formula, is the aggregate gradient of the tth iteration of the client model, N is the number of normal clients, q is the number of backdoor clients, j is the client number, t is the number of training iterations of the federated learning model, is the gradient of the client model at the tth iteration based on the jth client data, The client model is the model parameter of the t+1th round and the tth round iteration, η C The default client model learning rate.

4. The training method of the federated learning model based on split learning and watermarking technology according to claim 3 is characterized in that: The number of categories of the backdoor samples is 1, the number of the backdoor clients is 1, and the server model learning rate is equal to the client model learning rate.

5. The training method of the federated learning model based on split learning and watermarking technology according to claim 1, characterized in that: The backdoor samples are random noise samples.

6. A federated learning model based on split learning and watermarking technology, characterized by: The federated learning model is a model trained by the method described in any one of claims 1 to 5.

7. A prediction method for a federated learning model based on split learning and watermarking technology, characterized in that: Input the sample to be predicted into the federated learning model as described in claim 6, obtain the output result of the federated learning model, and convert the output result through the autoencoder to obtain a prediction result.

8. A verification method for a federated learning model based on split learning and watermarking technology, characterized in that: The model owner of the federated learning model as described in claim 6 inputs the federated learning model to be verified with a preset backdoor sample, obtains the output result of the federated learning model to be verified, and decodes the output result through the decoder to obtain a decoding result, and determines whether the decoding result is consistent with the category of the preset backdoor sample. If they are consistent, it is determined that the model to be verified belongs to the model owner; otherwise, it is determined that the model to be verified does not belong to the model owner.

9. The verification method of the federated learning model based on split learning and watermarking technology according to claim 8 is characterized in that: Using multiple preset backdoor samples as verification samples of the federated learning model to be verified, and judging the accuracy of whether the categories of the multiple preset backdoor samples are consistent with the decoding results; when the accuracy is greater than a preset threshold, it is determined that the model to be verified belongs to the model owner; otherwise, it is determined that the model to be verified does not belong to the model owner.

10. A computer storage medium, characterized in that: The storage medium stores the federated learning model as claimed in claim 6.

Citation Information

Patent Citations

  • Watermark detection method and system based on federated learning model, and electronic equipment

    CN113901405A

  • Artificial intelligence model federal learning method combining homomorphic encryption and model watermarking

    CN115758402A