Anti-Byzantine attack detection method and system based on federal learning

By generating noise keys and obfuscation factors on the vehicle side, and generating obfuscation gradients in combination with constant sequences, it is transmitted to the traffic cloud server for Byzantine attack detection, the threat of Byzantine attacks to data privacy and system performance in the distributed federated learning system is solved, and efficient privacy protection and attack detection are achieved.

CN120050060APending Publication Date: 2025-05-27HUBEI UNIV OF TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411938573.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-26
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

In the distributed federated learning system, the security and privacy protection of data and model parameters are severe, and traditional solutions are difficult to effectively respond to Byzantine attacks, resulting in system performance degradation and user privacy leakage.

Method used

By generating noise keys and obfuscation factors on the vehicle side and generating obfuscation gradients in combination with constant sequences, it is transmitted to the traffic cloud server for Byzantine attack detection. This method can determine the normality of the vehicle or the Byzantine node identity by comparing the local gradient sum with the global gradient sum, thereby achieving data privacy protection and attack detection.

Benefits of technology

This method not only ensures the privacy and security of vehicle data, but also significantly reduces the communication overhead of the federated learning system against Byzantine attacks, improving the security and efficiency of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120050060A_ABST
    Figure CN120050060A_ABST
Patent Text Reader

Abstract

The invention provides an anti-Byzantine attack detection method and system based on federal learning, and relates to the technical field of privacy protection. The method comprises the following steps: aggregating local gradients of all vehicles to train a to-be-trained global model to obtain a trained global model; determining the total number of parameters in the trained global model, generating a group of constant sequences for all the vehicles according to the total number of parameters, and sending the group of constant sequences to all the vehicles; receiving a local gradient sum sent by the vehicle; determining a global gradient sum of the trained global model; performing Byzantine attack detection according to the local gradient sum and the global gradient sum; the local gradient sum is obtained by the corresponding vehicle according to a group of constant sequences, the local gradient and a group of confusion factors; a set of confusion factors is generated for the vehicle by the traffic management department. The method can ensure that the local gradient does not leak privacy in the uploading and aggregation process, reduces the calculation overhead, guarantees the safety of model parameters, and reduces the Byzantine attack.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of privacy protection, and more particularly, to an anti-Byzantine attack detection method and system based on federated learning. Background Art

[0002] With the development of distributed systems and machine learning technologies, many innovative applications have been widely used, especially distributed machine learning systems, which can effectively process large-scale data. However, these systems also face many new challenges, one of which is the Byzantine attack. The Byzantine attack can affect the performance of the overall system and the accuracy of global model training by spreading incorrect or malicious information to the system. Traditional distributed systems cannot effectively cope with these attacks, making effective Byzantine attack detection while maintaining system efficiency a research hotspot.

[0003] In a distributed federated learning system, the security and privacy protection of data and model parameters also face severe tests. Since data is transmitted between multiple nodes, malicious attackers may steal, tamper with, or forge data, thereby affecting the results of model training. This will not only affect the overall performance of the system, but may also pose a serious threat to user privacy. For example, once sensitive information such as vehicle networking data, medical data, and financial data is leaked, it will not only affect the personal privacy of users, but may also cause legal problems. Therefore, it is particularly important to implement an efficient privacy protection and Byzantine attack detection mechanism in a distributed federated learning system.

[0004] Currently, many solutions attempt to improve the security of the system through encryption technologies and privacy protection mechanisms. However, these solutions usually bring high computational and communication overheads, thereby affecting the efficiency and scalability of the system. For example, although the widely used homomorphic encryption scheme can perform calculations on encrypted data, its computational cost is relatively high and it is difficult to apply in a large-scale data environment. In addition, although some traditional Byzantine fault-tolerant algorithms can defend against attacks to a certain extent, their highly complex calculation processes make the system unable to handle a large number of concurrent tasks, affecting the actual application effect. Therefore, the Byzantine attack detection scheme not only needs to ensure that privacy is not leaked during the upload and aggregation processes, but also effectively reduce the computational overhead while ensuring the security of model parameters. Summary of the Invention

[0005] The purpose of the present invention is to provide an anti-Byzantine attack detection method and system based on federated learning for the deficiencies in the above-mentioned prior art, so as to ensure that local gradients do not leak privacy during the upload and aggregation processes, reduce the computational overhead, ensure the security of model parameters, and at the same time reduce Byzantine attacks.

[0006] To achieve the above object, the technical solution adopted in the embodiments of the present application is as follows:

[0007] In a first aspect, an anti-Byzantine attack detection method based on federated learning is provided in the embodiments of the present application, which is applied to a traffic cloud server and includes: aggregating the local gradients of all vehicles to train a global model to be trained to obtain a trained global model; determining the total number of parameters in the trained global model, and generating a set of constant sequences for all the vehicles according to the total number of parameters, and sending the set of constant sequences to all the vehicles; receiving the sum of the local gradients sent by the vehicles; determining the sum of the global gradients of the trained global model; performing Byzantine attack detection based on the sum of the local gradients and the sum of the global gradients; the sum of the local gradients is obtained by the corresponding vehicle according to the set of constant sequences, the local gradients and a set of confusion factors; the set of confusion factors is generated by the traffic management department for the vehicles; and the sum of the set of confusion factors is 0.

[0008] In an implementation manner, the performing Byzantine attack detection based on the sum of the local gradients and the sum of the global gradients includes: comparing the sum of the global gradients with the sum of the local gradients, and when the difference between the sum of the global gradients and the sum of the local gradients is within a first preset threshold range, the number of valid data is incremented by 1; otherwise, the number of valid data remains unchanged; determining whether the number of valid data reaches a second preset threshold, and when the number of valid data reaches the second preset threshold, the vehicle is a normal node; otherwise, the vehicle is a Byzantine node.

[0009] In an implementation manner, when the difference between the sum of the global gradients and the sum of the local gradients is within the first preset threshold range, the number of valid data is determined according to the following formula:

[0010]

[0011] where (a 1 , a 2 ) represents the first preset threshold range; represents the number of valid data; represents the sum of the local gradients; represents the sum of the global gradients.

[0012] In an implementation manner, when determining whether the number of valid data reaches the second preset threshold, Byzantine attack detection is performed according to the following formula:

[0013]

[0014] where βe represents the second preset threshold; represents the number of valid data.

[0015] In one embodiment, after detecting Byzantine attacks based on the local gradient and the global gradient sum, the method further includes: processing the trained global model with a confused gradient and an expansion factor; performing a modulo operation on the processed trained global model to eliminate the set of confused factors with a noise key, thereby obtaining the aggregated trained global model.

[0016] In one embodiment, after obtaining the aggregated trained global model, the method further includes: determining the next global model to be trained based on the aggregated trained global model, a learning rate, and the trained global model.

[0017] In a second aspect, an embodiment of the present application provides a Byzantine attack detection method based on federated learning, which is applied to a traffic management department and includes: generating a noise key and a set of confused factors for each vehicle, and sending the noise key and the set of confused factors to the corresponding vehicle, instructing the corresponding vehicle to obtain a local gradient sum according to the set of confused factors, a set of constant sequences, and a local gradient, and sending the local gradient sum to a traffic cloud server, instructing the traffic cloud server to detect Byzantine attacks based on the local gradient sum and the global gradient sum of a trained global model; the trained global model is obtained by the traffic cloud server aggregating the local gradients of all vehicles to train a global model to be trained; the set of constant sequences is determined by the traffic cloud server for the total number of parameters in the trained global model, and generated for all vehicles according to the total number of parameters; the sum of the set of confused factors is 0.

[0018] In a third aspect, an embodiment of the present application provides a Byzantine attack detection method based on federated learning, which is applied to a vehicle and includes: receiving a noise key, a set of confused factors sent by a traffic management department, and a set of constant sequences sent by a traffic cloud server; the sum of the set of confused factors is 0; obtaining a local gradient sum according to the set of confused factors, the set of constant sequences, and a local gradient, and sending the local gradient sum to the traffic cloud server, instructing the traffic cloud server to detect Byzantine attacks based on the local gradient sum and the global gradient sum of a trained global model; the trained global model is obtained by the traffic cloud server aggregating the local gradients of all vehicles to train a global model to be trained; the set of constant sequences is determined by the traffic cloud server for the total number of parameters in the trained global model, and generated for all vehicles according to the total number of parameters.

[0019] In one implementation, obtaining the local gradient sum according to the set of confusion factors, the set of constant sequences, and the local gradient includes: generating an extended confusion factor according to the set of confusion factors and the set of constant sequences, then obtaining a confused gradient according to the extended confusion factor and the local gradient, and then calculating the unit group gradient sum of the confused gradient in units of length n to obtain the local gradient sum; the sum of the set of confusion factors is 0.

[0020] Fourthly, an embodiment of the present application provides a federated learning system against Byzantine attacks, including: a traffic management department, configured to generate a noise key and a set of confusion factors for each vehicle, and send the noise key and the set of confusion factors to the vehicle; the sum of the set of confusion factors is 0; a vehicle, configured to receive the noise key, the set of confusion factors sent by the traffic management department, and a set of constant sequences sent by a traffic cloud server; obtain a local gradient sum according to the set of confusion factors, the set of constant sequences, and the local gradient, and send the local gradient sum to the traffic cloud server; a traffic cloud server, configured to aggregate the local gradients of all vehicles to train a global model to be trained to obtain a trained global model; determine the total number of parameters in the trained global model, and generate a set of constant sequences for all the vehicles according to the total number of parameters, and send the set of constant sequences to all the vehicles; receive the local gradient sum sent by the vehicle; determine the global gradient sum of the trained global model; and perform Byzantine attack detection according to the local gradient sum and the global gradient sum.

[0021] Fifthly, an embodiment of the present application provides a Byzantine attack detection device based on federated learning, which is applied to a traffic cloud server, including: a model training module, configured to aggregate the local gradients of all vehicles to train a global model to be trained to obtain a trained global model; a parameter generation module, configured to determine the total number of parameters in the trained global model, and generate a set of constant sequences for all the vehicles according to the total number of parameters, and send the set of constant sequences to all the vehicles; a determination module, configured to receive the local gradient sum sent by the vehicle; determine the global gradient sum of the trained global model; a detection module, configured to perform Byzantine attack detection according to the local gradient sum and the global gradient sum; the local gradient sum is obtained by the corresponding vehicle according to the set of constant sequences, the local gradient, and a set of confusion factors; the set of confusion factors is generated by the traffic management department for the vehicle; the sum of the set of confusion factors is 0.

[0022] In one embodiment, the detection module is configured to: compare the global gradient sum with the local gradient sum. When the difference between the global gradient sum and the local gradient sum is within a first preset threshold range, the number of valid data is incremented by 1; otherwise, the number of valid data remains unchanged. Determine whether the number of valid data reaches a second preset threshold. When the number of valid data reaches the second preset threshold, the vehicle is a normal node; otherwise, the vehicle is a Byzantine node.

[0023] In one embodiment, the detection module is configured to determine the number of valid data according to the following formula:

[0024]

[0025] where (a 1 , a 2 ) represents the first preset threshold range; represents the number of valid data; represents the local gradient sum; represents the global gradient sum.

[0026] In one embodiment, the detection module is configured to perform Byzantine attack detection according to the following formula:

[0027]

[0028] where βe represents the second preset threshold; represents the number of valid data.

[0029] In one embodiment, the model training module is further configured to: process the trained global model using the confusion gradient and the expansion factor; perform modular arithmetic on the processed trained global model to eliminate the set of confusion factors using the noise key, and obtain the aggregated trained global model.

[0030] In one embodiment, the model training module is further configured to: determine the next round of the global model to be trained according to the aggregated trained global model, the learning rate, and the trained global model.

[0031] The beneficial effects of this application are as follows: By combining the confusion factor with the local gradient to generate the confusion gradient, it not only ensures the data privacy and security of vehicles, but also greatly reduces the communication overhead of the federated learning system against Byzantine attacks; applying the system composed of the traffic management department, the traffic cloud server, and vehicles to the vehicle network, an artificial intelligence model is successfully obtained, and the travel efficiency and driving safety are improved by using this model; it can effectively detect Byzantine attacks, especially against random noise attacks and gradient reversal attacks, which helps to improve the security of the federated learning system against Byzantine attacks; on the premise of ensuring that the computational cost during the aggregation process is almost the same as that of plaintext calculation, the security of gradient information is guaranteed, and the computational overhead of the federated learning system against Byzantine attacks is reduced, which has high practicability. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the embodiments. It should be understood that the following drawings only show some embodiments of the present invention, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0033] Figure 1 It is a schematic flowchart of a federated learning method against Byzantine attacks provided by an embodiment of this application;

[0034] Figure 2 It is a schematic flowchart of a federated learning method against Byzantine attacks provided by an embodiment of this application;

[0035] Figure 3 It is a schematic flowchart of a method for detecting Byzantine attacks based on federated learning provided by an embodiment of this application;

[0036] Figure 4 It is a schematic flowchart of a method for detecting Byzantine attacks based on federated learning provided by an embodiment of this application;

[0037] Figure 5 It is an architecture diagram of a federated learning system against Byzantine attacks provided by an embodiment of this application;

[0038] Figure 6 It is a schematic flowchart of a method for detecting Byzantine attacks based on federated learning provided by an embodiment of this application;

[0039] Figure 7 It is a schematic structural diagram of a device for detecting Byzantine attacks based on federated learning provided by an embodiment of this application;

[0040] Figure 8 It is a schematic structural diagram of a computer device provided by an embodiment of this application. Detailed implementation manners

[0041] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some but not all of the embodiments of the present invention.

[0042] Therefore, the detailed description of the embodiments of the present application provided in the accompanying drawings is not intended to limit the scope of the present application claimed, but merely represents selected embodiments of the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in the present application without creative efforts fall within the scope of protection of the present application.

[0043] In the description of the present application, it should be noted that if terms such as "upper", "lower", etc. indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings, or the orientation or positional relationship in which the product of the present application is usually placed during use, it is only for the convenience of describing the present application and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as a limitation to the present application.

[0044] In addition, terms such as "first", "second", etc. in the description and claims of the present invention and the above accompanying drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0045] It should be noted that the features in the embodiments of the present application can be combined with each other without conflict.

[0046] Figure 1 A flowchart of a federated learning method against Byzantine attacks provided for the embodiments of the present application; as Figure 1 shown, applied to a traffic cloud server, the method includes:

[0047] Step 110: Aggregate the local gradients of all vehicles to train the global model to be trained, and obtain the trained global model.

[0048] Among them, the vehicle receives the to-be-trained global model of the current round sent by the traffic cloud server, and then uses local data to train the to-be-trained global model (usually optimizing for several rounds through gradient descent and calculating the local gradient), obtains the local gradient required for the trained global model, and sends the local gradient required for the trained global model back to the traffic cloud server. The traffic cloud server aggregates these local gradients to train the to-be-trained global model and obtains the trained global model g k .

[0049] Step 120: Determine the total number of parameters in the trained global model, generate a set of constant sequences for all vehicles according to the total number of parameters, and send the set of constant sequences to all vehicles.

[0050] Among them, the constant sequence (N 1 , N 2 ,..., N e ), e = G / n, where the constant sequence refers to a random constant sequence like 1, 2, 3; G represents the total number of parameters; n represents the number of a set of confounding factors; e represents the number of constants in the constant sequence.

[0051] Step 130: Receive the local gradient sum sent by the vehicle; determine the global gradient sum of the trained global model; perform Byzantine attack detection based on the local gradient sum and the global gradient sum.

[0052] Among them, the local gradient sum is obtained by the corresponding vehicle according to a set of constant sequences, the local gradient, and a set of confounding factors; a set of confounding factors is generated by the traffic management department for the vehicle; the sum of a set of confounding factors is 0.

[0053] The global gradient sum can be calculated by taking the unit group gradient sum in units of a fixed length; specifically, the above step 130 can further include the following steps:

[0054] Taking the length n as the unit, calculate the unit group gradient sum of the trained global model to obtain the global gradient sum.

[0055] Among them, the global gradient sum

[0056] Byzantine attack detection can be determined by comparing the global gradient sum with the local gradient; specifically, as Figure 2 shown, the above step 140 can further include the following step 210 and step 220:

[0057] Step 210: Compare the global gradient sum with the local gradient sum. When the difference between the global gradient sum and the local gradient sum is within the range of the first preset threshold, the number of valid data is incremented by 1; otherwise, the number of valid data remains unchanged.

[0058] Among them, the first preset threshold range can be set according to experience or by referring to relevant literature, and there is no limitation here.

[0059] The above step 210 is determined according to the following formula (1):

[0060]

[0061] Among them, (a 1 , a 2 ) represents the first preset threshold range; represents the number of valid data; represents the sum of local gradients; represents the sum of global gradients.

[0062] Step 220: Determine whether the number of valid data reaches the second preset threshold. When the number of valid data reaches the second preset threshold, the vehicle is a normal node; otherwise, the vehicle is a Byzantine node.

[0063] Among them, the second preset threshold can be set according to experience or by referring to relevant literature, and there is no limitation here.

[0064] The above step 220 is determined according to the following formula (2):

[0065]

[0066] Among them, βe is the second preset threshold.

[0067] The anti-Byzantine attack detection method based on federated learning provided by the embodiments of the present application first aggregates the local gradients of all vehicles to train the global model to be trained, and obtains the trained global model; secondly, determines the total number of parameters in the trained global model, and generates a set of constant sequences for all vehicles according to the total number of parameters, and sends the set of constant sequences to all vehicles; thirdly, receives the sum of the local gradients sent by the vehicles; determines the sum of the global gradients of the trained global model; performs Byzantine attack detection based on the sum of the local gradients and the sum of the global gradients; the sum of the local gradients is obtained by the corresponding vehicle according to a set of constant sequences, local gradients and a confusion factor; the confusion factor is generated by the traffic management department for the vehicle. In this way, by combining the confusion factor and the local gradient to generate the confused gradient, not only the data privacy and security of the vehicle are guaranteed, but also the communication overhead of the anti-Byzantine attack federated learning system is greatly reduced; the system composed of the traffic management department, the traffic cloud server, and the vehicle is applied to the vehicle network, and an artificial intelligence model is successfully obtained, and the travel efficiency and driving safety are improved by using this model; Byzantine attacks can be effectively detected, especially against random noise attacks and gradient reversal attacks, which helps to improve the security of the anti-Byzantine attack federated learning system; the security of the gradient information is guaranteed on the premise that the computational cost during the aggregation process is almost the same as that of plaintext calculation, and the computational overhead of the anti-Byzantine attack federated learning system is reduced, which has high practicality.

[0068] To improve the accuracy of the trained global model, the trained global model can be further adjusted; specifically, as Figure 3 shown, the anti-Byzantine attack detection method based on federated learning provided by the embodiments of the present application can further include the following steps 310 and 320:

[0069] Step 310: Process the trained global model with the confused gradient and the expansion factor.

[0070] Among them, the processing result Among them, represents the trained global model containing the confusion factor; f i k represents the local confused gradient of the i-th vehicle; represents the expansion factor of the i-th vehicle; m represents the number of vehicles participating in the training in the k-th round; p is a large prime number, generally 2048 bits.

[0071] Step 320: Perform modular arithmetic on the processed trained global model to eliminate a set of confusion factors with the noise key, and obtain the aggregated trained global model.

[0072] Among them, the expansion factor Among them, c is a constant.

[0073] The purpose of introducing the extension factor is to reduce the impact of malicious vehicles on model aggregation.

[0074] Modular arithmetic where 10 δ is used to amplify the gradient. δ usually represents the number of significant digits of the fractional part of the gradient, that is, the precision required when amplifying the gradient from a floating-point number to an integer; represents the trained global model containing the confusion factor; is the trained global model after removing the confusion factor.

[0075] In the next round of training, all vehicles participating in the training participate in the training based on the aggregated trained global model; the traffic cloud server determines the global model to be trained in the next round according to the aggregated trained global model, the learning rate, and the trained global model.

[0076] where the traffic cloud server calculates where η represents the learning rate; k represents the current training round; ε represents the noise key; g k+1 is the global model to be trained in the next round; g k is the trained global model of this round; is the trained global model after removing a set of confusion factors.

[0077] After introducing the Byzantine attack detection method based on federated learning on the traffic cloud server side of the exemplary embodiment of the present disclosure, next, the Byzantine attack detection method based on federated learning on the traffic management department side will be described:

[0078] Generate a noise key and a set of confusions for each vehicle, and send the noise key and a set of confusion factors to the corresponding vehicle, instruct the corresponding vehicle to obtain the sum of local gradients according to a set of confusion factors, a set of constant sequences, and the local gradient, and send the sum of local gradients to the traffic cloud server, instruct the traffic cloud server to perform Byzantine attack detection according to the sum of local gradients and the sum of global gradients of the trained global model; the trained global model is obtained by the traffic cloud server aggregating the local gradients of all vehicles to train the global model to be trained; a set of constant sequences is determined by the traffic cloud server for the total number of parameters in the trained global model and generated for all vehicles; the sum of a set of confusion factors is 0.

[0079] where the Traffic Management Department (TMD) generates a set of confusion factors (a 1 , a 2 ,..., a n ) for each vehicle, a 1 + a 2 +... + a n= 0。

[0080] The noise key ε satisfies the constraint condition wherein represents the expansion factor; ε represents the noise key; represents the confusion factor of the i-th vehicle; represents the expansion factor of the i-th vehicle; m represents the number of vehicles participating in the training in the k-th round.

[0081] Except that the execution subject of the above method is different from the federated learning-based anti-Byzantine attack detection method on the traffic cloud server side, the rest are the same and will not be elaborated here.

[0082] After introducing the federated learning-based anti-Byzantine attack detection method on the traffic management department side of the exemplary embodiment of the present disclosure, next, the federated learning-based anti-Byzantine attack detection method on the vehicle side will be described; as Figure 4 shown, the federated learning-based anti-Byzantine attack detection method on the vehicle side includes the following steps 410 and 420:

[0083] Step 410: Receive the noise key sent by the traffic management department, a set of confusion factors, and a set of constant sequences sent by the traffic cloud server; the sum of a set of confusion factors is 0.

[0084] Step 420: Obtain the sum of local gradients according to a set of confusion factors, a set of constant sequences, and local gradients, and send the sum of local gradients to the traffic cloud server, instructing the traffic cloud server to perform Byzantine attack detection based on the sum of local gradients and the sum of global gradients of the trained global model.

[0085] Among them, the trained global model is obtained by the traffic cloud server aggregating the local gradients of all vehicles to train the global model to be trained; a set of constant sequences is determined by the traffic cloud server for the total number of parameters in the trained global model and generated for all vehicles.

[0086] The calculation units of the sum of local gradients and the sum of global gradients are consistent. Specifically, the above obtaining the sum of local gradients according to a set of confusion factors, a set of constant sequences, and local gradients may further include the following steps:

[0087] Generate an extended confusion factor according to a set of confusion factors and the set of constant sequences, then obtain a confused gradient according to the extended confusion factor and local gradients, and then calculate the unit group gradient sum of the confused gradient in units of length n to obtain the sum of local gradients.

[0088] Among them, the extended confusion factor can be obtained by multiplying the confusion factor and the constant sequence; that is, the extended confusion factor

[0089] The confused gradient can be obtained by adding the local gradient and the extended confusion factor; that is, the confused gradient represents the j-th confused gradient of the h-th group in the k-th round of the vehicle; ε represents the noise key; represents the j-th local gradient of the h-th group in the k-th round of the vehicle; represents the j-th confusion factor of the h-th group of the vehicle.

[0090] The local gradient and

[0091] Except that the execution subject of the above method is different from the federated learning-based anti-Byzantine attack detection method on the traffic cloud server side, the rest are the same and will not be elaborated here.

[0092] After introducing the federated learning-based anti-Byzantine attack detection method on the vehicle side of the exemplary embodiments of the present disclosure, next, a federated learning system against Byzantine attacks will be described; as Figure 5 shown, the federated learning system 500 against Byzantine attacks includes:

[0093] The traffic management department 510 is used to generate a noise key and a set of confusion factors for each vehicle 520, and send the noise key and a set of confusion factors to the vehicle 520; the sum of a set of confusion factors is 0;

[0094] The vehicle 520 is used to receive the noise key, a set of confusion factors sent by the traffic management department 510, and a set of constant sequences sent by the traffic cloud server 530; obtain the sum of the local gradients according to a set of confusion factors, a set of constant sequences, and the local gradient, and send the sum of the local gradients to the traffic cloud server 530;

[0095] The traffic cloud server 530 is used to aggregate the local gradients of all vehicles 520 to train the to-be-trained global model to obtain the trained global model; determine the total number of parameters in the trained global model, and generate a set of constant sequences for all vehicles 520 according to the total number of parameters, and send a set of constant sequences to all vehicles 520; receive the sum of the local gradients sent by the vehicle 520; determine the sum of the global gradients of the trained global model; perform Byzantine attack detection according to the sum of the local gradients and the sum of the global gradients.

[0096] After introducing the federated learning method against Byzantine attacks of the exemplary embodiments of the present disclosure, next, as Figure 6 shown, the federated learning method against Byzantine attacks will be further described through an embodiment:

[0097] The federated learning method against Byzantine attacks of the exemplary embodiments of the present disclosure includes the following steps:

[0098] Step 1, System initialization:

[0099] Step 1.1: The traffic management department generates a noise key and a set of confusion factors for each vehicle, and the sum of a set of confusion factors is 0;

[0100] Step 1.2: Send the noise key and the confusion factors to the corresponding vehicle;

[0101] Step 1.3: Each vehicle obtains the encryption parameters composed of the corresponding confusion factors and the noise key;

[0102] Step 1.4: The traffic cloud server aggregates the local gradients of all vehicles to train the global model to be trained, obtains the trained global model, and sends the trained global model to all vehicles;

[0103] Step 1.5: The traffic cloud server calculates the total number of parameters in the trained global model and generates a set of constant sequences for all vehicles according to the total number of parameters.

[0104] Step 2: Byzantine attack detection:

[0105] Step 2.1: Each vehicle multiplies the corresponding confusion factor by a set of constant sequences to obtain an extended confusion factor;

[0106] Step 2.2: Add the extended confusion factor and the local gradient to obtain a confused gradient; calculate the sum of the unit group gradients in units of length n to obtain the local gradient sum;

[0107] Step 2.3: The traffic cloud server calculates the sum of the unit group gradients of the trained global model in units of length n to obtain the global gradient sum;

[0108] Step 2.4: The traffic cloud server compares the global gradient sum with the local gradient. When the difference between the global gradient sum and the local gradient sum is within the range of the first preset threshold, the number of valid data is incremented by 1; otherwise, the number of valid data remains unchanged; when the number of valid data reaches the second preset threshold, the vehicle is a normal node; otherwise, the vehicle is a Byzantine node.

[0109] Step 3: Aggregation and distribution of the model:

[0110] Step 3.1: The traffic cloud server multiplies the confused gradient by the extension to obtain an intermediate calculation result; perform a modulo operation on the intermediate calculation result to eliminate a set of confusion factors using the noise key to obtain the aggregated trained global model;

[0111] Step 3.2: The traffic cloud server calculates where η is the learning rate.

[0112] The Byzantine-attack-resistant federated learning method provided by the embodiments of the present application realizes an efficient Byzantine-attack-resistant federated learning system for the vehicle network (composed of a traffic management department, a traffic cloud server, and vehicles) by combining a confusion factor and a local gradient to generate a confused gradient, ensuring that privacy is not leaked during the upload and aggregation of gradients and significantly reducing the impact of Byzantine attacks.

[0113] After introducing the Byzantine-attack-resistant federated learning method of the exemplary embodiments of the present disclosure, next, reference is made to Figure 7 to describe the Byzantine-attack-resistant federated learning device 700 of the exemplary embodiments of the present disclosure.

[0114] Reference is made to Figure 7 , the Byzantine-attack detection device 700 based on federated learning, which is applied to a traffic cloud server, includes: a model training module 710 configured to aggregate the local gradients of all vehicles to train a global model to be trained; a parameter generation module 720 configured to determine the total number of parameters in the trained global model and generate a set of constant sequences for all vehicles according to the total number of parameters, and send the set of constant sequences to all vehicles; a determination module 730 configured to receive the local gradients sent by the vehicles and; determine the global gradient sum of the trained global model; a detection module 740 configured to perform Byzantine attack detection based on the local gradient sum and the global gradient sum; the local gradient sum is obtained by the corresponding vehicle according to a set of constant sequences, the local gradient, and a set of confusion factors; a set of confusion factors is generated by the traffic management department for the vehicles; and the sum of a set of confusion factors is 0.

[0115] In one embodiment, the detection module 740 is configured to: compare the global gradient sum with the local gradient sum, and when the difference between the global gradient sum and the local gradient sum is within the range of a first preset threshold, the number of valid data is incremented by 1; otherwise, the number of valid data remains unchanged; determine whether the number of valid data reaches a second preset threshold, and when the number of valid data reaches the second preset threshold, the vehicle is a normal node; otherwise, the vehicle is a Byzantine node.

[0116] In one embodiment, the detection module 740 is configured to: determine the number of valid data according to the following formula:

[0117]

[0118] where, (a 1 , a 2 ) represents the range of the first preset threshold; represents the number of valid data; represents the local gradient sum; represents the global gradient sum.

[0119] In one embodiment, the detection module 740 is configured to perform Byzantine attack detection according to the following formula:

[0120]

[0121] where βe represents the second preset threshold; represents the number of valid data.

[0122] In one embodiment, the model training module 710 is further configured to process the trained global model by using the confused gradient and the expansion factor; perform modular arithmetic on the processed trained global model to eliminate a set of confused factors by using a noise key, so as to obtain the aggregated trained global model.

[0123] In one embodiment, the model training module 710 is further configured to determine the next round of the global model to be trained according to the aggregated trained global model, the learning rate, and the trained global model.

[0124] The above device is used to execute the method provided in the foregoing embodiment, and its implementation principle and technical effect are similar, which will not be elaborated herein.

[0125] The above modules may be one or more integrated circuits configured to implement the above method, for example: one or more application specific integrated circuits (ASICs), or, one or more microprocessors, or, one or more field programmable gate arrays (FPGAs), etc. Again, when the above certain module is implemented in the form of a processing element scheduling program code, the processing element may be a general-purpose processor, such as a central processing unit (CPU) or other processors that can call program code. Again, these modules may be integrated together and implemented in the form of a system-on-a-chip (SOC).

[0126] Figure 8 The figure is a schematic diagram of a computer device provided by an embodiment of the present application. The device may be integrated into a terminal device or a chip of the terminal device, and the terminal may be a computing device with data processing capabilities.

[0127] The device includes: a processor 801, a storage medium 802, and a bus 803.

[0128] The storage medium 802 stores program instructions executable by the processor 801. When the computer device 800 runs, the processor 801 communicates with the storage medium 802 via the bus 803, and the processor 801 executes the program instructions to implement the above method embodiments. The specific implementation manners and technical effects are similar and will not be elaborated here.

[0129] Optionally, the present invention further provides a program product, such as a computer-readable storage medium, including a program which, when executed by a processor, is used to implement the above method embodiments.

[0130] In several embodiments provided by the present invention, it should be understood that the disclosed apparatus and method can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative. For example, the division of units is only a logical function division, and there may be other division manners in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of the apparatus or unit can be in electrical, mechanical or other forms.

[0131] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0132] In addition, in each embodiment of the present invention, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated units can be implemented in the form of hardware, or in the form of hardware plus software functional units.

[0133] The above integrated units implemented in the form of software functional units can be stored in a computer-readable storage medium. The above software functional units are stored in a storage medium and include several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor (English: processor) to execute some steps of the methods in each embodiment of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (English: Read-Only Memory, abbreviated as: ROM), random access memories (English: Random Access Memory, abbreviated as: RAM), magnetic disks or optical discs that can store program codes.

[0134] The above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.

Claims

1. A method for detecting Byzantine attacks based on federated learning, applied to a traffic cloud server, characterized in that: include: Aggregate the local gradients of all vehicles to train the global model to be trained, and obtain the trained global model; Determine the total number of parameters in the trained global model, generate a set of constant sequences for all the vehicles based on the total number of parameters, and send the set of constant sequences to all the vehicles; Receive the local gradient sum sent by the vehicle; determine the global gradient sum of the trained global model; perform Byzantine attack detection based on the local gradient sum and the global gradient sum; the local gradient sum is obtained by the corresponding vehicle according to the set of constant sequences, the local gradient and a set of confusion factors; the set of confusion factors is generated for the vehicle by the traffic management department; the sum of the set of confusion factors is 0.

2. The method according to claim 1, characterized in that The performing Byzantine attack detection according to the local gradient sum and the global gradient sum includes: Comparing the global gradient sum with the local gradient sum, when the difference between the global gradient sum and the local gradient sum is within a first preset threshold range, the number of valid data is increased by 1; otherwise, the number of valid data remains unchanged; Determine whether the amount of valid data reaches a second preset threshold value. When the amount of valid data reaches the second preset threshold value, the vehicle is a normal node; otherwise, the vehicle is a Byzantine node.

3. The method according to claim 2, characterized in that When the difference between the global gradient sum and the local gradient sum is within a first preset threshold range, the amount of valid data is determined according to the following formula: Wherein, (a1, a2) represents the first preset threshold range; Indicates the number of valid data; represents the local gradient and; represents the global gradient and .

4. The method according to claim 2, characterized in that: The determining whether the amount of valid data reaches a second preset threshold value is to perform Byzantine attack detection according to the following formula: Wherein, βe represents the second preset threshold; Indicates the number of valid data.

5. The method according to claim 1, characterized in that After performing Byzantine attack detection according to the local gradient sum and the global gradient sum, the method further includes: Processing the trained global model using obfuscation gradients and expansion factors; A modular operation is performed on the processed trained global model to eliminate the set of confusion factors using a noise key to obtain the aggregated trained global model.

6. The method according to claim 5, characterized in that After obtaining the aggregated trained global model, the method further includes: The next round of global model to be trained is determined according to the aggregated trained global model, the learning rate, and the trained global model.

7. A method for detecting anti-Byzantine attacks based on federated learning, applied to traffic management departments, characterized in that: include: Generate a noise key and a set of confusion factors for each vehicle, and send the noise key and the set of confusion factors to the corresponding vehicle, instruct the corresponding vehicle to obtain a local gradient sum according to the set of confusion factors, a set of constant sequences and the local gradient, and send the local gradient sum to the traffic cloud server, instructing the traffic cloud server to perform Byzantine attack detection according to the local gradient sum and the global gradient sum of the trained global model; the trained global model is obtained by the traffic cloud server to train the global model to be trained by aggregating the local gradients of all vehicles; the set of constant sequences is the total number of parameters in the trained global model determined by the traffic cloud server, and is generated for all the vehicles according to the total number of parameters; the sum of the set of confusion factors is 0.

8. A method for detecting anti-Byzantine attacks based on federated learning, applied to vehicles, characterized in that: include: Receive a noise key, a set of confusion factors and a set of constant sequences sent by a traffic management department; The sum of the set of confounding factors is 0; A local gradient sum is obtained according to the set of confusion factors, the set of constant sequences, and local gradients, and the local gradient sum is sent to the traffic cloud server, instructing the traffic cloud server to perform Byzantine attack detection according to the local gradient sum and the global gradient sum of the trained global model; the trained global model is obtained by the traffic cloud server aggregating the local gradients of all vehicles to train the global model to be trained; the set of constant sequences is the total number of parameters in the trained global model determined by the traffic cloud server, and is generated for all the vehicles according to the total number of parameters.

9. The method according to claim 8, characterized in that The step of obtaining the local gradient sum according to the set of confusion factors, the set of constant sequences, and the local gradient comprises: An extended confusion factor is generated according to the set of confusion factors and the set of constant sequences, a confusion gradient is obtained according to the extended confusion factor and the local gradient, and a unit group gradient sum of the confusion gradient is calculated in units of length n to obtain the local gradient sum.

10. A federated learning system resistant to Byzantine attacks, characterized in that: include: A traffic management department, configured to generate a noise key and a set of confusion factors for each vehicle, and send the noise key and the set of confusion factors to the vehicle; The sum of the set of confounding factors is 0; The vehicle is used to receive the noise key, the set of confusion factors and the set of constant sequences sent by the traffic management department; obtain a local gradient sum according to the set of confusion factors, the set of constant sequences and the local gradient, and send the local gradient sum to the traffic cloud server; The traffic cloud server is used to aggregate the local gradients of all vehicles to train the global model to be trained, and obtain the trained global model; determine the total number of parameters in the trained global model, and generate a set of constant sequences for all the vehicles according to the total number of parameters, and send the set of constant sequences to all the vehicles; receive the local gradient sum sent by the vehicle; determine the global gradient sum of the trained global model; and perform Byzantine attack detection according to the local gradient sum and the global gradient sum.