Confrontation-based federated learning optimization method and system, terminal and medium

By adopting an adversarial-based method in federated learning, using generative adversarial networks and domain adversarial networks to generate and train pseudo-datasets and feature extraction networks, the non-independent and same distribution problem caused by different data distributions is solved, and the effectiveness and security of federated learning are improved.

CN120069006APending Publication Date: 2025-05-30SHANDONG ZHICHUANG DIGITAL TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510225639.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-27
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In federated learning, different data distributions of each participating node lead to non-independent and same distribution, which affects the federated learning effect, resulting in poor training effect or difficulty converging.

Method used

Adversarial-based federated learning optimization method is adopted, and a feudal data identification network is built to conduct adversarial training, a pseudo-data set is generated, and a domain adversarial network is used to transform and adversarial training of the task target network to generate a feature extraction network that can ignore the differences in data distribution.

Benefits of technology

It effectively reduces the impact of non-independent homogeneous distribution problems on federated learning effects, improves the quality and efficiency of federated learning, and ensures the security of real data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120069006A_ABST
    Figure CN120069006A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of machine learning, in particular to an adversarial-based federated learning optimization method and system, a terminal and a medium, and the method comprises the steps: representing the data distribution of each participant through employing a generative adversarial network, generating a pseudo data set, guaranteeing the safety of real data, and improving the accuracy of the data. And then training the domain adversarial network by using the pseudo data set of each participant to obtain a second feature extraction network capable of neglecting the data distribution difference of each participant, so that each participant performs federated modeling based on a target network formed by combining the second feature extraction network and a second task network. And the influence of the non-independent identically distributed problem on the federated modeling process is reduced. In combination with a deep learning technology, the problem of poor federated learning effect caused by different data distribution of participants is solved by using the advantage that the generative adversarial network can generate a pseudo data set with the same distribution as real data and the advantage that the domain adversarial network can neglect the data distribution condition.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of machine learning, and particularly to an adversarial-based federated learning optimization method, system, terminal, and medium. Background Art

[0002] Federated learning is an emerging distributed machine learning paradigm aimed at solving the balance problem between data privacy protection and model training efficiency. In traditional machine learning scenarios, data usually needs to be centralized on a central server for model training, which not only may pose a risk of data leakage but also is limited by the data silo phenomenon, that is, data is scattered in different institutions or individuals and is difficult to effectively integrate and utilize. Federated learning allows each data holder (such as mobile devices, enterprise servers, etc.) to train models locally and only upload intermediate results such as model parameters or gradients to the central server for aggregation to generate a global model, realizing cross-device and cross-institutional knowledge sharing and model optimization without directly sharing the original data. This method greatly enhances data privacy protection because the original data always remains local, reducing the risk of data leakage.

[0003] Federated learning is essentially distributed learning, and data exists on each participating node. However, it is very difficult for the data on each participating node to be consistent in distribution, that is, there is a non-independent and identically distributed (Non-IID) situation among each dataset. In this case, if the models of each participating node are aggregated, the training effect will be poor, and even the situation of difficult convergence may occur, ultimately seriously affecting the effect of federated learning.

[0004] In the case where the data distributions of each participating node in federated learning are different, how to effectively reduce the impact of the non-independent and identically distributed situation of each dataset on the effect of federated learning, so that federated learning can still achieve good results when the data distributions of each client are different, has become an urgent problem to be solved. Summary of the Invention

[0005] To solve the technical problem of how to effectively reduce the impact of the non-independent and identically distributed situation of each dataset on the effect of federated learning, the present invention provides an adversarial-based federated learning optimization method, and also provides an adversarial-based federated learning optimization system, a terminal, and a medium.

[0006] To achieve the above object, in a first aspect, the technical solution adopted by an adversarial-based federated learning optimization method in the present invention is as follows: An adversarial-based federated learning optimization method includes the following steps: S1. Build a first identically - distributed data generation network and a genuine - fake data identification network at each participant in federated learning. Each group of the first identically - distributed data generation network and the genuine - fake data identification network corresponds to a participant in federated learning. Let the first identically - distributed data generation network and the genuine - fake data identification network conduct adversarial training. After reaching the first training threshold, obtain the second identically - distributed data generation network; S2. Each participant encrypts and uploads its second identically - distributed data generation network to the aggregation node. At the aggregation node, based on each second identically - distributed data generation network, generate a pseudo - dataset with the same distribution as the real data of each participant, and label each piece of data in each pseudo - dataset. The label content is the identifier of the corresponding participant; S3. The aggregation node builds a task - target network and a participant classification network, and splits the task - target network into a first feature extraction network and a first task network. Let the first feature extraction network, the first task network, and the participant classification network conduct adversarial training with each other. After reaching the second training threshold, obtain the second feature extraction network and the second task network; S4. The aggregation node combines the second feature extraction network and the second task network to obtain the target network. Each participant conducts federated modeling based on the target network to obtain the final target network.

[0007] As a preferred implementation of an adversarial - based federated learning optimization method, the steps of building a first identically - distributed data generation network and a genuine - fake data identification network at each participant in federated learning in step S1 include the following steps: Each participant in federated learning builds a first identically - distributed data generation network based on the type of the real data of the corresponding participant. The input of the first identically - distributed data generation network is Gaussian noise, and the output is pseudo - data, and the pseudo - data has the same distribution as the real data of the corresponding participant; Each participant in federated learning builds a genuine - fake data identification network based on the way that the last layer of the feed - forward neural network is a binary - classification fully - connected layer. The input of the genuine - fake data identification network is a randomly - mixed data of the pseudo - data output by the corresponding first identically - distributed data generation network and the real data of the corresponding participant, and the output is the probability that the input data is pseudo - data.

[0008] As a preferred implementation of an adversarial - based federated learning optimization method, the steps of making the first identically - distributed data generation network and the genuine - fake data identification network conduct adversarial training in step S1 include the following steps: The training objective of the first identically - distributed data generation network is to generate pseudo - data that makes the genuine - fake data identification network unable to correctly determine the authenticity of the data; The training objective of the genuine - fake data identification network is to distinguish pseudo - data from the real data of the corresponding participant.

[0009] As a preferred implementation of an adversarial-based federated learning optimization method, the steps of the aggregation node constructing a task target network and a participant classification network, and splitting the task target network into a first feature extraction network and a first task network include the following steps: The aggregation node constructs a task target network based on the actual task of the current federated learning, and constructs a participant classification network based on the way of connecting a fully connected layer with the same number of neurons as the number of participants at the end of the feedforward neural network; The input of the first feature extraction network is the labeled data obtained in step S2, and the output is the extracted data features; The inputs of the first task network and the participant classification network are the output of the first feature extraction network. There is a gradient reversal layer between the first task network and the participant classification network. The output of the first task network is the classification result of the data, and the output of the participant classification network is the probability that the data comes from each participant.

[0010] As a preferred implementation of an adversarial-based federated learning optimization method, the steps of making the first feature extraction network, the first task network, and the participant classification network train against each other include the following steps: The training objective of the first feature extraction network is to enable the first task network to correctly complete the classification based on the extracted data features, and at the same time make the participant classification network unable to correctly distinguish the data source; The training objective of the first task network is to use the data features extracted by the first feature extraction network for correct classification; The training objective of the participant classification network is to determine which participant the data comes from according to the output of the first feature extraction network.

[0011] As a preferred implementation of an adversarial-based federated learning optimization method, the steps of each participant in step S4 performing federated modeling based on the target network to obtain the final target network include the following steps: S41. The aggregation node distributes the target network to each participant. Each participant trains the target network based on its own real data. During training, the parameters of the second feature extraction network are locked, the parameters of the second task network are adjusted, and all the trained target networks are sent to the aggregation node for network aggregation and test verification; S42. Determine whether the result of the test verification reaches the third training threshold. If it reaches the third training threshold, stop and obtain the final target network; if it does not reach the third training threshold, repeat step S41 until the third training threshold is reached.

[0012] As a preferred implementation of an adversarial-based federated learning optimization method, the identifier of the participant described in step S2 is a data domain identifier.

[0013] Second aspect, the technical solution adopted by an adversarial-based federated learning optimization system in the present invention is as follows: An adversarial-based federated learning optimization system includes a network construction module, an adversarial training module, a labeling module, and a federated modeling module, where: The network construction module is configured to construct a first identically distributed data generation network and a genuine / fake data identification network at each participant in federated learning. Each group of the first identically distributed data generation network and the genuine / fake data identification network corresponds to a participant in federated learning; additionally, a task target network and a participant classification network are constructed at the aggregation node, and the task target network is split into a first feature extraction network and a first task network; The adversarial training module is configured to perform adversarial training between the first identically distributed data generation network and the genuine / fake data identification network, and obtain a second identically distributed data generation network after reaching a first training threshold; additionally, perform adversarial training among the first feature extraction network, the first task network, and the participant classification network, and obtain a second feature extraction network and a second task network after reaching a second training threshold; The labeling module is configured to enable each participant to encrypt and upload its second identically distributed data generation network to the aggregation node, generate a pseudo-dataset with the same distribution as the real data of each participant based on each second identically distributed data generation network at the aggregation node, and label each piece of data in each pseudo-dataset, where the label content is the identifier of the corresponding participant; The federated modeling module is configured to enable the aggregation node to combine the second feature extraction network and the second task network to obtain a target network; enable each participant to perform federated modeling based on the target network to obtain a final target network.

[0014] Third aspect, the technical solution adopted by a terminal in the present invention is as follows: A terminal includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the steps of any one of the above-mentioned adversarial-based federated learning optimization methods.

[0015] Fourth aspect, the technical solution adopted by a medium in the present invention is as follows: A storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps of any one of the above-mentioned adversarial-based federated learning optimization methods.

[0016] The beneficial effects of the present invention include: In the present invention, the first identically distributed data generation network and the authenticity data identification network form a generative adversarial network, and the first feature extraction network, the first task network, and the participant classification network form a domain adversarial network. First, the present invention uses the generative adversarial network to represent real data and generate a pseudo-dataset, uploading the data distribution of each participant without leaving the domain, ensuring the security of real data. Then, the federated learning task target network is transformed into a domain adversarial network, and the domain adversarial network is adversarially trained using the data in the pseudo-datasets of each participant to obtain a second feature extraction network that can ignore the data distribution differences of each participant. By locking the parameters of the second feature extraction network, each participant can perform federated modeling based on the target network obtained by combining the second feature extraction network and the second task network, which can reduce the impact of the non-independent and identically distributed problem on the federated modeling process and greatly improve the quality of federated learning.

[0017] The present invention combines deep learning technology, making use of the advantage that the generative adversarial network can generate a pseudo-dataset with the same distribution as real data and the advantage that the domain adversarial network can ignore the data distribution situation, effectively solving the problem of poor federated learning effect caused by different data distributions of each participant in the past. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions of the present invention, the drawings required for description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0019] Figure 1 It is a schematic flowchart of an adversarial-based federated learning optimization method in a specific embodiment of the present invention; Figure 2 It is a schematic structural diagram of an adversarial-based federated learning optimization system in a specific embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0020] In federated learning, different data distributions include different feature distributions of data (for example, medical data from different hospitals, some hospitals focus on heart disease data, and some focus on cancer data), different label distributions of data (such as product evaluation data from different regions, with more positive reviews in some regions and more negative reviews in others), etc.

[0021] In federated learning, different data distributions will reduce the federated learning effect in various aspects. For example: In terms of model training, due to different data distributions, when each participant calculates gradients, the directions and magnitudes may vary greatly. These differences may conflict with each other during the aggregation process of federated learning, affecting the convergence speed and accuracy of the algorithm. Taking neural networks as an example, when calculating gradients through backpropagation, different data distributions will lead to chaotic gradient updates. Just like students (participants) in different places have different learning materials (data) to train a knowledge quiz model, they obtain different optimization directions, and it is difficult for the model to converge to a good state. Moreover, different data distributions are likely to trap the models of each participant in local optima. The data of each participant has its own pattern, and the model may find a local optimal solution when adapting to this local data. When aggregating the model parameters of these locally optimal models, it is very difficult to obtain a globally optimal model.

[0022] In terms of data representation, different data distributions mean inconsistent feature spaces. The data of different participants may have different feature dimensions, meanings, and value ranges. For example, the user data of different e-commerce platforms (participants) may focus on purchase frequency for some and commodity category preferences for others. It is very difficult to directly fuse this data with different feature spaces for model training. At the same time, it is very difficult to learn a unified data representation. In traditional machine learning, it is easy to learn data representation when the data distribution is relatively consistent, but in federated learning, due to large data differences, it is more difficult to learn a general data representation, which affects the model performance.

[0023] Therefore, in the case where the data distributions of each participating node in federated learning are different, how to effectively reduce the impact of the non-independent and identically distributed situation of each dataset on the effect of federated learning, so that federated learning can still achieve good results when the data distributions of each client are different, has become an urgent problem to be solved. Based on this, the present invention provides an adversarial-based federated learning optimization method, and also provides an adversarial-based federated learning optimization system, a terminal, and a medium.

[0024] Before describing the technical content of the specific embodiments of the present invention, first introduce the professional knowledge involved in the present invention: Generative Adversarial Networks (GANs) is a generative model based on deep learning, consisting of two parts: a generator and a discriminator. Its inspiration comes from the concept of "adversarial" in game theory. Through the continuous competition and cooperation between the generator and the discriminator, the goal of generating realistic data is achieved. In GANs, the generator is responsible for capturing the latent distribution of real data samples and generating new data samples; while the discriminator is a binary classifier used to distinguish whether the input data is real data or fake data generated by the generator. These two networks are trained adversarially to continuously optimize themselves, enabling the generator to generate more realistic data, while the discriminator is also constantly improving its ability to distinguish between true and false.

[0025] Domain-Adversarial Neural Networks (DANN) is a special type of network in deep transfer learning. Its core idea comes from the Nash equilibrium of generative adversarial networks (GANs) and game theory. DANN mainly consists of three parts: a feature extractor, a label classifier, and a domain discriminator, aiming to solve the transfer learning problem caused by the difference in data distribution between different domains. In DANN, the feature extractor is responsible for mapping the data from the source domain and the target domain to the same feature space, so that the label classifier can accurately classify the source domain data while the domain discriminator cannot distinguish which domain the data comes from. The label classifier classifies the data from the source domain and tries to assign the correct labels as much as possible. The domain discriminator classifies the data in the feature space and tries to distinguish which domain the data comes from.

[0026] Federated modeling is a service that realizes model iteration and update based on federated learning technology while meeting the compliance policies and data value protection requirements of each participating party. It adopts a joint computing mode to complete model research and development and effect evaluation without the original data leaving the local. Federated learning is the foundation and core technology of federated modeling, and federated modeling is a specific manifestation of federated learning in practical applications. Through federated learning, multiple participating parties can jointly train a machine learning model while maintaining data privacy; and federated modeling, on this basis, realizes model iteration, update, and effect evaluation through providing a visual operation platform and various technical means.

[0027] To make the objectives, features, and advantages of the present invention more obvious and understandable, the technical solutions in the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the specific embodiments of the present invention. Obviously, the embodiments described below are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the scope of protection of the present application.

[0028] Referring to Figure 1 , an adversarial-based federated learning optimization method proposed in this embodiment includes the following steps: S1. Build a first identically distributed data generation network and a genuine and fake data identification network at each participant in federated learning. Each group of the first identically distributed data generation network and the genuine and fake data identification network corresponds to a participant in federated learning. Make the first identically distributed data generation network and the genuine and fake data identification network conduct adversarial training, and obtain a second identically distributed data generation network after reaching the first training threshold; S2. Each participant encrypts and uploads its second identically distributed data generation network to the aggregation node. At the aggregation node, a pseudo-dataset with the same distribution as the real data of each participant is generated based on each second identically distributed data generation network, and each data in each pseudo-dataset is labeled with the content of the identifier of the corresponding participant; S3. The aggregation node builds a task objective network and a participant classification network, and splits the task objective network into a first feature extraction network and a first task network. Make the first feature extraction network, the first task network, and the participant classification network conduct adversarial training with each other, and obtain a second feature extraction network and a second task network after reaching the second training threshold; S4. The aggregation node combines the second feature extraction network and the second task network to obtain a target network. Each participant conducts federated modeling based on the target network to obtain the final target network.

[0029] In this embodiment, building a first identically distributed data generation network and a genuine and fake data identification network at each participant in federated learning in step S1 includes the following steps: Each participant in federated learning builds a first identically distributed data generation network based on the type of the real data of the corresponding participant. The input of the first identically distributed data generation network is Gaussian noise, and the output is pseudo-data, and the pseudo-data has the same distribution as the real data of the corresponding participant. Among them, Gaussian noise refers to a probability density function that follows a Gaussian distribution random variable; Each participant in federated learning builds a genuine and fake data identification network based on the way that the last layer of the feedforward neural network is connected to a binary classification fully connected layer. The input of the genuine and fake data identification network is a random mixed data of the pseudo-data output by the corresponding first identically distributed data generation network and the real data of the corresponding participant, and the output is the probability that the input data is pseudo-data.

[0030] After building the first identically distributed data generation network and the genuine and fake data identification network according to the above method, further, making the first identically distributed data generation network and the genuine and fake data identification network conduct adversarial training in step S1 includes the following steps: The training objective of the first identically distributed data generation network is to generate pseudo-data that makes the genuine and fake data identification network unable to correctly determine the authenticity of the data; The training objective of the true and false data identification network is to distinguish false data from the real data of the corresponding participating parties.

[0031] In this embodiment, the steps for the aggregation node to build the task target network and the participating party classification network, and split the task target network into the first feature extraction network and the first task network are as follows: The aggregation node builds the task target network based on the actual task of this federated learning, and builds the participating party classification network in the way of connecting a fully connected layer with the same number of neurons as the number of participating parties at the end of the feedforward neural network; The input of the first feature extraction network is the labeled data obtained in step S2, and the output is the extracted data features; The inputs of the first task network and the participating party classification network are the output of the first feature extraction network. There is a gradient reversal layer between the first task network and the participating party classification network. The output of the first task network is the classification result of the data, and the output of the participating party classification network is the probability that the data comes from each participating party; among them, when the first task network backpropagates to the first feature extraction network, the gradient reversal layer adds a -γ to the gradient, so that the parameters of the first feature extraction network learn in the opposite direction.

[0032] After building the task target network and the participating party classification network according to the above method, and splitting the task target network into the first feature extraction network and the first task network, further, the steps for the first feature extraction network, the first task network and the participating party classification network to perform adversarial training in step S3 are as follows: The training objective of the first feature extraction network is, based on the extracted data features, to enable the first task network to correctly complete the classification, and at the same time enable the participating party classification network to not correctly distinguish the data source; The training objective of the first task network is to use the data features extracted by the first feature extraction network for correct classification; The training objective of the participating party classification network is to determine which participating party the data comes from according to the output of the first feature extraction network.

[0033] In this embodiment, the steps for each participating party in step S4 to perform federated modeling based on the target network and obtain the final target network are as follows: S41. The aggregation node distributes the target network to each participating party, so that each participating party trains the target network based on its own real data. When training, lock the parameters of the second feature extraction network, adjust the parameters of the second task network, send all the trained target networks to the aggregation node for network aggregation, and perform test verification; among them, when performing network aggregation, each parameter takes the average value; S42. Determine whether the result of the test verification reaches the third training threshold. If it reaches the third training threshold, stop and obtain the final target network. If it does not reach the third training threshold, repeat step S41 until the third training threshold is reached.

[0034] In this embodiment, the first i.i.d. data generation network and the genuine and fake data identification network constitute a generative adversarial network, and the first feature extraction network, the first task network, and the participant classification network constitute a domain adversarial network.

[0035] In this embodiment, first, the generative adversarial network is used to represent the real data, and the generative adversarial network is used to generate a pseudo-dataset that is consistent with the real data distribution of each participant. It can upload the data distribution of each participant without the data leaving the domain, ensuring the security of the real data. Then, the task target network of federated learning is transformed into a domain adversarial network. The domain adversarial network performs adversarial training based on the data in the pseudo-datasets of each participant to obtain a second feature extraction network that can ignore the differences in the data distributions of each participant. The second feature extraction network is used to replace the feature extraction network in the original task target network, and the parameters of the second feature extraction network are locked. Each participant performs federated modeling based on the target network obtained by combining the second feature extraction network and the second task network, reducing the impact of the non-i.i.d. problem on the federated modeling process and greatly improving the quality of federated learning.

[0036] This embodiment combines deep learning techniques, taking advantage of the fact that the generative adversarial network can generate a pseudo-dataset with the same distribution as the real data and the domain adversarial network can ignore the data distribution situation, effectively solving the problem of poor federated learning effect caused by different data distributions of each participant in the past.

[0037] In some embodiments, the identifier of the participant described in step S2 is a data domain identifier, which can be simply named with Arabic numerals.

[0038] In a more specific embodiment, the technical solution of an adversarial-based federated learning method is as follows: First, each participant in the federated learning constructs a first i.i.d. data generation network and a genuine and fake data identification network. The input of the first i.i.d. data generation network is Gaussian noise, and the output is fake data with the same distribution as the real data of the corresponding participant. The input of the genuine and fake data identification network is a randomly mixed data set of the fake data generated by the corresponding first i.i.d. data generation network and the real data of the corresponding participant, and real and fake labels are respectively attached. The output of the genuine and fake data identification network is the probability that the input data is fake data. The training objective of the first i.i.d. data generation network is to generate fake data that makes the genuine and fake data identification network unable to correctly determine the authenticity of the data. The training objective of the genuine and fake data identification network is to strongly distinguish between fake data and the real data of this participant. The first i.i.d. data generation network and the genuine and fake data identification network are trained adversarially, and after reaching the first training threshold, a second i.i.d. data generation network is obtained.

[0039] Then, each participant in the federated learning encrypts and uploads its second i.i.d. data generation network to the aggregation node. The aggregation node uses the second i.i.d. data generation network uploaded by each participant to generate a fake data set with the same distribution as the real data of each participant, and at the same time attaches a label to each data in each fake data set, and the label content is the identifier of each participant.

[0040] After that, a task objective network for this federated learning is constructed. The aggregation node initializes the task objective network for this federated learning, and splits the task objective network into a first feature extraction network and a first task network. At the same time, the aggregation node constructs a participant classification network. The input of the first feature extraction network is the labeled data in all the fake data sets obtained in the previous step, and the output is the extracted data features. The output of the first feature extraction network is respectively used as the input of the first task network and the participant classification network, and a gradient reversal layer is added between the first task network and the participant classification network. The training objective of the first feature extraction network is based on the extracted data features, enabling the first task network to correctly complete the classification, and at the same time making the participant classification network unable to correctly distinguish the data source. The objective of the first task network is to be able to correctly classify the data features extracted by the first feature extraction network. The training objective of the participant classification network is to be able to determine from which participant the data comes according to the output of the first feature extraction network. The first feature extraction network, the first task network, and the participant classification network are trained adversarially against each other, and after reaching the second training threshold, a second feature extraction network and a second task network are obtained.

[0041] Finally, the aggregation node combines the second feature extraction network and the second task network to obtain the target network, and starts the federated modeling process: The aggregation node distributes the target network to each participant. Each participant uses the local real data to train the target network. During training, the parameters of the second feature extraction network are locked, and only the parameters of the second task network are adjusted. Then each participant sends the target network to the aggregation node for network aggregation and performs test verification. If the third threshold is reached, the training stops. If the third threshold is not reached, the federated modeling process continues until the third threshold is reached to obtain the final target network.

[0042] In the above embodiments, the specific structure of the first homogeneous distribution data generation network is built according to the data types of the participants. The true and false data identification network adopts a feedforward neural network and finally connects to a binary classification fully connected layer. The Gaussian noise refers to a random quantity whose probability density function follows a Gaussian distribution. The first training threshold, the second training threshold, and the third training threshold are hyperparameters, which are set and adjusted according to the actual training situation. The identifier of each participant is a data domain identifier, which can be simply named with Arabic numerals. The task target network is built according to the actual task. The participant classification network is a feedforward neural network, and the number of neurons in the output layer is the number of participants. Its function is to distinguish which participant the input data comes from according to the input data. The gradient reversal layer adds a -γ to the gradient when the first task network backpropagates to the first feature extraction network, so that the parameters of the first feature extraction network learn in the opposite direction. The network aggregation takes the average value of each parameter.

[0043] As Figure 2 shown, the following is a federated learning optimization system based on confrontation provided by an embodiment of the present disclosure. A federated learning optimization system based on confrontation and a federated learning optimization method based on confrontation in each of the above embodiments belong to the same inventive concept. Details not described in detail in the embodiments of the federated learning optimization system based on confrontation can refer to the embodiments of the federated learning optimization method based on confrontation above.

[0044] A federated learning optimization system based on confrontation includes a network construction module, an adversarial training module, a labeling module, and a federated modeling module, where: The network construction module is configured to build a first homogeneous distribution data generation network and a true and false data identification network at each participant in federated learning. Each group of the first homogeneous distribution data generation network and the true and false data identification network corresponds to a participant participating in federated learning; in addition, a task target network and a participant classification network are built at the aggregation node, and the task target network is split into a first feature extraction network and a first task network; The adversarial training module is configured to perform adversarial training on the first i.i.d. data generation network and the real / fake data identification network, and obtain the second i.i.d. data generation network after reaching the first training threshold. Additionally, perform adversarial training on the first feature extraction network, the first task network, and the participant classification network, and obtain the second feature extraction network and the second task network after reaching the second training threshold. The labeling module is configured to enable each participant to encrypt and upload their respective second i.i.d. data generation networks to the aggregation node, generate a pseudo-dataset with the same distribution as each participant's real data based on each second i.i.d. data generation network at the aggregation node, and label each piece of data in each pseudo-dataset with the identifier of the corresponding participant. The federated modeling module is configured to enable the aggregation node to combine the second feature extraction network and the second task network to obtain the target network. Enable each participant to perform federated modeling based on the target network to obtain the final target network.

[0045] An embodiment of this application also proposes a terminal, including a memory, a processor, a communication unit, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the steps of an adversarial-based federated learning optimization method. The memory, the processor, and the communication unit communicate through one or more buses.

[0046] The processor may include one or more processing units. For example, the processor may include a central processing unit (CPU), an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural network processing unit (NPU), etc. Among them, different processing units may be independent devices or integrated in one or more processors.

[0047] Among them, the processor may be the nerve center and command center of the terminal. The controller can generate operation control signals according to the instruction operation code and timing signals to complete the control of fetching instructions and executing instructions.

[0048] The memory is used to store the execution instructions of the processor. The memory can be implemented by any type of volatile or non-volatile storage terminal or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. When the execution instructions in the memory are executed by the processor, the terminal can execute some or all of the steps in the above-mentioned embodiments of the adversarial-based federated learning optimization method.

[0049] The wireless communication function of the electronic device can be implemented by an antenna, a wireless communication module, a modulation and demodulation processor, a baseband processor, etc.

[0050] The wireless communication module can provide solutions for wireless communication including wireless local area network, Bluetooth, global navigation satellite system, frequency modulation, near-field communication technology, infrared technology, etc. applied to the electronic device.

[0051] This embodiment also proposes a storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the steps of any one of the above-mentioned adversarial-based federated learning optimization methods.

[0052] The above description of the disclosed embodiments enables those skilled in the art to implement or use the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to these embodiments shown herein, but rather to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A federated learning optimization method based on adversarial learning, characterized in that: The following steps are involved: S1. Build a first identically distributed data generation network and an authenticity data identification network at each participant in the federated learning. Each set of first identically distributed data generation networks and authenticity data identification networks corresponds to a participant in the federated learning. Perform adversarial training on the first identically distributed data generation network and the authenticity data identification network, and obtain a second identically distributed data generation network after reaching a first training threshold. S2. Each participant uploads its second identically distributed data generation network to the aggregation node through encryption. On the aggregation node, a pseudo data set with the same distribution as the real data of each participant is generated based on each second identically distributed data generation network, and each piece of data in each pseudo data set is labeled with the label content being the identifier of the corresponding participant. S3, the aggregation node builds a task target network and a participant classification network, splits the task target network into a first feature extraction network and a first task network; trains the first feature extraction network, the first task network and the participant classification network against each other, and obtains a second feature extraction network and a second task network after reaching a second training threshold; S4. The aggregation node combines the second feature extraction network and the second task network to obtain the target network; each participant performs federated modeling based on the target network to obtain the final target network.

2. The adversarial federated learning optimization method according to claim 1, characterized in that: The step S1 of building a first identically distributed data generation network and a true and false data identification network at each federated learning participant includes the following steps: Each participant in federated learning builds a first identically distributed data generation network based on the type of the corresponding participant's real data. The input of the first identically distributed data generation network is Gaussian noise, and the output is pseudo data. The pseudo data has the same distribution as the corresponding participant's real data. Each participant in federated learning builds a true or false data identification network based on a feedforward neural network that is finally connected to a binary classification fully connected layer. The input of the true or false data identification network is the pseudo data output by the corresponding first identically distributed data generation network and the random mixed data of the corresponding participant's real data. The output is the probability that the input data is pseudo data.

3. The adversarial federated learning optimization method according to claim 2, characterized in that: The step S1 of performing adversarial training on the first identically distributed data generation network and the true and false data identification network comprises the following steps: The training goal of the first identically distributed data generation network is to generate fake data that makes it impossible for the authenticity identification network to correctly determine the authenticity of the data; The training goal of the authenticity data identification network is to distinguish fake data from the real data of the corresponding participants.

4. The adversarial federated learning optimization method according to claim 1, characterized in that: The aggregation node in step S3 builds a task target network and a participant classification network, and splits the task target network into a first feature extraction network and a first task network, including the following steps: The aggregation node builds the task target network based on the actual task of this federated learning, and builds the participant classification network based on the fully connected layer of the feedforward neural network that is connected to the same number of neurons as the participants; The input of the first feature extraction network is the labeled data obtained in step S2, and the output is the extracted data features; The input of the first task network and the participant classification network is the output of the first feature extraction network. A gradient reversal layer is provided between the first task network and the participant classification network. The output of the first task network is the classification result of the data, and the output of the participant classification network is the probability that the data comes from each participant.

5. The adversarial federated learning optimization method according to claim 4, characterized in that: The step S3 of training the first feature extraction network, the first task network, and the participant classification network against each other includes the following steps: The training goal of the first feature extraction network is to enable the first task network to correctly complete the classification based on the extracted data features, while making it impossible for the participant classification network to correctly distinguish the data source; The training goal of the first task network is to correctly classify the data features extracted by the first feature extraction network; The training goal of the participant classification network is to determine which participant the data comes from based on the output of the first feature extraction network.

6. The adversarial federated learning optimization method according to claim 1, characterized in that: In step S4, each participant performs federation modeling based on the target network, and obtaining the final target network includes the following steps: S41, the aggregation node sends the target network to each participant, and each participant trains the target network based on their own real data, locks the parameters of the second feature extraction network during training, adjusts the parameters of the second task network, sends all trained target networks to the aggregation node for network aggregation, and performs test verification; S42: Determine whether the result of the test verification reaches the third training threshold. If so, stop and obtain the final target network. If not, repeat step S41 until the third training threshold is reached.

7. The adversarial federated learning optimization method according to claim 1, characterized in that: The identifier of the participant in step S2 is the data domain identifier.

8. A federated learning optimization system based on adversarial learning, characterized in that: It includes network building module, adversarial training module, spike module and federated modeling module, among which: The network building module is configured to build a first identically distributed data generation network and a true and false data identification network at each participant of the federated learning, and each group of the first identically distributed data generation network and the true and false data identification network corresponds to a participant participating in the federated learning; in addition, a task target network and a participant classification network are built at the aggregation node, and the task target network is split into a first feature extraction network and a first task network; The adversarial training module is configured to conduct adversarial training on the first identically distributed data generation network and the true and false data identification network, and obtain the second identically distributed data generation network after reaching the first training threshold; in addition, the first feature extraction network, the first task network and the participant classification network are subjected to adversarial training against each other, and obtain the second feature extraction network and the second task network after reaching the second training threshold; The labeling module is configured to enable each participant to upload its own second identically distributed data generation network to the aggregation node in encrypted form, generate a pseudo data set with the same distribution as the real data of each participant based on each second identically distributed data generation network on the aggregation node, and label each data in each pseudo data set, and the label content is the identifier of the corresponding participant; The federated modeling module is configured to enable the aggregation node to combine the second feature extraction network and the second task network to obtain a target network; and enable each participant to perform federated modeling based on the target network to obtain a final target network.

9. A terminal comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the program, the steps of the adversarial-based federated learning optimization method as described in any one of claims 1 to 7 are implemented.

10. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the adversarial-based federated learning optimization method as described in any one of claims 1 to 7 are implemented.