Federal learning method and system for detecting and defending poisoning attack under differential privacy
By adopting differential privacy and adaptive noise-added decision-making mechanisms in federated learning, combined with segmented clustering analysis to detect malicious clients, the problem of attack identification caused by model perturbation under differential privacy is solved, and the coordinated optimization of privacy and security is achieved.
Patent Information
- Application Number
- CN202510542723.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-28
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2045-04-28
AI Technical Summary
Although differential privacy can protect user data privacy in federated learning, the random noise introduced will mask the abnormal characteristics in model updates, making it difficult for the server to accurately identify the poisoning behavior of malicious clients, weakening the detection and defense effects of poisoning attacks.
A federated learning method that detects and prevents poisoning attacks under differential privacy is adopted, and a local model update on the client is achieved by defining differential privacy on the client and combining an adaptive noise-added decision mechanism. The server receives the local model update of the client, performs malicious update detection based on segmented clustering analysis, and identifies the cluster with the largest number of clients as a collection of malicious clients, and deletes it from training.
On the premise of protecting the user's local data from being leaked, the server can identify the client that uploads exceptions, so as to maintain the performance of the global model during system training when facing poisoning attacks, making it close to the training effect in an attack-free environment.
Smart Images

Figure CN120069009A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of distributed machine learning, and more specifically, relates to a federated learning method and system for detecting and defending poisoning attacks under differential privacy. Background Art
[0002] Deep learning technology has high flexibility, automatic feature extraction ability and end-to-end training advantages, and has achieved excellent performance in complex tasks such as image recognition and natural language processing. Traditional model training usually requires collecting large-scale data from each client to a central server, and this centralized solution will bring serious privacy risks. To alleviate the privacy problem, federated learning is proposed as a solution.
[0003] However, federated learning still faces many security challenges. One prominent problem is the privacy leakage that may be caused by local model updates, and another key threat is poisoning attacks. In terms of privacy protection, differential privacy can, to a certain extent, prevent the server from inferring the client's local data by introducing random noise. However, after adding differential privacy noise, the perturbation of model updates will mask abnormal behaviors, thus reducing the ability to identify malicious clients, and further affecting the defense of poisoning attacks by defense algorithms. In terms of defending against poisoning attacks, malicious clients usually construct the model gradients they upload to make their numerical distance close to that of the model updates of benign clients, making it difficult for distance-based anomaly detection methods to distinguish normal and malicious behaviors, so as to achieve the purpose of interfering with the global model or seeking their own interests.
[0004] Chinese Patent Document CN117634594A discloses an adaptive clustering federated learning method with differential privacy. The server adaptively clusters clients based on the similarity of local model parameters, obtains multiple clusters, and divides the clients into different clusters. For each client within a cluster, the server performs intra-cluster aggregation calculation based on the local model parameters of all clients within the cluster to obtain an intra-cluster global model, and performs cross-validation on all intra-cluster global models, selects one intra-cluster global model as the optimal intra-cluster global model, and the other intra-cluster global models as non-optimal intra-cluster global models; performs inter-cluster aggregation calculation on all non-optimal intra-cluster global models to obtain an inter-cluster global model, and adds the inter-cluster global model to the intra-cluster optimal global model to obtain a global model.
[0005] The mainstream privacy protection technologies in current federated learning include differential privacy, homomorphic encryption, and secure multi-party computing. Among them, homomorphic encryption can complete model aggregation operations in an encrypted state, but the computational and communication overhead is large, and it is difficult to apply to resource-constrained device scenarios; although secure multi-party computing can achieve stronger privacy isolation, the protocol is complex, the implementation cost is high, and the system collaboration requirements are strong. In contrast, differential privacy effectively prevents the server from inferring the user's original data by injecting noise into the local model. While protecting privacy, it has good flexibility and efficiency. It is suitable for federated learning tasks in large-scale, heterogeneous environments, and therefore becomes the privacy protection method finally adopted in this scheme. Although differential privacy has significant advantages in protecting user data privacy, the random noise it introduces will to some extent mask the abnormal features in the model update, making it difficult for the server to accurately identify the poisoning behavior of malicious clients in the aggregation stage, thereby weakening the detection and defense effect of poisoning attacks and increasing the security risks faced by the system.
[0006] In summary, although the differential privacy mechanism can alleviate privacy risks, it will weaken the server's ability to identify poisoning attacks due to the introduction of noise, thereby reducing the security and robustness of the system. To address the above challenges, it is necessary to design a federated learning mechanism that takes into account both privacy protection and poisoning defense, while effectively suppressing the risk of the server's reverse inference of the original data, while improving the ability to identify malicious client behavior, and achieving coordinated optimization of privacy and security. Summary of the invention
[0007] The present invention aims to overcome at least one defect of the above-mentioned prior art and provide a federated learning method for detecting and defending poisoning attacks under differential privacy, so as to solve the problem of difficulty in identifying attacks caused by model perturbations under differential privacy, and can accurately screen out abnormal clients that pose a threat to the global model, thereby achieving coordinated optimization of privacy and security.
[0008] The present invention also discloses a system loaded with a federated learning method for detecting and defending against poisoning attacks under differential privacy.
[0009] The detailed technical scheme of the present invention is as follows: A federated learning method for detecting and defending poisoning attacks under differential privacy, the method comprising: S1. Define differential privacy on the client side. S2. The client downloads the global model of the server, uses the local training data set to train the local model, calculates the differential privacy noise and combines the adaptive noise addition decision mechanism to implement the client local model update; the sample data of the data set is image data; S3, the server receives the local model update from the client and performs malicious update detection based on segment clustering analysis; S4. The server assigns weights to each client and aggregates and updates them to obtain a global model; S5. Each client obtains the trained global model, completes one iteration, and repeats steps S2 - S4 until the set number of training rounds is reached, and the server outputs the final global model.
[0010] Preferably according to the present invention, the S1 specifically includes: Differential privacy is defined as follows: A random mechanism for the dataset whose mapping satisfies -differential privacy if for any two adjacent datasets and that differ by only one element, and any output subset O, there is: (1) In formula (1), represents probability; is the privacy budget parameter, used to measure the privacy protection strength; represents the upper bound of the probability allowed in case the privacy guarantee may fail; and are adjacent datasets; is the random mechanism applied to the dataset; represents () the set of any possible output events.
[0011] Preferably according to the present invention, the S2 specifically includes: Differential privacy federated learning model training involves multiple rounds of communication between the client and the server: In each round of training denoted as , where ; Suppose there are clients in the system, and each client owns a local training dataset , which contains data samples, where ; The federated learning system sequentially performs the following steps: S21: At the beginning of the first round of training , the server initializes the global model as ; In addition, at the beginning of each round of training , each client downloads the latest global model from the server
[0012] S22: Each client uses the local training dataset Train using the Stochastic Gradient Descent (SGD) method based on the downloaded global model Calculate the local update for this round to obtain the local model ; (2) In Equation (2), is the learning rate, represents the loss function calculated on the local dataset , and represents the global model; S23: Since the local updates of some clients may be too large, affecting the stability of the global model, gradient clipping is performed on the local model parameters: (3) In Equation (3), is the gradient clipping threshold to ensure that the norm of the local update does not exceed the set maximum range, thus ensuring the control of the privacy budget; S24: Calculate the sensitivity : To meet the differential privacy constraint, the global sensitivity needs to be calculated: (4) The global sensitivity represents the maximum impact range of a single client update on the global model and is used for subsequent noise calculation; S25: Calculate the variance of the differential privacy noise: According to the set privacy budget , calculate the variance of the Gaussian noise that needs to be added in this round: (5) where controls the amplitude of the added noise. The larger the privacy budget , the smaller the required noise. To ensure that the local updates of each client satisfy differential privacy, Gaussian noise needs to be added to the local model parameters; S26: Model update adaptive noise addition decision mechanism: When the model uploaded in this round is almost the same as the previous round, in fact, no new sensitive information is contributed, so there is no need to add noise again, thus avoiding the cumulative interference caused by adding noise in each round in conventional differential privacy and effectively reducing the injection of invalid noise; If the change amount of the model is less than or equal to the preset ratio threshold : (6) In Equation (6), Represents the proportional threshold, Represents the model change amount, Represents the local model of the i-th client in the (t - 1)-th round, Represents the local model of the i-th client in the t-th round; Then the global model of this round is replaced by the global model of the previous round: (7) If the model change amount is greater than the proportional threshold : (8) Then add noise normally: (9) In formula (9), Represents the local model added with differential privacy noise; Represents the standard Gaussian distribution; Represents the identity matrix.
[0013] According to the preference of the present invention, the S3 specifically includes: S31: The server collects the local model updates processed by differential privacy noise from all clients ; S32: The server divides the local model update of each client into n sub-vector segments: The complete local model update is divided into n sub-vector segments according to the dimension to extract the update values in different dimension intervals: (10) (11)
[0014] (12) Among them, Represents the client The sub-vector of the local update vector on the n-th segment; S33: For each sub-vector segment, the server performs clustering analysis on the parameter sets of all clients on this segment. Preferably, the K-Means clustering algorithm is used to divide the local updates with similar parameter distributions into several clusters, and the cluster containing the largest number of clients is identified, and the cluster containing the largest number of clients is defined as the malicious client set.
[0015] According to the preference of the present invention, the use of the K-Means clustering algorithm to divide the local updates with similar parameter distributions into several clusters and identify the cluster containing the largest number of clients specifically means: For each sub-vector segment, first, randomly select Use a data point as the initial clustering center, denoted as ; Then, for each data point, assign it to the nearest clustering center: (13) where represents the r-th data point; represents the data point to the clustering center the square of the Euclidean distance represents the number of the clustering center that makes the distance the smallest , used to assign data points; Finally, update each clustering center Let it be the mean of all data points in the corresponding cluster: (14) where, represents the cluster corresponding to the clustering center ; Repeat the above steps until all clustering centers converge or reach the maximum number of iterations; Then, for each sub-vector segment, use the K-means clustering algorithm to identify the cluster with the largest number of clients: (15) In formula (15), represents the cluster with the largest number of clients; q represents the label of the sub-vector segment; the model update collection of the q-th sub-vector segment.
[0016] According to the preference of the present invention, the specific steps of S4 include: S41: After clustering, traverse each client to check whether it belongs to the cluster with the largest number of clients . If it is found that the client belongs to this cluster, then delete it from the training, and then aggregate the models to calculate the global model : (16) where, represents the set of remaining clients, that is, the clients still retained after excluding the largest clustering cluster; J represents the total number of remaining model updates; j represents the label of the remaining model updates; represents the aggregated global model; represents the j-th model update in the t-th round; S42: Finally, the algorithm returns the final global model parameters .
[0017] In another aspect of the present invention, a federated learning system for detecting and defending against poisoning attacks under differential privacy is further provided, including clients and a server participating in federated learning. The clients and the server participating in federated learning perform federated learning using the above-mentioned federated learning method.
[0018] Compared with the prior art, the beneficial effects of the present invention are as follows: (1) The present invention slices the model update vector uploaded by the client by dimension and divides it into multiple sub-vector segments. The clustering algorithm is applied to each sub-segment to fully mine the feature differences of the model in different local regions. By combining gradient slicing with local clustering, the server can still identify the abnormal clients uploading data while protecting the local data of users from being leaked, so as to maintain the performance of the global model during the system training process in the face of poisoning attacks, making it close to the training effect in a non-attack environment.
[0019] (2) In order to reduce the consumption of privacy budget, the present invention designs a model update adaptive noise-adding decision mechanism to enhance the privacy protection effect. Brief Description of the Drawings
[0020] Figure 1 It is a schematic flowchart of the federated learning method described in the present invention.
[0021] Figure 2 It is a schematic diagram of the federated learning architecture described in Embodiment 1 of the present invention.
[0022] Figure 3 It is a test accuracy graph of the global model protected by the defense algorithm of the present invention, the Bulyan defense algorithm, the Median defense algorithm, and the M-Krum defense algorithm respectively under the Lie attack in the FEMNIST dataset.
[0023] Figure 4 It is a test accuracy graph of the global model protected by the defense algorithm of the present invention, the Bulyan defense algorithm, the Median defense algorithm, and the M-Krum defense algorithm respectively under the Fang attack in the FEMNIST dataset.
[0024] Figure 5 It is a test accuracy graph of the global model protected by the defense algorithm of the present invention, the Bulyan defense algorithm, the Median defense algorithm, and the M-Krum defense algorithm respectively under the MinMax attack in the FEMNIST dataset. Detailed Embodiments
[0025] The following further describes the present disclosure in conjunction with the drawings and embodiments.
[0026] Embodiment 1 As Figure 1, this embodiment provides a federated learning method for detecting and defending poisoning attacks under differential privacy. The method includes: S1. Define differential privacy at the client side; The definition of differential privacy is as follows: A random mechanism for the data set satisfies - differential privacy if for any two adjacent data sets and that differ by only one element, and any output subset O, there is: (1) In formula (1), represents probability; is the privacy budget parameter, used to measure the privacy protection strength; represents the upper bound of the probability allowed in the case where the privacy guarantee may fail; and are adjacent data sets; is the random mechanism applied to the data set; represents () the set of any possible output events.
[0027] S2. The client downloads the global model of the server, trains the local model using the local training data set, calculates the differential privacy noise, and combines the adaptive noise addition decision mechanism to update the local model of the client. Specifically, it includes: The training of the differential privacy federated learning model involves multiple rounds of communication between the client and the server: In each round of training denoted as , where ; Suppose there are clients in the system, and each client owns the local training data set , which contains data samples, where ; The federated learning system sequentially executes the following steps: S21: At the beginning of the first round of training , the server initializes the global model as ; In addition, at the beginning of each round of training , each client downloads the latest global model from the server
[0028] S22: Each client uses the local training data set for training, adopts the stochastic gradient descent method SGD, and based on the downloaded global model Calculate the local update of this round to obtain the local model ; (2) In formula (2), is the learning rate, represents the loss function calculated on the local dataset , represents the global model; S23: Since the local updates of some clients may be too large, affecting the stability of the global model, gradient clipping is performed on the local model parameters: (3) In formula (3), is the gradient clipping threshold to ensure that the norm of the local update does not exceed the set maximum range, thus ensuring the control of the privacy budget; S24: Calculate the sensitivity : To meet the differential privacy constraint, the global sensitivity needs to be calculated: (4) The global sensitivity represents the maximum impact range of a single client update on the global model and is used for subsequent noise calculation; S25: Calculate the variance of the differential privacy noise: According to the set privacy budget , calculate the variance of the Gaussian noise to be added in this round: (5) Among them, controls the amplitude of the added noise. The larger the privacy budget , the smaller the required noise. To ensure that the local updates of each client meet differential privacy, Gaussian noise needs to be added to the local model parameters; S26: Model update adaptive noise addition decision mechanism: When the model uploaded in this round is almost the same as the previous round, in fact, no new sensitive information is contributed, so there is no need to add noise again, thus avoiding the cumulative interference caused by adding noise in each round in conventional differential privacy and effectively reducing the injection of invalid noise; If the model change amount is less than or equal to the proportional threshold : (6) represents the proportional threshold, represents the model change amount, Denote the local model of the $i$-th client at the $(t - 1)$-th round, Denote the local model of the $i$-th client at the $t$-th round; Then the global model of this round is replaced by the global model of the previous round: (7) If the model change amount is greater than the ratio threshold : (8) Then add noise normally: (9) In formula (9), represents the local model added with differential privacy noise; represents the standard Gaussian distribution; represents the identity matrix.
[0029] S3. The server receives the local model updates from the clients and performs malicious update detection based on segmented clustering analysis, specifically including: S31: The server collects the local model updates of all clients processed by differential privacy ; S32: The server divides the local model update vector of each client into multiple sub-vector segments. According to the dimension, the complete model update is sliced into several sub-vector segments to extract the update values in different dimension intervals. For example, the model update can be evenly divided into three segments by dimension, denoted as: (10) (11) (12) respectively represent the sub-vectors of the local update vector of the client on the three segments; S33: For each sub-vector segment, the server performs clustering analysis on the parameter sets of all clients on this segment. Preferably, the K-Means clustering algorithm is used to divide the local updates with similar parameter distributions into several clusters, and the cluster with the largest number of clients is identified. The cluster with the largest number of clients is defined as the malicious client set, specifically as follows: For each sub-vector segment, first, randomly select data points as the initial clustering centers, denoted as ; Then, for each data point, assign it to the nearest clustering center: (13) where represents the $r$-th data point; Represents a data point to the cluster center The square of the Euclidean distance Represents the number of the cluster center that minimizes the distance , used to assign data points; Finally, update each cluster center Let it be the mean of all data points in the corresponding cluster: (14) Wherein, Represents the cluster center The corresponding cluster; Repeat the above steps until all cluster centers converge or reach the maximum number of iterations; Then, for each sub-vector segment , use the K-means clustering algorithm to identify the cluster with the largest number of clients: (15) In Equation (15), Represents the cluster with the largest number of clients; q represents the label of the sub-vector segment; The model update collection of the q-th sub-vector segment.
[0030] S4. The server assigns weights to each client and aggregates and updates to obtain a global model, specifically including: S41: After clustering, traverse each client Whether it belongs to the cluster with the largest number of clients . If it is found that the client belongs to this cluster, it will be removed from the training, and then the model aggregates and calculates the global model : (14) Wherein, Represents the set of remaining clients, that is, the clients still retained after excluding the largest clustering cluster; J represents the total number of remaining model updates; j represents the label of the remaining model updates; Represents the aggregated global model; Represents the j-th model update in the t-th round; S42: Finally, the algorithm returns the final global model parameters , preferably, the global model is a convolutional neural network model ResNet-18.
[0031] In another aspect of the present invention, there is also provided a federated learning system for detecting and defending poisoning attacks under differential privacy, including clients and servers participating in federated learning. The clients and servers participating in federated learning perform federated learning using the above-mentioned federated learning method.
[0032] S5. Repeat steps S2 - S4 until the set number of training rounds is reached, and output the final global model.
[0033] Figure 2 The overall architecture of the federated learning system is shown. The server is located in the center and is responsible for coordinating the model training and update of each client. Benign clients upload parameters after training the model based on local data. The server aggregates them and then distributes the global model. There may be malicious clients in the system, and the models they upload may contain attack behaviors. Therefore, the server introduces an attack detection mechanism to conduct a security review of the uploaded content, thereby improving the overall robustness and security of federated learning.
[0034] The sample data of the dataset in this embodiment is image data, such as the FEMNIST dataset; preferably, the FEMNIST dataset is used as the processing data to verify the test accuracy of the global model protected by the method of the present invention, the Bulyan defense algorithm, the Median defense algorithm, and the M - Krum defense algorithm under three types of attacks: Lie attack, Fang attack, and MinMax attack. The global model is preferably the convolutional neural network model ResNet - 18, and the test results are as Figures 3 - 5 shown: Figure 3 is the test accuracy graph of the global model protected by the defense algorithm of the present invention, the Bulyan defense algorithm, the Median defense algorithm, and the M - Krum defense algorithm respectively under the Lie attack in the FEMNIST dataset. As the test accuracy gradually stabilizes, it can be clearly seen that the test accuracy of the present invention is higher than that of the Bulyan defense algorithm, the Median defense algorithm, and the M - Krum defense algorithm.
[0035] Figure 4 is the test accuracy graph of the global model protected by the defense algorithm of the present invention, the Bulyan defense algorithm, the Median defense algorithm, and the M - Krum defense algorithm respectively under the Fang attack in the FEMNIST dataset. As the test accuracy gradually stabilizes, it can be clearly seen that the test accuracy of the present invention is higher than that of the Bulyan defense algorithm, the Median defense algorithm, and the M - Krum defense algorithm.
[0036] Figure 5 is the test accuracy graph of the global model protected by the defense algorithm of the present invention, the Bulyan defense algorithm, the Median defense algorithm, and the M - Krum defense algorithm respectively under the MinMax attack in the FEMNIST dataset. As the test accuracy gradually stabilizes, it can be clearly seen that the test accuracy of the present invention is higher than that of the Bulyan defense algorithm, the Median defense algorithm, and the M - Krum defense algorithm.
[0037] In summary, from the experimental results, the defense algorithm of the method described in this embodiment has achieved higher accuracy compared to other defense algorithms.
[0038] Embodiment 2, This embodiment provides a federated learning system for detecting and defending poisoning attacks under differential privacy, including clients and a server participating in federated learning. The clients and the server participating in federated learning perform federated learning using the above-mentioned federated learning method.
[0039] Obviously, the above embodiments of the present invention are merely examples for clearly illustrating the technical solutions of the present invention, rather than limitations on the specific implementation manners of the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the claims of the present invention shall be included within the protection scope of the claims of the present invention.
Claims
1. A federated learning method for detecting and defending poisoning attacks under differential privacy, characterized in that: The method comprises: S1. Define differential privacy on the client side. S2. The client downloads the global model of the server, uses the local training data set to train the local model, calculates the differential privacy noise and combines the adaptive noise addition decision mechanism to implement the client local model update; the sample data of the data set is image data; S3, the server receives the local model update from the client and performs malicious update detection based on segment clustering analysis; S4, the server assigns weights to each client and aggregates and updates to obtain a global model; S5. Each client obtains the trained global model, completes one iteration, and repeats steps S2-S4 until the set training round is reached, and the server outputs the final global model.
2. The federated learning method for detecting and defending against poisoning attacks under differential privacy according to claim 1, characterized in that: The S1 specifically includes: Differential privacy is defined as follows: a random mechanism For the dataset The mapping satisfies -Differential privacy: if for any two adjacent data sets that differ by only one element and , and any output subset O, we have: (1) In formula (1), represents probability; is the privacy budget parameter, which is used to measure the strength of privacy protection; represents the upper bound of the probability allowed when the privacy guarantee may fail; and For adjacent data sets; is the random mechanism imposed on the dataset; express ()Any set of possible output events.
3. The federated learning method for detecting and defending against poisoning attacks under differential privacy according to claim 1, characterized in that: The S2 specifically includes: Training a differentially private federated learning model involves multiple rounds of communication between the client and the server: ,in, ; There are a total of clients, each client Have a local training dataset , which contains data samples, among which, ; The federated learning system performs the following steps in sequence: S21: In the first round of training At the beginning, the server initializes the global model as ; In addition, in each round of training Start each client Download the latest global model from the server S22: Each client Using a local training dataset Training is performed using stochastic gradient descent (SGD) based on the downloaded global model Calculate the local update of this round and get the local model ; (2) In formula (2), is the learning rate, Indicates that the local dataset The loss function calculated above is: Represents the global model; S23: Since the local updates of some clients may be too large, thus affecting the stability of the global model, the local model parameters are gradient clipped: (3) In formula (3), The gradient clipping threshold ensures that the norm of the local update does not exceed the set maximum range, thereby ensuring the control of the privacy budget; S24: Calculation sensitivity : In order to satisfy the differential privacy constraint, the global sensitivity needs to be calculated : (4) Global Sensitivity Indicates the maximum impact range of a single client update on the global model, which is used for subsequent noise calculations; S25: Calculate the differential privacy noise variance: According to the privacy budget set , calculate the variance of the Gaussian noise that needs to be added in this round : (5) in, Controlling the added noise amplitude, privacy budget The larger it is, the smaller the noise required. In order to ensure that each client's local update satisfies differential privacy, Gaussian noise needs to be added to the local model parameters. S26: Model update adaptive noise decision mechanism: When the model uploaded in this round is almost the same as the previous round, it actually does not contribute new sensitive information, so there is no need to add noise again, thus avoiding the cumulative interference caused by each round of noise addition in conventional differential privacy and effectively reducing invalid noise injection; If the model change is less than or equal to the preset proportional threshold : (6) In formula (6), represents the ratio threshold, Represents the model change, represents the local model of the i-th client in round t-1, represents the local model of the i-th client in round t; Then the global model of this round is replaced by the global model of the previous round: (7) If the model change is greater than the proportional threshold : (8) Then add noise normally: (9) In formula (9), represents the local model with differential privacy noise added; represents the standard Gaussian distribution; Represents the identity matrix.
4. The federated learning method for detecting and defending against poisoning attacks under differential privacy according to claim 1, characterized in that: The S3 specifically includes: S31: The server collects local model updates processed with differential privacy noise from all clients ; S32: The server divides each client's local model update into n sub-vector segments: Divide the complete local model update into n sub-vector segments according to the dimension to extract the update values in different dimension intervals: (10) (11) (12) in, Represents the client The subvector of the local update vector on the nth segment; S33: For each sub-vector segment, the server performs cluster analysis on the parameter set of all clients on the segment, uses the K-Means clustering algorithm to divide local updates with similar parameter distribution into several clusters, and identifies the cluster with the largest number of clients. The cluster with the largest number of clients is defined as a malicious client set.
5. The federated learning method for detecting and defending poisoning attacks under differential privacy according to claim 4, characterized in that: The K-Means clustering algorithm is used to divide local updates with similar parameter distribution into several clusters, and the cluster containing the largest number of clients is identified, specifically: For each subvector segment, first, randomly select data points as the initial cluster centers, denoted as ; Then, for each data point we assign it to the nearest cluster center: (13) in represents the rth data point; Represents data points To cluster center The square of the Euclidean distance Indicates the number of the cluster center that minimizes the distance , used to allocate data points; Finally, update each cluster center Let it be the mean of all data points in the corresponding cluster: (14) in, Represents the cluster center The corresponding clusters; Repeat the above steps until all cluster centers converge or the maximum number of iterations is reached; Then, for each subvector segment, the K-means clustering algorithm is used to identify the cluster containing the largest number of clients: (15) In formula (15), represents the cluster with the largest number of clients; q represents the number of the subvector segment; The set of model updates for the qth sub-vector segment.
6. The federated learning method for detecting and defending against poisoning attacks under differential privacy according to claim 1, characterized in that: The S4 specifically includes: S41: After clustering, traverse each client Whether it belongs to the cluster with the largest number of clients If the client is found to belong to the cluster, it is removed from the training, and then the models are aggregated to calculate the global model. : (16) in, represents the set of remaining clients, i.e., the clients that are retained after excluding the largest cluster; J represents the total number of remaining model updates; j represents the number of the remaining model updates; Represents the global model after aggregation; represents the jth model update in the tth round; S42: Finally, the algorithm returns the final global model parameters .
7. A federated learning system for detecting and defending poisoning attacks under differential privacy, characterized in that: The method comprises a client and a server participating in federated learning, wherein the client and the server participating in federated learning perform federated learning using the federated learning method described in any one of claims 1 to 6.
Citation Information
Patent Citations
Self-adaptive privacy protection federal learning method
CN116739079A
Self-adaptive clustering federal learning method with differential privacy
CN117634594A
Federal learning method and device for resisting poisoning attack under differential privacy protection constraint and computer readable storage medium
CN118378255A
Federated learning method against backdoor attack
WO2025039338A1
Cited By
Privacy protection method for heterogeneous federated learning environment
CN120880799A
A privacy protection method for a heterogeneous federated learning environment
CN120880799B
Federal learning security training method and system based on differential privacy
CN121119057A
Safety clustering federated learning method and system based on generalization parameters
CN121257784A